Trust

Compliance Matrix

Cloudgenio delivers cloud and IT programmes for European enterprises in regulated sectors. The matrix below describes the frameworks we align with and how we embed them into our delivery model.

AreaFrameworksScopePosture
Information securityISO/IEC 27001, NIS2Governance, risk management, access control, incident response, supplier managementControls aligned with ISO/IEC 27001; NIS2 obligations tracked in delivery governance.
Data protectionGDPR / AVGPersonal data processing, data subject rights, records of processing, international transfersData protection by design and by default in client engagements; DPA clauses standard.
Financial sector resilienceDORAICT risk management, incident reporting, digital operational resilience testingDORA-aligned controls applied to delivery for financial-sector clients.
HealthcareNEN 7510Information security in healthcare, including patient data handlingHealthcare engagements scoped to NEN 7510 controls and data-residency requirements.
Dutch public sectorBIOBaseline information security for government and public organisationsPublic-domain programmes mapped to BIO controls during policy-alignment workshops.
Cloud and data residencyEU Data Act, Schrems II guidanceData location, sovereignty, transfer safeguards, cloud provider selectionEU data residency by default; sovereign cloud options where required.

How to read this matrix

This matrix describes the control areas and frameworks we use to structure client engagements. It is not a certification or audit report. Specific certification status, scope, and evidence are shared under non-disclosure agreement during procurement or due diligence with qualified parties. If you need a tailored compliance statement, contact us through our Contact page.