{
  "$comment": "Noraina services support these controls and produce evidence for them. Certification is granted by an accredited auditor. Entries with reviewed=false are drafts pending validation.",
  "publisher": "Noraina Ltd",
  "url": "https://www.noraina.cloud/compliance/",
  "language": "en",
  "generated": "2026-10-09",
  "frameworks": [
    {
      "id": "iso-27001",
      "name": "ISO/IEC 27001:2022",
      "short": "ISO 27001",
      "scope": "International standard for information security management systems.",
      "audience": "Any organisation that needs to show customers a certified security management system.",
      "referenceNote": "References are Annex A control numbers.",
      "controls": [
        {
          "id": "5.15",
          "title": "Access control rules"
        },
        {
          "id": "5.29",
          "title": "Security during disruption"
        },
        {
          "id": "5.30",
          "title": "ICT readiness for business continuity"
        },
        {
          "id": "5.33",
          "title": "Protection of records"
        },
        {
          "id": "8.5",
          "title": "Secure authentication"
        },
        {
          "id": "8.12",
          "title": "Data leakage prevention"
        },
        {
          "id": "8.13",
          "title": "Information backup"
        },
        {
          "id": "8.14",
          "title": "Redundancy of processing facilities"
        },
        {
          "id": "8.15",
          "title": "Logging"
        },
        {
          "id": "8.16",
          "title": "Monitoring activities"
        },
        {
          "id": "8.20",
          "title": "Network security"
        },
        {
          "id": "8.22",
          "title": "Segregation of networks"
        },
        {
          "id": "8.23",
          "title": "Web filtering"
        },
        {
          "id": "8.24",
          "title": "Use of cryptography"
        },
        {
          "id": "8.26",
          "title": "Application security requirements"
        }
      ]
    },
    {
      "id": "ens",
      "name": "Esquema Nacional de Seguridad (Real Decreto 311/2022)",
      "short": "ENS",
      "scope": "Spain's mandatory security framework for the public sector and the companies that supply it.",
      "audience": "Public bodies in Spain and any supplier providing them with ICT services.",
      "referenceNote": "References are measures from Annex II of RD 311/2022.",
      "controls": [
        {
          "id": "op.acc.2",
          "title": "Access requirements"
        },
        {
          "id": "op.acc.4",
          "title": "Access rights management"
        },
        {
          "id": "op.acc.6",
          "title": "Authentication of internal users"
        },
        {
          "id": "op.exp.8",
          "title": "Activity logging"
        },
        {
          "id": "op.mon.1",
          "title": "Intrusion detection"
        },
        {
          "id": "op.mon.3",
          "title": "Surveillance"
        },
        {
          "id": "op.cont.2",
          "title": "Continuity plan"
        },
        {
          "id": "op.cont.3",
          "title": "Periodic continuity tests"
        },
        {
          "id": "op.cont.4",
          "title": "Alternative means"
        },
        {
          "id": "mp.com.1",
          "title": "Secure perimeter"
        },
        {
          "id": "mp.info.6",
          "title": "Backups"
        },
        {
          "id": "mp.s.2",
          "title": "Protection of web services and applications"
        },
        {
          "id": "mp.s.3",
          "title": "Web browsing protection"
        },
        {
          "id": "mp.s.4",
          "title": "Denial-of-service protection"
        }
      ]
    },
    {
      "id": "pci-dss",
      "name": "PCI DSS v4.0.1",
      "short": "PCI DSS",
      "scope": "Security standard of the payment card industry for every system that stores, processes or transmits card data.",
      "audience": "Merchants, payment service providers and any company whose website or systems touch card payments.",
      "referenceNote": "References are PCI DSS requirement numbers; titles are our own summaries.",
      "controls": [
        {
          "id": "1.3.1",
          "title": "Inbound traffic to the card data environment restricted"
        },
        {
          "id": "4.2.1",
          "title": "Strong cryptography for card data over public networks"
        },
        {
          "id": "6.4.2",
          "title": "Automated protection of public-facing web applications"
        },
        {
          "id": "6.4.3",
          "title": "Inventory and authorisation of payment page scripts"
