Frameworks & Standards
Fluent in the standards that govern modern enterprise risk.
From control frameworks and zero-trust reference models to an EU regulatory landscape that is now live rather than looming — DORA supervised, NIS2 enforced, AI Act transparency duties in effect, CRA reporting obligations applicable — applied across Banking, Aviation, Defence, Government, and Critical National Infrastructure.
Control & architecture frameworks
| Framework | Purpose | Where it applies |
|---|---|---|
| NIST CSF 2.0 | Risk-based cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond, Recover (Feb 2024) | Enterprise-wide programme & board reporting |
| ISO/IEC 27001:2022 | Information security management system (ISMS) certification standard | Certification, audit, supplier assurance |
| NIST SP 800-207 | Zero Trust Architecture — identity-first, resource-centric security | Architecture & access design |
| CIS Controls | Prioritised, prescriptive technical safeguards | Hardening & baseline assurance |
| SABSA | Business-driven security architecture method | Security architecture & design authority |
| TOGAF | Enterprise architecture framework and method | Operating-model & enterprise design |
NIST CSF 2.0 added the Govern function and broadened scope to all organisations, not just critical infrastructure.
Regulatory & operational resilience
| Regulation | Scope | Status |
|---|---|---|
| DORA | Digital Operational Resilience Act — ICT risk, incident reporting, third-party oversight, resilience testing for EU financial entities | Applying since Jan 2025 · live & supervised |
| NIS2 Directive | Raised cybersecurity baseline & incident handling for essential/important entities and critical infrastructure | National laws in force · enforcement stepping up |
| Cyber Resilience Act (CRA) | Security requirements for products with digital elements — vulnerability handling, actively exploited-vulnerability and incident reporting, lifecycle support duties | In force Dec 2024 · reporting applicable since 11 Sep 2026 · full application 11 Dec 2027 |
| IEC 62443 | Security for industrial automation and control systems — zones, conduits, and security levels for OT estates | Applied standard |
| GDPR | Personal data protection & breach notification | In force |
| ISO 27001:2022 | Shared risk-management foundation that DORA & NIS2 build on | Certifiable |
DORA builds on — not replaces — ISO 27001, NIS2, and GDPR; the disciplines converge for ICT risk and incident handling. With CRA reporting duties live since September 2026, product security now sits inside the same incident-reporting machinery.
AI governance & emerging tech
| Standard | Purpose | Relevance |
|---|---|---|
| EU AI Act | Risk-tiered regulation of AI systems across the EU. In force since Aug 2024; prohibited practices applied Feb 2025, GPAI rules Aug 2025, transparency duties live since August 2026. High-risk obligations deferred by the Digital Omnibus to Dec 2027 and Aug 2028 | AI adoption strategy & controls — transparency obligations are current, high-risk classification is the planning horizon |
| ISO/IEC 42001 | AI management system (AIMS) — governance for responsible AI | Certifiable AI governance |
| NIST AI RMF | Voluntary framework to manage AI risk across govern, map, measure and manage | AI risk identification & mitigation — the practical spine for agent governance |
| Agentic AI governance | Control of autonomous agents — inventory, identity, scoped permissions, and audit trails for actions taken without a human in the loop | The fastest-growing attack surface: shadow agents, over-permissioned service identities, no evidential record |
| Post-Quantum Readiness | Migration toward quantum-resistant cryptography. NIST PQC standards finalised Aug 2024; FIPS 140-2 validated certificates moved to the Historical list in September 2026; NIST deprecates RSA-2048 and ECC P-256 in 2030 | Crypto discovery, inventory and agility — a multi-year programme with a fixed end date |
CISOs are now managing the "regulatory collision" where NIS2, DORA, the CRA and the EU AI Act intersect on AI systems — all of them live, all of them supervised.
Applied outcomes
Standards in service of the business.
Frameworks are a means, not an end. Kai uses them to reduce risk, earn regulator trust, and unlock value.
Harmonised compliance
Consolidating overlapping obligations (DORA · NIS2 · CRA · ISO 27001) into a single, defensible control set that answers one supervisor as readily as four.
Zero-trust resilience
Identity-first architectures aligned to NIST SP 800-207 that limit blast radius and lateral movement — human, machine and agent identities alike, with IEC 62443 zoning where IT meets OT.
Governed autonomy
Agent inventory, scoped permissions and audit trails so the enterprise can deploy autonomous AI with control — mapped to the EU AI Act, ISO 42001 and the NIST AI RMF.
Put the frameworks to work.
Translate standards into a defensible, board-ready control posture.