Frameworks & Standards
Fluent in the standards that govern modern enterprise risk.
From control frameworks and zero-trust reference models to the converging EU regulatory landscape — applied across Banking, Aviation, Defence, Government, and Critical National Infrastructure.
Control & architecture frameworks
| Framework | Purpose | Where it applies |
|---|---|---|
| NIST CSF 2.0 | Risk-based cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond, Recover (Feb 2024) | Enterprise-wide programme & board reporting |
| ISO/IEC 27001:2022 | Information security management system (ISMS) certification standard | Certification, audit, supplier assurance |
| NIST SP 800-207 | Zero Trust Architecture — identity-first, resource-centric security | Architecture & access design |
| CIS Controls | Prioritised, prescriptive technical safeguards | Hardening & baseline assurance |
| SABSA | Business-driven security architecture method | Security architecture & design authority |
| TOGAF | Enterprise architecture framework and method | Operating-model & enterprise design |
NIST CSF 2.0 added the Govern function and broadened scope to all organisations, not just critical infrastructure.
Regulatory & operational resilience
| Regulation | Scope | Status |
|---|---|---|
| DORA | Digital Operational Resilience Act — ICT risk, incident reporting, third-party oversight, resilience testing for EU financial entities | Applying since Jan 2025 · live & supervised |
| NIS2 Directive | Raised cybersecurity baseline & incident handling for essential/important entities and critical infrastructure | National laws in force · enforcement stepping up |
| Cyber Resilience Act (CRA) | Horizontal security requirements for products with digital elements — vulnerability handling, secure-by-design duties, actively-exploited-vulnerability and incident reporting | In force Dec 2024 · reporting obligations applicable since 11 Sep 2026 · full application 11 Dec 2027 |
| IEC 62443 | Security for industrial automation and control systems — zones and conduits, security levels, supplier and asset-owner duties | Applied standard · OT/ICS & CNI |
| GDPR | Personal data protection & breach notification | In force |
| ISO 27001:2022 | Shared risk-management foundation that DORA, NIS2 & the CRA build on | Certifiable |
DORA builds on — not replaces — ISO 27001, NIS2, the CRA and GDPR; the disciplines converge for ICT risk and incident handling. A 2026 reform proposal would ease some NIS2 obligations; the direction of travel is still tighter supervision.
AI governance & emerging tech
| Standard | Purpose | Relevance |
|---|---|---|
| EU AI Act | Risk-tiered regulation of AI systems across the EU. In force since Aug 2024; prohibited practices applied Feb 2025, GPAI rules Aug 2025, transparency duties now live since August 2026. High-risk obligations deferred by the Digital Omnibus to 2 Dec 2027 and 2 Aug 2028 | Live compliance today; high-risk readiness on a 2027–28 clock |
| ISO/IEC 42001 | AI management system (AIMS) — governance for responsible AI | Certifiable AI governance |
| NIST AI RMF | Voluntary framework to manage AI risk — Govern, Map, Measure, Manage | AI risk identification & mitigation; the practical spine for agentic AI controls |
| Agentic AI governance | Control of autonomous agents — discovery of shadow agents, scoped agent identity, permission boundaries, and an audit trail for every consequential action | The fastest-growing attack surface in the enterprise |
| Post-Quantum Migration | Cryptographic discovery and inventory, crypto agility, and migration to the NIST PQC standards finalised Aug 2024. NIST's CMVP has now moved all remaining FIPS 140-2 validated certificates to the Historical list; RSA-2048 and ECC P-256 are deprecated from 2030 | Live programme, not a future problem |
CISOs now manage the "regulatory collision" where NIS2, DORA, the CRA and the EU AI Act intersect on AI and connected products. Industry surveys in 2026 suggest only around 13% of organisations have post-quantum cryptography in production, and roughly 60% have not meaningfully begun.
Applied outcomes
Standards in service of the business.
Frameworks are a means, not an end. Kai uses them to reduce risk, earn regulator trust, and unlock value.
Harmonised compliance
Consolidating overlapping obligations (DORA · NIS2 · CRA · ISO 27001:2022) into a single, defensible control set — all of them live and supervised today.
Zero-trust resilience
Identity-first architectures aligned to NIST SP 800-207 that limit blast radius and lateral movement.
Governed agentic AI
Governance that lets the enterprise run autonomous agents with control — scoped identity, permission boundaries and audit trails, mapped to the EU AI Act, ISO 42001 and the NIST AI RMF.
Crypto agility
Discovery and inventory of cryptography in use, then a migration path to PQC that holds ahead of the 2030 deprecation of RSA-2048 and P-256.
Put the frameworks to work.
Translate standards into a defensible, board-ready control posture.