The regulatory stack

Frameworks we work in

Most of our clients are in scope of more than one of these at the same time, and the requirements overlap heavily. We map the overlap once and produce evidence that satisfies several regimes at a time — instead of running the same project three times.

EU regulation International standard Attestation & market demand

DORA

Financial entities & their ICT vendors

Digital operational resilience: ICT risk management, the annual Register of Information, incident reporting and resilience testing.

In force since Jan 2025

NIS2

18 sectors + public administrations

Article 21 risk-management measures, supply-chain security, incident reporting, and management-body accountability.

Enforced — fines & audits

EU AI Act

Anyone building or deploying AI

AI system inventory and risk classification, transparency obligations, governance, and the road to high-risk conformity.

Transparency live; high-risk 2027–28

Cyber Resilience Act

Software & connected-product makers

Secure-by-design evidence, software bill of materials, vulnerability handling and 24-hour reporting to ENISA.

Reporting from 11 Sep 2026

GDPR

Anyone processing EU personal data

Records of processing, DPAs, retention, subject rights, breach procedures — and outsourced DPO where you need one.

Mature enforcement

MiCA

Crypto-asset service providers

Operational and ICT obligations for authorised CASPs, aligned with the DORA requirements that sit alongside them.

CASP rules in force

ISO/IEC 27001

Any organisation proving security

Readiness and implementation support up to certification — with an accredited certification body completing the audit.

The universal baseline

ISO/IEC 42001

Organisations building or using AI

AI management systems — increasingly demanded in enterprise procurement, and roughly half the road to AI Act readiness.

Becoming a procurement gate

SOC 2

SaaS & service providers, esp. US-facing

Readiness for Type I and Type II: control design, evidence discipline and the gap work before an auditor is engaged.

Demanded in due diligence
Comply once, evidence many. An access-control policy, a supplier register or an incident procedure can satisfy DORA, NIS2, ISO 27001 and SOC 2 simultaneously — if it is written and evidenced with all of them in mind. That mapping is the single biggest saving available to a company in scope of several regimes, and it is where we start.
Where accreditation is required, we hand off — openly. ISO 27001 certification audits, SOC 2 attestation reports, statutory audits and legal interpretation are performed by accredited bodies and law firms we have vetted. We prepare you, they certify you, and we say which is which before you engage us.
Discuss your scope