Noru

Regulations · Beyond the SOC 2 checkbox

The regulations incumbents skip — proven from one evidence base.

DORA, NIS2, the Cyber Resilience Act and the Nordic schemes don't fit a SOC 2-shaped tool. Noru maps each one onto the controls and evidence you already collect, keeps the regulator's own clause on every mapping, and turns the incident clocks and testing cycles into work with an owner.

Companies that run their compliance program on Noru

The way this usually goes

US-built platforms cover SOC 2 and ISO well and treat DORA, NIS2 and CRA as an afterthought — if they cover them at all.

Every new regulation becomes a fresh spreadsheet, a fresh policy set and a fresh scramble.

The incident clocks live in a policy paragraph: nobody owns the twenty-four hours, and the register of information is a spreadsheet nobody has opened since it was filed.

The EU regulatory family

Built in, not bolted on.

DORA for the financial entity and for the ICT third parties it depends on, NIS2, the Cyber Resilience Act and PSD2 ship as frameworks in the same control library as ISO 27001 and SOC 2 — 31 frameworks in total, with the Nordic and national schemes a buyer in this market actually gets asked for.

  • DORADORA
  • DORA (ICT TPP)DORA (ICT TPP)
  • DORA (Critical ICT TPP)DORA (Critical ICT TPP)
  • NIS2NIS2
  • EU Cyber Resilience ActEU Cyber Resilience Act
  • PSD2PSD2

Also in the library

  • Svensk e-legitimation
  • BSI C5
  • ENS
  • Cyber Essentials
Choosing a Nordic player just like us over the larger American tools is a choice I am extremely happy with
Brickanta

One control, many clauses

Implement once. Answer every regulator.

Every framework in the library is mapped onto one shared set of controls, and each mapping keeps the regulator's own clause reference and a note on what that regulator means by it. Implement the control once and the evidence you already collect for it answers every clause it is mapped to — so the second regulation costs a fraction of the first, and the third less again.

IAM-05

Logical Access Review

Organization performs account and access reviews on a quarterly basis; corrective action is taken where applicable.

Evidence: the quarterly access review from the identity provider sync, with the personnel record it was reconciled against.

  • ISO 27001

    ISO 27001

    A.5.18

    Access rights reviewed and adjusted at regular intervals

  • SOC 2

    SOC 2

    CC6.2 · CC6.3

    Credentials registered and authorised; access reviewed and removed

  • NIS2

    NIS2

    Art. 21(2)(i)

    Access control policies as a cybersecurity risk-management measure

  • DORA

    DORA

    Art. 9(4)(c)

    Access management policies and strong authentication for ICT systems

  • EU Cyber Resilience Act

    EU Cyber Resilience Act

    Annex I, Part I (2)(d)

    Protection from unauthorised access by appropriate control mechanisms

  • GDPR

    GDPR

    Art. 32(1)(b)

    Ongoing confidentiality of processing systems and services

Audit/Calendar
3 need review

Deadlines as live work

Incident clocks and testing cycles, opened as tasks.

DORA and NIS2 are not only control sets; they start clocks. An early warning within twenty-four hours of becoming aware of a significant incident. A major ICT incident notified to the supervisor. Threat-led penetration testing on a cycle. A register of information kept current. Noru holds these as work with an owner and a date on the audit calendar, tied to the incident, the test or the vendor record they are about, rather than as a paragraph in a policy.

  • NIS2 Article 23 and DORA Article 19 notification steps tracked from awareness to final report
  • DORA Article 26 threat-led penetration testing planned against the evidence it will produce
  • DORA Article 28 register of information read from the vendor register, not typed in

Four ways evidence enters the vault

Proven from one evidence base.

A supervisor's question is answered by evidence, and the vault takes it four ways: synced from the providers you connect, mirrored from Noru's own registers, uploaded by a person, or detected in the document stores you already use. Every item is dated as it arrives, mapped to the controls it satisfies on the way in, and carries a fingerprint from the moment of capture — so the answer is the record, not a reconstruction.

4ways evidence reaches the vault, each one dated and mapped on arrival

Every item keeps what produced it and when it was captured

  • Data-source syncs

    Configuration, access and logging evidence read from the provider APIs you connect — AWS, GCP, Azure, Entra ID, GitHub and the rest — dated as it arrives and mapped to the controls it satisfies on the way in.

