Taking new engagements — Q4 hello@datadefenz.com
ServicesAll servicesGRC & Compliance7Security Culture1Risk Management3Technical Security5Leadership Advisory1Fast-Turnaround1
ProductsResourcesPracticeAboutBook a 30-minute callContact

Products & platforms

The DATADEFENZ product ecosystem

Regulatory and cybersecurity readiness, delivered as tools rather than as slide decks. Some are live on this site, one runs as a separate platform, and two are in active development — each is labelled honestly.

PDPA Compliance Navigator

Available
Sri Lanka Personal Data Protection Act

A guided navigator covering scope, controller and processor roles, responsibilities, the real commencement timeline, GDPR relationships, ISO 27001 and NIST alignment, evidence and readiness.

  • Scope assessment against the four s.2(1) triggers
  • Controller / processor role determination
  • Ten-dimension readiness self-assessment
  • GDPR comparison and ISO 27001 gap mapping
Explore PDPA Navigator

Regulatory Scope Navigator

Available
“Am I in scope?”

An applicability engine across eleven regulations, standards and frameworks. It answers which requirements are likely relevant to you — and, more usefully, why, and how confident that answer is.

  • Adaptive questioning — the path changes with your answers
  • Separates law from standard from framework from assurance
  • Confidence level on every verdict
  • Shows which of your answers drove each result
Run the assessment

ISO 27001 Gap Assessment

Available
ISO/IEC 27001:2022 readiness

Assessment against the clause 4–10 management-system requirements and all 93 Annex A controls, built around implementation, evidence and effectiveness rather than document counts.

  • Clauses 4–10 and Annex A, assessed separately
  • Statement of Applicability draft
  • Evidence expectations per control
  • Sequenced gap closure plan
See the service

NIS2 Compliance & Readiness Platform

Platform
Directive (EU) 2022/2555

A dedicated platform for assessing NIS2 applicability, requirements, organisational readiness, evidence and remediation. Hosted separately from this site.

  • Applicability and entity classification
  • Article 21 measure assessment
  • Evidence and remediation tracking
Explore Platform

SOC Maturity Assessment

Available
SOC-CMM · security operations capability

Assessment against the SOC-CMM, the open maturity and capability model the industry benchmarks security operations against. Five domains, with maturity and capability scored separately — delivered by dedicated security-operations specialists.

  • Business, People, Process, Technology and Services domains
  • Evidence-validated rather than self-reported
  • Element-level heat map and target maturity profile
  • Re-runnable annual baseline
See the assessment

HumanRISK

In development
Human cyber risk & security awareness

A human-risk platform helping organisations understand, measure and improve human-related cyber risk — simulation, adaptive training and population-level risk scoring rather than course-completion percentages.

  • Sector-matched simulation lures
  • Role-based adaptive training
  • Departmental risk tiering that trends over quarters
  • Reporting formatted as awareness-control evidence
See HumanRISK

AI Governance OS

In development
AI governance, risk & compliance

Governance • Risk • Compliance • Evidence. A platform to help organisations understand AI governance obligations, inventory and assess AI systems, manage AI risk, and prepare for emerging AI regulation including the EU AI Act.

  • AI system inventory and role determination
  • Risk classification support
  • Control mapping against existing ISMS work
  • Evidence model for technical documentation
Contact DATADEFENZ

Regimes & frameworks

What we help organisations understand, assess and prepare for.

Grouped by what they actually are, because the distinction matters more than the list. A regulation binds you whether you like it or not. A standard is something you choose to conform to. An assurance report is an auditor's opinion you commission. Treating them alike is how compliance budgets get misspent.

Privacy & data protection
  • Sri Lanka PDPANational legislation
  • GDPRRegulation
  • ISO/IEC 27701Standard
Cybersecurity & information security
  • ISO/IEC 27001Standard
  • NIST CSF 2.0Framework
  • NIST SP 800-53Control catalogue
  • NIST SP 800-171Control catalogue
  • CIS ControlsFramework
Security operations
  • SOC-CMMMaturity model
  • NIST SP 800-61Guidance
  • MITRE ATT&CKKnowledge base
EU digital & cyber regulation
  • NIS2Directive
  • DORARegulation
  • Cyber Resilience ActRegulation
  • EU AI ActRegulation
  • Data ActRegulation
  • eIDAS 2.0Regulation
Assurance & industry standards
  • SOC 2Assurance report
  • PCI DSSIndustry standard
Product, software & AI
  • EU AI ActRegulation
  • Cyber Resilience ActRegulation
  • IVDR — device softwareRegulation
Regulations — legal obligations Standards — structured requirements Frameworks — risk & control guidance Assurance — independent evidence

Building your compliance programme?

Talk to DATADEFENZ about your readiness.

Thirty minutes, no charge. Regulatory and cybersecurity readiness, assessed against your actual situation.