        },
        {
          "id": "7.2.1",
          "title": "Access granted by role and need to know"
        },
        {
          "id": "8.4.2",
          "title": "Multi-factor authentication for access to the card data environment"
        },
        {
          "id": "10.2.1",
          "title": "Audit logs enabled and active"
        },
        {
          "id": "10.5.1",
          "title": "Audit log history kept for at least twelve months"
        },
        {
          "id": "11.6.1",
          "title": "Detection of unauthorised changes to payment pages"
        }
      ]
    },
    {
      "id": "nis2",
      "name": "NIS2 Directive (EU) 2022/2555",
      "short": "NIS2",
      "scope": "EU directive on cybersecurity risk-management measures for essential and important entities.",
      "audience": "Medium and large companies in sectors such as energy, transport, health, digital infrastructure and manufacturing, and their suppliers.",
      "referenceNote": "References are points of Article 21(2).",
      "controls": [
        {
          "id": "21.2.b",
          "title": "Incident handling"
        },
        {
          "id": "21.2.c",
          "title": "Business continuity"
        },
        {
          "id": "21.2.e",
          "title": "Security in acquisition"
        },
        {
          "id": "21.2.h",
          "title": "Cryptography and encryption"
        },
        {
          "id": "21.2.i",
          "title": "Access control policies"
        },
        {
          "id": "21.2.j",
          "title": "Multi-factor authentication and secured communications"
        }
      ]
    },
    {
      "id": "dora",
      "name": "DORA Regulation (EU) 2022/2554",
      "short": "DORA",
      "scope": "EU regulation on digital operational resilience for the financial sector.",
      "audience": "Banks, insurers, investment firms, payment institutions and their critical ICT providers.",
      "referenceNote": "References are articles of the regulation.",
      "controls": [
        {
          "id": "art.9",
          "title": "Protection and prevention"
        },
        {
          "id": "art.10",
          "title": "Detection"
        },
        {
          "id": "art.11",
          "title": "Response and recovery"
        },
        {
          "id": "art.12",
          "title": "Backup"
        }
      ]
    },
    {
      "id": "gdpr",
      "name": "GDPR (EU) 2016/679",
      "short": "GDPR",
      "scope": "EU regulation on the protection of personal data.",
      "audience": "Any organisation processing personal data of people in the EU.",
      "referenceNote": "References are articles of the regulation.",
      "controls": [
        {
          "id": "32.1.a",
          "title": "Pseudonymisation and encryption"
        },
        {
          "id": "32.1.b",
          "title": "Confidentiality"
        },
        {
          "id": "32.1.c",
          "title": "Timely restoration of availability"
        },
        {
          "id": "art.33",
          "title": "Breach notification"
        }
      ]
    }
  ],
  "services": [
    {
      "id": "multi-dc-replication",
      "name": "Efficient Cloud Instances with replication",
      "category": "infrastructure",
      "summary": "Workloads run in one of our five data centres and replicate continuously to another of your choice, ready to fail over."
    },
    {
      "id": "immutable-offsite-backup",
      "name": "Efficient Cloud Backup",
      "category": "infrastructure",
      "summary": "Encrypted backups outside your cloud provider, in Wasabi object storage with Object Lock (WORM)."
    },
    {
      "id": "dns-redundancy",
      "name": "Efficient Cloud DNS (NorainaDNS)",
      "category": "infrastructure",
      "summary": "Your domains are served from a global anycast network with health-checked failover between origins, and on Enterprise from a redundant multi-cloud network as well."
    },
    {
      "id": "cloudflare-logging",
      "name": "Complete edge logging",
      "category": "security",
      "summary": "Cloudflare Enterprise Logpush keeps every request, security event and access decision, for as long as you need."
    },
    {
      "id": "cloudflare-app-security",
      "name": "Application and DDoS protection",
      "category": "security",
      "summary": "Cloudflare WAF, bot management, API protection and DDoS mitigation in front of every public application."
    },
    {
      "id": "cloudflare-zero-trust",
      "name": "Zero Trust access and data protection",
      "category": "security",
      "summary": "Cloudflare One verifies every user and device, filters web traffic and stops sensitive data from leaving."
