Compliance & Regulation

Compliance frameworks – which are supported by ViVeSec Box by default

ViVeSec Box is not just a technical protection, but an auditable compliance platform. The requirements of the following frameworks are architecturally and documented in the product - not as an after-the-fact module.

NIS2 EU Directive

NIS2 – Network and Information Systems Security

The EU NIS2 Directive imposes strict cybersecurity requirements on critical and important organizations – with obligations for recovery, incident management and business continuity.

How ViVeSec Box helps

  • Immutable, ransomware-resistant backup (NIS2 Article 21 – risk management measures)
  • Business continuity and recovery capability with documented RTO
  • Incident management capability: rapid recovery after an attack with auditable steps
  • Access control (RBAC), 4-eye principle for critical operations
  • Tamper-evident audit log for supervisory investigations
GDPR EU · Regulation

GDPR – General Data Protection Regulation

GDPR is the EU's General Data Protection Regulation, which imposes obligations on controllers and processors of personal data - integrity, confidentiality, availability.

How ViVeSec Box helps

  • On-premise storage – data does not leave the customer's infrastructure
  • AES-256 encryption at rest and in transit
  • Exportable audit log of data processing operations
  • Auditable implementation of data erasure requests (“right to be forgotten”)
  • Rapid recovery after a data breach (Art. 32 – technical and organizational measures)
ISO 27001 International Standard

ISO/IEC 27001 – Information Security Management System

ISO 27001 is the leading international information security standard. With ViVeSec Box, a significant part of Annex A controls can be technically implemented.

How ViVeSec Box helps

  • A.8.13 Information backup – immutable backup with WORM storage
  • A.5.30 ICT readiness for business continuity – Instant Recovery
  • A.8.3 Information access restriction – RBAC + 4-eye principle
  • A.8.15 Logging – tamper-evident, exportable audit log
  • A.8.24 Use of cryptography – AES-256 + CRYSTALS-Dilithium (NIST PQC)
CE EU · Compliance

CE marking – placing on the EU market

The ViVeSec Box has a CE Declaration of Conformity – the legal basis for placing on the EU market and certain public procurement procedures.

How ViVeSec Box helps

  • EMC – electromagnetic compatibility
  • LVD – low voltage electrical equipment
  • RoHS – Restriction of Hazardous Substances
  • EU-MADE – supply chain transparency
CC International Certification

Common Criteria – Security Target

ViVeSec Box comes with a Security Target document prepared according to the principles of Common Criteria (ISO/IEC 15408), which formally describes the resources to be protected, threat models and security functions. The architecture is based on the principles of EAL 2 assessment level.

How ViVeSec Box helps

  • TOE (Target of Evaluation) and its boundaries are precisely defined
  • Threat Models and Security Objectives
  • Safety Functional Requirements (SFRs)
  • Hardware TPM root-of-trust with documented initialization
  • EAL 2-based design and testing practices
UK CE UK · Certificate

UK Cyber Essentials

The UK's basic cybersecurity certification, which requires 5 essential controls. ViVeSec Box also technically supports the following controls.

How ViVeSec Box helps

  • Firewalls and routers – out-of-band management, network segmentation
  • Secure configuration – closed, dedicated platform, reduced attack surface
  • User access control – RBAC + 4-eye principle
  • Malware protection – immutable storage, ransomware-resistant architecture
  • Patch management – priority security patches as part of the license

Are you preparing for an audit? Let's talk.

Our experts help you prepare for NIS2, GDPR, ISO 27001 or DORA audits - with specific controls that can be implemented with ViVeSec Box.

Book a meeting →