  • Register mirrors

    Noru's own structured records — the personnel directory, the privacy data map, the vendor register — mirrored into the vault as evidence, so a register that is already right does not have to be exported to count.

  • Manual uploads

    Documents and offline activities no connector can observe — the signed contract, the board minute, the physical inspection — uploaded by a person and fingerprinted at capture like everything else.

  • Document integrations

    Files detected in the document stores you already use — SharePoint, Google Drive, Confluence — with location and filename used to infer the control each supports before anyone maps it by hand.

Adding a regulation

The second regulator costs a fraction of the first.

The first framework builds the program: the controls, the evidence, the policies. Every one after it starts from what the first one built. Load the regulation, see which of its clauses your existing controls already answer, work the gap, let the evidence you already collect count, and export the report — with Cortex drafting the policy set the regulation expects against your program.

01 · Load

Turn the regulation on

Add DORA, NIS2 or the CRA to your program. Its requirements are already mapped onto the shared control library, each with the regulator's own clause reference.

02 · Overlap

See what already counts

The controls your ISO 27001 or SOC 2 program implements answer their mapped clauses immediately, with the evidence you already collect.

03 · Gap

Work only the new

What is genuinely new to this regulation — the incident clocks, the register of information, the resilience testing — arrives as tasks with owners.

04 · Evidence

Let the vault answer

Evidence keeps flowing from the same syncs, mirrors and uploads; Cortex drafts the policy set the regulation expects against your program for review.

05 · Report

Export the package

Framework status reads from the live program, and the audit package for that regulation and period bundles controls, evidence, policies and milestones.

The next regulation starts from the controls and evidence this one added

Audit packages

Hand the supervisor a package, not a folder.

When the supervisor or the auditor asks, the answer is a package, not a folder: the controls in scope for that framework and that period, the evidence items that satisfy them, the policies and their acknowledgements, and the milestones of the audit itself, bundled from the program and exported. External audits keep their milestones on the calendar; internal audits keep their findings and schedule in the same place.

  • One package per framework and period, assembled from the live program
  • Evidence carries its capture fingerprint and provenance into the export
  • External and internal audits, with milestones and findings, on one calendar
Audit/Packages · DORA

Who it's for

One system, every stakeholder

Compliance & GRC

Map a new regulation onto controls you already run — no parallel program per regulator.

Security & CISO

DORA, NIS2 and CRA obligations tied to real systems and live evidence, not a policy binder.

Legal & risk

Every requirement traced to the control that answers it and the clause it answers — with the notification clocks on a calendar, not in a paragraph.

Leadership

One evidence base that answers every regulator your market and sector require, and an audit package per framework when they ask.

Book a demo

See it on your own data.

A walkthrough against the regulation you are actually facing, with your questions answered by practitioners.

  • 45 minutes, tailored to the frameworks and use cases you care about
  • Answers from practitioners, not a sales script
  • Leave with a concrete rollout plan — or a clear no-fit

We respond within one business day. No mailing lists, no spam.

FAQ

Frequently asked questions

What compliance leads in regulated Nordic and European companies ask before they add a second regulator.

Talk to us

Which regulations does Noru cover beyond SOC 2 and ISO?

DORA — for the financial entity and for ICT third-party providers, critical ones included — NIS2, the EU Cyber Resilience Act, PSD2 and GDPR, alongside SOC 2, ISO 27001, HIPAA, PCI DSS and 30+ frameworks in total, with national schemes such as Svensk e-legitimation, BSI C5 and ENS in the same library. Controls map once and reuse evidence across all of them.

We already have ISO 27001. How much extra work is DORA or NIS2?

Far less than starting over. Because controls and evidence are shared, adding DORA or NIS2 reuses what your ISO program already collects — Noru surfaces the overlap, and only the genuinely new requirements need work.

Do you handle sector-specific and national regulators?

Yes. Sector and national schemes — DORA for financial entities, NIS2 for essential and important entities, Svensk e-legitimation for Swedish e-ID providers under DIGG — live in the same control library and map onto your existing evidence the same way the generic frameworks do, each mapping keeping the regulator's own clause reference and guidance.

How current is the evidence when a regulator asks?

Evidence is synced continuously from your systems, mirrored from Noru's own registers, or uploaded, and every item is dated and fingerprinted as it arrives and linked to the requirements it satisfies. Framework status reads from that on the day, and an audit package for the framework and period bundles the controls, evidence, policies and milestones — not a snapshot reconstructed before an examination.