SectionCompliance & Frameworks

Cindera · Compliance & Frameworks

Compliance & Frameworks

Cindera is positioned to give SMEs a credible identity-and-access compliance story. This page tells you, honestly, what regulatory ground Cindera covers — and what it doesn't.

How Cindera maps to NIS2

NIS2 (Directive (EU) 2022/2555) requires essential and important entities to implement appropriate technical and organisational cybersecurity measures. Article 21(2) lists ten control areas in particular. Cindera addresses the identity-and-access subset of those controls directly, and provides supporting evidence for a few others.

Controls Cindera covers directly

Art. 21(2)(d)
Authentication and access control: enforced MFA, blocking of legacy authentication, conditional access posture, and MFA registration coverage.
Art. 21(2)(e)
Supply-chain security (identity surface): risky app consents, overprivileged service principals, and ownerless application registrations.
Art. 21(2)(i)
Access rights and privileged access management: excessive Global Administrators, dormant privileged accounts, permanent role assignments (PIM gaps), and break-glass account hygiene.
Art. 21(2)(j)
Multi-factor authentication: registration coverage, enforcement, and gaps left open by legacy protocols and report-only policies.
Art. 21(2)(c)
Business continuity (partial): break-glass account validation supports tenant recoverability if identity provisioning fails.

Audit evidence Cindera produces

  • A downloadable, dated PDF report listing every finding with its mapped NIS2 article, severity, and remediation status — suitable for inclusion in an audit pack.
  • A tamper-evident audit log of every action taken inside Cindera (finding closed, task created, consent revoked, report downloaded) retained for 7 years.
  • Historical trend data showing identity posture over time, which is what regulators want to see for measures-tested-regularly evidence.

What Cindera does NOT cover for NIS2

NIS2 is much broader than identity. Cindera does not address incident response and reporting (Art. 21(2)(b)), business continuity and crisis management beyond identity (Art. 21(2)(c)), encryption and cryptography policy (Art. 21(2)(h)), basic cyber hygiene and staff training (Art. 21(2)(g)), or physical and environmental security. For a wider self-assessment, take the free NIS2 readiness quiz — it covers all ten control areas at a high level.

How Cindera maps to GDPR

GDPR is about how personal data is processed; security is one essential ingredient. Cindera helps you demonstrate Article 32 and parts of Article 5.

Article 32 — Security of processing

  • Pseudonymisation and access control. Cindera evaluates whether access to personal data is appropriately restricted: MFA on accounts that can read user data, removal of dormant privileged accounts, conditional access on sensitive roles.
  • Confidentiality and integrity. Findings on risky app consents and overprivileged service principals highlight identities that could exfiltrate or modify personal data without an authorised business purpose.
  • Process for regularly testing measures.The recurring scan cadence (default nightly, schedulable weekly or monthly) and historical trends satisfy the "testing, assessing and evaluating the effectiveness" requirement for identity controls.

Article 5 — Principles relating to processing

  • Integrity and confidentiality (5(1)(f)).Cindera's identity hardening directly supports this principle by reducing the likelihood of unauthorised access.
  • Accountability (5(2)). The audit log inside Cindera, plus the dated reports, document who did what when — evidence you can present to a supervisory authority.

What Cindera does NOT cover for GDPR

Cindera is a security tool, not a privacy management platform. It does not handle records of processing (Art. 30), DPIA execution, data-subject access requests, consent management for end users, or lawful basis classification. Those remain the responsibility of your DPO and your privacy tooling.

Cyber-insurance readiness

Insurers have moved beyond box-ticking. Most renewal questionnaires now ask for specific identity controls — and quote-affecting evidence to back them up. The questions that come up almost every cycle are:

  • Is MFA enforced on all administrators? Cindera answers this directly with the admin MFA rule and the enforced MFA policy rule, both with a named-users list.
  • Is legacy authentication disabled? The legacy auth rule shows the exact conditional access policies that block it (or proves the gap).
  • How many privileged accounts do you have, and how often are they reviewed? The excessive Global Admins and dormant privileged rules give you a current number and an attestable review trail.
  • Do you separate admin and daily-use accounts? Findings on shared admin accounts surface during the excessive admins and break-glass checks.
  • Is third-party application access reviewed?The risky app consents and overprivileged service principal rules produce a reviewable inventory.

Bringing a Cindera PDF report to a renewal meeting demonstrably shortens the back-and-forth, and in our pilots it has moved the needle on premiums for two of the design partners.

Cindera's scope, honestly

Be specific with your auditor

A high Cindera score is evidence that your identity and access controls are in shape. It is not evidence that your overall NIS2 or GDPR compliance is complete. Anyone who tells you a single tool covers all of NIS2 is selling something.

The honest summary:

  • What Cindera covers well. Identity hygiene, access control, MFA posture, privileged access management, and third-party application risk in Microsoft 365.
  • What Cindera does not cover. Incident response and reporting, business continuity beyond identity recovery, staff awareness training, physical security, network segmentation, encryption-key management, vulnerability management on endpoints, and policy/governance documentation.
  • How to fill the gaps. Most SMEs combine Cindera with an MDM/EDR product (e.g. Microsoft Defender for Business), an incident-response retainer, and a lightweight policy set. Your DPO or compliance lead should sign off on the wider picture; Cindera owns the identity slice.

For a quick read on where you stand against the broader NIS2 surface, take the free 10-question NIS2 self-assessment. You'll get a one-page summary with the areas to prioritise.

Last updated · 2026-06-05