---
title: "Framework Matrix | OSS Controls Mapped to ISO 27001, NIS2,…"
description: "See how Offline Secure Storage and Control map to ISO 27001, UK GDPR, NIS2, DORA, PCI DSS, SOC 2 and NCSC CAF outcomes, control by control, with the evidence…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/compliance/frameworks#webpage",
      "url": "https://fire-vault.com/compliance/frameworks",
      "name": "Framework Matrix",
      "description": "See how Offline Secure Storage and Control map to ISO 27001, UK GDPR, NIS2, DORA, PCI DSS, SOC 2 and NCSC CAF outcomes, control by control, with the evidence…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/compliance/frameworks#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/compliance/frameworks#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Compliance",
          "item": "https://fire-vault.com/compliance"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Framework Matrix",
          "item": "https://fire-vault.com/compliance/frameworks"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Compliance",
          "item": "/compliance"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Framework matrix",
          "item": "/compliance/frameworks"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Co-operative Group 6.5M records ](https://www.bbc.co.uk/news/articles/cly7z9zj3l1o)[2026 Harrods Attempted intrusion ](https://www.reuters.com/business/retail-consumer/uk-luxury-retailer-harrods-latest-target-cyber-attack-2025-05-01/)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](https://www.gov.uk/government/news/legal-aid-agency-data-breach)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Co-operative Group 6.5M records ](https://www.bbc.co.uk/news/articles/cly7z9zj3l1o)[2026 Harrods Attempted intrusion ](https://www.reuters.com/business/retail-consumer/uk-luxury-retailer-harrods-latest-target-cyber-attack-2025-05-01/)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](https://www.gov.uk/government/news/legal-aid-agency-data-breach)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Compliance, framework matrix 

# Six controls. Eleven frameworks .

Offline Secure Storage® is one architecture, and it carries evidence into every framework an auditor is likely to test. This page shows the mapping control by control, with the evidence each control produces.

-   ISO 27001
-   UK GDPR
-   NIS2
-   DORA
-   PCI DSS
-   NCSC CAF

Book a mapping call[Compliance hub](/compliance)

![Security analyst reviewing an isolated workstation with disconnected cables](/assets/hero-square-analyst-CiP17E_k.jpg)

11

Frameworks mapped to OSS and Control

6

Control families that carry the mapping

1

Architecture behind every mapping

0

Certification claims made on your behalf

01 How to read this 

## One architecture, mapped to outcomes.

Frameworks overlap far more than they differ. Almost all of them ask the same four questions: who can reach the data, how is it protected at rest, can you prove what happened, and can you recover. Offline Secure Storage® answers all four with the same deployment.

This is a mapping , not a certification claim. Firevault holds Cyber Essentials Plus. Every other framework listed here is mapped as alignment: the controls produce evidence you can point at in your own submission, assessment or audit.

02 The matrix 

## Control by control, framework by framework.

Each control below is a physical property of the architecture, not a policy statement. That is what makes the evidence hold up.

Control 01

### Physical isolation

Data sits on hardware that is disconnected between sessions, so there is no network path to attack.

Evidence produced:  Session records showing when the hardware was connected, by whom, and for how long.

[ISO 27001 A.8](/solutions/oss/compliance/iso-27001) [UK GDPR Art. 32](/compliance/gdpr) [NIS2](/solutions/oss/compliance/nis2) [CAF B3](#caf)

Control 02

### Identity-verified access

Access is bound to a verified individual with multi-factor authentication, one vault per user.

Evidence produced:  KYC/AML records at provisioning, plus per-session authentication events.

[ISO 27001 A.5](/solutions/oss/compliance/iso-27001) [PCI DSS 7 & 8](/compliance/pci-dss) [SOC 2 CC6](/compliance) [CAF B2](#caf)

Control 03

### Hardware encryption

Quantum Key Encryption applied on the device itself, with keys held outside the connected estate.

Evidence produced:  Device encryption attestation and key custody statements.

