What each framework actually requires
Cyber and information-security governance for organisations in Ireland, the UK and the EU.
One assessment produces citations across all of these at once. Each page explains what the instrument is, who it binds, the dates that matter, and exactly what we do and do not do with it.
Covered on every assessment
NIS2 — Directive (EU) 2022/2555
Ireland and the EU
The EU's network and information security directive. It sets baseline cybersecurity risk-management measures and a strict incident-reporting clock for organisations that member states designate as essential or important entities.
ISO/IEC 27001:2022
Voluntary, any jurisdiction
The international standard for information security management systems. It is voluntary and certifiable: an accredited body audits your ISMS and issues a certificate with a three-year cycle.
DORA — Regulation (EU) 2022/2554
EU financial entities
The EU's Digital Operational Resilience Act. It is a regulation, not a directive, so it applies directly without national transposition — one rulebook for ICT risk across the EU financial sector.
NIST CSF 2.0
Voluntary, any jurisdiction
The US National Institute of Standards and Technology's Cybersecurity Framework. Version 2.0 is a voluntary, outcome-based framework organised as six functions, widely used outside the US as a common structure for describing a security programme.
NCSC Cyber Assessment Framework v4.0
United Kingdom
The UK National Cyber Security Centre's Cyber Assessment Framework. It is an outcome-based framework — it describes what good looks like rather than prescribing controls — and is the assessment method behind the UK's NIS Regulations.
GDPR — Regulation (EU) 2016/679
Ireland, the EU and the UK
The EU's General Data Protection Regulation. It governs the processing of personal data — what you may do with it, on what basis, and what rights the people it describes have.
Cyber Essentials v3.3 (NCSC UK)
IndicativeUK
The UK's baseline cyber security certification scheme, run by the NCSC and delivered through IASME. It defines five technical control themes and a scope boundary, and certifies against them: Cyber Essentials is a self-assessment verified by a Certification Body, and Cyber Essentials Plus adds a hands-on technical audit of the same controls.
CyFun 2025 Basic, Important and Essential (CCB CyberFundamentals)
IndicativeIreland and the EU
The CyberFundamentals Framework, published by the Centre for Cybersecurity Belgium. Ireland's National Cyber Security Centre has adopted it as a national NIS2 assessment and certification scheme. The 2025 edition is defined as a selection of NIST CSF 2.0 subcategories.
Cyber Resilience Act — Regulation (EU) 2024/2847
EU manufacturers of products with digital elements
The EU's Cyber Resilience Act. It sets cybersecurity requirements for products with digital elements placed on the EU market, and obliges manufacturers to report actively exploited vulnerabilities and severe incidents.
Named, not built
EU AI Act — Regulation (EU) 2024/1689
Named so it is visible as absent. Nothing in the product maps to it, and no figure from it appears anywhere.
Digital Services Act
Named so it is visible as absent.
Not covered, and worth knowing
The frameworks above are not everything that regulates cyber in the EU and UK. These are real regimes we do not assess against. None of them is a roadmap promise — adding one would need its primary text, a verified reference dataset and a citation on every control, the same as the rest.
Cyber Essentials Plus (the audited tier)
United Kingdom
We show indicative coverage against the five Cyber Essentials technical control themes, and list the requirements our questionnaire does not reach. Cyber Essentials Plus is different in kind: an assessor tests the controls hands-on, including vulnerability scans and a malware test on a sample of your devices. Nothing here simulates or prepares that audit, and certification at either tier is awarded by a Certification Body appointed through IASME.
NIS Regulations 2018 — designation and enforcement (SI 2018/506)
United Kingdom
We assess against the NCSC CAF, which is the framework used to measure compliance with the security duties in regulation 10, and the incident register runs the regulation 11 and 12 notification clock with the Regulations cited. What we do not do is determine whether you are an operator of essential services or a relevant digital service provider at all — that turns on sector thresholds set by the Regulations and applied by your designated competent authority — and nothing here touches the enforcement regime, information notices, inspections or penalties.
Cyber Security and Resilience Bill
United Kingdom
Before Parliament. It would replace the NIS Regulations 2018 and bring managed service providers into scope as regulated entities. Not law yet, so not assessed.
CER Directive (EU) 2022/2557 — the Chapter III resilience obligations
European Union
Critical Entities Resilience is the physical resilience counterpart to NIS2, covering many of the same entities. The incident register models its Article 15 notification clock — 24 hours, then a detailed report where relevant — for organisations that tell us a Member State identified them as a critical entity under Article 6. Everything else in Chapter III is outside this product: the Article 12 critical entity risk assessment, the Article 13 resilience measures and resilience plan, the liaison officer, and the Article 14 background-check procedure. Designation itself is done by your national authority and cannot be self-assessed here.
PSTI Act 2022 and RED Delegated Regulation 2022/30
UK and EU
Product security for consumer connectable products and radio equipment, aimed at the same manufacturers as the CRA and assessed nowhere here. Worth knowing how they differ from the reporting regimes we do model: the PSTI Act gives manufacturers duties to investigate a suspected compliance failure, to remedy it and notify the enforcement authority "as soon as possible", and to keep records of both for ten years — but it sets no hours or days, so there is no clock to run. The RED Delegated Regulation is a conformity regime with no notification duty at all.
eIDAS and the EU Cybersecurity Act
European Union
Trust services, and the European cybersecurity certification framework ENISA administers. Note that NIS2 Art. 23(4) gives trust service providers a 24-hour notification window rather than 72 — our incident register shows the general window and says so.
PCI DSS
Contractual, any jurisdiction
Not regulation, but mandatory by contract for anyone handling card data. A separate assessment regime with its own qualified assessors.