Compliance readiness brings your security posture into a state that an auditor, an enterprise procurement team and an investor accept, from gap analysis through concrete measures and examinable evidence to handover to the accredited body. We work toward NIS2, ISO 27001 and ISO 42001, the EU AI Act and GDPR and deliver a piece of evidence for every requirement, not just a grade. The attestation itself is issued by the accredited body, and we prepare everything so that this step runs smoothly.
Automated scanning is useful and part of the picture. But it stops at the surface: a list, a grade, another scan. What an audit, an enterprise procurement team and an investor want to see begins exactly where the scan stops, with calibrated triage and a piece of evidence per requirement.
Obligations come from the legislator. Buyers check certificates and questionnaires. Some of it is guidance only. We work out what actually applies to you.
Organisation-wide duties from NIS2: risk management, reporting lines and technical minimum measures cleanly set up and evidenced.
Legal obligationClassifying the risk class, obligations per class and the evidence a review expects, including the harmonised standards from CEN/CENELEC JTC 21 that make the AI Act concretely implementable.
Legal obligationRecords of processing, technical and organisational measures, and the associated documentation.
Legal obligationBuilding and maintaining the ISMS, control mapping and evidence, ready for the certification body.
Certifiable · buyers ask for itA management system for AI: roles, risks and controls around your AI systems, documented for examination. The certificate buyers increasingly ask for on AI products.
Certifiable · buyers ask for itCloud security criteria as a control framework, prepared for the examination by an auditor.
Auditor attestationGuidance for AI risk management, not a certificate. Useful as an implementation aid for ISO 42001 and as a trust signal towards customers, not as an audit criterion.
Guidance · not certifiableETSI standard for AI security (V2.1.1, Dec 2025): baseline cyber security for AI models and systems across the lifecycle, including protection against indirect prompt injection, with evidence per requirement.
Standard · conformity demonstrableAnother standard, a customer questionnaire or an industry-specific catalogue: tell us yours, we map it and build the evidence.
Book a free call →The frameworks named here refer solely to what CyberSec42 prepares you for. They are not a certification issued by CyberSec42.
We assess your state against the relevant framework and prioritise the gaps by risk and effort.
We implement the controls, map every requirement to a piece of evidence and close the gaps.
We prepare the evidence package, accompany the examination and keep the evidence current afterwards.
The honest boundary. CyberSec42 is not an accredited certification body and does not provide legal advice. We prepare, implement, collect evidence and accompany you up to the accredited body. The attestation is issued by the accredited body, and the legal assessment is the responsibility of your legal counsel. We state clearly what falls within our responsibility and what does not.
Compliance readiness brings your security and compliance posture into an examinable state: from gap analysis through the implementation of measures and the collection of evidence to handover to the accredited body. The goal is a piece of evidence per requirement, not just a score.
We prepare you for NIS2, ISO 27001, ISO 42001, ISO 23894, EU AI Act, EN 304 223, BSI C5 . Which framework is relevant depends on your target market and your customers.
No. CyberSec42 prepares, implements, collects evidence and accompanies you up to the accredited body. The attestation or certificate is issued by an accredited certification body or an approved auditor. CyberSec42 is not itself an accredited body and does not provide legal advice.
Especially then. The controls of NIS2, ISO 27001, ISO 42001 and the EU AI Act overlap heavily. We build the base once, cleanly, so the groundwork for one framework significantly shortens the path to the others.
With a first conversation in which we place the relevant framework and your current state. After that you know what is missing before you are examinable, and you receive a prioritised plan with evidence.
Let us place the relevant framework and your current state in a first conversation. After that you know what is missing before you are examinable.
Request a readiness conversationCyberSec42 is an independent technical security partner, not an accredited certification body and not a provider of legal advice.