Skip to content

Compliance & EU sovereignty

Built for European regulation, not retrofitted for it

Most security stacks route through US clouds and US models, then work backwards toward EU compliance. Cryvanta starts from the other end: data, detections and the model can all stay inside Europe.

Frameworks
NIS2 · DORA · GDPR
Residency
EU only
Model
Bring your own
Certification
In progress

The clock

None of this is coming. It arrived.

Every date below is in the past. The question a European board is being asked now is not whether to prepare, but what evidence it can produce.

  1. GDPR

    25 May 2018

    Applying for eight years

    Security telemetry routinely contains personal data, which puts your detection stack inside the regulation rather than beside it.

  2. NIS2

    17 Oct 2024

    Transposition deadline passed

    The date by which member states had to bring the directive into national law. Enforcement now depends on your jurisdiction, not on the directive.

  3. DORA

    17 Jan 2025

    Applying directly

    A regulation rather than a directive — it applies as written across the Union, with no national transposition step in between.

  4. Now

    Today

    Where that leaves you

    All three are live. What we can help with is the testing, detection and evidence they expect you to have.

The frameworks

Where Cryvanta fits your obligations

We don't make you compliant on our own — no tool does. We give you the detection, testing and evidence that these frameworks expect you to have.

NIS2

Directive (EU) 2022/2555

NIS2 widens who counts as an essential or important entity and raises the bar on risk management, incident handling and reporting. Our pentest gives you testing evidence today; the AI SOC platform, in early access, builds the detection, response and evidence trail those obligations lean on.

  • Continuous monitoring and detection
  • Documented, timestamped incident handling
  • Evidence you can hand to a regulator

DORA

Regulation (EU) 2022/2554

DORA holds financial entities and their ICT providers to operational-resilience standards — including resilience testing and monitoring. Our pentest supports the testing obligations; the AI SOC platform, in early access, supports the monitoring side. Formal TLPT under Articles 26–27 carries its own tester requirements — ask us where we stand.

  • Penetration testing for your resilience programme
  • Ongoing ICT-risk monitoring
  • Incident detection and reporting support

GDPR

Regulation (EU) 2016/679

Security telemetry can contain personal data, so we treat it that way. Erasure and retention aren't a policy document bolted on afterwards — they're controls built into the platform.

  • Right-to-erasure workflow
  • Enforced audit-log retention windows
  • Per-tenant data isolation

Data handling

Sovereignty as a default, not a tier

The things other vendors sell as an enterprise upgrade are how Cryvanta works out of the box.

Stays in the EU

Telemetry, findings and history are hosted in-region. Your security data doesn't have to cross the Atlantic to be useful.

Runs on your model

The AI analyst is provider-agnostic. Point it at an EU-hosted model and the reasoning stays sovereign too — not just the storage.

Erasable on request

A right-to-erasure workflow removes a subject's data in a single, audited transaction, with a dry-run before anything is deleted.

Retained on a schedule

Audit logs are held for exactly as long as your policy requires — enforced by the platform, not left to memory.

On certifications

We're building toward SOC 2 and formal certification, and we track those controls internally today. We're not certified yet, and we won't display a badge we haven't earned — we'll share our status openly instead. Cryvanta supports your compliance programme; it doesn't replace your own legal and regulatory judgement.

Talk through your regulatory picture

Tell us which frameworks you're accountable for and where your data has to live. We'll tell you clearly what we can help with — and what we can't.