---
title: "Compliance navigator: ISO 27001, ENS, PCI DSS, NIS2, DORA and GDPR"
description: "See which controls of your certification or regulation Noraina products and services support, and the audit evidence each one produces."
url: https://www.noraina.cloud/compliance/
language: en
---
# Compliance navigator: ISO 27001, ENS, PCI DSS, NIS2, DORA and GDPR

See which controls of your certification or regulation Noraina products and services support, and the audit evidence each one produces.

> Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.

Machine-readable dataset: https://www.noraina.cloud/compliance.json

## European by design

For many regulated companies, where data lives and who runs the platform matter as much as any control. Noraina is a European company, our platform runs in European data centres, and your data stays in the site you choose.

- Noraina Ltd is an Irish company, registered in Cork. Our contracts are under Irish law.
- Our platform runs in five data centres in Europe, operated by our own team: Dublin, Paris (two sites) and Barcelona inside the EU, and London in the UK.
- Your data stays where you put it. Our standard contract says we never transfer, store or process customer data outside the region you designate without your explicit consent.
- Efficient Cloud Backup stores its encrypted copies in the EU, with a key that neither we nor the storage provider know.
- We peer locally at INEX (Dublin), LINX (London) and France-IX (Paris).
- Our services support controls in European regulations, ENS, NIS2, DORA and GDPR, as well as ISO 27001, and our own operations are ISO 27001 certified.

Some of our services are built on providers headquartered outside Europe: Cloudflare, AWS, Microsoft Azure, Google Cloud and Wasabi. Each page says which one a service uses, and our privacy policy explains the safeguards for any transfer.

### A stack with no provider outside Europe

When your requirement is that every provider in the chain is European, we build it from our platform and our partner Bunny.net: servers in our EU data centres, with Bunny.net's CDN and Shield web application firewall in front. https://www.noraina.cloud/architectures/european-stack/

## ISO/IEC 27001:2022

International standard for information security management systems. References are Annex A control numbers.

15 controls supported.

### Efficient Cloud Instances with replication

- Control: 5.29 (Security during disruption); 5.30 (ICT readiness for business continuity); 8.14 (Redundancy of processing facilities)
- How we help: Your Hyper-V workloads run in one of our five data centres and replicate to a second site you choose, giving you a documented alternate processing facility with agreed recovery objectives.
- Evidence you get: Architecture and RPO/RTO statement, replication health reports, signed records of failover tests.
- Status: Mapping under review

### Efficient Cloud Backup

- Control: 8.13 (Information backup); 8.24 (Use of cryptography); 5.33 (Protection of records)
- How we help: Efficient Cloud Backup writes backups outside your cloud provider to Wasabi object storage, encrypted with a key only you hold and protected with Object Lock (WORM), so nobody can alter or delete them during the retention period, not even an attacker holding administrator credentials.
- Evidence you get: Backup policy settings, Object Lock retention configuration, restore test records.
- Status: Mapping under review

### Efficient Cloud DNS (NorainaDNS)

- Control: 5.29 (Security during disruption); 5.30 (ICT readiness for business continuity); 8.14 (Redundancy of processing facilities)
- How we help: Health checks switch records to a secondary service when the primary one fails, and on the Enterprise plan your zones are also authoritative on a redundant multi-cloud network, so name resolution has no single provider as a point of failure.
- Evidence you get: NS delegation showing both networks (Enterprise), zone and failover configuration (console or Terraform), health-check and failover event history.
- Status: Mapping under review

### Complete edge logging

- Control: 8.15 (Logging); 8.16 (Monitoring activities)
- How we help: Logpush streams every HTTP request, firewall event and Zero Trust access decision to the storage or SIEM you choose, such as R2, with the retention you define.
- Evidence you get: Logpush job inventory, retention settings, example investigation queries.
- Status: Mapping under review

### Application and DDoS protection

- Control: 8.20 (Network security); 8.26 (Application security requirements)
- How we help: WAF, bot management, API protection and DDoS mitigation in front of every internet-facing application.
- Evidence you get: Security configuration export, monthly threat reports, change history.
- Status: Mapping under review

### Zero Trust access and data protection

- Control: 5.15 (Access control rules); 8.5 (Secure authentication); 8.12 (Data leakage prevention); 8.22 (Segregation of networks); 8.23 (Web filtering)
- How we help: Access verifies every user and device before they reach an application, Gateway filters web and SaaS traffic, and DLP profiles stop sensitive data such as ID numbers or source code leaving through uploads, SaaS or AI tools.
- Evidence you get: Access policy export, DLP profiles and incidents, Gateway policy export, access logs.
- Status: Mapping under review


## Esquema Nacional de Seguridad (Real Decreto 311/2022)

Spain's mandatory security framework for the public sector and the companies that supply it. References are measures from Annex II of RD 311/2022.

