Cindera · Compliance & Frameworks
Compliance & Frameworks
Cindera is positioned to give SMEs a credible identity-and-access compliance story. This page tells you, honestly, what regulatory ground Cindera covers — and what it doesn't.
How Cindera maps to NIS2
NIS2 (Directive (EU) 2022/2555) requires essential and important entities to implement appropriate technical and organisational cybersecurity measures. Article 21(2) lists ten control areas in particular. Cindera addresses the identity-and-access subset of those controls directly, and provides supporting evidence for a few others.
Controls Cindera covers directly
- Art. 21(2)(d)
- Authentication and access control: enforced MFA, blocking of legacy authentication, conditional access posture, and MFA registration coverage.
- Art. 21(2)(e)
- Supply-chain security (identity surface): risky app consents, overprivileged service principals, and ownerless application registrations.
- Art. 21(2)(i)
- Access rights and privileged access management: excessive Global Administrators, dormant privileged accounts, permanent role assignments (PIM gaps), and break-glass account hygiene.
- Art. 21(2)(j)
- Multi-factor authentication: registration coverage, enforcement, and gaps left open by legacy protocols and report-only policies.
- Art. 21(2)(c)
- Business continuity (partial): break-glass account validation supports tenant recoverability if identity provisioning fails.
Audit evidence Cindera produces
- A downloadable, dated PDF report listing every finding with its mapped NIS2 article, severity, and remediation status — suitable for inclusion in an audit pack.
- A tamper-evident audit log of every action taken inside Cindera (finding closed, task created, consent revoked, report downloaded) retained for 7 years.
- Historical trend data showing identity posture over time, which is what regulators want to see for measures-tested-regularly evidence.
What Cindera does NOT cover for NIS2
How Cindera maps to GDPR
GDPR is about how personal data is processed; security is one essential ingredient. Cindera helps you demonstrate Article 32 and parts of Article 5.
Article 32 — Security of processing
- Pseudonymisation and access control. Cindera evaluates whether access to personal data is appropriately restricted: MFA on accounts that can read user data, removal of dormant privileged accounts, conditional access on sensitive roles.
- Confidentiality and integrity. Findings on risky app consents and overprivileged service principals highlight identities that could exfiltrate or modify personal data without an authorised business purpose.
- Process for regularly testing measures.The recurring scan cadence (default nightly, schedulable weekly or monthly) and historical trends satisfy the "testing, assessing and evaluating the effectiveness" requirement for identity controls.
Article 5 — Principles relating to processing
- Integrity and confidentiality (5(1)(f)).Cindera's identity hardening directly supports this principle by reducing the likelihood of unauthorised access.
- Accountability (5(2)). The audit log inside Cindera, plus the dated reports, document who did what when — evidence you can present to a supervisory authority.
What Cindera does NOT cover for GDPR
Cyber-insurance readiness
Insurers have moved beyond box-ticking. Most renewal questionnaires now ask for specific identity controls — and quote-affecting evidence to back them up. The questions that come up almost every cycle are:
- Is MFA enforced on all administrators? Cindera answers this directly with the admin MFA rule and the enforced MFA policy rule, both with a named-users list.
- Is legacy authentication disabled? The legacy auth rule shows the exact conditional access policies that block it (or proves the gap).
- How many privileged accounts do you have, and how often are they reviewed? The excessive Global Admins and dormant privileged rules give you a current number and an attestable review trail.
- Do you separate admin and daily-use accounts? Findings on shared admin accounts surface during the excessive admins and break-glass checks.
- Is third-party application access reviewed?The risky app consents and overprivileged service principal rules produce a reviewable inventory.
Bringing a Cindera PDF report to a renewal meeting demonstrably shortens the back-and-forth, and in our pilots it has moved the needle on premiums for two of the design partners.
Cindera's scope, honestly
Be specific with your auditor
The honest summary:
- What Cindera covers well. Identity hygiene, access control, MFA posture, privileged access management, and third-party application risk in Microsoft 365.
- What Cindera does not cover. Incident response and reporting, business continuity beyond identity recovery, staff awareness training, physical security, network segmentation, encryption-key management, vulnerability management on endpoints, and policy/governance documentation.
- How to fill the gaps. Most SMEs combine Cindera with an MDM/EDR product (e.g. Microsoft Defender for Business), an incident-response retainer, and a lightweight policy set. Your DPO or compliance lead should sign off on the wider picture; Cindera owns the identity slice.
For a quick read on where you stand against the broader NIS2 surface, take the free 10-question NIS2 self-assessment. You'll get a one-page summary with the areas to prioritise.