Gap Analysis
Systematic analysis of your existing processes and infrastructure against ISO 27001, GDPR, DORA, and NIS-2 requirements. Identification of gaps and prioritization of measures.
Compliance Framework
for Software & Infrastructure
Our Software Security Compliance Framework helps you make your infrastructure and software compliant with ISO 27001, ISO 9001, GDPR, DORA, and NIS-2. From gap analysis to successful audit.






























Compliance as Competitive Advantage
Gap Analysis
Systematic analysis of your existing processes and infrastructure against ISO 27001, GDPR, DORA, and NIS-2 requirements. Identification of gaps and prioritization of measures.
Control Mapping
Clear assignment of technical measures to regulatory controls. Traceable for auditors and management. Based on the Polycrate Security Framework.
Evidence Artifacts
Automated generation of audit evidence from your infrastructure. Logs, configurations, policies, and reports - exportable at any time.
Supported Standards
Our framework covers the most important regulatory requirements for European companies.
ISO 27001:2022
Annex A Controls fully mapped
32 detailed documentations
Control-to-App assignment
Shared Responsibility Model
Evidence export for audits
GDPR
Art. 17 - Right to Erasure
Art. 25 - Privacy by Design
Art. 28 - Data Processing
Art. 32 - Security of Processing
Technical & organizational measures
DORA
Digital Operational Resilience
ICT Risk Management
Incident Reporting
Resilience Testing
Third-Party Risk Management
NIS-2 / Critical Infrastructure
Critical Infrastructures
BSI IT-Grundschutz Mapping
Reporting Obligations
Supply Chain Security
Business Continuity
Other Standards
Industry-specific Standards
Custom Requirements
Special Regulatory Needs
Framework Extensions
Tailored Mappings
The Framework in Detail
Our Compliance Framework is more than just documentation - it's a living system that grows with your infrastructure.
Role-based Views
Dedicated documentation for CISOs, Data Protection Officers, Auditors, DevOps teams, and Legal/Procurement. No information overload.
Topic-based Navigation
Identity & Access Management, Logging & Audit, Backup & BCDR, Vulnerability Management, Network Security, Cryptography, and more.
App Compliance
For each Managed App, we document control mappings, shared responsibility, and evidence artifacts.
Bidirectional Navigation
Navigate from ISO controls to implementing apps or vice versa. Complete traceability.
Mermaid Diagrams
Complex processes and architectures as interactive diagrams. Understandable for technical and non-technical stakeholders.
Evidence Export
Concrete CLI commands for exporting evidence artifacts. Logs, configurations, policies - all documented.
Compliance Workshop
The Compliance Framework is part of our Software Compliance Workshop. In one intensive day, we bring your team up to speed.
Software Compliance Workshop
ISMS integration for Polycrate
Ready-to-use compliance documents
DORA conformity
NIS-2 requirements
EU regulations overview
Duration: 1 day
Audience: CIO / CISO / ISB
Framework Benefits
Why companies choose our Compliance Framework.
Audit-Ready
All evidence structured and exportable. No hectic preparation before audits. Continuous compliance instead of point-in-time checks.
Made in Germany
Developed in Germany for European requirements. No compromises on data protection and data sovereignty.
Living Documentation
The framework grows with your infrastructure. New apps, new controls, new regulations - continuously updated.
Polycrate Integration
Seamless integration with Polycrate for automated compliance. Policy as Code, GitOps, and declarative configuration.
Open Source Based
Based on proven open-source tools like Kubernetes, Grafana, and ArgoCD. Full transparency and control.
Shared Responsibility
Documented separation between platform responsibility and customer responsibility. No gray areas during audits.
Comparison with Alternatives
How our framework compares to other solutions.
| Criterion | ayedo | Big 4 Consulting |
|---|---|---|
| Cost | Fixed-price workshop | Daily rates from €2,000 |
| Technical Depth | Hands-on with your infra | Generic frameworks |
| Implementation | Ready immediately | Months of project |
| Maintenance | Continuous updates | One-time delivery |
| Criterion | ayedo | DIY / In-house |
|---|---|---|
| Time-to-Value | 1 day workshop | Months of setup |
| Expertise | 15+ years experience | Learning by doing |
| Currency | Continuously updated | Quickly outdated |
| Cost | One-time investment | Internal resources |
| Criterion | ayedo | GRC Platforms |
|---|---|---|
| Integration | Kubernetes-native | Usually superficial |
| Evidence | Automatic from infra | Manual input |
| Vendor Lock-in | Open source based | Proprietary |
| Ongoing Costs | No license fees | SaaS fees |
Frequently Asked Questions
Answers to the most important questions about the Compliance Framework.
Which companies is the framework suitable for?
The framework is aimed at companies that operate or are building cloud-native infrastructure and need to meet regulatory requirements such as ISO 27001, GDPR, DORA, or NIS-2. Particularly suitable for financial services, healthcare, critical infrastructure, and B2B SaaS providers.
Do I need to be an ayedo customer to use the framework?
The framework is optimized for the ayedo Platform and Polycrate, but can also serve as a reference for other Kubernetes environments. The full benefit unfolds in combination with our managed services.
What is included in the workshop?
The Software Compliance Workshop (€9,999.95) includes a full-day workshop with your team, access to the complete Compliance Framework, ISMS integration, gap analysis of your current situation, and concrete action planning. More about our workshops →
How is the framework updated?
The framework is continuously maintained. When new regulations, updated standards, or new apps are released, we expand the documentation. As a workshop participant, you receive access to all updates.
How long does implementation take?
The workshop itself takes one day. Full integration into your processes depends on your current state - typically 2-4 weeks for technical implementation, 2-3 months for organizational anchoring.