Home / Compliance

Multi-framework compliance

ISO 27001, NIS2, GDPR, HDS, DORA, SOC 2, PCI-DSS, NIST CSF — Galea centralises your compliance across all regulatory and normative frameworks.

A single dashboard for all your frameworks

Galea calculates your compliance rate in real time for each activated framework.

1

Activate your frameworks

Select the standards applicable to your organisation. Each framework is pre-loaded with its controls.

2

Assess each control

For each control, indicate the implementation level (Absent, Partial, In progress, Compliant) with supporting evidence.

3

Manage continuously

Real-time dashboard, corrective action plans, audit reports ready to submit to your auditors.

ISO 27001:2022

Information security management system

The international reference standard for ISMS. Galea pre-loads the 93 Annex A controls and guides your teams through each domain.

93Annex A controls
4Themes (Annex A)
37Organisational measures
Statement of Applicability (SoA)

Automatically generated, exportable as PDF and XLSX

Per-domain scoring

Compliance rate by ISO chapter with identified gaps

Evidence management

Attach supporting documents to each control

ISO 27001:2022
70%
Security policy
Access control
Incident management
Business continuity
NIS2 — EU Directive

Network and Information Systems security directive

Mandatory since October 2024 for essential and important entities in Europe. Galea guides you through the 10 required cybersecurity measures.

10Mandatory measures
72hNotification deadline
10M€Maximum fine
Essential / important entity classification

Galea automatically determines your NIS2 category

Security incident management

NIS2-compliant 24h/72h notification workflow

Supply chain

TPRM assessment of critical NIS2 suppliers

NIS2 Checklist
Risk management policy
Incident management
Business continuity
Supply chain security
MFA authentication
Communications encryption
Annual penetration testing

GDPR, HDS & DORA

GDPR

Personal data protection

Processing register, DPIA (Data Protection Impact Assessment), data subject rights management, data breaches. Galea supports your DPO in their daily mission.

Processing register Automated DPIA Data subject rights Supervisory authority notification
HDS

Health Data Hosting

Mandatory certification for hosting health data. Galea supports healthcare establishments and e-health players in their certification process.

Data flow mapping HDS controls Access management Traceability
DORA

Digital operational resilience

Digital Operational Resilience Act — mandatory for the financial sector since January 2025. Resilience testing, ICT risk management, incident reporting.

ICT risks Resilience testing Incident register Critical third parties

Audit your compliance for free

30-minute demo with a Galea expert, no commitment.

Start the audit
Free trial — No credit card

Ready to secure your organisation?

Join the companies that trust Galea to drive their cyber-résilience. 30-minute demo.

Already a customer? Go to the platform