Frameworks & Standards

Fluent in the standards that govern modern enterprise risk.

From control frameworks and zero-trust reference models to a live EU regulatory stack — DORA supervised, NIS2 enforcing, CRA reporting duties applicable, the AI Act phasing in — applied across Banking, Aviation, Defence, Government, and Critical National Infrastructure.

Control & architecture frameworks

FrameworkPurposeWhere it applies
NIST CSF 2.0Risk-based cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond, Recover (Feb 2024)Enterprise-wide programme & board reporting
ISO/IEC 27001:2022Information security management system (ISMS) certification standardCertification, audit, supplier assurance
NIST SP 800-207Zero Trust Architecture — identity-first, resource-centric securityArchitecture & access design
CIS ControlsPrioritised, prescriptive technical safeguardsHardening & baseline assurance
SABSABusiness-driven security architecture methodSecurity architecture & design authority
TOGAFEnterprise architecture framework and methodOperating-model & enterprise design

NIST CSF 2.0 added the Govern function and broadened scope to all organisations, not just critical infrastructure.

Regulatory & operational resilience

RegulationScopeStatus
DORADigital Operational Resilience Act — ICT risk, incident reporting, third-party oversight, resilience testing for EU financial entitiesApplying since Jan 2025 · supervised
NIS2 DirectiveRaised cybersecurity baseline & incident handling for essential/important entities and critical infrastructureTransposed & enforcing
Cyber Resilience Act (CRA)Security-by-design, vulnerability handling and lifecycle duties for products with digital elements — hardware, software and their supply chainsReporting duties live since 11 Sep 2026 · full application 11 Dec 2027
IEC 62443Security for industrial automation & control systems — OT/ICS zones, conduits and secure development lifecycleCertifiable · OT baseline
GDPRPersonal data protection & breach notificationIn force
ISO 27001:2022Shared risk-management foundation that DORA, NIS2 & the CRA build onCertifiable

DORA builds on — not replaces — ISO 27001, NIS2, and GDPR; the disciplines converge for ICT risk and incident handling. The CRA now pulls product and supply-chain security into the same reporting discipline.

AI governance & emerging tech

StandardPurposeRelevance
EU AI ActRisk-tiered regulation of AI systems across the EU — prohibited practices and GPAI duties already apply; transparency obligations live since August 2026; high-risk obligations deferred to 2 Dec 2027 and 2 Aug 2028AI adoption strategy & controls
ISO/IEC 42001AI management system (AIMS) — governance for responsible AI and for autonomous agents acting on the enterprise's behalfCertifiable AI governance
NIST AI RMFVoluntary framework to manage AI risk across map, measure, manage and governAI risk identification & mitigation
Agentic AI governanceIdentity, permissions and audit trails for autonomous agents — discovering shadow agents and containing permission sprawl across growing agent fleetsThe fastest-moving control gap in the enterprise
Post-Quantum ReadinessCryptographic discovery and inventory, crypto-agility and migration off RSA-2048 and ECC P-256, which NIST deprecates in 2030 — with FIPS 140-2 certificates now moved to the Historical listLive migration programme, not a horizon item

CISOs increasingly manage the "regulatory collision" where NIS2, DORA, the CRA and the EU AI Act intersect on AI systems and connected products.

Applied outcomes

Standards in service of the business.

Frameworks are a means, not an end. Kai uses them to reduce risk, earn regulator trust, and unlock value.

🧭

Harmonised compliance

Consolidating overlapping obligations (DORA · NIS2 · CRA · ISO 27001) into a single, defensible control set that survives live supervision.

🛡️

Zero-trust resilience

Identity-first architectures aligned to NIST SP 800-207 that limit blast radius — extended to autonomous agents and to OT/ICS zones under IEC 62443.

🤖

Governed agentic AI

Control over AI agents as well as AI models: agent inventory, scoped permissions and audit trails — mapped to the EU AI Act, ISO 42001 and the NIST AI RMF.

🔐

Post-quantum migration

Cryptographic discovery, agility and a sequenced migration plan ahead of NIST's 2030 deprecation of RSA-2048 and ECC P-256.

Put the frameworks to work.

Translate standards into a defensible, board-ready control posture.