A working reference of the standards, regulations and product-security regimes covered in my advisory practice. Each is informed by direct implementation and inspection experience.
Protection of Controlled Unclassified Information in nonfederal systems. Advisory covers Rev. 2 to Rev. 3 transition, SSP and POA&M maturity, and DFARS 252.204-7012 alignment.
Cybersecurity Maturity Model Certification readiness. Level 1 self-assessment scoping through Level 2 C3PAO assessment preparation, remediation planning and evidence curation.
Regulation (EU) 2016/679. Programme design, lawful-basis architecture, international transfer mechanisms (SCCs, TIAs), DPIAs, RoPA, and supervisory authority engagement.
UK-specific application of GDPR including ICO accountability expectations, UK-US Data Bridge utilisation and the Data Protection and Digital Information reform landscape.
Regulation (EU) 2024/1689. Risk classification, prohibited practices, high-risk system obligations, GPAI provider duties and the interaction with sectoral and data-protection law.
Security-by-design and lifecycle obligations for products with digital elements placed on the EU market. Conformity assessment routes, vulnerability handling and reporting to ENISA.
Regulation (EU) 2023/2854. B2B and B2G data sharing, IoT data access rights, cloud switching and interoperability requirements for data processing services.
Adjacent standards — ISO/IEC 27001, SOC 2, HIPAA, PCI DSS, NIS2 — covered as part of broader engagements where they intersect with the above.