Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

MODULE · COMPLIANCE

Compliance you can prove any day of the year.

Smart Compliance auto-maps your obligations across dozens of frameworks and thousands of controls, then monitors each control continuously against live evidence. Audit-ready stops being a season.

Control Atlas · one control, six frameworks Illustrative data

8 frameworks in scope 1 240 controls 4 512 mappings 1 118 controls verified 3 requirements open

ISO/IEC 27001 Equivalent

A.8.5 Secure authentication

Coverage 91 %
NIS2 Related

Art. 21(2)(j) Multi-factor authentication

Coverage 84 %
DORA Related

Art. 9(4)(d) Strong authentication

Coverage 78 %
Control Verified

A.8.5 · ISO/IEC 27001

Secure authentication

Evidence trail

  • IAM policy export 2 d
  • Directory scan 1 d
  • EDR posture report 6 h

Re-verified 3 Sept Fresh

SOC 2 Equivalent

CC6.1 Logical access

Coverage 88 %
NIST CSF 2.0 Related

PR.AA-03 Authentication

Coverage 73 %
PCI DSS 4.0 Partial

Req. 8.4 MFA

Coverage 62 %
Equivalent Related Partial

One control, implemented and verified once, answers every framework that requires it; each edge carries the mapping type the atlas assigned. In the product, every card opens on its requirements, its controls and the evidence behind each verdict.

CAPABILITIES

From framework text to verified control state.

Dozens of frameworks, one control set

ISO 27001, NIS2, DORA, SOC 2 and more, auto-mapped so one implemented control answers every framework that requires it. Implement once, comply everywhere.

Thousands of controls auto-mapped

Cross-framework mapping maintained by the platform, not by your spreadsheet. New framework? Your existing coverage is computed instantly.

Continuous controls monitoring

Controls are tied to live evidence and re-verified continuously. Degradations surface as they happen, with the failing signal attached.

Evidence that stays fresh

No more screenshot folders. Evidence is collected, dated, sourced and renewed automatically, every artifact traceable to its origin.

Gap analysis in context

See which requirements are covered, partially covered or open (by entity, scope and framework) and what closing each gap actually requires.

Audit mode

Give auditors a scoped, read-only view of verified controls and their evidence trail. Audits become a walkthrough, not an archaeology dig.

INSIDE THE MODULE

Four surfaces, one evidence trail.

Named here exactly as the product names them: what you read on this page is what you meet in the demo.

01

DORA

The obligations that apply to financial entities, followed where the evidence lives.

02

Concentration risk

Your exposure to critical ICT third-party providers, measured (DORA Article 29).

03

TLPT engagements

Threat-led penetration testing engagements, planned and documented.

04

Reports

The regulatory reports your supervisors expect, produced from the module.

LIVE EVIDENCE

A control is only as true as its last verification.

Declarative compliance rots silently: the policy says MFA, the export says enforced, and one misconfigured group says otherwise. Ernest reconciles declared state with observed state, continuously.

ernest - control monitoring

$ monitor control A.8.5 "Secure authentication" - ISO 27001

mapped to: NIS2 Art.21 · DORA Art.9 · SOC 2 CC6.1

evidence: IAM policy export · directory scan · EDR posture

verdict: VERIFIED

next check: continuous · drift alerts: enabled

  1. 01

    Map once

    Pick the frameworks that apply to you. The Control Atlas relates their requirements to one control set with typed, strength-rated mappings, so a control implemented once answers each of them.

  2. 02

    Prove with evidence

    Each control carries its evidence: collected, dated, sourced, validated by AI with visible confidence and reviewed by a person. Nothing is filed without a verdict.

  3. 03

    Verify and show

    Evidence is re-verified on its cycle and drift is flagged as it appears. Open a scoped, read-only view for the auditor: verified controls, their evidence trail, no archaeology.

FAQ

Compliance, in practice

Which frameworks are covered?

Dozens of frameworks including ISO 27001, NIS2, DORA, SOC 2, GDPR-related control sets and sectoral baselines such as IEC 62443 and TISAX, with thousands of controls auto-mapped across them. New frameworks are added by Mindlapse without re-implementation on your side.

What does “controls tied to live evidence” mean concretely?

Each control can be linked to the signals that prove it: identity and access configurations, cloud posture, endpoint coverage and other operational sources. The platform re-verifies the control against those signals and records a dated, sourced verdict.

Does it replace our ISMS processes?

No, it makes them verifiable. Your policies, scopes and responsibilities remain yours; Mindlapse keeps the control state, evidence and framework mapping continuously current underneath them.

How does multi-framework mapping reduce workload?

A control implemented and verified once propagates to every framework that requires it. Adding a regulation becomes a mapping review, not a new compliance project.

AUDIT-READY, ALWAYS

Pick a framework. See your real coverage.

Bring your current scope: we’ll show verified control state, gaps and the evidence trail live.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.