VulnTrek's regulatory focus

The frameworks VulnTrek maps evidence to, the instruments we track without mapping, and the boundary between the two — stated plainly so a compliance reviewer can check it rather than take it on trust.

Frameworks we map evidence to

Mappings are presentation-only. Attaching a framework citation to a finding changes which references are shown and nothing else: severity, SLA, status, totals and audit history are untouched. One region is active per organisation. CERT-In (Directions 2022, India): India's strictest reporting clock: cyber incidents must be reported to CERT-In within 6 hours of noticing. VulnTrek keeps the continuous trail that makes a 6-hour submission possible. DPDP Act (India, 2023, India): Coarse, governance-level support for the reasonable-security-safeguards duty and the breach-intimation trail — deliberately not a control-by-control mapping. RBI (opt-in) (Sector overlay, India): Opt-in overlay for RBI-regulated banks and NBFCs. Adds RBI cyber-security framework citations alongside CERT-In — never inferred from region alone. NIS2 (EU 2022/2555, European Union): Map findings to NIS2 Art. 21 risk-management measures and DORA ICT-risk controls, with exportable evidence packs for auditors. DORA (ICT Risk, European Union): ICT risk management mapping for financial entities — correlate vulnerability data with DORA operational resilience requirements. CRA (EU 2024/2847, European Union): Cyber Resilience Act alignment for products with digital elements — link vulnerability handling, incident reporting and secure-by-design evidence to CRA obligations. BSI C5 (C5:2020, European Union): Control-coverage views aligned to BSI C5 OPS and CIS v8 — useful as a starting point for your GRC team, not a substitute for audit. VulnTrek does not hold a C5 attestation. EU CSA (Certification, European Union): EU Cybersecurity Act certification scaffolding — organise vulnerability evidence to support candidate EUCC / EUCS assurance evaluations. EU AI Act (EU 2024/1689, European Union): AI system inventory, Annex III use-case classification, risk management and post-market monitoring evidence — AI exposure is inventoried as a first-class surface class alongside cloud, code and OT. ISO 27001 (A.8.8, Global): Vulnerability lifecycle, SLA breach history and remediation trails formatted to support A.8.8 / CC7.1 evidence requests.

Regulatory horizon — tracked, not mapped

These instruments are on our watch list because they shape the market VulnTrek sells into. No citations are attached to findings, no readiness claim is made, and nothing here changes severity, SLA, status, totals or audit history. EU Cloud and AI Development Act (CADA) — Proposed. Proposed 3 June 2026 — not adopted; Parliament and Council still to decide. Would introduce a tiered sovereignty assurance framework for cloud and AI services sold in the EU, with stricter tiers aimed at public sector and critical-infrastructure buyers. It would land on data residency and hosting arrangements for EU customers. We keep the platform deployable as an isolated, region-pinned tenant instance and keep our subprocessor list accurate so residency questions are answerable with facts rather than intent. EU Cyber Solidarity Act — In force. In force since 4 February 2025. Establishes the European Cybersecurity Alert System, a cybersecurity emergency mechanism, an EU cybersecurity reserve of incident-response providers, and incident review and testing arrangements for highly critical sectors. It places no duties on VulnTrek and none on our customers as software buyers. It matters because organisations in healthcare, energy and transport are drawn into resilience testing and incident review, and a continuous vulnerability record is what they are asked to show.

Our own compliance posture — stated plainly

VulnTrek is an early-stage platform built by an independent security team. We are in active preparation for ISO 27001 and SOC 2 Type I; neither is certified yet and we do not publish a target date we cannot guarantee. Our current controls — encryption in transit and at rest, least-privilege access, audit logging and per-tenant isolation — are documented on our Security & Compliance page and reviewed on every release. Hosting region is a deployment-time choice agreed in the order form and DPA; it is operational, not a separate legal guarantee.

What these mappings are — and are not

India (CERT-In, DPDP, the opt-in RBI overlay), NIS2, DORA, CRA, EU CSA, the EU AI Act and BSI C5-oriented evidence mappings are available now; ISO 27001 certification evidence is on the roadmap. A region changes only which citations are shown — never severity, SLA, status, totals or audit history. Nothing on this page is a statement that VulnTrek, or your organisation, is certified or compliant. Mappings are paraphrased from the public framework texts for orientation. They are an informational aid, not legal advice, an attestation or a certification determination, and should be reviewed against your auditor's interpretation before any formal attestation.