    }
  ],
  "mappings": [
    {
      "service": "multi-dc-replication",
      "framework": "iso-27001",
      "controls": [
        "5.29",
        "5.30",
        "8.14"
      ],
      "contribution": "Your Hyper-V workloads run in one of our five data centres and replicate to a second site you choose, giving you a documented alternate processing facility with agreed recovery objectives.",
      "evidence": "Architecture and RPO/RTO statement, replication health reports, signed records of failover tests.",
      "reviewed": false
    },
    {
      "service": "multi-dc-replication",
      "framework": "ens",
      "controls": [
        "op.cont.2",
        "op.cont.3",
        "op.cont.4"
      ],
      "contribution": "Provides the alternative means of processing your continuity plan relies on, and the periodic failover tests the plan has to include.",
      "evidence": "Continuity architecture document, failover test reports with dates and results.",
      "reviewed": false
    },
    {
      "service": "multi-dc-replication",
      "framework": "nis2",
      "controls": [
        "21.2.c"
      ],
      "contribution": "A second site and tested failover are the disaster-recovery part of the measures NIS2 requires.",
      "evidence": "Disaster-recovery plan inputs, failover test reports.",
      "reviewed": false
    },
    {
      "service": "multi-dc-replication",
      "framework": "dora",
      "controls": [
        "art.11",
        "art.12"
      ],
      "contribution": "A geographically separate recovery site with tested switchover supports your ICT response and recovery plans.",
      "evidence": "RPO/RTO statement, switchover test reports, site and provider details for your ICT third-party register.",
      "reviewed": false
    },
    {
      "service": "multi-dc-replication",
      "framework": "gdpr",
      "controls": [
        "32.1.b",
        "32.1.c"
      ],
      "contribution": "Keeps systems that process personal data available and restorable after an incident in the primary site.",
      "evidence": "Recovery test reports for your Article 32 documentation.",
      "reviewed": false
    },
    {
      "service": "immutable-offsite-backup",
      "framework": "iso-27001",
      "controls": [
        "8.13",
        "8.24",
        "5.33"
      ],
      "contribution": "Efficient Cloud Backup writes backups outside your cloud provider to Wasabi object storage, encrypted with a key only you hold and protected with Object Lock (WORM), so nobody can alter or delete them during the retention period, not even an attacker holding administrator credentials.",
      "evidence": "Backup policy settings, Object Lock retention configuration, restore test records.",
      "reviewed": false
    },
    {
      "service": "immutable-offsite-backup",
      "framework": "ens",
      "controls": [
        "mp.info.6"
      ],
      "contribution": "Off-site, encrypted and immutable copies that can be restored when the original data is lost or encrypted by ransomware.",
      "evidence": "Backup scope and retention configuration, restore test records.",
      "reviewed": false
    },
    {
      "service": "immutable-offsite-backup",
      "framework": "nis2",
      "controls": [
        "21.2.c",
        "21.2.h"
      ],
      "contribution": "Backup management with encryption, the part of NIS2 that decides whether you recover from ransomware.",
      "evidence": "Backup and retention configuration, restore test records.",
      "reviewed": false
    },
    {
      "service": "immutable-offsite-backup",
      "framework": "dora",
      "controls": [
        "art.12"
      ],
      "contribution": "Backups held apart from your production systems and protected from change, with documented restoration procedures.",
      "evidence": "Backup policy settings, retention configuration, restore test records.",
      "reviewed": false
    },
    {
      "service": "immutable-offsite-backup",
      "framework": "gdpr",
      "controls": [
        "32.1.a",
        "32.1.c"
      ],
      "contribution": "Encrypted backups that let you restore access to personal data in a timely manner.",
      "evidence": "Encryption and restore test records.",
      "reviewed": false
    },
    {
      "service": "cloudflare-logging",
      "framework": "iso-27001",
      "controls": [
        "8.15",
        "8.16"
      ],
      "contribution": "Logpush streams every HTTP request, firewall event and Zero Trust access decision to the storage or SIEM you choose, such as R2, with the retention you define.",
      "evidence": "Logpush job inventory, retention settings, example investigation queries.",
