Regulations · Beyond the SOC 2 checkbox
The regulations incumbents skip — proven from one evidence base.
DORA, NIS2, the Cyber Resilience Act and the Nordic schemes don't fit a SOC 2-shaped tool. Noru maps each one onto the controls and evidence you already collect, keeps the regulator's own clause on every mapping, and turns the incident clocks and testing cycles into work with an owner.
Companies that run their compliance program on Noru
The way this usually goes
US-built platforms cover SOC 2 and ISO well and treat DORA, NIS2 and CRA as an afterthought — if they cover them at all.
Every new regulation becomes a fresh spreadsheet, a fresh policy set and a fresh scramble.
The incident clocks live in a policy paragraph: nobody owns the twenty-four hours, and the register of information is a spreadsheet nobody has opened since it was filed.
The EU regulatory family
Built in, not bolted on.
DORA for the financial entity and for the ICT third parties it depends on, NIS2, the Cyber Resilience Act and PSD2 ship as frameworks in the same control library as ISO 27001 and SOC 2 — 31 frameworks in total, with the Nordic and national schemes a buyer in this market actually gets asked for.
DORA
DORA (ICT TPP)
DORA (Critical ICT TPP)
NIS2
EU Cyber Resilience Act
PSD2
Also in the library
- Svensk e-legitimation
- BSI C5
- ENS
- Cyber Essentials
“Choosing a Nordic player just like us over the larger American tools is a choice I am extremely happy with”
One control, many clauses
Implement once. Answer every regulator.
Every framework in the library is mapped onto one shared set of controls, and each mapping keeps the regulator's own clause reference and a note on what that regulator means by it. Implement the control once and the evidence you already collect for it answers every clause it is mapped to — so the second regulation costs a fraction of the first, and the third less again.
IAM-05
Logical Access Review
Organization performs account and access reviews on a quarterly basis; corrective action is taken where applicable.
Evidence: the quarterly access review from the identity provider sync, with the personnel record it was reconciled against.
ISO 27001
A.5.18
Access rights reviewed and adjusted at regular intervals
SOC 2
CC6.2 · CC6.3
Credentials registered and authorised; access reviewed and removed
NIS2
Art. 21(2)(i)
Access control policies as a cybersecurity risk-management measure
DORA
Art. 9(4)(c)
Access management policies and strong authentication for ICT systems
EU Cyber Resilience Act
Annex I, Part I (2)(d)
Protection from unauthorised access by appropriate control mechanisms
GDPR
Art. 32(1)(b)
Ongoing confidentiality of processing systems and services
Deadlines as live work
Incident clocks and testing cycles, opened as tasks.
DORA and NIS2 are not only control sets; they start clocks. An early warning within twenty-four hours of becoming aware of a significant incident. A major ICT incident notified to the supervisor. Threat-led penetration testing on a cycle. A register of information kept current. Noru holds these as work with an owner and a date on the audit calendar, tied to the incident, the test or the vendor record they are about, rather than as a paragraph in a policy.
- NIS2 Article 23 and DORA Article 19 notification steps tracked from awareness to final report
- DORA Article 26 threat-led penetration testing planned against the evidence it will produce
- DORA Article 28 register of information read from the vendor register, not typed in
Four ways evidence enters the vault
Proven from one evidence base.
A supervisor's question is answered by evidence, and the vault takes it four ways: synced from the providers you connect, mirrored from Noru's own registers, uploaded by a person, or detected in the document stores you already use. Every item is dated as it arrives, mapped to the controls it satisfies on the way in, and carries a fingerprint from the moment of capture — so the answer is the record, not a reconstruction.
4ways evidence reaches the vault, each one dated and mapped on arrival
Every item keeps what produced it and when it was captured
Data-source syncs
Configuration, access and logging evidence read from the provider APIs you connect — AWS, GCP, Azure, Entra ID, GitHub and the rest — dated as it arrives and mapped to the controls it satisfies on the way in.
Register mirrors
Noru's own structured records — the personnel directory, the privacy data map, the vendor register — mirrored into the vault as evidence, so a register that is already right does not have to be exported to count.
Manual uploads
Documents and offline activities no connector can observe — the signed contract, the board minute, the physical inspection — uploaded by a person and fingerprinted at capture like everything else.
Document integrations
Files detected in the document stores you already use — SharePoint, Google Drive, Confluence — with location and filename used to infer the control each supports before anyone maps it by hand.
Adding a regulation
The second regulator costs a fraction of the first.