14 controls supported.

### Efficient Cloud Instances with replication

- Control: op.cont.2 (Continuity plan); op.cont.3 (Periodic continuity tests); op.cont.4 (Alternative means)
- How we help: Provides the alternative means of processing your continuity plan relies on, and the periodic failover tests the plan has to include.
- Evidence you get: Continuity architecture document, failover test reports with dates and results.
- Status: Mapping under review

### Efficient Cloud Backup

- Control: mp.info.6 (Backups)
- How we help: Off-site, encrypted and immutable copies that can be restored when the original data is lost or encrypted by ransomware.
- Evidence you get: Backup scope and retention configuration, restore test records.
- Status: Mapping under review

### Efficient Cloud DNS (NorainaDNS)

- Control: op.cont.2 (Continuity plan); op.cont.4 (Alternative means); mp.s.4 (Denial-of-service protection)
- How we help: On the Enterprise plan, a second authoritative DNS network is an alternative means for a service every application depends on, and keeps your domains resolving if one provider is under a denial-of-service attack or has an outage.
- Evidence you get: NS delegation showing both networks (Enterprise), failover configuration, health-check and failover event history.
- Status: Mapping under review

### Complete edge logging

- Control: op.exp.8 (Activity logging); op.mon.3 (Surveillance)
- How we help: Records user and system activity at the edge and feeds continuous monitoring.
- Evidence you get: Log retention configuration and sample activity reports.
- Status: Mapping under review

### Application and DDoS protection

- Control: mp.s.2 (Protection of web services and applications); mp.s.4 (Denial-of-service protection); op.mon.1 (Intrusion detection)
- How we help: Protects web services and applications, mitigates denial-of-service attacks and detects intrusion attempts.
- Evidence you get: Security configuration export and monthly threat reports.
- Status: Mapping under review

### Zero Trust access and data protection

- Control: op.acc.2 (Access requirements); op.acc.4 (Access rights management); op.acc.6 (Authentication of internal users); mp.s.3 (Web browsing protection); mp.com.1 (Secure perimeter)
- How we help: Identity-based access to each application, strong authentication, web browsing protection and a secure perimeter without VPNs.
- Evidence you get: Access and Gateway policy exports, authentication logs.
- Status: Mapping under review


## PCI DSS v4.0.1

Security standard of the payment card industry for every system that stores, processes or transmits card data. References are PCI DSS requirement numbers; titles are our own summaries.

9 controls supported.

### Complete edge logging

- Control: 10.2.1 (Audit logs enabled and active); 10.5.1 (Audit log history kept for at least twelve months)
- How we help: Logpush sends every request, security event and access decision to storage you control, such as R2, retained for twelve months or more.
- Evidence you get: Logpush job inventory, retention settings, sample log queries.
- Status: Mapping under review

### Application and DDoS protection

- Control: 4.2.1 (Strong cryptography for card data over public networks); 6.4.2 (Automated protection of public-facing web applications); 6.4.3 (Inventory and authorisation of payment page scripts); 11.6.1 (Detection of unauthorised changes to payment pages)
- How we help: Cloudflare WAF is the automated solution in front of your public web applications, TLS is enforced at the edge, and Page Shield keeps an inventory of the scripts on your payment pages and alerts on unauthorised changes.
- Evidence you get: WAF configuration and blocked-attack reports, TLS settings, Page Shield script inventory and change alerts.
- Status: Mapping under review

### Zero Trust access and data protection

- Control: 1.3.1 (Inbound traffic to the card data environment restricted); 7.2.1 (Access granted by role and need to know); 8.4.2 (Multi-factor authentication for access to the card data environment)
- How we help: Systems in the card data environment are reachable only through Cloudflare Access, per role and with multi-factor authentication, with no inbound ports open to the internet.
- Evidence you get: Access policy export, authentication logs, tunnel configuration.
- Status: Mapping under review


## NIS2 Directive (EU) 2022/2555

EU directive on cybersecurity risk-management measures for essential and important entities. References are points of Article 21(2).

6 controls supported.

