Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

BY ROLE · COMPLIANCE & DPO

Four auditors, one evidence base, no second collection.

Four frameworks, three notification clocks and one team collecting the same screenshot for each auditor. Mindlapse maps every requirement to one control set, keeps each control’s evidence dated and reviewed, and runs the incident cascade on one record.

Map once, prove continuously · One incident, one cascade · Auditor read-only view

Control Atlas · one control, three reporting duties Illustrative data

Frameworks in scope · 6 Controls · 1 240 Mappings · 4 512 Verified controls · 1 118 One control · three reporting duties

NIS2 Equivalent

Art. 23 Reporting obligations

Coverage 88 %
DORA Equivalent

Art. 19 Major ICT incident reporting

Coverage 86 %
GDPR-related set Related

Art. 33 Breach notification

Coverage 81 %
Control Verified

A.5.24 · ISO/IEC 27001

Incident management planning and preparation

Evidence trail

  • Incident response procedure 3 d
  • Tabletop exercise report 12 d
  • Notification templates 1 d

Re-verified yesterday Fresh

SOC 2 Related

CC7.3 Incident evaluation

Coverage 79 %
NIST CSF 2.0 Related

RS.MA Incident management

Coverage 74 %
PCI DSS 4.0 Partial

Req. 12.10 Incident response

Coverage 63 %
Equivalent Related Partial

One incident procedure, implemented and verified once; the clocks start from one record.

THE SITUATION

One screenshot, four binders, every quarter.

  1. The same control, four binders

    ISO, NIS2, DORA and SOC 2 each want the access review, each in its own format, each from you.

  2. Was it notifiable?

    The incident happened on Friday evening; by Monday three clocks are running and nobody has opened one.

  3. Evidence that was true in March

    The audit passed; the control drifted the month after, and nobody was told.

  4. Processors assessed by contract only

    The DPA is signed, the sub-processor list is a PDF, and nobody has asked the provider a security question since.

YOUR WEEK, YOUR QUARTER

Compliance is continuous when evidence ages visibly and every incident starts on one record.

Five moments a compliance lead recognises, and what the platform had already done when they arrived; then the three dates of the quarter that no longer begin with a collection.

A compliance week, then the quarter Illustrative data

Your week

  1. MON 09:10

    A control’s evidence passed its re-verification date.

    Ernest validated the new artefact with its confidence shown; you confirmed it in a minute.

    Surface: Control Atlas

  2. TUE 14:00

    A regulation was added to your scope.

    A mapping review opened, with coverage computed from the controls you already run.

    Surface: Control Atlas

  3. alert: WED 18:45

    An incident was classified against the regulatory criteria.

    The cascade assessed it, drafted the notification file and logged every step; your team filed it.

    Surface: Cyber Incidents

  4. verified: THU 10:30

    The auditor asked for their scope.

    Audit mode opened a scoped, read-only view of the verified controls and their evidence trail.

    Surface: Audit mode

  5. FRI 16:20

    A critical processor’s answer contradicted the evidence it uploaded.

    The contradiction was flagged with the evidence, before anyone signed the renewal.

    Surface: Supplier Hub

Your quarter

  1. WEEK 2

    Gap analysis.

    By entity, scope and framework, from the controls already verified.

    Surface: Control Atlas

  2. WEEK 6

    The policies are re-attested.

    Published, versioned, attested by the people they bind.

    Surface: Policies

  3. WEEK 11

    Regulatory status for the committee.

    NIS2, DORA and GDPR status read in the cockpit, from the same controls.

    Surface: Cyber Cockpit

Illustrative week: the moments are fictional, the surfaces are the product’s.

FROM THE FIELD

Built with the people the auditor calls first.

CYBER COLLECTIVE LAB · Edition 5

Compliance: NIS2, DORA and CRA - round table and field feedback

What compliance leads asked about the overlap: the round table on NIS2, DORA and CRA, and the field feedback on mapping the three once.

−50–70%
time-to-risk-decision
15–30%
cyber-budget optimization
2–3×
risk visibility across the organization

Measured with our design-partner CISOs, figures under continuous validation.

FAQ

Compliance asks

Do you monitor our controls automatically?

Not by pulling telemetry. It is continuous verification of evidence: each artefact is AI-validated on arrival, re-verified on its cycle and always dated and sourced; nothing is pulled from your infrastructure silently, and a human confirms every verdict.

Does it keep our GDPR processing records or run DPIAs?

No. The atlas carries GDPR-related control sets, intake scopes the privacy questions, and the cockpit reads the regulatory status; the register of processing activities and your DPIAs stay where you keep them.

Which regimes does the incident cascade cover?

DORA, NIS2, the CRA and the GDPR Article 33 and CERT Santé notifications: the incident is qualified once against each regime’s criteria, then the cascade assesses, drafts the notification file and logs it. Your team files it on the authority’s portal.

Can the auditor work inside the platform?

Yes, in Audit mode: a scoped, read-only view of the verified controls and their evidence trail, with the activity log; reports export when a document is required.

How do you add a framework we run that you do not list?

Mindlapse adds it to the atlas and maps its requirements to your existing control set, so nothing is re-implemented: coverage is computed from the controls you already run, and only the gaps become work.

EVIDENCE, VERIFIED

Bring one framework and one incident. Leave with both on one record.

A live session on your scope: frameworks, evidence, the cascade, Audit mode.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.