NIS2, DORA, GDPR and the EU AI Act rarely arrive one at a time, and your board and your auditors expect a single answer to all of them. IrisInfosec translates overlapping regulation into one auditable security programme: mapped controls, clear evidence, and governance a regulator and a board both recognise. Lawyer-led, across the EU, US and India.
We translate complex, overlapping regulation into practical, auditable programmes, then prove the controls actually hold. The result is regulatory confidence, measurable risk reduction and operational resilience.
Compliance without proof is paperwork,
which is why our governance work pairs naturally with independent testing and assessment.
Five services, one programme
Engage one service or run them as a single governance programme. Each links to a page with
full scope, approach and deliverables.
Map your obligations under NIS2, DORA, GDPR and the EU AI Act into clear controls, policies and board-level reporting.
Implement and certify ISO 27001, ISO 27701, ISO 42001, SOC 2 and NIST CSF 2.0, designed to pass the audit and hold after it.
GDPR and DPDPA programmes: DPIAs, RoPA, data subject requests, transfer mechanisms and DPO-as-a-Service.
Govern your AI to the EU AI Act, ISO 42001 and the NIST AI RMF: risk classification, an AI management system and model oversight.
Assess and monitor vendor and ICT third-party risk, with the registers and contractual controls DORA and NIS2 expect.
A short scoping call maps your obligations and tells you which services you actually need, and in what order.
Regulations & frameworks
We lead with the European stack because that is where obligation is sharpest, then extend the same control set to the US and India so one programme carries across your markets.
One control set, many regimes. Mapped once, so GDPR, DPDPA and CCPA evidence comes from the same programme.
Primary sources, not hearsay. We work from EUR-Lex, ENISA, NIST and ISO text, and cite the clause that applies.
Sector-aware. Financial services, health, technology and manufacturing each carry their own overlay, and we account for it.
| Regulation or framework | Who it applies to | |
|---|---|---|
| NIS2 | Essential and important entities across the EU | |
| DORA | EU financial entities and their ICT providers | |
| GDPR | Anyone handling EU and EEA personal data | |
| EU AI Act | Providers and deployers of AI in the EU | |
| ISO 27001 / 27701 / 42001 | Information, privacy and AI management systems | |
| SOC 2 (Type I & II) | Service organisations, common for US customers | |
| DPDPA / CCPA / HIPAA | India and US privacy and health overlays |
How we work
A measured, five-stage approach that ends in evidence and governance, not a binder that
ages on a shelf.
Establish which regulations and frameworks apply, and measure where you stand against each today.
Translate overlapping requirements into one control set, so a single effort answers several regimes at once.
Stand up the policies, processes and technical controls, working with your teams rather than around them.
Produce the records an auditor and a regulator will ask for, mapped to the relevant clause or criterion.
Board reporting, a living risk register and a cadence that keeps you compliant as obligations change.
What you receive
Practical artefacts, written so the people who report to a regulator and the people who run the
controls both find them useful.
A clear read of where you stand against each obligation, prioritised by risk and by deadline.
Every requirement mapped to a control, so one effort satisfies several regulations at once.
A policy set and a Statement of Applicability written for your organisation, not a generic template.
The records, logs and artefacts an auditor or regulator will ask for, organised against each clause.
Reporting your executives and your supervisor can both read, with the risk picture in plain terms.
We prepare you for the audit and stand beside you through it, then help maintain the certificate after.
Transform compliance from burden to advantage
Share the regulations and audits you are facing. We will map your obligations and send a staged plan
with dates, usually within 3 business days.
Why teams choose us
Most firms sell either compliance or testing. We hold both, so your governance is backed by
evidence that the controls actually work.
Founded by a global technology lawyer, so obligations are read at source and translated into action, not guessed at.
Governance and independent testing under one roof, so a control is not just documented, it is verified.
EU, US and India understood as peer markets, so a single programme carries across the regimes you operate under.
Security and regulation are the whole job. You get depth and responsiveness a broad consultancy struggles to match.
Delivery is backed by an ISO/IEC 27001 certified partner network, so capacity does not limit your timeline.
We leave you with governance you can run, so the second audit is easier than the first, not a repeat of it.
Questions, answered