Regulatory Coverage Overview

Consolidated view of European framework coverage and control implementation

European Framework Coverage

GDPR
Coverage92%
High coverage
NIS2
Coverage78%
Partial coverage
DORA
Coverage85%
High coverage
ISO 27001
Coverage88%
High coverage
CRA
Coverage65%
Partial coverage

Control Implementation Status

Control referenceControl descriptionFrameworkStatus
GDPR-32

Security of processing

Implement appropriate technical and organizational measures to ensure security of processing

GDPRCovered
GDPR-25

Data protection by design

Implement data protection principles and safeguards into processing activities

GDPRCovered
GDPR-33

Breach notification

Notify supervisory authority of personal data breaches within 72 hours

GDPRCovered
GDPR-35

Data protection impact assessment

Conduct DPIA for processing operations likely to result in high risk

GDPRPartial coverage
GDPR-30

Records of processing activities

Maintain records of all processing activities under controller responsibility

GDPRCovered
GDPR-44

Cross-border data transfers

Ensure appropriate safeguards for transfers of personal data to third countries

GDPRPartial coverage
NIS2-7.1

Risk management measures

Implement policies on risk analysis and information system security

NIS2Partial coverage
NIS2-8.3

Incident handling

Establish procedures to handle and respond to cybersecurity incidents

NIS2Partial coverage
NIS2-21.1

Supply chain security

Address security in supplier relationships and supply chain

NIS2Covered
NIS2-21.3

Business continuity

Implement business continuity and disaster recovery capabilities

NIS2Covered
NIS2-21.5

Security awareness training

Provide cybersecurity training and awareness programs for personnel

NIS2Partial coverage
DORA-9

ICT risk management

Establish comprehensive ICT risk management framework covering identification and protection

DORACovered
DORA-11

Incident reporting

Implement classification and reporting mechanisms for major ICT-related incidents

DORACovered
DORA-24

Third-party risk management

Manage ICT third-party risk through due diligence and ongoing monitoring

DORAPartial coverage
DORA-25

Testing and resilience

Conduct regular testing of ICT systems, controls, and recovery capabilities

DORACovered
DORA-28

ICT service monitoring

Monitor performance and availability of critical ICT services

DORACovered
ISO-A.8.2

Information classification

Classify information in terms of legal requirements, value, and criticality

ISO 27001Covered
ISO-A.12.1

Operational procedures

Document and maintain operating procedures for information processing facilities

ISO 27001Covered
ISO-A.18.1

Compliance with legal requirements

Identify and comply with applicable legislation and contractual requirements

ISO 27001Covered
ISO-A.9.2

User access provisioning

Implement formal user access provisioning process for all system types

ISO 27001Covered
ISO-A.12.6

Technical vulnerability management

Obtain timely information about technical vulnerabilities and take action

ISO 27001Partial coverage
ISO-A.17.1

Business continuity planning

Plan, implement, and maintain information security continuity

ISO 27001Covered
ISO-A.8.10

Information deletion

Delete information stored in systems, devices or media when no longer required

ISO 27002Covered
ISO-A.8.24

Data loss prevention

Apply data loss prevention measures to detect and prevent unauthorized disclosure

ISO 27002Partial coverage
ISO-A.5.23

Information security in cloud services

Establish processes for acquisition, use, management and exit from cloud services

ISO 27002Covered
ISO-A.8.9

Configuration management

Establish and document configuration management for networks, systems and applications

ISO 27002Covered
CRA-10

Security by design

Design and develop products with cybersecurity as integral component

CRAPartial coverage
CRA-15

Vulnerability handling

Establish process to address and remediate vulnerabilities throughout product lifecycle

CRACoverage gap identified
CRA-11.1

Secure development

Apply secure coding practices and vulnerability testing during development

CRAPartial coverage
CRA-11.2

Security documentation

Provide security documentation including instructions for secure use and configuration

CRACovered
CRA-20

Security update management

Implement mechanisms for secure delivery and installation of security updates

CRAPartial coverage

Demo environment — simulated data shown for regulatory mapping illustration.