CYBER COLLECTIVE LAB · Edition 5
Compliance: NIS2, DORA and CRA - round table and field feedback
CRA duties as the round table framed them for software makers: reporting first, the product file next, and what a SaaS team can do before the dates.
Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm. Grimaldi Forum, a ten-minute pitch.
Book the workshopOur Assises workshopBY INDUSTRY · TECH & SAAS
You are a supplier to entities under NIS2 and DORA, a buyer of sub-processors, and a manufacturer under the CRA if you ship software products. Mindlapse keeps one verified control set for all three roles, and we publish our own posture on the same terms we ask of vendors.
ISO 27001 and SOC 2 · NIS2 supplier clauses · CRA reporting · Sub-processors assessed
SecurityScorecard · Bitsight · Scovery
Answer once through the portal; the action plan syncs to your queue when you run Mindlapse too.
THE SITUATION
SIG, CAIQ, DORA Art. 30 addenda, NIS2 supplier clauses; the answers live in last quarter’s spreadsheet.
Sub-processors, open-source dependencies and cloud concentration your customers want to see through you.
ISO 27001 plus SOC 2 plus sector schemes, overlapping controls audited separately by engineers who own them part-time.
Hosting location, extraterritorial exposure and where the AI runs, asked in every European deal.
WHO IS IN SCOPE
Cloud, data-centre, DNS, TLD, CDN and trust service providers, MSPs and MSSPs are NIS2 Annex I entities; online marketplaces, search engines and social platforms are important entities, and the NIS2 implementing regulation fixes their technical requirements and significant-incident thresholds (details on the NIS2 page). SaaS outside these lists is a supplier to entities in scope. Software placed on the market falls under the CRA, SaaS generally outside it unless it is remote data processing tied to a product; providers to financial entities carry DORA Art. 30 clauses.
Written for
WHAT MINDLAPSE CHANGES
Surface: Control Atlas
The frameworks relate to one control set; a control implemented and verified once answers each of them, with dated, reviewed evidence the auditor reads in place.
Learn more
Surface: Mindlapse Trust Grade
Each sub-processor carries a grade computed from its assessment, the business impact of the service it runs for you and external ratings, weights shown; your customers see you graded the same way.
Learn more
Surface: Security by Design
A new feature or a new sub-processor enters as an initiative with security requirements attached at design, routed by criticality and exposure. Mindlapse reads no repository and scans no code; it governs the decision.
Learn more
Surface: Supplier Hub
Control narratives and questionnaire answers drafted from what the platform already holds, sourced line by line, for a person to confirm; when the customer runs Mindlapse, the answer and the action plan synchronize on both sides.
Learn more
THE OBLIGATIONS MAP
EU rows first; every "verifies" cell is a product claim at ledger level, no cell carries a date (dates live on the CRA and NIS2 pages), and the sentence under the table is the site’s one dated source.
| Regulation | Obligation | What Mindlapse verifies | Surface |
|---|---|---|---|
| NIS2 | Art. 21(2)(d) · your customers’ supply-chain duty | Answer once through the portal when the customer runs Mindlapse; the verified Control Atlas otherwise | Supplier Hub |
| NIS2 | Art. 21 and the implementing regulation · providers in scope | The implementing regulation’s requirements mapped to one control set, each control with dated, reviewed evidence | Control Atlas |
| DORA | Art. 30 · contractual provisions with financial customers | Your ICT contract held as living register data on the customer’s side (contracts, criticality, dependencies); remediation as a joint action plan both sides accept, reject or counter-propose | Supplier Hub |
| CRA | Art. 14 · reporting duties (dates on the CRA page) | Severe incidents recorded and qualified; actively exploited vulnerabilities as risks and actions with owners; the notifications drafted by the cascade from the record and logged; you file them | Risk Register |
| AI Act | Art. 50 and provider duties · transparency and what a provider owes | AI risks in the same register as every other risk; the obligations carried as controls with cross-framework mapping | Risk Register |
| GDPR | Art. 28 · processor duties | Sub-processors assessed as suppliers in the context of the service they run; re-assessment when terms or sub-processors change | Supplier Hub |
NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026.
