AI-generated image
Service area · Compliance & GRC

GRC & compliance with defensible audit-ready evidence

GRC is how an organisation governs security, measures its risk and proves compliance with evidence rather than assertion. DORA, NIS2, ENS and the AI Act each add their own obligations, but the governance, the risk register and the evidence trail underneath are shared. Most of the work is not the regulation — it is making the evidence defensible.

Built for regulated and demanding environments: governance, execution and defensible evidence.

Execution quality

“Security that runs”: operations + governance + auditability. We don’t stop at diagnosis: we close gaps, verify, and produce defensible evidence.

Enterprise

Coverage

8x5 · 16x5 · 24/7

By criticality and SLA

Evidence

Audit-ready

Control → record → review

Execution

Remediation

+ re-validation

Talk to an architect → Fast response · no commitment
← Back to services

What GRC & Compliance covers in practice

  • DORA consulting: governance, ICT risk, operational resilience, reporting and ICTL.
  • NIS2 readiness: classification (essential/important), measures and compliance plan.
  • ENS (Spain): implementation, categorisation, statement of applicability and audit.
  • ISO 27001: ISMS, SoA, risk assessment, policies, procedures and internal audit.
  • Third-party management: critical supplier assessment, evidence, SLAs and traceability.
  • Audit evidence: repository, ownership, review cadences, KPIs and tracking.

If your challenge is “comply and prove it”, we work with evidence and traceability: control → procedure → record → review → committee/audit.

If you need a comparative view to decide priorities, see our guide ENS vs ISO 27001 vs NIS2 vs DORA , where we explain differences, overlaps, applicability and where to start.

Why compliance stopped being a paperwork exercise

For years, complying meant having policies written in case somebody asked. That changed, and not because it became fashionable: it changed because lawmakers moved three specific pieces.

Accountability

NIS2 assigns approval and oversight of the measures to the management body, which can be held liable. The exposure no longer stops at the IT department.

Deadlines

An early warning within 24 hours, notification within 72, final report within a month. Those are not met by improvising on a Sunday night.

Third parties

DORA extends supervision to ICT providers. You can land in scope without being regulated, simply by supplying somebody who is.

That last point catches most people out. Hard2bit sees organisations pulled into scope by association: their customer is a financial entity or a public body, and suddenly controls are required that nobody had ever asked for. The customer does not wait — the questions arrive in the next procurement round.

Penalties stopped being symbolic too. NIS2 provides for up to 10 million euros or 2% of worldwide annual turnover for essential entities, and 7 million or 1.4% for important ones; the AI Act reaches 35 million or 7% for prohibited practices. In practice, though, the cost that shows up first is not the fine. It is the deal that stalls because there is nothing to show.

What makes audit evidence defensible

Most compliance programmes fail their first serious audit not because the controls are missing but because the proof is. Documentation describing what should happen is a claim. Evidence is what the process leaves behind when it actually happens. Four properties separate one from the other:

  • Generated, not written. The record is a by-product of doing the work, not a document produced afterwards to describe it.
  • Dated and owned. Every record carries when it happened and who is accountable. Anonymous evidence is not evidence.
  • Recurring on a cadence you can prove. A quarterly review is only quarterly if four of them exist.
  • Traceable in both directions. An auditor can go requirement → control → record, and back, without you narrating the journey.

A policy stating that access is reviewed quarterly is a claim. The signed quarterly review, with the accounts actually removed, is evidence. Hard2bit designs the flow so the second one is a by-product of normal operation, because compliance that depends on somebody remembering to document it will not survive a busy quarter.

What you must be able to prove, framework by framework

The question we get is rarely “what does the regulation say?” It is “what will they ask me to show?” This is what has to be ready, and for whom:

Framework Who it binds What you must be able to show To whom
NIS2 Essential and important entities across 18 sectors, by size and activity. Article 21 measures, an incident register showing the reporting deadlines were met, and proof that the management body approved and oversaw them. National competent authority
DORA Financial entities and their ICT providers. Applicable since January 2025. Register of information on third parties, digital operational resilience testing, and classification and reporting of major incidents. Financial supervisor
ENS Spanish public sector and anyone supplying it (RD 311/2022). System categorisation, Statement of Applicability, and certification for medium and high categories. Certification body and the public-sector client
ISO 27001 Voluntary, but required in practice by many tenders and contracts. An ISMS with defined scope, SoA, risk assessment, internal audit and management review. Certification auditor and your customers
AI Act Providers and deployers of AI systems in the EU, with obligations scaled by risk level. An inventory of AI systems and their classification, risk management and data quality for high-risk ones, and AI literacy for staff. Market surveillance authority

Indicative only, not legal advice. Actual applicability depends on the legal definition of entity type, the specific activity, thresholds and national transposition. For the in-depth comparison between frameworks see our guide ENS vs ISO 27001 vs NIS2 vs DORA; for the certification project itself, our ISO 27001 implementation service.

What’s included in this service area

  • Gap assessment and remediation roadmap
  • Policies, procedures and evidence
  • ICT and third-party risk management
  • Support for audits and security committees

How we work (from assessment to evidence)

  1. Step 1

    Gap assessment & scope

    Initial assessment against the target framework (DORA/NIS2/ENS/ISO) and actual scope.

