---
title: "Compliance engineering"
description: "Gap reviews and evidence for ISO 27001, ENS, PCI DSS, NIS2, DORA and GDPR, connecting each control to the infrastructure and security services that support it."
url: https://www.noraina.cloud/services/compliance-engineering/
language: en
---
# Compliance engineering

We look at the certification you are preparing, find the controls our infrastructure and security services can support, and give you the evidence your auditor will ask for.

## Start from the control, not the product

Every framework asks for the same things in different words: continuity, backup, logging, access control, protection against attacks. We map each of our services to the specific controls it supports in ISO 27001, ENS, PCI DSS, NIS2, DORA and GDPR, so you can see the effect before you buy anything.

## Evidence included

Each service comes with the records an auditor expects: configuration exports, retention settings, test reports and logs.

## What stays on your side

Policies, risk assessment, training and management review are yours. We say so clearly in the gap review, and can introduce you to consultants we work with for the management-system part.

## Frequently asked questions

### Can Noraina certify my company in ISO 27001 or ENS?

No supplier can. Certification is granted by an accredited certification body after auditing your whole management system. Noraina supports specific technical controls with its services and gives you the evidence for them.

### What is a gap review?

A short engagement in which we compare the controls of the framework you are preparing with what you have today, and tell you which gaps our services close, which stay on your side and how long it will realistically take.

### Noraina holds ISO 27001. Why does that matter to us?

Because our operations are audited against the same standard, the services we provide come with documented processes your auditor can rely on.

Last updated: 2026-10-05
