Reconectando con el servidor

Mantén esta pestaña abierta: tu trabajo no se ha perdido.

No hemos podido reconectar

Recarga la página para continuar donde lo dejaste.

La sesión ha caducado

Vuelve a cargar la página para iniciar sesión de nuevo.

Spain's authority is now operating and tick-box channels are under review. Would yours hold up?Act now →
Corporate integrity ›

Information Security

ISO/IEC 27001:2022 with the NIS2 deadlines, and those of ten jurisdictions, watched for you

A breach does not wait until Monday. The shortest deadline in the catalogue is three hours —the early alert to Chile's ANCI— and then come the 24 and 72 hours of NIS2 and the GDPR, counted from different moments: the GDPR counts from awareness, the Chilean act from classification. Here you open the incident, the system works out from the country of the affected assets and the kind of data which authorities must be told, computes each clock separately and warns the named officer —by email, because the scenario is a Sunday at three in the morning. And the 93 controls are not typed in: twelve of them are already evidenced by another programme on the platform, with real, dated proof.

5 screens of the programme
app.dsacompliance.net Information Security
01The crisis first: the legal clocks running, and only then the maturity
02The 93 controls with the column nobody else has: where the evidence comes from
03One incident, three jurisdictions and five clocks computed for you
04How much of each law the standard covers and —above all— what it leaves out
05Auditor mode: scoped access, a window that expires by itself and a trail of everything viewed
DSA Compliance

Screens from DSA Compliance v6.2 in a demo environment. All data shown is fictitious.

The obligation, precisely

What the rule requires, and in which article

For information only, not legal advice. Always check against the consolidated text in force.

ISO/IEC 27001:2022, cl. 6.1.3
A statement of applicability over the 93 Annex A controls, justifying the inclusion or exclusion of each one and leaving none undecided.
Directive (EU) 2022/2555 (NIS2), art. 21 and 23
Risk-management measures, supply-chain security and notification to the CSIRT within 24 hours (early warning), 72 hours (notification) and one month (final report).
GDPR art. 32, 33 and 34
Technical and organisational measures appropriate to the risk, notification to the authority within 72 hours of becoming aware, and communication to data subjects where the risk is high.
Act 21.663 (Chile), art. 9
Early alert to ANCI within 3 hours of classifying the incident as having significant effect, and a final report within 15 working days.
Lei 13.709 (LGPD, Brazil), art. 48
Communication to the ANPD and to data subjects, within a reasonable period, of incidents that may bring relevant risk or harm.
Penalty regime

NIS2: up to €10,000,000 or 2 % of worldwide turnover for essential entities, with personal liability for the management body. GDPR art. 32: up to €10,000,000 or 2 %. Chilean Act 21.663: up to 20,000 UTM. And in several jurisdictions the penalty reaches the director personally, not only the company.

Rules it covers
ISO 27001Annex A · 2022NIS2EU 2022/2555RGPDArt. 32Ley 21.663ANCI · CL

The badges identify the obligation the program digitises. They are not certifications or conformity accreditations.

What it leaves as evidence

What gets handed over when somebody asks

  • Statement of applicability for the 93 controls, with decision, justification and owner
  • An editable file for the auditor: statement, coverage per legal framework, tests and incidents
  • Incident register with an insert-only timeline sealed by SHA-256 fingerprints
  • Acknowledgement of every notification to the authority, with the date sent against the deadline
  • Dated control tests: restores with their actual RTO, drills and access reviews
  • A trail of everything the external auditor looked at, with date and time
  • Security-notice channel log: what staff reported, when, and how each notice ended
  • Declared jurisdictions set against the countries where assets or incidents actually are
Who it applies to
Essential and important entities under NIS2, and their supply chain
Organisations processing personal data at scale, or special categories of it
Suppliers whose corporate customers require ISO 27001 by contract
Public-tender bidders whose specifications ask for a certificate in force
Groups with subsidiaries in several countries and a different notification deadline in each
International framework

This programme implements certifiable ISO standards. If your organisation already is, here you see which part is solved and which laws it covers in each country where you operate.

ISO 27001 · Information security
Frequently asked questions

What we get asked about Security

Does this certify ISO 27001?

No, and no software can. Certification is granted by an independent accredited body. What the programme does is prepare the system and gather the evidence so that audit can be passed, and hand it over in the format it is asked for.

How does it know who must be notified?

From the country of the affected assets and the kind of data compromised. Every obligation in the catalogue carries its legal basis, its authority, its deadline and the moment from which it is counted —which is not the same in every rule. If the starting datum is missing, awareness is used, which always yields the shortest deadline.

Do the 93 controls have to be typed in?

Not all of them. Around a quarter are already evidenced by another programme you have —training, supplier vetting, the processing register, the asset inventory, workplaces— with real, dated proof, and they recompute themselves.

Is holding ISO 27001 enough for NIS2?

It covers much of the ground, but not all of it. What NIS2 adds and has to be solved separately are the fixed notification deadlines, registration with the national authority and the express liability of the management body. The programme shows that gap instead of hiding it.

What is auditor mode?

A read-only access scoped to the modules within that audit's scope, with a mandatory expiry date and an insert-only record of everything the auditor looked at. It works the same for ISO 27001, for data protection and for health and safety, because a company is audited on several things at once.

How does a security notice reach you from the workforce?

Through three separate channels, and hardly anyone has the third. Two are inbound: the security notice — a laptop left on a train, an account still live after someone leaves — and suspected phishing, where what matters is the reporting rate. The third is outbound: nothing comes in through it; what goes out is what the organisation files with the CSIRT, the data authority or the supervisor, and every filing keeps its registration reference. Control A.6.8 asks for exactly that event-reporting channel.

How do I know a jurisdiction isn't slipping past me?

The programme cross-checks what the organisation has declared against the countries where it actually holds assets and has had incidents, and flags three different gaps: what is declared but the catalogue cannot yet measure, the countries where you operate without having declared anything, and — the one nobody shows — the countries our catalogue does not reach yet. That last one is stated in those words, because it is our gap and hiding it would be worse. Declaring or not declaring switches off no obligation: the law applies either way, and the deadline clock never looks at that tick box.

Vea Security running with their cases

A 30-minute guided demo on the real platform, or a one-hour assessment session with a consultant.

Other programmes from Corporate integrity
← The 21 programmes of the platform