Frameworks & Standards
Fluent in the standards that govern modern enterprise risk.
From control frameworks and zero-trust reference models to a live EU regulatory stack — DORA supervised, NIS2 enforcing, CRA reporting duties applicable, the AI Act phasing in — applied across Banking, Aviation, Defence, Government, and Critical National Infrastructure.
Control & architecture frameworks
| Framework | Purpose | Where it applies |
|---|---|---|
| NIST CSF 2.0 | Risk-based cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond, Recover (Feb 2024) | Enterprise-wide programme & board reporting |
| ISO/IEC 27001:2022 | Information security management system (ISMS) certification standard | Certification, audit, supplier assurance |
| NIST SP 800-207 | Zero Trust Architecture — identity-first, resource-centric security | Architecture & access design |
| CIS Controls | Prioritised, prescriptive technical safeguards | Hardening & baseline assurance |
| SABSA | Business-driven security architecture method | Security architecture & design authority |
| TOGAF | Enterprise architecture framework and method | Operating-model & enterprise design |
NIST CSF 2.0 added the Govern function and broadened scope to all organisations, not just critical infrastructure.
Regulatory & operational resilience
| Regulation | Scope | Status |
|---|---|---|
| DORA | Digital Operational Resilience Act — ICT risk, incident reporting, third-party oversight, resilience testing for EU financial entities | Applying since Jan 2025 · supervised |
| NIS2 Directive | Raised cybersecurity baseline & incident handling for essential/important entities and critical infrastructure | Transposed & enforcing |
| Cyber Resilience Act (CRA) | Security-by-design, vulnerability handling and lifecycle duties for products with digital elements — hardware, software and their supply chains | Reporting duties live since 11 Sep 2026 · full application 11 Dec 2027 |
| IEC 62443 | Security for industrial automation & control systems — OT/ICS zones, conduits and secure development lifecycle | Certifiable · OT baseline |
| GDPR | Personal data protection & breach notification | In force |
| ISO 27001:2022 | Shared risk-management foundation that DORA, NIS2 & the CRA build on | Certifiable |
DORA builds on — not replaces — ISO 27001, NIS2, and GDPR; the disciplines converge for ICT risk and incident handling. The CRA now pulls product and supply-chain security into the same reporting discipline.
AI governance & emerging tech
| Standard | Purpose | Relevance |
|---|---|---|
| EU AI Act | Risk-tiered regulation of AI systems across the EU — prohibited practices and GPAI duties already apply; transparency obligations live since August 2026; high-risk obligations deferred to 2 Dec 2027 and 2 Aug 2028 | AI adoption strategy & controls |
| ISO/IEC 42001 | AI management system (AIMS) — governance for responsible AI and for autonomous agents acting on the enterprise's behalf | Certifiable AI governance |
| NIST AI RMF | Voluntary framework to manage AI risk across map, measure, manage and govern | AI risk identification & mitigation |
| Agentic AI governance | Identity, permissions and audit trails for autonomous agents — discovering shadow agents and containing permission sprawl across growing agent fleets | The fastest-moving control gap in the enterprise |
| Post-Quantum Readiness | Cryptographic discovery and inventory, crypto-agility and migration off RSA-2048 and ECC P-256, which NIST deprecates in 2030 — with FIPS 140-2 certificates now moved to the Historical list | Live migration programme, not a horizon item |
CISOs increasingly manage the "regulatory collision" where NIS2, DORA, the CRA and the EU AI Act intersect on AI systems and connected products.
Applied outcomes
Standards in service of the business.
Frameworks are a means, not an end. Kai uses them to reduce risk, earn regulator trust, and unlock value.
Harmonised compliance
Consolidating overlapping obligations (DORA · NIS2 · CRA · ISO 27001) into a single, defensible control set that survives live supervision.
Zero-trust resilience
Identity-first architectures aligned to NIST SP 800-207 that limit blast radius — extended to autonomous agents and to OT/ICS zones under IEC 62443.
Governed agentic AI
Control over AI agents as well as AI models: agent inventory, scoped permissions and audit trails — mapped to the EU AI Act, ISO 42001 and the NIST AI RMF.
Post-quantum migration
Cryptographic discovery, agility and a sequenced migration plan ahead of NIST's 2030 deprecation of RSA-2048 and ECC P-256.
Put the frameworks to work.
Translate standards into a defensible, board-ready control posture.