Trust
Compliance Matrix
Cloudgenio delivers cloud and IT programmes for European enterprises in regulated sectors. The matrix below describes the frameworks we align with and how we embed them into our delivery model.
| Area | Frameworks | Scope | Posture |
|---|---|---|---|
| Information security | ISO/IEC 27001, NIS2 | Governance, risk management, access control, incident response, supplier management | Controls aligned with ISO/IEC 27001; NIS2 obligations tracked in delivery governance. |
| Data protection | GDPR / AVG | Personal data processing, data subject rights, records of processing, international transfers | Data protection by design and by default in client engagements; DPA clauses standard. |
| Financial sector resilience | DORA | ICT risk management, incident reporting, digital operational resilience testing | DORA-aligned controls applied to delivery for financial-sector clients. |
| Healthcare | NEN 7510 | Information security in healthcare, including patient data handling | Healthcare engagements scoped to NEN 7510 controls and data-residency requirements. |
| Dutch public sector | BIO | Baseline information security for government and public organisations | Public-domain programmes mapped to BIO controls during policy-alignment workshops. |
| Cloud and data residency | EU Data Act, Schrems II guidance | Data location, sovereignty, transfer safeguards, cloud provider selection | EU data residency by default; sovereign cloud options where required. |
How to read this matrix
This matrix describes the control areas and frameworks we use to structure client engagements. It is not a certification or audit report. Specific certification status, scope, and evidence are shared under non-disclosure agreement during procurement or due diligence with qualified parties. If you need a tailored compliance statement, contact us through our Contact page.