      "reviewed": false
    },
    {
      "service": "cloudflare-logging",
      "framework": "ens",
      "controls": [
        "op.exp.8",
        "op.mon.3"
      ],
      "contribution": "Records user and system activity at the edge and feeds continuous monitoring.",
      "evidence": "Log retention configuration and sample activity reports.",
      "reviewed": false
    },
    {
      "service": "cloudflare-logging",
      "framework": "nis2",
      "controls": [
        "21.2.b"
      ],
      "contribution": "Complete logs are what make incident detection, analysis and reporting possible.",
      "evidence": "Log inventory and the queries used in incident handling.",
      "reviewed": false
    },
    {
      "service": "cloudflare-logging",
      "framework": "dora",
      "controls": [
        "art.10"
      ],
      "contribution": "Edge logs and security events feed the mechanisms that detect anomalous activity.",
      "evidence": "Log inventory, alerting rules, retention settings.",
      "reviewed": false
    },
    {
      "service": "cloudflare-logging",
      "framework": "gdpr",
      "controls": [
        "art.33"
      ],
      "contribution": "Lets you establish what happened, and to which data, within the 72-hour notification window.",
      "evidence": "Log retention configuration, investigation runbook.",
      "reviewed": false
    },
    {
      "service": "cloudflare-app-security",
      "framework": "iso-27001",
      "controls": [
        "8.20",
        "8.26"
      ],
      "contribution": "WAF, bot management, API protection and DDoS mitigation in front of every internet-facing application.",
      "evidence": "Security configuration export, monthly threat reports, change history.",
      "reviewed": false
    },
    {
      "service": "cloudflare-app-security",
      "framework": "ens",
      "controls": [
        "mp.s.2",
        "mp.s.4",
        "op.mon.1"
      ],
      "contribution": "Protects web services and applications, mitigates denial-of-service attacks and detects intrusion attempts.",
      "evidence": "Security configuration export and monthly threat reports.",
      "reviewed": false
    },
    {
      "service": "cloudflare-app-security",
      "framework": "nis2",
      "controls": [
        "21.2.e"
      ],
      "contribution": "Virtual patching and API schema validation reduce exposure while vulnerabilities are being fixed.",
      "evidence": "WAF rule history and threat reports.",
      "reviewed": false
    },
    {
      "service": "cloudflare-app-security",
      "framework": "dora",
      "controls": [
        "art.9"
      ],
      "contribution": "Protection and prevention controls at the edge for your customer-facing services.",
      "evidence": "Security configuration export and threat reports.",
      "reviewed": false
    },
    {
      "service": "cloudflare-app-security",
      "framework": "gdpr",
      "controls": [
        "32.1.b"
      ],
      "contribution": "Keeps applications that process personal data available and protected against attack.",
      "evidence": "Threat reports for your Article 32 documentation.",
      "reviewed": false
    },
    {
      "service": "cloudflare-zero-trust",
      "framework": "iso-27001",
      "controls": [
        "5.15",
        "8.5",
        "8.12",
        "8.22",
        "8.23"
      ],
      "contribution": "Access verifies every user and device before they reach an application, Gateway filters web and SaaS traffic, and DLP profiles stop sensitive data such as ID numbers or source code leaving through uploads, SaaS or AI tools.",
      "evidence": "Access policy export, DLP profiles and incidents, Gateway policy export, access logs.",
      "reviewed": false
    },
    {
      "service": "cloudflare-zero-trust",
      "framework": "ens",
      "controls": [
        "op.acc.2",
        "op.acc.4",
        "op.acc.6",
        "mp.s.3",
        "mp.com.1"
      ],
      "contribution": "Identity-based access to each application, strong authentication, web browsing protection and a secure perimeter without VPNs.",
      "evidence": "Access and Gateway policy exports, authentication logs.",
      "reviewed": false
    },
    {
      "service": "cloudflare-zero-trust",
      "framework": "nis2",
      "controls": [
        "21.2.i",
        "21.2.j"
      ],
      "contribution": "Access control policies enforced per application, with multi-factor authentication and encrypted connections.",
      "evidence": "Access policy export and authentication logs.",
      "reviewed": false
    },
    {
      "service": "cloudflare-zero-trust",
      "framework": "dora",
      "controls": [
