Frameworks we work in
Most of our clients are in scope of more than one of these at the same time, and the requirements overlap heavily. We map the overlap once and produce evidence that satisfies several regimes at a time — instead of running the same project three times.
DORA
Digital operational resilience: ICT risk management, the annual Register of Information, incident reporting and resilience testing.
In force since Jan 2025NIS2
Article 21 risk-management measures, supply-chain security, incident reporting, and management-body accountability.
Enforced — fines & auditsEU AI Act
AI system inventory and risk classification, transparency obligations, governance, and the road to high-risk conformity.
Transparency live; high-risk 2027–28Cyber Resilience Act
Secure-by-design evidence, software bill of materials, vulnerability handling and 24-hour reporting to ENISA.
Reporting from 11 Sep 2026GDPR
Records of processing, DPAs, retention, subject rights, breach procedures — and outsourced DPO where you need one.
Mature enforcementMiCA
Operational and ICT obligations for authorised CASPs, aligned with the DORA requirements that sit alongside them.
CASP rules in forceISO/IEC 27001
Readiness and implementation support up to certification — with an accredited certification body completing the audit.
The universal baselineISO/IEC 42001
AI management systems — increasingly demanded in enterprise procurement, and roughly half the road to AI Act readiness.
Becoming a procurement gateSOC 2
Readiness for Type I and Type II: control design, evidence discipline and the gap work before an auditor is engaged.
Demanded in due diligence