The first framework builds the program: the controls, the evidence, the policies. Every one after it starts from what the first one built. Load the regulation, see which of its clauses your existing controls already answer, work the gap, let the evidence you already collect count, and export the report — with Cortex drafting the policy set the regulation expects against your program.
01 · Load
Turn the regulation on
Add DORA, NIS2 or the CRA to your program. Its requirements are already mapped onto the shared control library, each with the regulator's own clause reference.
02 · Overlap
See what already counts
The controls your ISO 27001 or SOC 2 program implements answer their mapped clauses immediately, with the evidence you already collect.
03 · Gap
Work only the new
What is genuinely new to this regulation — the incident clocks, the register of information, the resilience testing — arrives as tasks with owners.
04 · Evidence
Let the vault answer
Evidence keeps flowing from the same syncs, mirrors and uploads; Cortex drafts the policy set the regulation expects against your program for review.
05 · Report
Export the package
Framework status reads from the live program, and the audit package for that regulation and period bundles controls, evidence, policies and milestones.
Audit packages
Hand the supervisor a package, not a folder.
When the supervisor or the auditor asks, the answer is a package, not a folder: the controls in scope for that framework and that period, the evidence items that satisfy them, the policies and their acknowledgements, and the milestones of the audit itself, bundled from the program and exported. External audits keep their milestones on the calendar; internal audits keep their findings and schedule in the same place.
- One package per framework and period, assembled from the live program
- Evidence carries its capture fingerprint and provenance into the export
- External and internal audits, with milestones and findings, on one calendar
Who it's for
One system, every stakeholder
Compliance & GRC
Map a new regulation onto controls you already run — no parallel program per regulator.
Security & CISO
DORA, NIS2 and CRA obligations tied to real systems and live evidence, not a policy binder.
Legal & risk
Every requirement traced to the control that answers it and the clause it answers — with the notification clocks on a calendar, not in a paragraph.
Leadership
One evidence base that answers every regulator your market and sector require, and an audit package per framework when they ask.
What's included
Platform modules working together
This solution runs on the same system of record as everything else — add modules later without re-platforming.
Controls
Implement once, satisfy many
One control library, mapped across ISO 27001, SOC 2, GDPR and 30+ frameworks — the same evidence reused everywhere.
Evidence Vault
Never chase a screenshot again
Evidence collected continuously from your systems, versioned, tagged and linked to controls automatically.
Audits
Walk in already prepared
Plan internal and external audits against evidence that already exists, on a calendar the whole team can see.
Policies
Keep every policy acknowledged
AI-assisted drafting, versioning, approvals and acknowledgements, mapped to the controls they satisfy.
Works with
- more
Book a demo
See it on your own data.
A walkthrough against the regulation you are actually facing, with your questions answered by practitioners.
- 45 minutes, tailored to the frameworks and use cases you care about
- Answers from practitioners, not a sales script
- Leave with a concrete rollout plan — or a clear no-fit
FAQ
Frequently asked questions
What compliance leads in regulated Nordic and European companies ask before they add a second regulator.
Talk to usWhich regulations does Noru cover beyond SOC 2 and ISO?
DORA — for the financial entity and for ICT third-party providers, critical ones included — NIS2, the EU Cyber Resilience Act, PSD2 and GDPR, alongside SOC 2, ISO 27001, HIPAA, PCI DSS and 30+ frameworks in total, with national schemes such as Svensk e-legitimation, BSI C5 and ENS in the same library. Controls map once and reuse evidence across all of them.
We already have ISO 27001. How much extra work is DORA or NIS2?
Far less than starting over. Because controls and evidence are shared, adding DORA or NIS2 reuses what your ISO program already collects — Noru surfaces the overlap, and only the genuinely new requirements need work.
Do you handle sector-specific and national regulators?
Yes. Sector and national schemes — DORA for financial entities, NIS2 for essential and important entities, Svensk e-legitimation for Swedish e-ID providers under DIGG — live in the same control library and map onto your existing evidence the same way the generic frameworks do, each mapping keeping the regulator's own clause reference and guidance.
How current is the evidence when a regulator asks?
Evidence is synced continuously from your systems, mirrored from Noru's own registers, or uploaded, and every item is dated and fingerprinted as it arrives and linked to the requirements it satisfies. Framework status reads from that on the day, and an audit package for the framework and period bundles the controls, evidence, policies and milestones — not a snapshot reconstructed before an examination.


