---
title: "Compliance: NIS2, DORA and GDPR with Offline | Firevault"
description: "How Firevault OSS and Control map to NIS2, DORA, UK GDPR, ISO 27001, PCI DSS, NCSC CAF, FCA operational resilience, Cyber Essentials Plus, NHS DSPT and SRA."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/compliance#webpage",
      "url": "https://fire-vault.com/compliance",
      "name": "Compliance: NIS2, DORA and GDPR with Offline",
      "description": "How Firevault OSS and Control map to NIS2, DORA, UK GDPR, ISO 27001, PCI DSS, NCSC CAF, FCA operational resilience, Cyber Essentials Plus, NHS DSPT and SRA.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/compliance#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/compliance#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Compliance: NIS2, DORA and GDPR with Offline",
          "item": "https://fire-vault.com/compliance"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Compliance",
          "item": "/compliance"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Co-operative Group 6.5M records ](https://www.bbc.co.uk/news/articles/cly7z9zj3l1o)[2026 Harrods Attempted intrusion ](https://www.reuters.com/business/retail-consumer/uk-luxury-retailer-harrods-latest-target-cyber-attack-2025-05-01/)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](https://www.gov.uk/government/news/legal-aid-agency-data-breach)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Co-operative Group 6.5M records ](https://www.bbc.co.uk/news/articles/cly7z9zj3l1o)[2026 Harrods Attempted intrusion ](https://www.reuters.com/business/retail-consumer/uk-luxury-retailer-harrods-latest-target-cyber-attack-2025-05-01/)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](https://www.gov.uk/government/news/legal-aid-agency-data-breach)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Compliance 

# Regulatory alignment, mapped to Firevault .

We map Firevault OSS and Control to the frameworks that matter most: NIS2, DORA, UK GDPR, ISO 27001, PCI DSS, CAF, FCA, Cyber Essentials Plus, NHS DSPT and the SRA. Alignment, not a certification claim.

-   NIS2
-   DORA
-   UK GDPR
-   ISO 27001
-   NCSC CAF

Book a mapping call[Framework matrix](/compliance/frameworks)

![Security analyst reviewing an isolated workstation with disconnected cables](/assets/hero-square-analyst-CiP17E_k.jpg)

11

Frameworks mapped to Firevault

OSS & Control coverage

24h

NIS2 significant-incident window

EU Directive 2022/2555

72h

UK GDPR breach notification window

ICO / Article 33

CAF-aligned

Controls mapped to NCSC outcomes

Alignment, not certification

01 How we talk about compliance 

## Alignment, evidenced. Not certification, claimed.

Regulators do not ask for a badge. They ask for demonstrable technical and organisational measures, proportionate to the risk. Offline Secure Storage® takes data offline. Control governs the path used to reach systems and data. Both produce evidence a regulator or auditor can read.

Where we say CAF-aligned , we mean controls mapped to NCSC CAF outcomes. Where we say Article 32 supporting , we mean measures a controller can point to. We do not issue certifications and do not accept audit outcomes on your behalf.

02 Core frameworks 

## The three that drive most conversations.

NIS2, DORA and UK GDPR set the tone for how regulators expect crown-jewel data and critical services to be protected.

[

EU In force · UK CS&R Bill 2025 

#### NIS2

Network & Information Security Directive 2

Risk-based security measures, 24-hour significant-incident reporting and supply-chain assurance for essential and important entities.

How Firevault helps:  OSS supports business continuity and offline gold copies. Control governs the path used to reach essential systems and provides evidence for incident timelines.

](/solutions/oss/compliance/nis2)

[Explore mapping](/solutions/oss/compliance/nis2) [UK CS&R Bill](https://www.gov.uk/government/collections/cyber-security-and-resilience-bill)

[

EU Applies from January 2025 

#### DORA

Digital Operational Resilience Act

ICT risk management, resilience testing, third-party monitoring and threat-intelligence sharing across the financial sector.

How Firevault helps:  OSS holds recoverable copies away from live ICT. Control provides time-bound, evidenced access windows for third parties and privileged users.

](/solutions/oss/compliance/dora)

[Explore mapping](/solutions/oss/compliance/dora) [DORA resource](https://www.digital-operational-resilience-act.com/)

[

UK / EU In force since 2018 

#### UK GDPR

General Data Protection Regulation

Article 25 privacy-by-design, Article 32 appropriate technical measures and 72-hour breach notification for personal data.

How Firevault helps:  Offline storage supports appropriate technical measures under Article 32. Identity-locked, time-boxed access supports proportionality and accountability.

](/compliance/gdpr)

[Explore mapping](/compliance/gdpr) [ICO guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/)

03 Sector & standards coverage 

## Standards, sector rules and certifications.

ISO 27001, NCSC CAF, PCI DSS, FCA operational resilience, Cyber Essentials Plus, NHS DSPT and SRA. Mapped, not marketed.

[Framework matrix](/compliance/frameworks)

[

International Ongoing certification cycle 

#### ISO 27001

Information Security Management Systems

Annex A controls covering asset management, access control, cryptography and operations security across the ISMS.

How Firevault helps:  OSS contributes to A.8 asset protection and A.10 cryptography evidence. Control supports A.9 access control with time-bound windows and full audit trails.

](/solutions/oss/compliance/iso-27001)

[Explore mapping](/solutions/oss/compliance/iso-27001) [ISO 27001](https://www.iso.org/standard/27001)

[

UK CNI operators · CAF-aligned 

#### NCSC CAF 4.0

Cyber Assessment Framework

Four objectives: managing security risk, protecting against attack, detecting events and minimising the impact of incidents.

How Firevault helps:  We map Firevault controls to CAF outcomes rather than claim certification. Control supports Objective B; OSS supports Objective D recoverability.

](/compliance/frameworks)

[Explore mapping](/compliance/frameworks) [NCSC CAF](https://www.ncsc.gov.uk/collection/caf)

[

Global v4.0 mandatory March 2025 

#### PCI DSS 4.0

Payment Card Industry Data Security Standard

Cardholder-data protection, cryptography, access on a need-to-know basis and continuous security monitoring.

How Firevault helps:  OSS holds account-data copies off the cardholder data environment. Control enforces least-privilege, session-bound access paths.

](/compliance/pci-dss)

[Explore mapping](/compliance/pci-dss) [PCI SSC](https://www.pcisecuritystandards.org/)

[

UK Full compliance March 2025 

#### FCA Op Res

FCA PS21/3 Operational Resilience

Identify important business services, set impact tolerances and evidence resilience under severe-but-plausible scenarios.

How Firevault helps:  OSS gives recoverable copies outside the live estate. Control demonstrates the ability to sever and re-lock paths during a scenario test.

](/compliance/frameworks)

[Explore mapping](/compliance/frameworks) [PS21/3](https://www.fca.org.uk/publications/policy-statements/ps21-3-building-operational-resilience)

[

UK Annual certification 

#### Cyber Essentials Plus

UK Government-backed certification

Boundary firewalls, secure configuration, access control, malware protection and patch management, verified hands-on.

How Firevault helps:  Firevault deployments run on dedicated, hardened hardware with identity-locked access and time-boxed connectivity.

](/solutions/oss/compliance/cyber-essentials)

[Explore mapping](/solutions/oss/compliance/cyber-essentials) [NCSC CE+](https://www.ncsc.gov.uk/cyberessentials/overview)

[

UK Annual submission (30 June) 

#### NHS DSPT

Data Security & Protection Toolkit

Ten National Data Guardian standards covering confidentiality, integrity, availability and third-party assurance.

How Firevault helps:  OSS supports Standard 7 confidentiality and integrity for patient records held offline. Control supports Standard 9 IT protection.

](/oss-for-healthcare)

[Explore mapping](/oss-for-healthcare) [NHS DSPT](https://www.dsptoolkit.nhs.uk/)

[

UK Ongoing obligation 

#### SRA Standards

Solicitors Regulation Authority

Client confidentiality, information security, third-party assurance and incident response for regulated law firms.

How Firevault helps:  Deep coverage on the Legal page: matter files, disclosure bundles and privileged records under evidence-grade custody.

](/legal)

[Explore mapping](/legal) [SRA guidance](https://www.sra.org.uk/solicitors/guidance/cyber-security/)

04 Product lines 

## Two lines. Different evidence.

Most compliance programmes use both: OSS for recoverable copies and confidentiality, Control for path governance and access windows.

### Offline Secure Storage®

Recoverable copies held offline. Supports Article 32 measures, NIS2 continuity, ISO 27001 A.8/A.10 and DORA recovery.

[By need](/solutions/oss) [Industries](/oss-for-industry) [Compliance](/compliance)

[Explore Offline](/solutions/oss)

### Control

Path governance for IT and OT. Supports NIS2 supply chain, CAF Objective B, PCI DSS need-to-know and FCA impact tolerances.

[Blueprints](/control-blueprints) [Industries](/control-for-industry) [Use cases](/control-for-industry)

[Explore Control](/solutions/control)

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

![David Bailey](/assets/david-bailey-CnLw95Ao.jpg)

![Kenny Phipps](/assets/kenny-phipps-DxIqwaIL.jpg)

Online Now 

Concierge 

## Map Firevault to your regulator's language.

Send us the frameworks that apply to your organisation. We will map OSS and Control controls to the specific outcomes your auditor is testing against.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up