Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

BY INDUSTRY · TECH & SAAS

Trust as a product feature. One control set, every audit.

You are a supplier to entities under NIS2 and DORA, a buyer of sub-processors, and a manufacturer under the CRA if you ship software products. Mindlapse keeps one verified control set for all three roles, and we publish our own posture on the same terms we ask of vendors.

ISO 27001 and SOC 2 · NIS2 supplier clauses · CRA reporting · Sub-processors assessed

Mindlapse Trust Grade · as your customer sees you Illustrative data
B Good +4.2 improving ↗ Your company · SaaS · customer data
Risk scoring (NIST CSF) 82 × 0.40 +32.8 pts
Business impact 55 × 0.35 · customer data +19.25 pts
EASM · external ratings 79 × 0.25 +19.75 pts

SecurityScorecard · Bitsight · Scovery

Coverage: 3/3 signals Last computed: today

Answer once through the portal; the action plan syncs to your queue when you run Mindlapse too.

THE SITUATION

The same evidence, retyped every week.

  1. Every customer sends its own questionnaire

    SIG, CAIQ, DORA Art. 30 addenda, NIS2 supplier clauses; the answers live in last quarter’s spreadsheet.

  2. Supplier and buyer at once

    Sub-processors, open-source dependencies and cloud concentration your customers want to see through you.

  3. Certification stacking

    ISO 27001 plus SOC 2 plus sector schemes, overlapping controls audited separately by engineers who own them part-time.

  4. Sovereignty as a sales objection

    Hosting location, extraterritorial exposure and where the AI runs, asked in every European deal.

WHO IS IN SCOPE

Who is in scope in tech and SaaS?

Cloud, data-centre, DNS, TLD, CDN and trust service providers, MSPs and MSSPs are NIS2 Annex I entities; online marketplaces, search engines and social platforms are important entities, and the NIS2 implementing regulation fixes their technical requirements and significant-incident thresholds (details on the NIS2 page). SaaS outside these lists is a supplier to entities in scope. Software placed on the market falls under the CRA, SaaS generally outside it unless it is remote data processing tied to a product; providers to financial entities carry DORA Art. 30 clauses.

Written for

  • SaaS editors Suppliers to entities under NIS2 and DORA
  • Cloud, hosting, MSP and MSSP NIS2 Annex I and its implementing regulation
  • Software and device makers under the CRA The CRA, reporting duties first
  • AI providers AI Act GPAI and transparency duties

THE OBLIGATIONS MAP

What your customers and the regulations ask, and what Mindlapse verifies.

EU rows first; every "verifies" cell is a product claim at ledger level, no cell carries a date (dates live on the CRA and NIS2 pages), and the sentence under the table is the site’s one dated source.

What your customers and the regulations ask, and what Mindlapse verifies.
Regulation Obligation What Mindlapse verifies Surface
NIS2 Art. 21(2)(d) · your customers’ supply-chain duty Answer once through the portal when the customer runs Mindlapse; the verified Control Atlas otherwise Supplier Hub
NIS2 Art. 21 and the implementing regulation · providers in scope The implementing regulation’s requirements mapped to one control set, each control with dated, reviewed evidence Control Atlas
DORA Art. 30 · contractual provisions with financial customers Your ICT contract held as living register data on the customer’s side (contracts, criticality, dependencies); remediation as a joint action plan both sides accept, reject or counter-propose Supplier Hub
CRA Art. 14 · reporting duties (dates on the CRA page) Severe incidents recorded and qualified; actively exploited vulnerabilities as risks and actions with owners; the notifications drafted by the cascade from the record and logged; you file them Risk Register
AI Act Art. 50 and provider duties · transparency and what a provider owes AI risks in the same register as every other risk; the obligations carried as controls with cross-framework mapping Risk Register
GDPR Art. 28 · processor duties Sub-processors assessed as suppliers in the context of the service they run; re-assessment when terms or sub-processors change Supplier Hub

NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026.

A QUARTER, THEN THE DAY A CUSTOMER ASKS

A normal quarter answers once and re-verifies on its cycle; the request finds the narrative already sourced.

