Compliance & EU sovereignty
Built for European regulation, not retrofitted for it
Most security stacks route through US clouds and US models, then work backwards toward EU compliance. Cryvanta starts from the other end: data, detections and the model can all stay inside Europe.
- Frameworks
- NIS2 · DORA · GDPR
- Residency
- EU only
- Model
- Bring your own
- Certification
- In progress
The clock
None of this is coming. It arrived.
Every date below is in the past. The question a European board is being asked now is not whether to prepare, but what evidence it can produce.
GDPR
25 May 2018
Applying for eight years
Security telemetry routinely contains personal data, which puts your detection stack inside the regulation rather than beside it.
NIS2
17 Oct 2024
Transposition deadline passed
The date by which member states had to bring the directive into national law. Enforcement now depends on your jurisdiction, not on the directive.
DORA
17 Jan 2025
Applying directly
A regulation rather than a directive — it applies as written across the Union, with no national transposition step in between.
Now
Today
Where that leaves you
All three are live. What we can help with is the testing, detection and evidence they expect you to have.
The frameworks
Where Cryvanta fits your obligations
We don't make you compliant on our own — no tool does. We give you the detection, testing and evidence that these frameworks expect you to have.
NIS2
Directive (EU) 2022/2555
NIS2 widens who counts as an essential or important entity and raises the bar on risk management, incident handling and reporting. Our pentest gives you testing evidence today; the AI SOC platform, in early access, builds the detection, response and evidence trail those obligations lean on.
- Continuous monitoring and detection
- Documented, timestamped incident handling
- Evidence you can hand to a regulator
DORA
Regulation (EU) 2022/2554
DORA holds financial entities and their ICT providers to operational-resilience standards — including resilience testing and monitoring. Our pentest supports the testing obligations; the AI SOC platform, in early access, supports the monitoring side. Formal TLPT under Articles 26–27 carries its own tester requirements — ask us where we stand.
- Penetration testing for your resilience programme
- Ongoing ICT-risk monitoring
- Incident detection and reporting support
GDPR
Regulation (EU) 2016/679
Security telemetry can contain personal data, so we treat it that way. Erasure and retention aren't a policy document bolted on afterwards — they're controls built into the platform.
- Right-to-erasure workflow
- Enforced audit-log retention windows
- Per-tenant data isolation
Data handling
Sovereignty as a default, not a tier
The things other vendors sell as an enterprise upgrade are how Cryvanta works out of the box.
Stays in the EU
Telemetry, findings and history are hosted in-region. Your security data doesn't have to cross the Atlantic to be useful.
Runs on your model
The AI analyst is provider-agnostic. Point it at an EU-hosted model and the reasoning stays sovereign too — not just the storage.
Erasable on request
A right-to-erasure workflow removes a subject's data in a single, audited transaction, with a dry-run before anything is deleted.
Retained on a schedule
Audit logs are held for exactly as long as your policy requires — enforced by the platform, not left to memory.
On certifications
We're building toward SOC 2 and formal certification, and we track those controls internally today. We're not certified yet, and we won't display a badge we haven't earned — we'll share our status openly instead. Cryvanta supports your compliance programme; it doesn't replace your own legal and regulatory judgement.

Talk through your regulatory picture
Tell us which frameworks you're accountable for and where your data has to live. We'll tell you clearly what we can help with — and what we can't.