Compliance
One set of controls. Several regimes over it.
You do not keep four parallel folders for four auditors. The ISO 27001 controls are the base, and NIS2, CRA and SOC 2 lay over them, with their own requirements only where they genuinely differ.
ISO 27001
Annex A and clauses 4 to 10
The base everything else sits on. All 93 Annex A controls plus the 27 management system requirements, each with a document, an approval and an audit log entry.
- Ingest the documentation you already have, from an archive or from your document library
- Analysis that separates a control with no policy from one with a policy and no sign it is practised
- Policies drafted for the missing controls, approved by a human before they go live
- In platform editor, with version history and document export
NIS2
Article 21, points a to j
Mapped onto the ISO controls you already run rather than a separate document set. Plus the part ISO does not cover: the incident register and the statutory notification deadlines.
- Per article view, showing the real state of each point
- Incident register carrying the 24 and 72 hour deadlines, with overdue flagged
- Final report, with the status flow through to closure
CRA
Regulation (EU) 2024/2847
Reporting obligations have been live since 11 September 2026. The module opens with scope determination, because most companies owe nothing and that has to be said before any clock starts.
- Manufacturer role determination, recorded and dated including for the negative case
- All four deadlines, from early warning to final report
- SBOM ingestion, with vulnerabilities linked to the product they affect
- Annex I laid over your active ISO controls
ISO 9001
Quality management system
The same document, approval and evidence flow as ISO 27001, for organisations running both systems.
- Its own question set for the guided interview
- The same approval rules and the same audit log
SOC 2
Trust Services Criteria
Criteria labelling where it matters: the alert filter, the scan checks, and the evidence attached to a report.
- Scan checks carry the criterion they support
- Evidence attaches to the audit report as structured snapshots
GDPR
Including Romanian Law 190/2018
The evidence workflow accepts any documentation under any framework label, and generated policies are written in the right national legal context.
- Legal requirements register, linked to the controls that cover them
- Policies drafted with the national references, not only the regulation articles
CRAAutomated checks
Scans scoped to the controls an auditor actually asks about.
This is not a generic penetration test. It is a set of checks that map directly onto controls, run monthly and on demand. Each failure becomes a finding carrying its framework label, and critical findings open a case on their own.
| Automated checks | Compliance |
|---|
| HTTP redirects to HTTPS | ISO 27001 A.10.1, NIS2 Art. 21(2)(d) |
| TLS certificate validity and expiry | ISO 27001 A.10.1, SOC 2 CC6.1 |
| Weak protocols accepted, TLS 1.0 and 1.1 | ISO 27001 A.10.1, NIS2 Art. 21(2)(d) |
| HSTS header present | ISO 27001 A.14.1, NIS2 Art. 21(2)(e) |
| Content Security Policy | ISO 27001 A.14.2, SOC 2 CC6.1 |
| Framing protection | ISO 27001 A.14.1, SOC 2 CC6.1 |
| Server version not disclosed | ISO 27001 A.12.6 |
| CORS not wildcarded | ISO 27001 A.14.1, NIS2 Art. 21(2)(e) |
| Sensitive paths not exposed | ISO 27001 A.9.4 |
| Cookie security attributes | ISO 27001 A.14.1 |
| SPF record present and not permissive | ISO 27001 A.13.2, NIS2 Art. 21(2)(h) |
| DMARC at quarantine or reject | ISO 27001 A.13.2, NIS2 Art. 21(2)(h) |
An audit report is built from what happened, not from what was written about what happened.
A report can carry a policy document, a written summary, an uploaded file, or a snapshot of a real case as structured proof that incidents are genuinely being detected and managed. The report moves through review and approval, and the client receives the published version read only, with every piece of evidence attached and a document export.
Request a quote