Turn Overlapping Regulation Into
One Programme You Can Defend

NIS2, DORA, GDPR and the EU AI Act rarely arrive one at a time, and your board and your auditors expect a single answer to all of them. IrisInfosec translates overlapping regulation into one auditable security programme: mapped controls, clear evidence, and governance a regulator and a board both recognise. Lawyer-led, across the EU, US and India.

5

Compliance disciplines under one accountable team.

EU-first

NIS2, DORA, GDPR and the EU AI Act.

Lawyer-led

Founded and reviewed by a global technology lawyer.

Audit-ready

Evidence mapped to the frameworks you report against.

The IrisInfosec position

Cybersecurity Is Now A Board And Regulatory Responsibility, Not Only An IT Function.

We translate complex, overlapping regulation into practical, auditable programmes, then prove the controls actually hold. The result is regulatory confidence, measurable risk reduction and operational resilience.

In one line

Compliance without proof is paperwork,

which is why our governance work pairs naturally with independent testing and assessment.

Five services, one programme

What We Cover

Engage one service or run them as a single governance programme. Each links to a page with
full scope, approach and deliverables.

Regulatory Compliance & Cyber Governance

Map your obligations under NIS2, DORA, GDPR and the EU AI Act into clear controls, policies and board-level reporting.

NIS2 DORA GDPR EU AI Act
Explore

Security & Risk Framework Implementation

Implement and certify ISO 27001, ISO 27701, ISO 42001, SOC 2 and NIST CSF 2.0, designed to pass the audit and hold after it.

ISO 27001 SOC 2 NIST CSF 2.0
Explore

Privacy & Data Protection Programs

GDPR and DPDPA programmes: DPIAs, RoPA, data subject requests, transfer mechanisms and DPO-as-a-Service.

GDPR DPDPA DPO-as-a-Service
Explore

AI Governance & Responsible AI

Govern your AI to the EU AI Act, ISO 42001 and the NIST AI RMF: risk classification, an AI management system and model oversight.

EU AI Act ISO 42001 NIST AI RMF Model governance
Explore

Third-Party & Supply Chain Risk

Assess and monitor vendor and ICT third-party risk, with the registers and contractual controls DORA and NIS2 expect.

Vendor risk ICT register Monitoring
Explore

Not Sure Where To Start?

A short scoping call maps your obligations and tells you which services you actually need, and in what order.

Scoping call Obligations map Priorities
Book a scoping call

Regulations & frameworks

EU-First, And Ready For The Regimes You Face Elsewhere

We lead with the European stack because that is where obligation is sharpest, then extend the same control set to the US and India so one programme carries across your markets.

One control set, many regimes. Mapped once, so GDPR, DPDPA and CCPA evidence comes from the same programme.

Primary sources, not hearsay. We work from EUR-Lex, ENISA, NIST and ISO text, and cite the clause that applies.

Sector-aware. Financial services, health, technology and manufacturing each carry their own overlay, and we account for it.

Regulation or framework Who it applies to
NIS2 Essential and important entities across the EU
DORA EU financial entities and their ICT providers
GDPR Anyone handling EU and EEA personal data
EU AI Act Providers and deployers of AI in the EU
ISO 27001 / 27701 / 42001 Information, privacy and AI management systems
SOC 2 (Type I & II) Service organisations, common for US customers
DPDPA / CCPA / HIPAA India and US privacy and health overlays

How we work

From Obligation To A Programme You Can Run

A measured, five-stage approach that ends in evidence and governance, not a binder that
ages on a shelf.

01

Assess & Gap

Establish which regulations and frameworks apply, and measure where you stand against each today.

02

Map To Obligations

Translate overlapping requirements into one control set, so a single effort answers several regimes at once.

03

Implement Controls

Stand up the policies, processes and technical controls, working with your teams rather than around them.

04

Evidence & Document

Produce the records an auditor and a regulator will ask for, mapped to the relevant clause or criterion.

05

Govern & Sustain

Board reporting, a living risk register and a cadence that keeps you compliant as obligations change.

What you receive

Evidence Your Board And Your Auditors Accept

Practical artefacts, written so the people who report to a regulator and the people who run the
controls both find them useful.

Gap Assessment

A clear read of where you stand against each obligation, prioritised by risk and by deadline.

Control And Obligation Map

Every requirement mapped to a control, so one effort satisfies several regulations at once.

Policies And Procedures

A policy set and a Statement of Applicability written for your organisation, not a generic template.

Evidence Pack

The records, logs and artefacts an auditor or regulator will ask for, organised against each clause.

Board And Regulator Reporting

Reporting your executives and your supervisor can both read, with the risk picture in plain terms.

Audit And Certification Support

We prepare you for the audit and stand beside you through it, then help maintain the certificate after.

Transform compliance from burden to advantage

Tell Us Which Deadlines Are On Your Desk

Share the regulations and audits you are facing. We will map your obligations and send a staged plan
with dates, usually within 3 business days.

Why teams choose us

Lawyer-Led, And Able To Prove It

Most firms sell either compliance or testing. We hold both, so your governance is backed by
evidence that the controls actually work.

01

Founder-Led Regulatory Authority

Founded by a global technology lawyer, so obligations are read at source and translated into action, not guessed at.

02

One Team Across Regulation And Proof

Governance and independent testing under one roof, so a control is not just documented, it is verified.

03

Multi-Jurisdiction Range

EU, US and India understood as peer markets, so a single programme carries across the regimes you operate under.

04

Specialist, Not Generalist

Security and regulation are the whole job. You get depth and responsiveness a broad consultancy struggles to match.

05

Certified Partner Ecosystem

Delivery is backed by an ISO/IEC 27001 certified partner network, so capacity does not limit your timeline.

06

Built To Sustain

We leave you with governance you can run, so the second audit is easier than the first, not a repeat of it.

Questions, answered

Cyber Risk And Compliance FAQ

Governance-first means treating security as a board and regulatory responsibility, not only an IT task. We translate overlapping regulation such as NIS2, DORA, GDPR and the EU AI Act into one auditable programme of mapped controls, evidence and reporting that a regulator and a board both recognise.

Possibly. DORA applies to financial entities and their ICT third-party providers in the EU. NIS2 applies to essential and important entities across many other sectors. Where DORA applies it generally takes precedence for financial entities on ICT risk, but many groups fall under both, so we map the obligations together to avoid duplicate work.

Both govern personal data, and a programme built to GDPR covers much of the DPDPA, but they differ on consent, cross-border transfers and breach timelines. We map a single control set to both, plus CCPA where US consumers are in scope, so one privacy programme satisfies several regimes.

ISO 27001 certifies an information security management system and is recognised globally. SOC 2 is an attestation report common with US customers. Many firms need both. We design one control set that produces evidence for each, so you are not running two separate projects.

A gap assessment takes a few weeks. A full ISO 27001 or SOC 2 readiness programme typically runs three to nine months depending on scope and current maturity. You get a staged plan with dates after a short scoping call.

Yes. We can act as your outsourced Data Protection Officer or support your in-house DPO across the EU and India, covering RoPA, DPIAs, data subject requests, transfer mechanisms and regulator engagement.

Make Your Next Audit The Easy Part

Book a call with an advisor who reads the regulation at source. We map
your obligations and send a staged plan with dates, no obligation.