### Efficient Cloud Instances with replication

- Control: 21.2.c (Business continuity)
- How we help: A second site and tested failover are the disaster-recovery part of the measures NIS2 requires.
- Evidence you get: Disaster-recovery plan inputs, failover test reports.
- Status: Mapping under review

### Efficient Cloud Backup

- Control: 21.2.c (Business continuity); 21.2.h (Cryptography and encryption)
- How we help: Backup management with encryption, the part of NIS2 that decides whether you recover from ransomware.
- Evidence you get: Backup and retention configuration, restore test records.
- Status: Mapping under review

### Efficient Cloud DNS (NorainaDNS)

- Control: 21.2.c (Business continuity)
- How we help: Automates failover between services and, on the Enterprise plan, removes DNS as a single point of failure, part of the business continuity and disaster-recovery measures NIS2 requires.
- Evidence you get: DNS architecture description, failover configuration, failover event history.
- Status: Mapping under review

### Complete edge logging

- Control: 21.2.b (Incident handling)
- How we help: Complete logs are what make incident detection, analysis and reporting possible.
- Evidence you get: Log inventory and the queries used in incident handling.
- Status: Mapping under review

### Application and DDoS protection

- Control: 21.2.e (Security in acquisition)
- How we help: Virtual patching and API schema validation reduce exposure while vulnerabilities are being fixed.
- Evidence you get: WAF rule history and threat reports.
- Status: Mapping under review

### Zero Trust access and data protection

- Control: 21.2.i (Access control policies); 21.2.j (Multi-factor authentication and secured communications)
- How we help: Access control policies enforced per application, with multi-factor authentication and encrypted connections.
- Evidence you get: Access policy export and authentication logs.
- Status: Mapping under review


## DORA Regulation (EU) 2022/2554

EU regulation on digital operational resilience for the financial sector. References are articles of the regulation.

4 controls supported.

### Efficient Cloud Instances with replication

- Control: art.11 (Response and recovery); art.12 (Backup)
- How we help: A geographically separate recovery site with tested switchover supports your ICT response and recovery plans.
- Evidence you get: RPO/RTO statement, switchover test reports, site and provider details for your ICT third-party register.
- Status: Mapping under review

### Efficient Cloud Backup

- Control: art.12 (Backup)
- How we help: Backups held apart from your production systems and protected from change, with documented restoration procedures.
- Evidence you get: Backup policy settings, retention configuration, restore test records.
- Status: Mapping under review

### Efficient Cloud DNS (NorainaDNS)

- Control: art.11 (Response and recovery)
- How we help: Switches traffic to a secondary service automatically and, on the Enterprise plan, keeps critical domains resolvable through the failure of a single DNS provider, supporting the response and recovery arrangements DORA asks for.
- Evidence you get: DNS architecture description, failover configuration, failover event history.
- Status: Mapping under review

### Complete edge logging

- Control: art.10 (Detection)
- How we help: Edge logs and security events feed the mechanisms that detect anomalous activity.
- Evidence you get: Log inventory, alerting rules, retention settings.
- Status: Mapping under review

### Application and DDoS protection

- Control: art.9 (Protection and prevention)
- How we help: Protection and prevention controls at the edge for your customer-facing services.
- Evidence you get: Security configuration export and threat reports.
- Status: Mapping under review

### Zero Trust access and data protection

- Control: art.9 (Protection and prevention)
- How we help: Strong authentication and least-privilege access to ICT systems.
- Evidence you get: Access policy export and access logs.
- Status: Mapping under review


## GDPR (EU) 2016/679

EU regulation on the protection of personal data. References are articles of the regulation.

4 controls supported.

### Efficient Cloud Instances with replication

- Control: 32.1.b (Confidentiality); 32.1.c (Timely restoration of availability)
- How we help: Keeps systems that process personal data available and restorable after an incident in the primary site.
- Evidence you get: Recovery test reports for your Article 32 documentation.
- Status: Mapping under review

### Efficient Cloud Backup

- Control: 32.1.a (Pseudonymisation and encryption); 32.1.c (Timely restoration of availability)
- How we help: Encrypted backups that let you restore access to personal data in a timely manner.
- Evidence you get: Encryption and restore test records.
- Status: Mapping under review

### Efficient Cloud DNS (NorainaDNS)

- Control: 32.1.b (Confidentiality); 32.1.c (Timely restoration of availability)
- How we help: Automatic failover, and on the Enterprise plan a second authoritative DNS network, help keep services that process personal data available, and restore access quickly when a primary service fails.
- Evidence you get: NS delegation showing both networks (Enterprise), failover configuration and event history.
- Status: Mapping under review

### Complete edge logging

- Control: art.33 (Breach notification)
- How we help: Lets you establish what happened, and to which data, within the 72-hour notification window.
- Evidence you get: Log retention configuration, investigation runbook.
- Status: Mapping under review

### Application and DDoS protection

- Control: 32.1.b (Confidentiality)
- How we help: Keeps applications that process personal data available and protected against attack.
- Evidence you get: Threat reports for your Article 32 documentation.
- Status: Mapping under review

### Zero Trust access and data protection

- Control: 32.1.b (Confidentiality)
- How we help: Only authorised people reach personal data, and DLP blocks it from leaving through unapproved channels.
- Evidence you get: Access policy export, DLP incident reports.
- Status: Mapping under review

