Frameworks & Standards
Fluent in the standards that govern modern enterprise risk.
From control frameworks and zero-trust reference models to an EU regulatory landscape that is now live and being supervised — DORA, NIS2, the AI Act and the CRA — applied across Banking, Aviation, Defence, Government, and Critical National Infrastructure.
Control & architecture frameworks
| Framework | Purpose | Where it applies |
|---|---|---|
| NIST CSF 2.0 | Risk-based cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond, Recover (Feb 2024) | Enterprise-wide programme & board reporting |
| ISO/IEC 27001:2022 | Information security management system (ISMS) certification standard | Certification, audit, supplier assurance |
| NIST SP 800-207 | Zero Trust Architecture — identity-first, resource-centric security | Architecture & access design |
| CIS Controls | Prioritised, prescriptive technical safeguards | Hardening & baseline assurance |
| SABSA | Business-driven security architecture method | Security architecture & design authority |
| TOGAF | Enterprise architecture framework and method | Operating-model & enterprise design |
NIST CSF 2.0 added the Govern function and broadened scope to all organisations, not just critical infrastructure.
Regulatory & operational resilience
| Regulation | Scope | Status |
|---|---|---|
| DORA | Digital Operational Resilience Act — ICT risk, incident reporting, third-party oversight, resilience testing for EU financial entities | Applying since Jan 2025 · live & supervised |
| NIS2 Directive | Raised cybersecurity baseline & incident handling for essential/important entities and critical infrastructure | Transposed · enforcement stepping up |
| Cyber Resilience Act (CRA) | Secure-by-design, vulnerability handling and incident reporting for products with digital elements placed on the EU market | In force Dec 2024 · reporting duties since 11 Sep 2026 · full application 11 Dec 2027 |
| IEC 62443 | Security for industrial automation and control systems — zones, conduits and security levels across OT/ICS estates | Certifiable · CNI baseline |
| GDPR | Personal data protection & breach notification | In force |
| ISO/IEC 27001:2022 | Shared risk-management foundation that DORA, NIS2 & the CRA build on | Certifiable |
DORA builds on — not replaces — ISO/IEC 27001:2022, NIS2, and GDPR; with the CRA now adding product-side reporting, the disciplines converge on ICT risk and incident handling.
AI governance & emerging tech
| Standard | Purpose | Relevance |
|---|---|---|
| EU AI Act | Risk-tiered regulation of AI systems across the EU — in force since Aug 2024; prohibited practices applied Feb 2025, GPAI rules Aug 2025, transparency duties live since August 2026; high-risk obligations deferred to 2 Dec 2027 and 2 Aug 2028 | AI adoption strategy & controls |
| ISO/IEC 42001 | AI management system (AIMS) — governance for responsible AI | Certifiable AI governance |
| NIST AI RMF | Voluntary framework to manage AI risk across the AI lifecycle | AI risk identification & mitigation, including autonomous agents |
| Agentic AI governance | Identity, permissioning and audit trails for autonomous AI agents — countering shadow agents and permission sprawl as agent fleets grow | The emerging enterprise attack surface |
| Post-Quantum Migration | NIST PQC standards finalised Aug 2024; cryptographic discovery, inventory and agility, with RSA-2048 and ECC P-256 deprecated from 2030 and all remaining FIPS 140-2 certificates now on NIST's Historical list | Migration planning under way now |
CISOs are now managing the "regulatory collision" where NIS2, DORA, the CRA and the EU AI Act intersect on AI systems — all of them live, not pending.
Applied outcomes
Standards in service of the business.
Frameworks are a means, not an end. Kai uses them to reduce risk, earn regulator trust, and unlock value.
Harmonised compliance
Consolidating overlapping live obligations (DORA · NIS2 · CRA · ISO/IEC 27001:2022) into a single, defensible control set.
Zero-trust & OT resilience
Identity-first architectures aligned to NIST SP 800-207, extended into OT and ICS under IEC 62443 to limit blast radius and lateral movement.
Governed AI agents
Governance that lets the enterprise run autonomous agents with control — identity, least privilege and audit trails, mapped to the EU AI Act, ISO 42001 and the NIST AI RMF.
Put the frameworks to work.
Translate standards into a defensible, board-ready control posture.