[ISO 27001 A.10](/solutions/oss/compliance/iso-27001) [UK GDPR Art. 32(1)(a)](/compliance/gdpr) [PCI DSS 3](/compliance/pci-dss) [HIPAA](/compliance/hipaa)

Control 04

### Session logging

Every access window is opened, recorded and closed, producing a readable audit trail.

Evidence produced:  Time-stamped access logs exportable for auditors and regulators.

[SOC 2 CC7](/compliance) [DORA](/solutions/oss/compliance/dora) [FCA resilience](/compliance) [CAF C1](#caf)

Control 05

### Data classification

Live, recovery and retained data are separated, so only the right classes ever go offline.

Evidence produced:  Documented classification of what is held offline and why.

[ISO 27001 A.5.12](/solutions/oss/compliance/iso-27001) [NHS DSPT 7](/oss-for-healthcare) [SRA standards](/legal) [What OSS stores](/what-oss-stores)

Control 06

### Recoverable copies

Gold copies held away from the connected estate, so recovery does not depend on the compromised environment.

Evidence produced:  Retrieval tests and recovery timelines evidenced per vault.

[NIS2 continuity](/solutions/oss/compliance/nis2) [DORA recovery](/solutions/oss/compliance/dora) [NCSC ransomware](/compliance/ncsc-ransomware-resistant-backups) [CAF D1](#caf)

03 What the auditor receives 

## The evidence pack, in plain terms.

Mapping is only useful if it produces artefacts. These are the documents and exports a deployment generates.

### Access audit logs

Who opened which vault, when, from where, and for how long.

### Encryption attestation

Device-level encryption and key custody, stated in writing.

### Provisioning records

Identity verification completed before any access was granted.

### Classification schedule

What is held offline, by data class, and the reason for each.

### Retrieval tests

Evidence that recovery works, with measured timelines.

### Control statements

Auditor-ready wording per framework, ready to paste into a submission.

CAF-aligned

## Mapped to CAF outcomes, not certified against CAF.

Firevault is not certified against the NCSC Cyber Assessment Framework. CAF is a self-assessment framework for essential service operators. The sections below show how our products help you evidence CAF outcomes in your own submission.

### Offline Secure Storage and CAF

Using Offline Secure Storage supports CAF Objective B (Protecting against cyber attack) and Objective D (Minimising the impact of incidents). Gold copies live on hardware that is physically disconnected between sessions, giving operators evidence of protective isolation and a recoverable state.

Supports outcomes

B3 Data Security B5 Resilient Networks & Systems D1 Response & Recovery Planning 

[How OSS maps](/solutions/oss)

### Taking Control, deploying Blueprints and CAF

Deploying a Control Blueprint supports CAF Objective A (Managing security risk) and Objective C (Detecting cyber security events). Blueprints document identity-verified access, session logging and segregation between operational and archived data, so the controls can be pointed at CAF outcomes in a self-assessment.

Supports outcomes

A2 Risk Management A4 Supply Chain C1 Security Monitoring 

[See Control Blueprints](/control-blueprints)

### Deploying Firebreak and CAF

Deploying Firebreak supports CAF Objective B (Protecting against cyber attack) at the network boundary of operational technology environments. Firebreak enforces physical-layer separation between OT and IT, giving CNI operators evidence of controlled paths for CAF network security outcomes.

Supports outcomes

B2 Identity & Access Control B4 System Security B5 Resilient Networks & Systems 

[Explore Firebreak](/firebreak)

Firevault maps controls to CAF outcomes to help essential service operators evidence their own self-assessment. Full mapping detail is available on request.

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

![David Bailey](/assets/david-bailey-CnLw95Ao.jpg)

![Kenny Phipps](/assets/kenny-phipps-DxIqwaIL.jpg)

Online Now 

Concierge 

## Send us the frameworks that apply to you.

We will map Offline Secure Storage® and Control to the specific outcomes your auditor is testing, and give you the wording to use.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up