| FrameworkNIS2Essential and important entities | CapabilitiesZTNA | What it expectsArt. 21(2)(d)Control supply-chain access for suppliers, integrators and MSPs at application level and for a defined period. Art. 21(1) + Art. 21(3)Apply security measures proportionate to current risk and the state of the art. | Contribution Gives third parties time-boxed access to specific applications and re-evaluates user, device and context during each session. |
|---|
| FrameworkNIS2Essential and important entities | CapabilitiesPAM | What it expectsCIR Annex §11.3Use dedicated administration accounts with strong authentication and limited privileges. CIR Annex §11.4Separate administration systems and access paths from production. Art. 23Maintain evidence that supports the 24-hour early warning and 72-hour incident notification process. | Contribution Gives administrators individual accounts, isolates privileged access and records sessions so teams can reconstruct what happened during an incident. |
|---|
| FrameworkNIS2Essential and important entities | CapabilitiesAgentic AI | What it expectsArt. 21(2)(i)Apply access-control policies to non-human identities as well as people. Art. 23Keep enough attribution to reconstruct what happened during an incident and identify the actor responsible. | Contribution Gives each agent its own identity and scoped permissions, checks tool access through the MCP proxy and records the actions the agent performs. |
|---|
| FrameworkNIS2Essential and important entities | CapabilitiesIGA | What it expectsArt. 21(2)(i) + CIR Annex §11.2Document how access is granted, reviewed and removed, including joiner/mover/leaver processes, recertification and segregation of duties. CIR Annex §11.2–§11.3Revoke access when roles change or people leave, so orphaned and dormant accounts do not accumulate. | Contribution Automates the identity lifecycle, access reviews and revocation, with evidence of who holds each entitlement and under whose authority. |
|---|
| FrameworkNIS2Essential and important entities | CapabilitiesAuthentication & SSO | What it expectsArt. 21(2)(j) + CIR Annex §11.6–§11.7Apply MFA or continuous authentication to remote and critical access. CIR Annex §11.5Give every user a unique identity and retire shared logins. | Contribution Centralises MFA and authentication policies, gives users individual identities and protects credentials through SSO and credential injection. |
|---|
| FrameworkDORAFinancial entities | CapabilitiesZTNA | What it expectsArts. 28–30 + Art. 28(8)Control ICT-provider access and revoke it as part of third-party exit arrangements. RTS Art. 13Segregate and isolate critical systems. Arts. 26–27Reduce the externally exposed surface tested during threat-led penetration testing. | Contribution Brokers provider access to individual applications, isolates critical systems at the session layer and reduces public exposure of management interfaces. |
|---|
| FrameworkDORAFinancial entities | CapabilitiesPAM | What it expectsRTS Art. 21Use dedicated administrative accounts and automated privileged access management where feasible. RTS Art. 12 + Arts. 17–19Maintain logs that support monitoring and major-incident reporting. Art. 30(3)Make ICT-provider access, inspection and audit rights operational and traceable. | Contribution Brokers, limits and records administrator and ICT-provider sessions, with privileges tied to the approved task and period. |
|---|
| FrameworkDORAFinancial entities | CapabilitiesAgentic AI | What it expectsArt. 28Treat agents acting on critical financial systems as governed ICT dependencies with an owner and bounded mandate. Sensitive financial operationsApply pre-execution authorisation and human validation where actions are irreversible. Art. 18Distinguish whether a human or an agent initiated an incident-relevant action. | Contribution Gives agents defined owners and permissions, applies approval before sensitive actions and preserves attribution between human and machine activity. |
|---|
| FrameworkDORAFinancial entities | CapabilitiesIGA | What it expectsArt. 9(4)(c) + RTS Art. 20Maintain one unique identity for each employee, contractor and ICT third-party user. Art. 8(1)Review access more frequently for systems supporting critical or important functions. | Contribution Governs internal and third-party identities from one model, with access reviews aligned to the criticality of the systems involved. |
|---|
| FrameworkDORAFinancial entities | CapabilitiesAuthentication & SSO | What it expectsRTS Art. 21Use strong authentication for remote access, privileged access and ICT assets supporting critical or important functions. Art. 8(1)Match authentication strength to the criticality of the system or function. | Contribution Applies stronger authentication where risk is higher and reduces shared or embedded credentials across financial systems. |
