Compliance
Regulation, translated into engineering work
A standard is a document until somebody turns it into a backlog with owners and dates. That translation is most of the job.
In short
Compliance work translates regulatory and standards requirements into specific engineering and process changes, and produces the evidence that they operated. Cloudgap delivers certification programmes against ISO 27001, ISO 42001, SOC 2, Cyber Essentials and PCI DSS, and readiness work for the EU AI Act, DORA and UK data protection law.
The translation
Compliance budget as an investment, or as a cost centre
The difference is whether the work leaves anything behind. A programme run to pass an audit produces a certificate and a set of documents that decay from the day they are signed. A programme run to change how the organisation operates produces the same certificate and a set of controls that are still working at the surveillance audit.
In practice the divergence happens early, at scoping. Scope drawn to satisfy the auditor produces the first outcome. Scope drawn around what the business actually needs to be able to prove - to a customer, a regulator or an investor - produces the second, and it is usually smaller.
The other divergence is who does the work. A programme where a consultant writes everything and the internal team learns nothing fails at the first surveillance audit, because nobody inside the organisation understands what they are maintaining.
Standards
Standards we run programmes against
Each has a reference page written for practitioners, and a side-by-side comparison if you are choosing between them.
- ISO 27001ISO/IEC 27001 is the international standard for information security management systems.
- ISO 42001ISO/IEC 42001 is the international standard for AI management systems, published in December 2023.
- SOC 2SOC 2 is an attestation report produced by an independent CPA firm against the AICPA Trust Services Criteria.
- NIST AI RMFThe NIST AI Risk Management Framework is voluntary guidance for managing risk in artificial intelligence systems, published by the US National Institute of Standards and Technology in January 2023.
- NIST 800-53NIST Special Publication 800-53 is a catalogue of security and privacy controls published by the US National Institute of Standards and Technology.
- Cyber EssentialsCyber Essentials is a UK government-backed certification scheme covering five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.
- PCI DSSPCI DSS is the Payment Card Industry Data Security Standard, maintained by the PCI Security Standards Council.
- GDPRThe UK GDPR, read alongside the Data Protection Act 2018, governs how organisations process personal data in the United Kingdom.
Regulatory horizon
The deadlines behind the standards
Every date below is checked against the regulator, the Commission or the issuing body, and stamped with the day it was last read. Where a deadline has moved, what moved it is stated. If you only read one thing here, read the deferrals - a postponed obligation is not a withdrawn one.
Last verified 25 August 2026 · 11 obligations tracked
| Obligation | Date | Status | Who it hits | Source |
|---|---|---|---|---|
| EU AI ActAnnex III standalone high-risk system obligations applyDeferred from 2 August 2026 by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026. A 16-month deferral, granted because harmonised standards and national competent authorities were not ready. The obligation was postponed, not withdrawn. | 14 months away | Deferred | Providers and deployers of AI used in employment, education, credit and insurance scoring, essential services, law enforcement, migration and the administration of justice.How we handle this -> | European Commission, Shaping Europe's digital futureRead 25 August 2026 |
| EU AI ActAnnex I high-risk obligations apply to AI embedded in regulated productsDeferred by Regulation (EU) 2026/1744, the Digital Omnibus on AI. A 12-month deferral. | 22 months away | Deferred | Manufacturers placing AI inside products already covered by EU product-safety law - medical devices, machinery, lifts, toys, vehicles.How we handle this -> | European Commission, Shaping Europe's digital futureRead 25 August 2026 |
| UK Cyber Security and Resilience BillBefore Parliament. Not yet law, and no commencement date is set.Introduced to the Commons on 12 November 2025. Passed Commons stages and moved to the Lords. Commencement is staged from Royal Assent, with the substantive duties left to secondary legislation. The government has said it intends to consult on implementation during 2026. | Before Parliament | If enacted as drafted: existing NIS sectors plus medium and large managed service providers, data centres, large load controllers and designated critical suppliers. Initial incident notification within 24 hours, fuller report within 72.How we handle this -> | GOV.UK, Cyber Security and Resilience Bill factsheets (page last updated 30 June 2026)Read 25 August 2026 | |
| EU AI ActArticle 50 transparency obligations apply | 2 months ago | In force | Any provider or deployer whose AI interacts with people or generates synthetic audio, image, video or text. Chatbots must disclose they are machines; synthetic media must be machine-readably marked.How we handle this -> | European Commission, Shaping Europe's digital futureRead 25 August 2026 |
| Cyber EssentialsRequirements for IT Infrastructure v3.3 and the Danzell question set applyStricter marking on MFA and on timely security updates, where a shortfall is now an automatic fail rather than a finding. Greater emphasis on passwordless authentication and passkeys. Scoping tightened: any specified device connected to the internet is in scope. | 5 months ago | In force | Every organisation certifying or recertifying. Applies to all applications registered from 27 April 2026.How we handle this -> | IASME, Cyber Essentials delivery partner for the NCSCRead 25 August 2026 |
Start
Three ways in, depending on how close the deadline is.
- Book it
Book a discovery call
Thirty minutes, no deck. We work out whether there is a real engagement here, and say so if there is not.
- Go
Check the EU AI Act applies
Six questions, a dated list of the obligations that reach you, and a calendar file so the deadlines land somewhere you will see them again.
- Go
Request a roadmap
You know the obligation and the deadline. We scope the sprints, the deliverables and the dates.
Or just email a human: hello@cloudgap.ai
We reply within24 hours