        "art.9"
      ],
      "contribution": "Strong authentication and least-privilege access to ICT systems.",
      "evidence": "Access policy export and access logs.",
      "reviewed": false
    },
    {
      "service": "cloudflare-zero-trust",
      "framework": "gdpr",
      "controls": [
        "32.1.b"
      ],
      "contribution": "Only authorised people reach personal data, and DLP blocks it from leaving through unapproved channels.",
      "evidence": "Access policy export, DLP incident reports.",
      "reviewed": false
    },
    {
      "service": "cloudflare-app-security",
      "framework": "pci-dss",
      "controls": [
        "4.2.1",
        "6.4.2",
        "6.4.3",
        "11.6.1"
      ],
      "contribution": "Cloudflare WAF is the automated solution in front of your public web applications, TLS is enforced at the edge, and Page Shield keeps an inventory of the scripts on your payment pages and alerts on unauthorised changes.",
      "evidence": "WAF configuration and blocked-attack reports, TLS settings, Page Shield script inventory and change alerts.",
      "reviewed": false
    },
    {
      "service": "cloudflare-logging",
      "framework": "pci-dss",
      "controls": [
        "10.2.1",
        "10.5.1"
      ],
      "contribution": "Logpush sends every request, security event and access decision to storage you control, such as R2, retained for twelve months or more.",
      "evidence": "Logpush job inventory, retention settings, sample log queries.",
      "reviewed": false
    },
    {
      "service": "cloudflare-zero-trust",
      "framework": "pci-dss",
      "controls": [
        "1.3.1",
        "7.2.1",
        "8.4.2"
      ],
      "contribution": "Systems in the card data environment are reachable only through Cloudflare Access, per role and with multi-factor authentication, with no inbound ports open to the internet.",
      "evidence": "Access policy export, authentication logs, tunnel configuration.",
      "reviewed": false
    },
    {
      "service": "dns-redundancy",
      "framework": "iso-27001",
      "controls": [
        "5.29",
        "5.30",
        "8.14"
      ],
      "contribution": "Health checks switch records to a secondary service when the primary one fails, and on the Enterprise plan your zones are also authoritative on a redundant multi-cloud network, so name resolution has no single provider as a point of failure.",
      "evidence": "NS delegation showing both networks (Enterprise), zone and failover configuration (console or Terraform), health-check and failover event history.",
      "reviewed": false
    },
    {
      "service": "dns-redundancy",
      "framework": "ens",
      "controls": [
        "op.cont.2",
        "op.cont.4",
        "mp.s.4"
      ],
      "contribution": "On the Enterprise plan, a second authoritative DNS network is an alternative means for a service every application depends on, and keeps your domains resolving if one provider is under a denial-of-service attack or has an outage.",
      "evidence": "NS delegation showing both networks (Enterprise), failover configuration, health-check and failover event history.",
      "reviewed": false
    },
    {
      "service": "dns-redundancy",
      "framework": "nis2",
      "controls": [
        "21.2.c"
      ],
      "contribution": "Automates failover between services and, on the Enterprise plan, removes DNS as a single point of failure, part of the business continuity and disaster-recovery measures NIS2 requires.",
      "evidence": "DNS architecture description, failover configuration, failover event history.",
      "reviewed": false
    },
    {
      "service": "dns-redundancy",
      "framework": "dora",
      "controls": [
        "art.11"
      ],
      "contribution": "Switches traffic to a secondary service automatically and, on the Enterprise plan, keeps critical domains resolvable through the failure of a single DNS provider, supporting the response and recovery arrangements DORA asks for.",
      "evidence": "DNS architecture description, failover configuration, failover event history.",
      "reviewed": false
    },
    {
      "service": "dns-redundancy",
      "framework": "gdpr",
      "controls": [
        "32.1.b",
        "32.1.c"
      ],
      "contribution": "Automatic failover, and on the Enterprise plan a second authoritative DNS network, help keep services that process personal data available, and restore access quickly when a primary service fails.",
      "evidence": "NS delegation showing both networks (Enterprise), failover configuration and event history.",
      "reviewed": false
    }
  ]
}