Know what matters. See what Kaamos supports.
Use this as a practical information bank for EU regulations, assurance frameworks, and public-sector criteria. Supported frameworks are marked with a ribbon; the rest help you understand what buyers and regulators may ask for before you commit roadmap time.
Binding EU regulations
Legal regimes and directives that can bind EU software companies directly or through regulated customers.
- binding
DORA
EU regulation for ICT risk management and operational resilience in the financial sector.
- binding
EU AI Act
EU regulation for AI providers and deployers, with stronger duties for high-risk and general-purpose AI systems.
- Supportedbinding
GDPR
EU privacy regulation governing personal data processing, security, accountability, and data-subject rights.
- Supportedbinding
NIS2
EU cybersecurity directive for essential and important entities, including many digital providers and ICT service companies.
- binding
CRA
EU regulation introducing cybersecurity obligations for products with digital elements placed on the EU market.
- binding
MDR / IVDR
EU medical device and in vitro diagnostic regulations, including requirements for qualifying software.
- binding
DSA
EU regulation for intermediary, hosting, and online platform services offered to EU users.
- binding
ePrivacy
EU rules for cookies, tracking, electronic marketing, and confidentiality of electronic communications.
- binding
MiCA
EU regulation for crypto-asset issuers and crypto-asset service providers.
- binding
PSD2
EU directive for payment services, strong customer authentication, open banking, and operational requirements.
- binding
eIDAS 2.0
EU digital identity and trust-services regulation expanding the European Digital Identity framework.
Voluntary security frameworks
Voluntary frameworks that buyers ask for because they make security work auditable and repeatable.
- Supportedrecommended
ISO 27001
International standard for building and certifying an information security management system.
- recommended
ISO 42001
International management-system standard for organizations developing or using AI systems.
- Supportedrecommended
SOC 2
AICPA attestation used by enterprise buyers to evaluate security, availability, confidentiality, processing integrity, and privacy controls.
- recommended
ISO 27701
Privacy information management extension to ISO 27001 and ISO 27002.
- recommended
Cyber Essentials
UK cybersecurity certification focused on core technical controls.
- recommended
NIST CSF
Cybersecurity framework commonly used as a shared vocabulary for risk, controls, and maturity.
Public-sector and contractual criteria
Criteria that become binding through procurement, public-sector contracts, or payment networks.
- binding
PCI DSS
Payment-card security standard required by card networks for environments that store, process, or transmit cardholder data.
- binding
Julkri
Finnish public-administration security criteria for non-classified information and public-sector procurement.
- binding
Katakri
Finnish national security audit criteria used for classified information and high-assurance public-sector work.