NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian, Arabic and Chinese.See what’s new →
LEARN
Deep-dive guides to DORA, NIS2, ISO 27001, GDPR, SOC 2 and the EU AI Act: what each one actually requires, article by article, and how to evidence it.
Browse by subject
One hub per framework. Each walks the whole programme in the order the work happens, from scope through evidence, and pulls in the templates and comparisons at the point you need them. If you want the product rather than the reading, go to frameworks.
23 pagesDORAEverything on DORA in work order: scope and readiness, ICT risk governance, the register of information, incidents, resilience testing and audit evidence.20 pagesEU AI ActThe EU AI Act in the order you need it: who is in scope and from when, how systems are classified, what providers and deployers must document, and fines.14 pagesNIS2NIS2 from scope to audit: essential and important entities, the Article 21 measures, the overlap with ISO 27001 and DORA, costs, and management liability.12 pagesCyber Resilience ActThe Cyber Resilience Act for manufacturers, importers and distributors: who it covers, the 2026 and 2027 dates, essential requirements and penalties.7 pagesThird-party riskThird-party risk management end to end: the lifecycle, how to assess a vendor, what a security questionnaire should ask, and what DORA and NIS2 add on top.8 pagesISO 27001ISO 27001 in the order the work happens: how the 93 Annex A controls are organised, how the Statement of Applicability selects them, and choosing software.8 pagesSOC 2SOC 2 from the first buyer request to the report: what the attestation is, choosing criteria and report type, scoring readiness, and picking software.8 pagesGDPRVenvera's GDPR pages in working order: a compliance checklist to find the gaps, templates for the Article 30 register and DPIAs, and choosing software.7 pageseIDAS 2.0eIDAS 2.0 from scope to software: who must accept the EU Digital Identity Wallet, the 24 December 2027 deadline, cost, fines and a readiness checklist.7 pagesSolvency IISolvency II from the three pillars to the ORSA review: scope, Pillar 2 governance in Articles 41 to 49, what a supervisor tests, and choosing tools.3 pagesMiCAMiCA from capital to sanctions: the Annex IV capital floors and fixed overheads test that set the cost of authorisation, and the Article 111 penalty tiers.6 pagesHIPAAHIPAA in the order the work happens: covered entities and business associates, the Security Rule risk analysis and its template, and choosing software.6 pagesPCI DSSPCI DSS from scope to tooling: who must comply, which SAQ or ROC route applies, a checklist for the 12 requirements of v4.0.1, and how platforms compare.6 pagesUAE IAUAE IA in work order: designation, the always applicable core, the risk assessment that selects the rest, the P1 to P4 order, a checklist and cost.4 pagesSaudi NCA ECCSaudi NCA ECC in the order the work happens: what ECC-2:2024 asks in each domain, what the 2024 revision changed, what it costs and how to judge software.5 pagesSAMA CSFSAMA CSF from requirements to tooling: what the four domains and 32 subdomains ask for, why level 3 is a floor, what it costs and how to judge software.5 pagesNDPANigeria's NDPA in working order: duties section by section, the 200 data subject line for major importance, section 48 penalties, a checklist and software.3 pagesCMMC 2.0CMMC 2.0 in working order: which level your contract sets, drawing the CUI boundary, self-assessing the Level 2 practices, the POA&M and choosing software.2 pagesCyber EssentialsCyber Essentials from self-assessment to certificate: scope, the five NCSC technical controls, Cyber Essentials Plus, and which software fits a UK bid.2 pagesNIST CSF 2.0NIST CSF 2.0 as the work happens: rate the six functions against a target profile, read the gap, then choose software that scores maturity, not tick boxes.1 pagesFedRAMPFedRAMP under the 2026 Consolidated Rules: who is in scope, the six exclusions, Classes A to D, the Rev 5 and 20x paths, costs, and GovRAMP and CMMC.












































































































