Compliance that runs every day, not the week before the audit.
We implement the technical controls behind NIS2, DORA, the EU AI Act, SOC 2 and ISO 27001 in your infrastructure as code, then keep them enforced, monitored and evidenced continuously, with remediation shipped as pull requests your engineers merge.
DigitalCare is an engineering partner, not an auditor or a certification body. We build, monitor and remediate the technical controls and produce the evidence. Certification is issued by your auditor. We never certify anyone and we do not promise an audit outcome.
Two kinds of pressure: the deal you want to close, and the law you are already under.
The technical work underneath is largely the same. What differs is who asks, what they accept as proof, and what happens if the answer is thin.
SOC 2
The report enterprise buyers ask for by name, most often Type II, which covers a period rather than a date. It attests that your controls actually operated over three to twelve months, so the evidence has to exist continuously, not be assembled the week before.
ISO 27001
The certificate European, UK and Asian buyers and public tenders ask for. Certification covers a management system: scope, risk treatment, a Statement of Applicability against the 93 controls of Annex A, internal audit, then a three-year cycle with annual surveillance audits.
NIS2
Essential and important entities across many sectors, and often their suppliers by contract. Most member states have transposed and national supervision is live: in July 2026 the Commission referred four of the remaining ones to the EU Court.
DORA
Financial entities: ICT risk management, incident reporting, resilience testing, registers of information. ICT vendors are bound through contract, and providers designated as critical sit under direct EU oversight.
EU AI Act
Disclosure for chatbots and marking of generated content apply now. The high-risk obligations (oversight, logging, traceability, data governance) were deferred to December 2027 and August 2028.
Cyber Resilience Act
Manufacturers of products with digital elements start reporting actively exploited vulnerabilities and severe incidents: 24 hours to an early warning, 72 hours to a notification. The full obligations follow in December 2027.
Dates are as publicly published and current as of August 2026; your scope and the dates that actually bind you depend on your sector, size and member state. We are engineers, not your legal counsel.
Different questions, one infrastructure underneath.
Most teams end up doing more than one, usually because buyers on different markets ask for different things. The controls overlap heavily; the proof each one wants does not.
| SOC 2 | ISO 27001 | NIS2 | |
|---|---|---|---|
| What it is | An auditor’s report on how your controls operated | Certification of a management system | EU law, with a supervisory authority behind it |
| Who asks for it | Enterprise buyers, most often from the US | European, UK and Asian buyers, public tenders | Your national regulator, and customers by contract |
| What you get | A Type I or Type II report shared under NDA | A certificate valid three years, with annual surveillance | No certificate: you show evidence on request |
| What decides the outcome | Whether controls operated across the whole period | Whether the management system exists and is followed | Whether the service stays resilient and incidents are reported in time |
| The engineering work | Continuous, attributable evidence | Controls mapped to Annex A, plus the documented system | Enforced controls, tested recovery, a 24 and 72 hour reporting path |
Our part is the same in all three cases: build and operate the controls, and make the evidence a by-product of running the system. The report, the certificate and the regulator’s judgement stay with your auditor and your authority.
A binder and a screenshot folder that went stale a week later.
That is what most compliance projects produce. But the technical controls behind every one of these frameworks (access control, encryption in transit and at rest, logging and retention, backup and restore testing, change management, vulnerability management, incident response, supplier oversight) are infrastructure work.
That is what we do. And it is what we keep doing after the certificate is issued, because a control that isn’t enforced between audits was never a control.
Every control has an implementation, an artifact your auditor asks for, and a name against it.
| Control | How it’s implemented | Evidence the auditor wants | Who produces it |
|---|---|---|---|
| Access control | RBAC and SSO defined as code, least privilege by default | Access reviews and role diffs over time | Generated from the repository history |
| Change management | GitOps: every change is a reviewed pull request | Merge history as the audit trail: who approved what, when | Produced by the workflow itself |
| Logging & monitoring | Centralized logs with defined retention, alerting on the gaps | Coverage and retention proof across systems | Metatron, continuously |
| Vulnerability management | Scanning in the pipeline and in the running cluster | Open and closed findings with timestamps | Verdict opens the remediation pull requests |
| Encryption | In transit and at rest, keys and secrets managed, enforced by policy | Configuration state and policy denial records | Policy engine, evidence collected automatically |
| Backup & restore | Automated backups plus scheduled restore tests, not just backup jobs | Restore test results with dates and outcomes | Scheduled and evidenced by the platform |
| Incident response | On-call rotation, runbooks, defined severities and comms paths | Incident timelines and postmortems | Produced by the operations you already pay for |
Assess, implement, harden, operate.
