Loading...
Loading...
COMPLIANCE
Twelve frameworks. 3 International, 3 European Union, 6 National.
ISO 27001 The international standard for information security management (ISO/IEC 27001:2022). Voluntary, so no fines, but enterprise clients often require it by contract. Common in SaaS and IT companies that handle sensitive data.
SOC 2 An attestation against the AICPA trust criteria, US in origin but used worldwide. Voluntary with no legal fines, yet it is the report enterprise buyers ask for before signing. Mainly for SaaS and cloud providers, especially those selling into the US.
CIS Controls v8 A prioritized set of best practices from the Center for Internet Security. Voluntary and unregulated, with no fines. Used as a practical baseline that maps into the regulated frameworks.
NIS2 EU Directive 2022/2555 covering cybersecurity across 18 critical sectors. Applicable since the 17 October 2024 transposition deadline, through each country's national law. Fines reach 10 million euros or 2 percent of global turnover for essential entities, with personal liability for management. It applies to medium and large entities in critical sectors and their key suppliers.
DORA EU Regulation 2022/2554 on ICT resilience for the financial sector, fully applicable since 17 January 2025. Financial entities face fines up to 2 percent of worldwide turnover and critical ICT providers up to 5 million euros per day. It covers roughly 22,000 EU financial entities and their critical ICT providers.
GDPR EU Regulation 2016/679 on personal data, in force since 25 May 2018, with Article 32 tying directly to what Spectre scans. Fines reach 20 million euros or 4 percent of global turnover. It applies to anyone processing the personal data of people in the EU, anywhere in the world.
ENS (Spain) Spain's security framework for public-sector systems, set by Royal Decree 311/2022 and supervised by the CCN. No fixed fines, but conformity is a precondition to win or keep public contracts. It binds the Spanish public sector and any private provider, local or foreign, that handles its information.
Cyber Essentials (UK) A UK government scheme run by the NCSC, built on five technical controls. Mandatory since October 2014 for government and MOD contracts involving sensitive data. No fines, but without it you cannot bid on those contracts, and private supply chains increasingly demand it.
NCA ECC (Saudi Arabia) The Essential Cybersecurity Controls from Saudi Arabia's NCA (ECC-2:2024), mandatory since 2018 and now expanding to the private sector. No fixed fines, but the NCA can order remediation and exclude you from government contracts. It applies to government, critical infrastructure, and increasingly private organizations.
NESA / IA (UAE) The UAE Information Assurance Standards from NESA, mandatory for in-scope entities since roughly 2012 to 2014. Enforced through audits rather than fixed fines. It covers UAE government and semi-government bodies and critical national infrastructure.
NIA (Qatar) Qatar's National Information Assurance framework from the NCSA, certification-based and mandatory for in-scope entities. Enforced through audit and certification, not fixed fines. It applies to government, critical infrastructure, and regulated organizations.
Cyber Trust Mark (Singapore) A risk-based certification from Singapore's CSA. Voluntary today but becoming mandatory between 2026 and 2027 for critical infrastructure owners, auditors, and licensed providers. No fines, but it will be required to operate in those roles.
Detect
Spectre scans your systems and surfaces what actually matters.
Remediate
Sentra fixes the issues safely and non-disruptively, with Vizati as the control layer.
Prove
Every change is cryptographically signed with a trail that's ready for your audits.