Skip to content
Phalanx
roRequest a quote
Menu+

Compliance

One set of controls. Several regimes over it.

You do not keep four parallel folders for four auditors. The ISO 27001 controls are the base, and NIS2, CRA and SOC 2 lay over them, with their own requirements only where they genuinely differ.

ISO 27001

Annex A and clauses 4 to 10

The base everything else sits on. All 93 Annex A controls plus the 27 management system requirements, each with a document, an approval and an audit log entry.

  • Ingest the documentation you already have, from an archive or from your document library
  • Analysis that separates a control with no policy from one with a policy and no sign it is practised
  • Policies drafted for the missing controls, approved by a human before they go live
  • In platform editor, with version history and document export

NIS2

Article 21, points a to j

Mapped onto the ISO controls you already run rather than a separate document set. Plus the part ISO does not cover: the incident register and the statutory notification deadlines.

  • Per article view, showing the real state of each point
  • Incident register carrying the 24 and 72 hour deadlines, with overdue flagged
  • Final report, with the status flow through to closure

CRA

Regulation (EU) 2024/2847

Reporting obligations have been live since 11 September 2026. The module opens with scope determination, because most companies owe nothing and that has to be said before any clock starts.

  • Manufacturer role determination, recorded and dated including for the negative case
  • All four deadlines, from early warning to final report
  • SBOM ingestion, with vulnerabilities linked to the product they affect
  • Annex I laid over your active ISO controls

ISO 9001

Quality management system

The same document, approval and evidence flow as ISO 27001, for organisations running both systems.

  • Its own question set for the guided interview
  • The same approval rules and the same audit log

SOC 2

Trust Services Criteria

Criteria labelling where it matters: the alert filter, the scan checks, and the evidence attached to a report.

  • Scan checks carry the criterion they support
  • Evidence attaches to the audit report as structured snapshots

GDPR

Including Romanian Law 190/2018

The evidence workflow accepts any documentation under any framework label, and generated policies are written in the right national legal context.

  • Legal requirements register, linked to the controls that cover them
  • Policies drafted with the national references, not only the regulation articles
CRA

Automated checks

Scans scoped to the controls an auditor actually asks about.

This is not a generic penetration test. It is a set of checks that map directly onto controls, run monthly and on demand. Each failure becomes a finding carrying its framework label, and critical findings open a case on their own.

Automated checksCompliance
HTTP redirects to HTTPSISO 27001 A.10.1, NIS2 Art. 21(2)(d)
TLS certificate validity and expiryISO 27001 A.10.1, SOC 2 CC6.1
Weak protocols accepted, TLS 1.0 and 1.1ISO 27001 A.10.1, NIS2 Art. 21(2)(d)
HSTS header presentISO 27001 A.14.1, NIS2 Art. 21(2)(e)
Content Security PolicyISO 27001 A.14.2, SOC 2 CC6.1
Framing protectionISO 27001 A.14.1, SOC 2 CC6.1
Server version not disclosedISO 27001 A.12.6
CORS not wildcardedISO 27001 A.14.1, NIS2 Art. 21(2)(e)
Sensitive paths not exposedISO 27001 A.9.4
Cookie security attributesISO 27001 A.14.1
SPF record present and not permissiveISO 27001 A.13.2, NIS2 Art. 21(2)(h)
DMARC at quarantine or rejectISO 27001 A.13.2, NIS2 Art. 21(2)(h)

The evidence

An audit report is built from what happened, not from what was written about what happened.

A report can carry a policy document, a written summary, an uploaded file, or a snapshot of a real case as structured proof that incidents are genuinely being detected and managed. The report moves through review and approval, and the client receives the published version read only, with every piece of evidence attached and a document export.

Request a quote