Compliance & frameworks.
We build and operate security programs mapped to the standards your auditors and customers expect. These are the frameworks we assess and build client programs against.
We help you build, run and evidence programs against these frameworks. We are not a certification body or audit firm; your auditor or assessor issues the report or certificate.
Frameworks we work against
IEC 62443
OT / ICS security for industrial environments: zones, conduits and security-level assessments.
IEC 62443 gap assessment →EU Cyber Resilience Act
Readiness for products with digital elements sold into the EU: obligations, timelines and evidence.
EU CRA briefing →FDA Premarket Cybersecurity
Section 524B readiness for medical device makers: SBOMs, threat modeling and postmarket plans.
Medical Devices →SOC 2 Type II
Readiness and evidence programs for SaaS and service companies: controls, monitoring and audit support.
Software & SaaS Security →NIST CSF 2.0
Program structure and maturity measurement across govern, identify, protect, detect, respond and recover.
NIST CSF 2.0 checklist →MITRE ATT&CK
Detection engineering and threat intelligence mapped to real adversary behavior.
Threat Intel Command Center →CIS Controls
Prioritized safeguards for pragmatic, measurable hardening.
Governance, Risk & Compliance →ISO/SAE 21434 and UNECE R155/R156
Bench and in-vehicle security testing, with CSMS and software-update evidence mapped to ISO/SAE 21434 and UNECE R155/R156.
Automotive →GDPR Articles 30 and 32
Records of processing and technical measures for personal data that reaches AI tools through the browser.
GDPR Browser Compliance →