|---|
| FrameworkISO/IEC 27001:2022 & 27002:2022Any sector | CapabilitiesZTNA | What it expectsA.8.20–A.8.22Protect network services and maintain network segregation. A.8.3 + A.6.7Restrict information access consistently for on-site and remote users. A.8.12 + A.8.23Reduce data leakage and control web access. | Contribution Enforces access per user and application. Browser isolation can restrict downloads and clipboard activity when users work from external or unmanaged devices. |
|---|
| FrameworkISO/IEC 27001:2022 & 27002:2022Any sector | CapabilitiesPAM | What it expectsA.8.2Restrict privileged rights, make them individually attributable and review them regularly. A.8.15 + A.8.16Log and monitor privileged activity. A.5.19–A.5.22Control supplier administration through managed access channels. | Contribution Vaults credentials, limits privileged access and creates searchable records of administrator and supplier activity. |
|---|
| FrameworkISO/IEC 27001:2022 & 27002:2022Any sector | CapabilitiesAgentic AI | What it expectsA.5.16Govern agents and service accounts as owned and reviewable non-human identities. A.8.16Extend monitoring to agent behaviour and anomalous tool calls. Clause 4.3Bring authorised AI use and Shadow AI inside the ISMS scope. | Contribution Registers agents as governed identities, monitors their actions and brings approved AI connectors into the same security perimeter as other access paths. |
|---|
| FrameworkISO/IEC 27001:2022 & 27002:2022Any sector | CapabilitiesIGA | What it expectsA.5.16 + A.5.18Control identity provisioning, access reviews and withdrawal of rights. A.5.15 + A.5.3Enforce access control and segregation of duties. Clauses 9.2–9.3Keep evidence of recertification for internal audit and management review. | Contribution Records provisioning, approvals, segregation of duties, reviews and withdrawals in one auditable workflow. |
|---|
| FrameworkISO/IEC 27001:2022 & 27002:2022Any sector | CapabilitiesAuthentication & SSO | What it expectsA.5.17 + A.8.5Protect authentication information and centrally enforce secure authentication, password and MFA policies. A.5.16Maintain one identity per person across the organisation. | Contribution Centralises SSO, MFA and credential policies while reducing local accounts and the number of passwords organisations need to govern. |
|---|
| FrameworkEHDSHealthcare and health data | CapabilitiesZTNA | What it expectsArt. 73(1)(a)–(b)Restrict access to authorised natural persons and protect health data against unauthorised reading, copying or removal. Art. 73(2)Allow only non-personal or anonymised data to leave the secure environment. Arts. 86–87Support storage constraints by keeping controlled access to data in place. | Contribution Browser isolation and VDI can restrict download, clipboard and printing while keeping protected health data inside the controlled environment. |
|---|
| FrameworkEHDSHealthcare and health data | CapabilitiesPAM | What it expectsArt. 73(1)(c)Limit the input, inspection, modification and deletion of health data to authorised and identifiable individuals. Art. 73(1)(e)Keep identifiable access and activity logs for at least one year. Vendor and biomedical maintenance controlsBroker and monitor maintenance access to EHR systems and connected medical devices. | Contribution Controls EHR administrators, biomedical teams and vendors through approved sessions tied to named identities and recorded at action level. |
|---|
| FrameworkEHDSHealthcare and health data | CapabilitiesAgentic AI | What it expectsData permit and care relationship controlsGive clinical AI assistants an identity scoped to the data they are authorised to use. Art. 73(1)(b) + Art. 73(2)Prevent agents from reading or exporting health datasets beyond their authorised scope. Art. 27Apply logging and human oversight where AI systems interact with health data. | Contribution Gives clinical agents their own scoped identities, restricts bulk data access and keeps agent activity attributable to the user and process that initiated it. |
|---|
| FrameworkEHDSHealthcare and health data | CapabilitiesIGA | What it expectsArts. 11–12Base health-professional access on care role and the actual care relationship. Art. 8 + Art. 71Enforce patient access restrictions and opt-outs as active access rules. Art. 9Be able to show patients who accessed their health data. | Contribution Turns care roles, patient restrictions and opt-outs into live access rules, with the identity trail needed to show who consulted a patient record and when. |
|---|