Four moments of an ordinary quarter in a SaaS company, and what the platform had already done; then the day a bank’s auditor asks, in three steps.

A quarter in tech, then the request Illustrative data

A normal quarter

  1. WEEK 1

    A customer running Mindlapse enrolled you on its portal.

    Ernest drafted the answers from your own documents, sourced line by line; you confirmed them.

    Surface: Supplier Hub

  2. alert: WEEK 4

    The SOC 2 evidence came up for re-verification.

    Re-verified on its cycle; drift on one control was flagged with a dated verdict.

    Surface: Control Atlas

  3. WEEK 8

    An actively exploited vulnerability in your product.

    Recorded as a risk with an owner; its CRA notification opened as an action, drafted by the cascade for you to file.

    Surface: Risk Register

  4. verified: WEEK 12

    The ISO auditor arrives.

    Audit mode opened a scoped, read-only view of the verified controls and their evidence trail.

    Surface: Control Atlas

The day the customer asks

  1. THE REQUEST

    A bank’s DORA auditor asks for your Art. 30 evidence and your sub-processor chain.

    Both were read from the register: the sub-processors as assessed suppliers, the contract data the customer holds.

    Surface: Supplier Hub

  2. WHAT OPENS

    The sub-processors as assessed suppliers, the verified controls, the joint action plan agreed with that customer.

    Each sub-processor with its grade and its context; each control with its dated verdict; the plan with what both sides accepted.

    Surface: Control Atlas

  3. WHAT IS EXPORTED

    The control narratives and the evidence.

    Drafted by Ernest, sourced line by line, confirmed by you; synchronized on both sides when the customer runs Mindlapse.

    Surface: Supplier Hub

Illustrative quarter: the moments are fictional, the surfaces are the product’s.

FROM THE FIELD

Built with the CISOs who send the questionnaires.

CYBER COLLECTIVE LAB · Edition 5

Compliance: NIS2, DORA and CRA - round table and field feedback

CRA duties as the round table framed them for software makers: reporting first, the product file next, and what a SaaS team can do before the dates.

CYBER COLLECTIVE LAB · Edition 1

Takeaways from the AI Action Summit

Takeaways from the AI Action Summit, read from the provider’s side: where AI duties meet the rest of a software company’s obligations.

−50–70%
time-to-risk-decision
15–30%
cyber-budget optimization
2–3×
risk visibility across the organization

Measured with our design-partner CISOs, figures under continuous validation.

FAQ

Tech and SaaS ask

Does it answer our customers’ security questionnaires for us?

Not as an inbound workflow. When your customer runs Mindlapse you answer once through its portal and the action plans sync on both sides; otherwise the verified Control Atlas and the control narratives Ernest drafts from it, sourced line by line, are what you send.

Does it scan our code or generate SBOMs?

No. Mindlapse reads no repository, runs no scanner and produces no SBOM; it holds the governance layer: the product record, its risk assessment, the CRA actions with owners, and what your engineering toolchain produces, kept as dated, reviewed evidence.

Is pure SaaS in CRA scope?

Generally not. The CRA covers products with digital elements placed on the market; a service delivered as SaaS sits outside it unless it is remote data processing tied to such a product, in which case that processing is in scope. Your financial customers reach you through DORA Art. 30 instead, your NIS2 customers through their supply-chain duty; the CRA page carries the dates and the entity test.

Is Mindlapse itself certified?

ISO 27001 is in progress and SOC 2 Type II is planned; neither is claimed before it is reached, and the trust center carries the dates. What holds today: customer data kept and processed inside the EU only, primary infrastructure in France, full isolation per tenant, and the evaluation pack, questionnaire, DPA and hosting attestations, on request under NDA.

Where does the AI run?

In Europe, on open-source model foundations operated inside the EU. Your governance data never trains a model, on anyone’s side, each inference is traced, and Ernest proposes while a person confirms; the sources behind each draft are shown.

TRUST, VERIFIED

Bring your last two audits. Leave with the one control set that answers both.

A live session on your stack: frameworks, sub-processors, the auditor’s read-only view.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.