Frameworks & Standards

Fluent in the standards that govern modern enterprise risk.

From control frameworks and zero-trust reference models to an EU regulatory landscape that is now live rather than looming — DORA supervised, NIS2 enforced, AI Act transparency duties in effect, CRA reporting obligations applicable — applied across Banking, Aviation, Defence, Government, and Critical National Infrastructure.

Control & architecture frameworks

FrameworkPurposeWhere it applies
NIST CSF 2.0Risk-based cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond, Recover (Feb 2024)Enterprise-wide programme & board reporting
ISO/IEC 27001:2022Information security management system (ISMS) certification standardCertification, audit, supplier assurance
NIST SP 800-207Zero Trust Architecture — identity-first, resource-centric securityArchitecture & access design
CIS ControlsPrioritised, prescriptive technical safeguardsHardening & baseline assurance
SABSABusiness-driven security architecture methodSecurity architecture & design authority
TOGAFEnterprise architecture framework and methodOperating-model & enterprise design

NIST CSF 2.0 added the Govern function and broadened scope to all organisations, not just critical infrastructure.

Regulatory & operational resilience

RegulationScopeStatus
DORADigital Operational Resilience Act — ICT risk, incident reporting, third-party oversight, resilience testing for EU financial entitiesApplying since Jan 2025 · live & supervised
NIS2 DirectiveRaised cybersecurity baseline & incident handling for essential/important entities and critical infrastructureNational laws in force · enforcement stepping up
Cyber Resilience Act (CRA)Security requirements for products with digital elements — vulnerability handling, actively exploited-vulnerability and incident reporting, lifecycle support dutiesIn force Dec 2024 · reporting applicable since 11 Sep 2026 · full application 11 Dec 2027
IEC 62443Security for industrial automation and control systems — zones, conduits, and security levels for OT estatesApplied standard
GDPRPersonal data protection & breach notificationIn force
ISO 27001:2022Shared risk-management foundation that DORA & NIS2 build onCertifiable

DORA builds on — not replaces — ISO 27001, NIS2, and GDPR; the disciplines converge for ICT risk and incident handling. With CRA reporting duties live since September 2026, product security now sits inside the same incident-reporting machinery.

AI governance & emerging tech

StandardPurposeRelevance
EU AI ActRisk-tiered regulation of AI systems across the EU. In force since Aug 2024; prohibited practices applied Feb 2025, GPAI rules Aug 2025, transparency duties live since August 2026. High-risk obligations deferred by the Digital Omnibus to Dec 2027 and Aug 2028AI adoption strategy & controls — transparency obligations are current, high-risk classification is the planning horizon
ISO/IEC 42001AI management system (AIMS) — governance for responsible AICertifiable AI governance
NIST AI RMFVoluntary framework to manage AI risk across govern, map, measure and manageAI risk identification & mitigation — the practical spine for agent governance
Agentic AI governanceControl of autonomous agents — inventory, identity, scoped permissions, and audit trails for actions taken without a human in the loopThe fastest-growing attack surface: shadow agents, over-permissioned service identities, no evidential record
Post-Quantum ReadinessMigration toward quantum-resistant cryptography. NIST PQC standards finalised Aug 2024; FIPS 140-2 validated certificates moved to the Historical list in September 2026; NIST deprecates RSA-2048 and ECC P-256 in 2030Crypto discovery, inventory and agility — a multi-year programme with a fixed end date

CISOs are now managing the "regulatory collision" where NIS2, DORA, the CRA and the EU AI Act intersect on AI systems — all of them live, all of them supervised.

Applied outcomes

Standards in service of the business.

Frameworks are a means, not an end. Kai uses them to reduce risk, earn regulator trust, and unlock value.

🧭

Harmonised compliance

Consolidating overlapping obligations (DORA · NIS2 · CRA · ISO 27001) into a single, defensible control set that answers one supervisor as readily as four.

🛡️

Zero-trust resilience

Identity-first architectures aligned to NIST SP 800-207 that limit blast radius and lateral movement — human, machine and agent identities alike, with IEC 62443 zoning where IT meets OT.

🤖

Governed autonomy

Agent inventory, scoped permissions and audit trails so the enterprise can deploy autonomous AI with control — mapped to the EU AI Act, ISO 42001 and the NIST AI RMF.

Put the frameworks to work.

Translate standards into a defensible, board-ready control posture.