| FrameworkEHDSHealthcare and health data | CapabilitiesAuthentication & SSO | What it expectsArt. 16 + Art. 23Support interoperable identification and authentication of health professionals, including national and cross-border identity mechanisms. Art. 73(1)(d)Give each user an individual, unique identity and confidential access method. | Contribution Gives clinicians individual identities while fast re-authentication and roaming sessions keep shared clinical workstations practical. |
|---|
| FrameworkNIST SP 800-53 Rev. 5US federal and defence supply chain | CapabilitiesZTNA | What it expectsSC-7 + AC-4Protect boundaries and enforce information flows at the application level. SP 800-207Apply Zero Trust access decisions to individual resources. AC-17 + AC-20Control remote access from unmanaged, BYOD and partner endpoints. | Contribution Connects users to authorised applications rather than the wider network and applies access policy to each session and endpoint context. |
|---|
| FrameworkNIST SP 800-53 Rev. 5US federal and defence supply chain | CapabilitiesPAM | What it expectsAC-6(5) + AC-6(9)Restrict privileged accounts to defined personnel and audit privileged functions. AU-2 + AU-6 + AU-12Generate, review and analyse audit records. AC-17 + MA-4Authenticate, monitor and terminate remote vendor maintenance according to schedule. | Contribution Grants controlled privileged access, records administrative actions and closes maintenance sessions when the approved work ends. |
|---|
| FrameworkNIST SP 800-53 Rev. 5US federal and defence supply chain | CapabilitiesAgentic AI | What it expectsIA-9Identify and authenticate non-person entities before they are allowed to act. AC-6Apply least privilege to the tools and actions an agent may use. NIST AI RMFMake AI system behaviour governable, measurable and accountable. | Contribution Authenticates agents separately, limits their tool calls and records their activity for governance, measurement and investigation. |
|---|
| FrameworkNIST SP 800-53 Rev. 5US federal and defence supply chain | CapabilitiesIGA | What it expectsAC-2 + AC-5 + AC-6Govern accounts, segregation of duties and least privilege through controlled provisioning and review. AC-2(3) + AC-2(13)Automatically disable inactive or high-risk accounts. SP 800-37Maintain testable access-control evidence for RMF authorisation and ATO renewal. | Contribution Automates account governance and reviews while producing access-control evidence for assessments and authorisation renewals. |
|---|
| FrameworkNIST SP 800-53 Rev. 5US federal and defence supply chain | CapabilitiesAuthentication & SSO | What it expectsIA-2(1) + IA-2(2)Require MFA for privileged and non-privileged accounts. IA-5 + SP 800-63BManage authenticators and support appropriate assurance levels, including phishing-resistant methods. IA-8Identify and authenticate contractors, partners and other external users. | Contribution Applies central authentication policies to employees and external users, with stronger methods where higher assurance is required. |
|---|
| FrameworkISA/IEC 62443Industrial automation and OT | CapabilitiesZTNA | What it expectsSR 5.1 + SR 5.2Maintain network segmentation and zone-boundary protection. Purdue-model disciplineKeep remote users on the authorised asset rather than placing them on the OT network. 62443-3-2Support the target security-level case for remote-access conduits. | Contribution Creates identity-based, application-level connections to specific OT assets while preserving zones, conduits and existing network segmentation. |
|---|
| FrameworkISA/IEC 62443Industrial automation and OT | CapabilitiesPAM | What it expectsSR 1.13 + SR 2.1Broker, approve and time-box OEM and integrator maintenance sessions. SR 2.8–SR 2.11Record auditable events, timestamps and changes to industrial assets. Credential managementProtect shared engineering credentials that are difficult to rotate. | Contribution Brokers OT maintenance, vaults credentials and records who changed an industrial asset, what they changed and when. |
|---|
| FrameworkISA/IEC 62443Industrial automation and OT | CapabilitiesAgentic AI | What it expectsIndustrial write controlsRequire human validation before an agent sends an irreversible command to a controller. Least-privilege operationKeep diagnostics and optimisation agents read-only where write access is unnecessary. SR 2.8Extend auditability to machine-initiated commands. | Contribution Keeps industrial agents within defined read or write permissions, supports human approval before critical actions and records machine-initiated commands. |
|---|
