Compliance navigator: ISO 27001, ENS, PCI DSS, NIS2, DORA and GDPR
See which controls of your certification or regulation Noraina products and services support, and the audit evidence each one produces.
Which certification are you working towards?
Pick one to see which of its controls our services support, and the evidence you get for your auditor.
Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.
European by design
For many regulated companies, where data lives and who runs the platform matter as much as any control. Noraina is a European company, our platform runs in European data centres, and your data stays in the site you choose.
Some of our services are built on providers headquartered outside Europe: Cloudflare, AWS, Microsoft Azure, Google Cloud and Wasabi. Each page says which one a service uses, and our privacy policy explains the safeguards for any transfer.
A stack with no provider outside Europe
When your requirement is that every provider in the chain is European, we build it from our platform and our partner Bunny.net: servers in our EU data centres, with Bunny.net's CDN and Shield web application firewall in front.
Reference architecture- Noraina Ltd is an Irish company, registered in Cork. Our contracts are under Irish law.
- Our platform runs in five data centres in Europe, operated by our own team: Dublin, Paris (two sites) and Barcelona inside the EU, and London in the UK.
- Your data stays where you put it. Our standard contract says we never transfer, store or process customer data outside the region you designate without your explicit consent.
- Efficient Cloud Backup stores its encrypted copies in the EU, with a key that neither we nor the storage provider know.
- We peer locally at INEX (Dublin), LINX (London) and France-IX (Paris).
- Our services support controls in European regulations, ENS, NIS2, DORA and GDPR, as well as ISO 27001, and our own operations are ISO 27001 certified.
All frameworks
- ISO 27001
International standard for information security management systems.
15 controls supported
- ENS
Spain's mandatory security framework for the public sector and the companies that supply it.
14 controls supported
- PCI DSS
Security standard of the payment card industry for every system that stores, processes or transmits card data.
9 controls supported
- NIS2
EU directive on cybersecurity risk-management measures for essential and important entities.
6 controls supported
- DORA
EU regulation on digital operational resilience for the financial sector.
4 controls supported
- GDPR
EU regulation on the protection of personal data.
4 controls supported
Tell us what you are preparing for
We reply with the controls we can cover, what stays on your side, and a realistic timeline.