Products & platforms
The DATADEFENZ product ecosystem
Regulatory and cybersecurity readiness, delivered as tools rather than as slide decks. Some are live on this site, one runs as a separate platform, and two are in active development — each is labelled honestly.
PDPA Compliance Navigator
AvailableA guided navigator covering scope, controller and processor roles, responsibilities, the real commencement timeline, GDPR relationships, ISO 27001 and NIST alignment, evidence and readiness.
- Scope assessment against the four s.2(1) triggers
- Controller / processor role determination
- Ten-dimension readiness self-assessment
- GDPR comparison and ISO 27001 gap mapping
Regulatory Scope Navigator
AvailableAn applicability engine across eleven regulations, standards and frameworks. It answers which requirements are likely relevant to you — and, more usefully, why, and how confident that answer is.
- Adaptive questioning — the path changes with your answers
- Separates law from standard from framework from assurance
- Confidence level on every verdict
- Shows which of your answers drove each result
ISO 27001 Gap Assessment
AvailableAssessment against the clause 4–10 management-system requirements and all 93 Annex A controls, built around implementation, evidence and effectiveness rather than document counts.
- Clauses 4–10 and Annex A, assessed separately
- Statement of Applicability draft
- Evidence expectations per control
- Sequenced gap closure plan
NIS2 Compliance & Readiness Platform
PlatformA dedicated platform for assessing NIS2 applicability, requirements, organisational readiness, evidence and remediation. Hosted separately from this site.
- Applicability and entity classification
- Article 21 measure assessment
- Evidence and remediation tracking
SOC Maturity Assessment
AvailableAssessment against the SOC-CMM, the open maturity and capability model the industry benchmarks security operations against. Five domains, with maturity and capability scored separately — delivered by dedicated security-operations specialists.
- Business, People, Process, Technology and Services domains
- Evidence-validated rather than self-reported
- Element-level heat map and target maturity profile
- Re-runnable annual baseline
HumanRISK
In developmentA human-risk platform helping organisations understand, measure and improve human-related cyber risk — simulation, adaptive training and population-level risk scoring rather than course-completion percentages.
- Sector-matched simulation lures
- Role-based adaptive training
- Departmental risk tiering that trends over quarters
- Reporting formatted as awareness-control evidence
AI Governance OS
In developmentGovernance • Risk • Compliance • Evidence. A platform to help organisations understand AI governance obligations, inventory and assess AI systems, manage AI risk, and prepare for emerging AI regulation including the EU AI Act.
- AI system inventory and role determination
- Risk classification support
- Control mapping against existing ISMS work
- Evidence model for technical documentation
Regimes & frameworks
What we help organisations understand, assess and prepare for.
Grouped by what they actually are, because the distinction matters more than the list. A regulation binds you whether you like it or not. A standard is something you choose to conform to. An assurance report is an auditor's opinion you commission. Treating them alike is how compliance budgets get misspent.
- Sri Lanka PDPANational legislation
- GDPRRegulation
- ISO/IEC 27701Standard
- ISO/IEC 27001Standard
- NIST CSF 2.0Framework
- NIST SP 800-53Control catalogue
- NIST SP 800-171Control catalogue
- CIS ControlsFramework
- SOC-CMMMaturity model
- NIST SP 800-61Guidance
- MITRE ATT&CKKnowledge base
- NIS2Directive
- DORARegulation
- Cyber Resilience ActRegulation
- EU AI ActRegulation
- Data ActRegulation
- eIDAS 2.0Regulation
- SOC 2Assurance report
- PCI DSSIndustry standard
- EU AI ActRegulation
- Cyber Resilience ActRegulation
- IVDR — device softwareRegulation
Building your compliance programme?
Talk to DATADEFENZ about your readiness.
Thirty minutes, no charge. Regulatory and cybersecurity readiness, assessed against your actual situation.
