CYBER COLLECTIVE LAB · Edition 5
Compliance: NIS2, DORA and CRA - round table and field feedback
What compliance leads asked about the overlap: the round table on NIS2, DORA and CRA, and the field feedback on mapping the three once.
Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm. Grimaldi Forum, a ten-minute pitch.
Book the workshopOur Assises workshopBY ROLE · COMPLIANCE & DPO
Four frameworks, three notification clocks and one team collecting the same screenshot for each auditor. Mindlapse maps every requirement to one control set, keeps each control’s evidence dated and reviewed, and runs the incident cascade on one record.
Map once, prove continuously · One incident, one cascade · Auditor read-only view
Frameworks in scope · 6 Controls · 1 240 Mappings · 4 512 Verified controls · 1 118 One control · three reporting duties
Art. 23 Reporting obligations
Art. 19 Major ICT incident reporting
Art. 33 Breach notification
A.5.24 · ISO/IEC 27001
Incident management planning and preparation
Evidence trail
Re-verified yesterday Fresh
CC7.3 Incident evaluation
RS.MA Incident management
Req. 12.10 Incident response
One incident procedure, implemented and verified once; the clocks start from one record.
THE SITUATION
ISO, NIS2, DORA and SOC 2 each want the access review, each in its own format, each from you.
The incident happened on Friday evening; by Monday three clocks are running and nobody has opened one.
The audit passed; the control drifted the month after, and nobody was told.
The DPA is signed, the sub-processor list is a PDF, and nobody has asked the provider a security question since.
WHAT MINDLAPSE CHANGES
Surface: Control Atlas
Every requirement of every framework in scope maps to one control set; a control implemented and verified once answers each framework that requires it, with the mapping type in the open.
Learn more
Surface: Control Atlas
Each artefact is validated on arrival, re-verified on its cycle and always dated and sourced; nothing is pulled from your infrastructure without you knowing, and a human confirms.
Learn more
Surface: Cyber Incidents
An incident is qualified once against each regime’s criteria; the cascade assesses, drafts the notification file and logs it, and your team files it.
Learn more
Surface: Supplier Hub
A processor answers through the portal, its answers are checked against the evidence it uploads, and a contradiction is flagged with the evidence.
Learn more
Surface: Control Atlas
Ernest verifies each claim against the evidence you upload or connect and your cyber knowledge graph, and shows its sources; you confirm.
Learn more
YOUR WEEK, YOUR QUARTER
Five moments a compliance lead recognises, and what the platform had already done when they arrived; then the three dates of the quarter that no longer begin with a collection.
Your week
MON 09:10
A control’s evidence passed its re-verification date.
Ernest validated the new artefact with its confidence shown; you confirmed it in a minute.
Surface: Control Atlas
TUE 14:00
A regulation was added to your scope.
A mapping review opened, with coverage computed from the controls you already run.
Surface: Control Atlas
alert: WED 18:45
An incident was classified against the regulatory criteria.
The cascade assessed it, drafted the notification file and logged every step; your team filed it.
Surface: Cyber Incidents
verified: THU 10:30
The auditor asked for their scope.
Audit mode opened a scoped, read-only view of the verified controls and their evidence trail.
Surface: Audit mode
FRI 16:20
A critical processor’s answer contradicted the evidence it uploaded.
The contradiction was flagged with the evidence, before anyone signed the renewal.
Surface: Supplier Hub
Your quarter
WEEK 2
Gap analysis.
By entity, scope and framework, from the controls already verified.
Surface: Control Atlas
WEEK 6
The policies are re-attested.
Published, versioned, attested by the people they bind.
Surface: Policies
WEEK 11
Regulatory status for the committee.
NIS2, DORA and GDPR status read in the cockpit, from the same controls.
Surface: Cyber Cockpit
Illustrative week: the moments are fictional, the surfaces are the product’s.
FROM THE FIELD
CYBER COLLECTIVE LAB · Edition 5
What compliance leads asked about the overlap: the round table on NIS2, DORA and CRA, and the field feedback on mapping the three once.
Measured with our design-partner CISOs, figures under continuous validation.
UNDER THE HOOD
FAQ
Not by pulling telemetry. It is continuous verification of evidence: each artefact is AI-validated on arrival, re-verified on its cycle and always dated and sourced; nothing is pulled from your infrastructure silently, and a human confirms every verdict.
No. The atlas carries GDPR-related control sets, intake scopes the privacy questions, and the cockpit reads the regulatory status; the register of processing activities and your DPIAs stay where you keep them.
DORA, NIS2, the CRA and the GDPR Article 33 and CERT Santé notifications: the incident is qualified once against each regime’s criteria, then the cascade assesses, drafts the notification file and logs it. Your team files it on the authority’s portal.
Yes, in Audit mode: a scoped, read-only view of the verified controls and their evidence trail, with the activity log; reports export when a document is required.
Mindlapse adds it to the atlas and maps its requirements to your existing control set, so nothing is re-implemented: coverage is computed from the controls you already run, and only the gaps become work.
Read it next
The register of information as living data, concentration on the chain, one control set for DORA and NIS2.
Learn more
Care pathways as the map, télémaintenance under due diligence, unpatchable devices governed.
Learn more
Every téléservice with a decision file, every obligation on one evidence base, hosted only in Europe.
Learn more
Also by outcome
EVIDENCE, VERIFIED
A live session on your scope: frameworks, evidence, the cascade, Audit mode.
Our host’s audience measurement (Vercel) uses no cookies and is not covered by this choice. Google Analytics and marketing trackers stay off until you say otherwise. Read the cookie policy