Frameworks & Standards

Fluent in the standards that govern modern enterprise risk.

From control frameworks and zero-trust reference models to an EU regulatory landscape that is now live and being supervised — DORA, NIS2, the AI Act and the CRA — applied across Banking, Aviation, Defence, Government, and Critical National Infrastructure.

Control & architecture frameworks

FrameworkPurposeWhere it applies
NIST CSF 2.0Risk-based cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond, Recover (Feb 2024)Enterprise-wide programme & board reporting
ISO/IEC 27001:2022Information security management system (ISMS) certification standardCertification, audit, supplier assurance
NIST SP 800-207Zero Trust Architecture — identity-first, resource-centric securityArchitecture & access design
CIS ControlsPrioritised, prescriptive technical safeguardsHardening & baseline assurance
SABSABusiness-driven security architecture methodSecurity architecture & design authority
TOGAFEnterprise architecture framework and methodOperating-model & enterprise design

NIST CSF 2.0 added the Govern function and broadened scope to all organisations, not just critical infrastructure.

Regulatory & operational resilience

RegulationScopeStatus
DORADigital Operational Resilience Act — ICT risk, incident reporting, third-party oversight, resilience testing for EU financial entitiesApplying since Jan 2025 · live & supervised
NIS2 DirectiveRaised cybersecurity baseline & incident handling for essential/important entities and critical infrastructureTransposed · enforcement stepping up
Cyber Resilience Act (CRA)Secure-by-design, vulnerability handling and incident reporting for products with digital elements placed on the EU marketIn force Dec 2024 · reporting duties since 11 Sep 2026 · full application 11 Dec 2027
IEC 62443Security for industrial automation and control systems — zones, conduits and security levels across OT/ICS estatesCertifiable · CNI baseline
GDPRPersonal data protection & breach notificationIn force
ISO/IEC 27001:2022Shared risk-management foundation that DORA, NIS2 & the CRA build onCertifiable

DORA builds on — not replaces — ISO/IEC 27001:2022, NIS2, and GDPR; with the CRA now adding product-side reporting, the disciplines converge on ICT risk and incident handling.

AI governance & emerging tech

StandardPurposeRelevance
EU AI ActRisk-tiered regulation of AI systems across the EU — in force since Aug 2024; prohibited practices applied Feb 2025, GPAI rules Aug 2025, transparency duties live since August 2026; high-risk obligations deferred to 2 Dec 2027 and 2 Aug 2028AI adoption strategy & controls
ISO/IEC 42001AI management system (AIMS) — governance for responsible AICertifiable AI governance
NIST AI RMFVoluntary framework to manage AI risk across the AI lifecycleAI risk identification & mitigation, including autonomous agents
Agentic AI governanceIdentity, permissioning and audit trails for autonomous AI agents — countering shadow agents and permission sprawl as agent fleets growThe emerging enterprise attack surface
Post-Quantum MigrationNIST PQC standards finalised Aug 2024; cryptographic discovery, inventory and agility, with RSA-2048 and ECC P-256 deprecated from 2030 and all remaining FIPS 140-2 certificates now on NIST's Historical listMigration planning under way now

CISOs are now managing the "regulatory collision" where NIS2, DORA, the CRA and the EU AI Act intersect on AI systems — all of them live, not pending.

Applied outcomes

Standards in service of the business.

Frameworks are a means, not an end. Kai uses them to reduce risk, earn regulator trust, and unlock value.

🧭

Harmonised compliance

Consolidating overlapping live obligations (DORA · NIS2 · CRA · ISO/IEC 27001:2022) into a single, defensible control set.

🛡️

Zero-trust & OT resilience

Identity-first architectures aligned to NIST SP 800-207, extended into OT and ICS under IEC 62443 to limit blast radius and lateral movement.

🤖

Governed AI agents

Governance that lets the enterprise run autonomous agents with control — identity, least privilege and audit trails, mapped to the EU AI Act, ISO 42001 and the NIST AI RMF.

Put the frameworks to work.

Translate standards into a defensible, board-ready control posture.