  2. Step 2

    Roadmap & quick wins

    Readiness plan prioritised by risk, effort and dependencies.

  3. Step 3

    Implementation & evidence

    Policies, procedures, controls and audit-ready evidence.

  4. Step 4

    Governance & follow-up

    KPIs, committees, reviews, third parties and continuous improvement of the management system.

Regulatory impact evaluator (indicative)

Indicative (not legal advice). Designed to avoid “claiming applicability” and instead estimate likely frameworks by jurisdiction, sector, size and role (regulated / provider).

Important: actual applicability depends on legal definitions, activities, thresholds (e.g., NIS2), jurisdictions and contracts. Use it to prioritise the next step and prepare evidence.

DORA NIS2 ENS ISO 27001 GDPR

This estimation is used to prioritise work (assessment/roadmap). It does not replace legal analysis.

Result

We show indicative likelihood by framework + the most useful next step to produce evidence.

Impact level (operations / audit)

Complete the form to see the explanation.

Most likely frameworks (indicative)

Recommended next step

  • Complete the evaluator to get recommendations.

Typical deliverables (audit-ready)

  • Requirement → control → evidence map (traceability).
  • Controls catalog / SoA with owners and review cadences.
  • Risk-based roadmap (quick wins + milestones).

Review it in 30–45 min?

We’ll return a minimal scope, quick wins, and a short plan to build defensible evidence.

Request session

Response within 24h · no spam

FAQ (GRC & Compliance)

What does GRC actually cover?

Three things that most organisations run separately and should not. Governance is who decides, who is accountable and how that reaches the management body. Risk is a live register that drives decisions rather than a spreadsheet refreshed before an audit. Compliance is proving, with evidence, that the controls you claim are the controls you operate. Standards and regulations sit on top of that foundation — a certification project is a means, not the discipline itself. Where Hard2bit adds value is in building the foundation once so it serves every regime you fall under, instead of running a separate project per acronym.

What makes audit evidence defensible?

Four things, and documentation is not one of them on its own. Evidence is defensible when it is generated by the process rather than written about it; when it carries a date and a named owner; when there is a review cadence that demonstrably happened; and when an auditor can walk the chain backwards from requirement to control to record without you narrating it. A policy stating that access is reviewed quarterly is a claim. The signed quarterly review with the accounts removed is evidence.

Do we need ISO 27001 certification to comply with NIS2 or DORA?

No. Neither certifies, and that misunderstanding is expensive. NIS2 and DORA are supervised: what you must produce is evidence of measures and of reporting within the deadlines. ENS does require certification at medium and high category. ISO 27001 is voluntary, but it is the proof a customer or a tender accepts fastest, and it covers a large share of what NIS2 asks for in Article 21 — which is why it is usually the most economical place to start.

What are the penalties for non-compliance?

NIS2 provides for up to 10 million euros or 2% of worldwide annual turnover, whichever is higher, for essential entities, and 7 million or 1.4% for important ones. The AI Act reaches 35 million or 7% for prohibited practices. It also places approval and oversight of the measures with the management body, so the exposure no longer stops at the IT department. In practice, though, the cost that shows up first is not the fine — it is the contract that does not get signed because there is nothing to show.

We are a supplier and our customer is regulated. Does this apply to us?

Not directly, and yes in practice. DORA and NIS2 require regulated entities to control their supply chain, so the obligation reaches you through the contract even though the regulation does not name you. This is the most common way organisations find themselves in scope unexpectedly: the customer is a financial entity or a public body, and suddenly controls are required that nobody had asked for. The difference between handling it and losing the account is usually having prepared before the procurement questionnaire arrives.

What deadlines does NIS2 set for reporting an incident?

An early warning within 24 hours of becoming aware, a full incident notification within 72 hours, and a final report within one month. Those are not deadlines you meet by improvising on a Sunday night — they assume a classification procedure, a named responsible person and a channel already agreed with the authority. Building that before an incident is a fraction of the work of building it during one.

Does the AI Act affect us if we only use third-party AI?

It can. The regulation distinguishes between those who develop an AI system and those who deploy it, and deployers carry obligations of their own, including AI literacy for the staff operating it. The first step is not legal but inventory: knowing which AI systems exist in the organisation, who uses them and for what. In many companies that list does not exist, and tools contracted by business units surface that nobody has reviewed.

Is this for real audits or just documentation?

It is audit-oriented: each control maps to evidence, a review cadence, a named owner and traceability from requirement to control to record. Documentation not backed by real records collapses in the first serious audit, and it protects nothing in the meantime.

What if we are an ICT provider or a critical third party?

We cover supply-chain impact: provider classification, SLAs and controls, evidence, reporting and contractual obligations, with particular focus on DORA and NIS2 depending on your role and customer type. If you supply a financial entity, the register of information and the exit clauses stop being paperwork and become contract conditions.

What do we need to start?

A 30 to 45 minute scoping session covering jurisdictions, critical services, third parties, key customers and existing documentation. From there Hard2bit defines quick wins and a roadmap. You do not need to arrive with anything organised — part of the value of the session is organising it.

Services in this area

Talk to an expert →

Concepts from our cybersecurity glossary that connect directly with this service.

Is this service area a fit for your case?

We’ll run a short assessment to define scope, priorities, and a realistic roadmap.