Frameworks & Standards

Fluent in the standards that govern modern enterprise risk.

From control frameworks and zero-trust reference models to the converging EU regulatory landscape — applied across Banking, Aviation, Defence, Government, and Critical National Infrastructure.

Control & architecture frameworks

FrameworkPurposeWhere it applies
NIST CSF 2.0Risk-based cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond, Recover (Feb 2024)Enterprise-wide programme & board reporting
ISO/IEC 27001:2022Information security management system (ISMS) certification standardCertification, audit, supplier assurance
NIST SP 800-207Zero Trust Architecture — identity-first, resource-centric securityArchitecture & access design
CIS ControlsPrioritised, prescriptive technical safeguardsHardening & baseline assurance
SABSABusiness-driven security architecture methodSecurity architecture & design authority
TOGAFEnterprise architecture framework and methodOperating-model & enterprise design

NIST CSF 2.0 added the Govern function and broadened scope to all organisations, not just critical infrastructure.

Regulatory & operational resilience

RegulationScopeStatus
DORADigital Operational Resilience Act — ICT risk, incident reporting, third-party oversight, resilience testing for EU financial entitiesApplying since Jan 2025 · live & supervised
NIS2 DirectiveRaised cybersecurity baseline & incident handling for essential/important entities and critical infrastructureNational laws in force · enforcement stepping up
Cyber Resilience Act (CRA)Horizontal security requirements for products with digital elements — vulnerability handling, secure-by-design duties, actively-exploited-vulnerability and incident reportingIn force Dec 2024 · reporting obligations applicable since 11 Sep 2026 · full application 11 Dec 2027
IEC 62443Security for industrial automation and control systems — zones and conduits, security levels, supplier and asset-owner dutiesApplied standard · OT/ICS & CNI
GDPRPersonal data protection & breach notificationIn force
ISO 27001:2022Shared risk-management foundation that DORA, NIS2 & the CRA build onCertifiable

DORA builds on — not replaces — ISO 27001, NIS2, the CRA and GDPR; the disciplines converge for ICT risk and incident handling. A 2026 reform proposal would ease some NIS2 obligations; the direction of travel is still tighter supervision.

AI governance & emerging tech

StandardPurposeRelevance
EU AI ActRisk-tiered regulation of AI systems across the EU. In force since Aug 2024; prohibited practices applied Feb 2025, GPAI rules Aug 2025, transparency duties now live since August 2026. High-risk obligations deferred by the Digital Omnibus to 2 Dec 2027 and 2 Aug 2028Live compliance today; high-risk readiness on a 2027–28 clock
ISO/IEC 42001AI management system (AIMS) — governance for responsible AICertifiable AI governance
NIST AI RMFVoluntary framework to manage AI risk — Govern, Map, Measure, ManageAI risk identification & mitigation; the practical spine for agentic AI controls
Agentic AI governanceControl of autonomous agents — discovery of shadow agents, scoped agent identity, permission boundaries, and an audit trail for every consequential actionThe fastest-growing attack surface in the enterprise
Post-Quantum MigrationCryptographic discovery and inventory, crypto agility, and migration to the NIST PQC standards finalised Aug 2024. NIST's CMVP has now moved all remaining FIPS 140-2 validated certificates to the Historical list; RSA-2048 and ECC P-256 are deprecated from 2030Live programme, not a future problem

CISOs now manage the "regulatory collision" where NIS2, DORA, the CRA and the EU AI Act intersect on AI and connected products. Industry surveys in 2026 suggest only around 13% of organisations have post-quantum cryptography in production, and roughly 60% have not meaningfully begun.

Applied outcomes

Standards in service of the business.

Frameworks are a means, not an end. Kai uses them to reduce risk, earn regulator trust, and unlock value.

🧭

Harmonised compliance

Consolidating overlapping obligations (DORA · NIS2 · CRA · ISO 27001:2022) into a single, defensible control set — all of them live and supervised today.

🛡️

Zero-trust resilience

Identity-first architectures aligned to NIST SP 800-207 that limit blast radius and lateral movement.

🤖

Governed agentic AI

Governance that lets the enterprise run autonomous agents with control — scoped identity, permission boundaries and audit trails, mapped to the EU AI Act, ISO 42001 and the NIST AI RMF.

🧬

Crypto agility

Discovery and inventory of cryptography in use, then a migration path to PQC that holds ahead of the 2030 deprecation of RSA-2048 and P-256.

Put the frameworks to work.

Translate standards into a defensible, board-ready control posture.