CyberTwin
EUROPEAN UNION · DORA & NIS2

Your DORA register and NIS2 posture, from the configs you already run.

The Digital Operational Resilience Act and NIS2 both want evidence you can produce on demand — not a binder you rebuild every quarter. Upload your firewall, cloud and identity exports and CyberTwin builds your DORA ICT-risk register, scores your NIS2 and GDPR posture, and reconciles the DORA, NIS2, GDPR and US-state notification clocks on one board — every control labeled proven or modeled.

SCORED FROM YOUR UPLOADED CONFIGS · COVERAGE, NOT CERTIFICATION
DORADORA

Digital Operational Resilience Act — ICT risk management for EU financial entities.

NIS2NIS2

The expanded network + information security directive for essential/important entities.

GDPRGDPR

The data-protection regime whose breach clock reconciles alongside DORA + NIS2.

ISOISO 27001

The management-system backbone most EU programs map their controls onto.

CECyber Essentials

The UK baseline, scored alongside the EU set for cross-border programs.

Part of the 24 frameworks CyberTwin scores. Every control is labeled proven from your config or modeled from a crosswalk — a score built only on derived mappings is capped, because a crosswalk never masquerades as an audit.

The documents you hand the regulator.

DORA ICT-risk register

A populated register generated from your uploaded artifacts and dependency evidence — the on-demand evidence base for the ICT-risk register DORA requires, not a spreadsheet you maintain by hand. Coverage you can hand to counsel, not a certification.

The notification clocks, reconciled

DORA, NIS2, GDPR, US-state and SEC notification deadlines on one cited board, so an incident’s clocks are never tracked in five places.

NIS2 board-freeze certificate

A signed, dated attestation of your posture at a point in time — the tamper-evident record a board wants before it signs off.

Auditor evidence pack

Every control mapped to a concrete artifact, proven-vs-modeled labeled — show-me over trust-me, before the audit starts.

All generated from configs you already have — 1,917 deterministic checks across 37 vendors. No agent, no live scan, nothing fabricated. Decision support for your compliance function — never a filing determination or an accreditation CyberTwin holds.