Six controls. Eleven frameworks.
Offline Secure Storage® is one architecture, and it carries evidence into every framework an auditor is likely to test. This page shows the mapping control by control, with the evidence each control produces.
- ISO 27001
- UK GDPR
- NIS2
- DORA
- PCI DSS
- NCSC CAF

11
Frameworks mapped to OSS and Control
6
Control families that carry the mapping
1
Architecture behind every mapping
0
Certification claims made on your behalf
One architecture, mapped to outcomes.
Frameworks overlap far more than they differ. Almost all of them ask the same four questions: who can reach the data, how is it protected at rest, can you prove what happened, and can you recover. Offline Secure Storage® answers all four with the same deployment.
This is a mapping, not a certification claim. Firevault holds Cyber Essentials Plus. Every other framework listed here is mapped as alignment: the controls produce evidence you can point at in your own submission, assessment or audit.
Control by control, framework by framework.
Each control below is a physical property of the architecture, not a policy statement. That is what makes the evidence hold up.
Control 01
Physical isolation
Data sits on hardware that is disconnected between sessions, so there is no network path to attack.
Evidence produced: Session records showing when the hardware was connected, by whom, and for how long.
Control 02
Identity-verified access
Access is bound to a verified individual with multi-factor authentication, one vault per user.
Evidence produced: KYC/AML records at provisioning, plus per-session authentication events.
Control 03
Hardware encryption
Quantum Key Encryption applied on the device itself, with keys held outside the connected estate.
Evidence produced: Device encryption attestation and key custody statements.
Control 04
Session logging
Every access window is opened, recorded and closed, producing a readable audit trail.
Evidence produced: Time-stamped access logs exportable for auditors and regulators.
Control 05
Data classification
Live, recovery and retained data are separated, so only the right classes ever go offline.
Evidence produced: Documented classification of what is held offline and why.
Control 06
Recoverable copies
Gold copies held away from the connected estate, so recovery does not depend on the compromised environment.
Evidence produced: Retrieval tests and recovery timelines evidenced per vault.
The evidence pack, in plain terms.
Mapping is only useful if it produces artefacts. These are the documents and exports a deployment generates.
Access audit logs
Who opened which vault, when, from where, and for how long.
Encryption attestation
Device-level encryption and key custody, stated in writing.
Provisioning records
Identity verification completed before any access was granted.
Classification schedule
What is held offline, by data class, and the reason for each.
Retrieval tests
Evidence that recovery works, with measured timelines.
Control statements
Auditor-ready wording per framework, ready to paste into a submission.
CAF-aligned
Mapped to CAF outcomes, not certified against CAF.
Firevault is not certified against the NCSC Cyber Assessment Framework. CAF is a self-assessment framework for essential service operators. The sections below show how our products help you evidence CAF outcomes in your own submission.
Offline Secure Storage and CAF
Using Offline Secure Storage supports CAF Objective B (Protecting against cyber attack) and Objective D (Minimising the impact of incidents). Gold copies live on hardware that is physically disconnected between sessions, giving operators evidence of protective isolation and a recoverable state.
Supports outcomes
Taking Control, deploying Blueprints and CAF
Deploying a Control Blueprint supports CAF Objective A (Managing security risk) and Objective C (Detecting cyber security events). Blueprints document identity-verified access, session logging and segregation between operational and archived data, so the controls can be pointed at CAF outcomes in a self-assessment.
Supports outcomes
Deploying Firebreak and CAF
Deploying Firebreak supports CAF Objective B (Protecting against cyber attack) at the network boundary of operational technology environments. Firebreak enforces physical-layer separation between OT and IT, giving CNI operators evidence of controlled paths for CAF network security outcomes.
Supports outcomes
Firevault maps controls to CAF outcomes to help essential service operators evidence their own self-assessment. Full mapping detail is available on request.



Send us the frameworks that apply to you.
We will map Offline Secure Storage® and Control to the specific outcomes your auditor is testing, and give you the wording to use.
Takes about 2 minutes. No account needed.