Compliance
Where SentriKat stands against the frameworks that matter for EU security teams and regulated industries.
Last updated: 2026-04-16
GDPR
CompliantEU General Data Protection Regulation. SentriKat acts as data processor for SaaS customers; an on-premises deployment processes no personal data externally.
FADP (revFADP)
CompliantSwiss Federal Act on Data Protection. Equivalent safeguards to GDPR, applied to Swiss and EU residents.
NIS2 Directive
ReadyArticles 12 (EU vulnerability database) and 21 (risk-management measures). SentriKat ships signed NIS2 gap reports out of the box.
DORA
ReadyDigital Operational Resilience Act. SentriKat supports ICT risk management and third-party register reporting for regulated financial entities.
ISO/IEC 27001:2022
In progress (target Q4 2026)Information Security Management System. Gap assessment complete, external certification audit scheduled.
SOC 2 Type I
Planned (Q1 2027)Security, availability, and confidentiality Trust Services Criteria for the SaaS platform.
EU Cyber Resilience Act
ReadyMandatory from 11 September 2026. SentriKat publishes CycloneDX and SPDX SBOMs for every release and tracks vendor advisories for embedded components.
CISA BOD 22-01
ReadyKnown Exploited Vulnerabilities catalog. SentriKat ingests the CISA KEV feed daily and ships signed BOD 22-01 reports.
PCI-DSS v4.0
ReadyRelevant controls for vulnerability management (Req. 6, 11). SentriKat exports evidence in JSON and PDF with HMAC-SHA256 integrity.
Documents under NDA
The DPIA, full pen-test reports, and internal control narratives are available to enterprise prospects under a mutual NDA. Contact [email protected] to request access.