Back

Governance, Risk and Compliance (GRC) platform for NIS2, DORA and the EU AI Act, with multi-framework control mapping and cybersecurity integration

1. Title

Governance, Risk and Compliance (GRC) platform for NIS2, DORA and the EU AI Act, with multi-framework control mapping and cybersecurity integration

2. Short Summary

CyberPal Tech, a Romanian cybersecurity SME offers Griffin, a cybersecurity platform that includes a dedicated GRC workspace, Horizon Compliance, designed to help organisations manage cybersecurity and regulatory compliance requirements across multiple frameworks, including NIS2, DORA, the EU AI Act, GDPR, ISO 27001 and NIST.

The platform enables organisations to map common internal controls across multiple regulatory frameworks, perform gap assessments, monitor remediation actions and generate compliance reports. Its GRC capabilities are integrated with cybersecurity functionalities such as attack-surface management, threat modelling and AI-assisted analysis of security data.

The company is seeking international partners, particularly compliance consultants, GRC integrators, cybersecurity consultancies, audit firms and risk management service providers, for technical and commercial cooperation.

3. Full Description of the Technology

Griffin is a cybersecurity platform developed by a Romanian SME, incorporating Horizon Compliance, a GRC workspace designed to help organisations assess, document and continuously monitor cybersecurity and regulatory compliance requirements for defined legal entities.

The solution addresses the complexity faced by organisations that need to comply simultaneously with multiple European regulations, cybersecurity standards and risk management frameworks. Its catalogue currently maps 17 instruments, including NIS2, DORA, the EU AI Act, GDPR, PCI-DSS, SOX, SEC Cyber, ISO 27001/27002/22301/31000, NIST CSF and SP 800-53, SOC 2, CIS and COBIT, with additional frameworks continuously incorporated.

A key functionality is multi-framework control mapping. Instead of assessing each framework independently, organisations can work with a shared set of universal controls and subcontrols. A single remediation action can therefore address gaps affecting several regulatory instruments, reducing duplicated compliance work.

The GRC workspace enables users to:

• onboard organisational profiles, including critical or important functions, ICT processes and third-party dependencies;

• define applicable regulatory and cybersecurity frameworks;

• configure compliance assessment scope, including DORA source filters such as Articles, obligations, RTS and ITS;

• assess and document controls and subcontrols, including evidence status and supporting notes;

• map common controls against multiple regulatory requirements;

• perform gap assessments at requirement, control and subcontrol level;

• identify, prioritise and track remediation actions;

• monitor compliance progress through dashboards and posture scores;

• generate on-demand and scheduled compliance and management reports;

• perform recurring external intelligence scans based on the organisation’s compliance profile;

• use AI-assisted capabilities to analyse exposure, assets, findings and related security data.

The GRC functionality is complemented by cybersecurity capabilities covering vulnerability management, penetration testing, attack-surface management, threat intelligence and security monitoring. This enables compliance processes to be connected with actual cybersecurity findings, vulnerabilities and organisational risks.

The technology can therefore be integrated into existing compliance, audit, cybersecurity and risk management services, providing partners with a digital environment for managing assessments, controls, evidence, gaps and remediation activities.

4. Advantages and Innovations

Multi-framework control mapping, allowing a common control to address requirements from several regulatory and cybersecurity frameworks;

Consolidated gap assessment at requirement, control and subcontrol level, with prioritisation and tracking of corrective actions;

Continuous compliance intelligence, combining practitioner-led assessments with recurring external intelligence scans;

Integration of GRC and cybersecurity information, connecting compliance requirements with vulnerabilities, exposure and security findings;

AI-assisted analysis of compliance and cybersecurity data to support the interpretation of findings and prioritisation of actions;

Catalogue-driven and modular architecture, allowing the incorporation of additional regulatory frameworks, industries and customer requirements;

• Support for major European regulatory requirements, including NIS2, DORA and the EU AI Act, alongside internationally recognised cybersecurity frameworks;

Integration with existing professional services, enabling consultants, auditors and risk management providers to use the platform as part of their own customer services;

• Support for DORA-related assessment requirements, including TLPT/TIBER-aligned testing obligations;

• Potential for localisation and adaptation to specific regulatory, sectoral and customer requirements.

5. Keywords

Governance Risk and Compliance
GRC Platform
NIS2
DORA
EU AI Act
GDPR
Cybersecurity Compliance
Multi-Framework Compliance
Control Mapping
Risk Management
Continuous Compliance
Cybersecurity Risk
Attack Surface Management
Threat Intelligence
AI-Assisted GRC
Regulatory Compliance
ISO 27001
NIST
Digital Operational Resilience

6. Partner Sought

The company is looking for international partners interested in integrating the GRC technology into existing compliance, audit, cybersecurity or risk management services and offering it to their customers.

Target partners include:

• compliance consulting companies;

• GRC integrators and technology providers;

• cybersecurity consultancies;

• audit and assurance firms;

• risk management service providers;

• organisations providing regulatory and sector-specific compliance services.

Partners may contribute to:

• integrating the platform into existing compliance or risk management services;

• introducing and deploying the solution for their customers;

• identifying and implementing pilot use cases;

• providing sector-specific regulatory and compliance expertise;

• defining requirements for new functionalities and regulatory frameworks;

• localising and adapting the platform to specific markets;

• jointly delivering GRC and cybersecurity projects;

• participating in joint R&D and European-funded projects.

Depending on the market and partner profile, cooperation may develop into commercial agreements with technical assistance, technology cooperation, joint service delivery or further co-development.

7. Stage of Development

Available for demonstration – the GRC platform and its compliance management functionalities are available for demonstration to potential technology and commercial partners.

8. Intellectual Property Rights Status

Confidential know-how – proprietary know-how related to the platform architecture, GRC functionality, multi-framework control mapping and integration of compliance and cybersecurity capabilities.

9. Type of Partnership Sought

• Commercial agreement with technical assistance

• Technology cooperation

• Joint service delivery

• Investment agreement

• R&D cooperation

• Joint participation in European-funded projects

#technologyoffer

Leave a Reply

Your email address will not be published. Required fields are marked *

4 + seventeen =