| FrameworkISA/IEC 62443Industrial automation and OT | CapabilitiesIGA | What it expectsFR 1 / SR 1.1Identify and authenticate human users on every interface. SR 2.1Assign permissions according to role and zone, giving operators, maintenance engineers and integrators distinct access rights. 62443-2-4Maintain documented and auditable account management for service providers. | Contribution Gives OT users and service providers named, role-based access with a clear record of who is entitled to reach each environment. |
|---|
| FrameworkISA/IEC 62443Industrial automation and OT | CapabilitiesAuthentication & SSO | What it expectsSR 1.5 + SR 1.7Manage authenticators and password strength, including on assets that cannot enforce these controls natively. SR 1.13Authenticate and approve maintenance access before it reaches industrial systems. | Contribution Uses central authentication and credential injection to protect access to legacy HMIs, PLCs and other OT assets while preserving operational availability. |
|---|
| FrameworkTISAX / VDA ISAAutomotive supply chain | CapabilitiesZTNA | What it expectsSupplier access controlsGive suppliers per-application access while keeping the corporate network protected. Prototype Protection controlsAllow sensitive prototype information to be viewed under controls that can restrict downloading. Connected IT and OT scopeApply consistent enforcement across enterprise and manufacturing systems. | Contribution Gives suppliers controlled access to authorised applications and can keep prototype information off external devices through browser isolation. |
|---|
| FrameworkTISAX / VDA ISAAutomotive supply chain | CapabilitiesPAM | What it expectsPrototype Protection controlsMake administration of engineering, PLM and MES systems traceable. Supplier access controlsGrant supplier and integrator administrators temporary elevation for the intervention period. Audit evidenceBe able to determine who could have accessed or removed sensitive design data. | Contribution Gives suppliers temporary privileged access and records administrative sessions around systems holding engineering and prototype information. |
|---|
| FrameworkTISAX / VDA ISAAutomotive supply chain | CapabilitiesAgentic AI | What it expectsPrototype Protection controlsKeep engineering and prototype information inside the assessed environment when AI tools are used. Identity and scope controlsGive approved agents limited access to the engineering data they require. Incident handling and information classificationMaintain traceability of what an agent accessed. | Contribution Governs agent identities and connectors, limits their access to engineering information and records which protected data they read. |
|---|
| FrameworkTISAX / VDA ISAAutomotive supply chain | CapabilitiesIGA | What it expectsVDA ISA Control DomainMaintain a documented identity and access lifecycle for employees, agency staff and supplier personnel. Prototype Protection moduleGrant access to prototype and pre-series information on a need-to-know basis and withdraw it when the project ends. | Contribution Applies the same identity governance to employees and suppliers, including project-based access to sensitive engineering and prototype data. |
|---|
| FrameworkTISAX / VDA ISAAutomotive supply chain | CapabilitiesAuthentication & SSO | What it expectsVDA ISA 4.1.xRequire unique identification, hardened login procedures and MFA for external and remote access. Data Protection moduleProtect access to personal data belonging to employees, agency staff and suppliers. | Contribution Applies consistent authentication across engineering, PLM and manufacturing systems and reduces unmanaged local accounts. |
|---|
| FrameworkSOC 2SaaS, BPO and cloud providers | CapabilitiesZTNA | What it expectsCC6.6Protect systems from threats originating outside the system boundary. CC6.7Prevent information from moving to unauthorised endpoints. System description requirementsMaintain a controlled and describable access path. | Contribution Keeps management interfaces away from direct internet exposure and isolates customer data from unmanaged endpoints. |
|---|
| FrameworkSOC 2SaaS, BPO and cloud providers | CapabilitiesPAM | What it expectsCC6.1 + CC6.3Restrict privileged access to identifiable and reviewed users. CC7.2Monitor administrative activity and maintain evidence for investigations. Third-party administrationKeep contractor and subservice-provider administration supervised. | Contribution Replaces shared administrator access with named sessions and records internal and external privileged activity for monitoring and investigation. |
|---|
| FrameworkSOC 2SaaS, BPO and cloud providers | CapabilitiesAgentic AI | What it expectsCC6.1Authenticate and authorise machine principals and automation identities before they access protected systems. CC7.2Monitor agent activity affecting systems and customer data. Attribution controlsMaintain evidence of automated actions that affect information inside the system boundary. | