Compliance, framework matrix

Six controls. Eleven frameworks.

Offline Secure Storage® is one architecture, and it carries evidence into every framework an auditor is likely to test. This page shows the mapping control by control, with the evidence each control produces.

  • ISO 27001
  • UK GDPR
  • NIS2
  • DORA
  • PCI DSS
  • NCSC CAF
Compliance hub
Security analyst reviewing an isolated workstation with disconnected cables

11

Frameworks mapped to OSS and Control

6

Control families that carry the mapping

1

Architecture behind every mapping

0

Certification claims made on your behalf

01How to read this

One architecture, mapped to outcomes.

Frameworks overlap far more than they differ. Almost all of them ask the same four questions: who can reach the data, how is it protected at rest, can you prove what happened, and can you recover. Offline Secure Storage® answers all four with the same deployment.

This is a mapping, not a certification claim. Firevault holds Cyber Essentials Plus. Every other framework listed here is mapped as alignment: the controls produce evidence you can point at in your own submission, assessment or audit.

02The matrix

Control by control, framework by framework.

Each control below is a physical property of the architecture, not a policy statement. That is what makes the evidence hold up.

Control 01

Physical isolation

Data sits on hardware that is disconnected between sessions, so there is no network path to attack.

Evidence produced: Session records showing when the hardware was connected, by whom, and for how long.

Control 02

Identity-verified access

Access is bound to a verified individual with multi-factor authentication, one vault per user.

Evidence produced: KYC/AML records at provisioning, plus per-session authentication events.

Control 03

Hardware encryption

Quantum Key Encryption applied on the device itself, with keys held outside the connected estate.

Evidence produced: Device encryption attestation and key custody statements.

Control 04

Session logging

Every access window is opened, recorded and closed, producing a readable audit trail.

Evidence produced: Time-stamped access logs exportable for auditors and regulators.

Control 05

Data classification

Live, recovery and retained data are separated, so only the right classes ever go offline.

Evidence produced: Documented classification of what is held offline and why.

Control 06

Recoverable copies

Gold copies held away from the connected estate, so recovery does not depend on the compromised environment.

Evidence produced: Retrieval tests and recovery timelines evidenced per vault.

03What the auditor receives

The evidence pack, in plain terms.

Mapping is only useful if it produces artefacts. These are the documents and exports a deployment generates.

Access audit logs

Who opened which vault, when, from where, and for how long.

Encryption attestation

Device-level encryption and key custody, stated in writing.

Provisioning records

Identity verification completed before any access was granted.

Classification schedule

What is held offline, by data class, and the reason for each.

Retrieval tests

Evidence that recovery works, with measured timelines.

Control statements

Auditor-ready wording per framework, ready to paste into a submission.

CAF-aligned

Mapped to CAF outcomes, not certified against CAF.

Firevault is not certified against the NCSC Cyber Assessment Framework. CAF is a self-assessment framework for essential service operators. The sections below show how our products help you evidence CAF outcomes in your own submission.

Offline Secure Storage and CAF

Using Offline Secure Storage supports CAF Objective B (Protecting against cyber attack) and Objective D (Minimising the impact of incidents). Gold copies live on hardware that is physically disconnected between sessions, giving operators evidence of protective isolation and a recoverable state.

Supports outcomes

B3 Data SecurityB5 Resilient Networks & SystemsD1 Response & Recovery Planning
How OSS maps

Taking Control, deploying Blueprints and CAF

Deploying a Control Blueprint supports CAF Objective A (Managing security risk) and Objective C (Detecting cyber security events). Blueprints document identity-verified access, session logging and segregation between operational and archived data, so the controls can be pointed at CAF outcomes in a self-assessment.

Supports outcomes

A2 Risk ManagementA4 Supply ChainC1 Security Monitoring
See Control Blueprints

Deploying Firebreak and CAF

Deploying Firebreak supports CAF Objective B (Protecting against cyber attack) at the network boundary of operational technology environments. Firebreak enforces physical-layer separation between OT and IT, giving CNI operators evidence of controlled paths for CAF network security outcomes.

Supports outcomes

B2 Identity & Access ControlB4 System SecurityB5 Resilient Networks & Systems
Explore Firebreak

Firevault maps controls to CAF outcomes to help essential service operators evidence their own self-assessment. Full mapping detail is available on request.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Send us the frameworks that apply to you.

We will map Offline Secure Storage® and Control to the specific outcomes your auditor is testing, and give you the wording to use.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up