Gap assessment against the frameworks in scope
Which frameworks actually apply, what the current state of the technical controls is, and a prioritized gap list with a remediation plan, ordered by risk and effort, not alphabetically.
Controls as code
Network policy, secrets management, RBAC and SSO, encryption, centralized logging and retention, backup and restore testing, a hardened CI/CD supply chain, and policy as code so the compliant option is the default one.
Kubernetes security posture
Cluster hardening, admission policy, image provenance and signing, runtime monitoring and benchmark drift: the natural extension of Managed Kubernetes rather than a separate product.
Continuous evidence, not an annual sprint
Continuous evidence collection, drift detection, remediation pull requests, and audit support when your auditor asks. We answer the technical questions so your team doesn’t rebuild the story each cycle.
Continuous monitoring is evidence collection. Remediation is a pull request.
Metatron already watches infrastructure continuously and investigates deviations with evidence chains attached rather than raising a bare alert, which is exactly what an auditor means by continuous monitoring. Verdict ships fixes as pull requests a human reviews and merges, so every remediation carries its own audit trail and a named approver. Read-only investigation, human-gated change, full auditability.
Control implemented
As code, in your repositories, enforced by policy.
Posture monitored
Metatron watches configuration, coverage and drift continuously.
Deviation investigated
Read-only: what changed, where, when, and what it affects.
Fix merged by a human
Verdict proposes; a senior engineer reviews, merges and owns it.
Evidence stored
Timestamped, attributable, ready when the auditor asks. Then the loop repeats.
The old shape: a once-a-year audit sprint that reconstructs the last twelve months from memory and screenshots. The loop above is the same work, spread across every day, produced by the system that does the work anyway.
Four situations, and one where you should not hire us.
EU SaaS and fintech facing NIS2 or DORA
Obligations landing on a fixed date, against infrastructure that was built for speed rather than for evidence.
Startups whose enterprise deals hinge on a questionnaire
SOC 2 or ISO 27001 has become a sales blocker, and the honest answers require engineering work first.
Companies deploying AI systems under the AI Act
Data flows, logging, retention and human oversight become infrastructure questions. A private LLM deployment answers several of them structurally: the data never leaves your perimeter.
Public sector organizations aligning with EU frameworks
Documented data flows, residency and continuity requirements, with the operational record to back them. See the Government case.
If you need only a certificate and have no infrastructure to change, an auditor or a compliance platform is the cheaper and more direct route. We are worth hiring when the controls themselves have to be built and then kept running.
Open source, in your accounts, with the evidence in your systems.
If you already run a compliance platform, we integrate with it and feed it the technical evidence instead of duplicating your control register.
FAQ9 questionsCloseOpen
Are you an auditor?
No, and that is better for you. We are an engineering partner: we build, monitor and remediate the technical controls and produce the evidence. Your auditor issues the certification. The party implementing controls should not be the party attesting to them.
Do you guarantee we pass the audit?
No one honest can promise that. What we can do is make the technical evidence real, current and continuously produced, so your audit reviews a live system instead of a folder of screenshots from last quarter.
Does NIS2 apply to us?
It reaches well beyond classic critical infrastructure: essential and important entities across many sectors, and frequently their suppliers through contractual requirements. Applicability depends on your sector, size and national transposition, which is what the gap assessment establishes.
What does DORA require from an ICT provider like you?
DORA places obligations on financial entities for how they manage ICT third parties: contractual terms, oversight, incident reporting paths, exit strategies and testing. Practically, we support your register of information, produce incident timelines and evidence, and work to the contractual requirements your legal team sets.
What about the AI Act if we run AI internally?
Obligations depend on your role, provider or deployer, and on the risk classification of the system. On the infrastructure side the recurring questions are data flows, logging and retention, human oversight and traceability. A private LLM deployment answers several of them structurally, because inference stays inside your perimeter.
How long does a gap assessment take?
It is a scoped engagement rather than an open-ended project: frameworks in scope, current state of the technical controls, a prioritized gap list and a remediation plan. Duration is agreed up front and depends on how many frameworks and environments are involved.
Can you work with our existing auditor or compliance platform?
Yes. Your auditor stays your auditor and we produce what they ask for. If you already run a compliance platform, we feed the technical evidence into it rather than duplicating your control register.
What can the agents change?
Nothing directly. Monitoring and investigation are read-only; every remediation ships as a pull request a human reviews and merges, which is also what gives each fix an audit trail.
How is this different from a penetration test?
A penetration test is a point-in-time attempt to break in. This is the ongoing engineering work of implementing, enforcing and evidencing controls. They complement each other; neither replaces the other.
