CyberSec42
Compliance Readiness

Compliance that ends in evidence.

CyberSec42

Compliance readiness brings your security posture into a state that an auditor, an enterprise procurement team and an investor accept, from gap analysis through concrete measures and examinable evidence to handover to the accredited body. We work toward NIS2, ISO 27001 and ISO 42001, the EU AI Act and GDPR and deliver a piece of evidence for every requirement, not just a grade. The attestation itself is issued by the accredited body, and we prepare everything so that this step runs smoothly.

Where the scan stops

A score is not an attestation. That is where the work begins.

Automated scanning is useful and part of the picture. But it stops at the surface: a list, a grade, another scan. What an audit, an enterprise procurement team and an investor want to see begins exactly where the scan stops, with calibrated triage and a piece of evidence per requirement.

How far an automated scan takes you List of raw findingsLetter scoreautomatic re-check
The threshold to being examinable
Where we start work Triage: real versus false positiveEvidence per requirementEvidence from operationsSupport up to the accredited body
Frameworks

The frameworks that apply to you.

Obligations come from the legislator. Buyers check certificates and questionnaires. Some of it is guidance only. We work out what actually applies to you.

NIS2

NIS2

Organisation-wide duties from NIS2: risk management, reporting lines and technical minimum measures cleanly set up and evidenced.

Legal obligation
EU AI Act

EU AI Act

Classifying the risk class, obligations per class and the evidence a review expects, including the harmonised standards from CEN/CENELEC JTC 21 that make the AI Act concretely implementable.

Legal obligation
GDPR

GDPR and TOMs

Records of processing, technical and organisational measures, and the associated documentation.

Legal obligation
ISO 27001

ISO 27001

Building and maintaining the ISMS, control mapping and evidence, ready for the certification body.

Certifiable · buyers ask for it
ISO 42001

ISO 42001

A management system for AI: roles, risks and controls around your AI systems, documented for examination. The certificate buyers increasingly ask for on AI products.

Certifiable · buyers ask for it
BSI C5

BSI C5

Cloud security criteria as a control framework, prepared for the examination by an auditor.

Auditor attestation
ISO 23894

ISO 23894

Guidance for AI risk management, not a certificate. Useful as an implementation aid for ISO 42001 and as a trust signal towards customers, not as an audit criterion.

Guidance · not certifiable
EN 304 223

EN 304 223 V2.1.1

ETSI standard for AI security (V2.1.1, Dec 2025): baseline cyber security for AI models and systems across the lifecycle, including protection against indirect prompt injection, with evidence per requirement.

Standard · conformity demonstrable
+

Your framework missing?

Another standard, a customer questionnaire or an industry-specific catalogue: tell us yours, we map it and build the evidence.

Book a free call →

The frameworks named here refer solely to what CyberSec42 prepares you for. They are not a certification issued by CyberSec42.

How it works

From the gap to examinable evidence.

Step 1

Gap analysis

We assess your state against the relevant framework and prioritise the gaps by risk and effort.

Step 2

Measures and evidence

We implement the controls, map every requirement to a piece of evidence and close the gaps.

Step 3

Handover to the body

We prepare the evidence package, accompany the examination and keep the evidence current afterwards.

Why CyberSec42

Compliance that an auditor signs off.

The honest boundary. CyberSec42 is not an accredited certification body and does not provide legal advice. We prepare, implement, collect evidence and accompany you up to the accredited body. The attestation is issued by the accredited body, and the legal assessment is the responsibility of your legal counsel. We state clearly what falls within our responsibility and what does not.

Frequently asked

Compliance readiness, briefly explained.

What is compliance readiness?

Compliance readiness brings your security and compliance posture into an examinable state: from gap analysis through the implementation of measures and the collection of evidence to handover to the accredited body. The goal is a piece of evidence per requirement, not just a score.

Which frameworks does CyberSec42 cover?

We prepare you for NIS2, ISO 27001, ISO 42001, ISO 23894, EU AI Act, EN 304 223, BSI C5 . Which framework is relevant depends on your target market and your customers.

Does CyberSec42 certify or audit itself?

No. CyberSec42 prepares, implements, collects evidence and accompanies you up to the accredited body. The attestation or certificate is issued by an accredited certification body or an approved auditor. CyberSec42 is not itself an accredited body and does not provide legal advice.

Is a framework worth it if we need several?

Especially then. The controls of NIS2, ISO 27001, ISO 42001 and the EU AI Act overlap heavily. We build the base once, cleanly, so the groundwork for one framework significantly shortens the path to the others.

How do we get started?

With a first conversation in which we place the relevant framework and your current state. After that you know what is missing before you are examinable, and you receive a prioritised plan with evidence.

Compliance that an auditor signs off.

Let us place the relevant framework and your current state in a first conversation. After that you know what is missing before you are examinable.

Request a readiness conversation

CyberSec42 is an independent technical security partner, not an accredited certification body and not a provider of legal advice.