A QUARTER, THEN THE DAY A CUSTOMER ASKS
Four moments of an ordinary quarter in a SaaS company, and what the platform had already done; then the day a bank’s auditor asks, in three steps.
A normal quarter
WEEK 1
A customer running Mindlapse enrolled you on its portal.
Ernest drafted the answers from your own documents, sourced line by line; you confirmed them.
Surface: Supplier Hub
alert: WEEK 4
The SOC 2 evidence came up for re-verification.
Re-verified on its cycle; drift on one control was flagged with a dated verdict.
Surface: Control Atlas
WEEK 8
An actively exploited vulnerability in your product.
Recorded as a risk with an owner; its CRA notification opened as an action, drafted by the cascade for you to file.
Surface: Risk Register
verified: WEEK 12
The ISO auditor arrives.
Audit mode opened a scoped, read-only view of the verified controls and their evidence trail.
Surface: Control Atlas
The day the customer asks
THE REQUEST
A bank’s DORA auditor asks for your Art. 30 evidence and your sub-processor chain.
Both were read from the register: the sub-processors as assessed suppliers, the contract data the customer holds.
Surface: Supplier Hub
WHAT OPENS
The sub-processors as assessed suppliers, the verified controls, the joint action plan agreed with that customer.
Each sub-processor with its grade and its context; each control with its dated verdict; the plan with what both sides accepted.
Surface: Control Atlas
WHAT IS EXPORTED
The control narratives and the evidence.
Drafted by Ernest, sourced line by line, confirmed by you; synchronized on both sides when the customer runs Mindlapse.
Surface: Supplier Hub
Illustrative quarter: the moments are fictional, the surfaces are the product’s.
FROM THE FIELD
CYBER COLLECTIVE LAB · Edition 5
CRA duties as the round table framed them for software makers: reporting first, the product file next, and what a SaaS team can do before the dates.
CYBER COLLECTIVE LAB · Edition 1
Takeaways from the AI Action Summit, read from the provider’s side: where AI duties meet the rest of a software company’s obligations.
Measured with our design-partner CISOs, figures under continuous validation.
UNDER THE HOOD
FAQ
Not as an inbound workflow. When your customer runs Mindlapse you answer once through its portal and the action plans sync on both sides; otherwise the verified Control Atlas and the control narratives Ernest drafts from it, sourced line by line, are what you send.
No. Mindlapse reads no repository, runs no scanner and produces no SBOM; it holds the governance layer: the product record, its risk assessment, the CRA actions with owners, and what your engineering toolchain produces, kept as dated, reviewed evidence.
Generally not. The CRA covers products with digital elements placed on the market; a service delivered as SaaS sits outside it unless it is remote data processing tied to such a product, in which case that processing is in scope. Your financial customers reach you through DORA Art. 30 instead, your NIS2 customers through their supply-chain duty; the CRA page carries the dates and the entity test.
ISO 27001 is in progress and SOC 2 Type II is planned; neither is claimed before it is reached, and the trust center carries the dates. What holds today: customer data kept and processed inside the EU only, primary infrastructure in France, full isolation per tenant, and the evaluation pack, questionnaire, DPA and hosting attestations, on request under NDA.
In Europe, on open-source model foundations operated inside the EU. Your governance data never trains a model, on anyone’s side, each inference is traced, and Ernest proposes while a person confirms; the sources behind each draft are shown.
Read it next
Your Monday posture: risks, exceptions, suppliers and the pack, from one register.
Learn more
Security decided at the start, assisted by AI, proven at closure.
Learn more
Map every framework to one control set; prove it any day; run the incident cascade on one record.
Learn more
Also by outcome
GLOSSARY
TRUST, VERIFIED
A live session on your stack: frameworks, sub-processors, the auditor’s read-only view.
Our host’s audience measurement (Vercel) uses no cookies and is not covered by this choice. Google Analytics and marketing trackers stay off until you say otherwise. Read the cookie policy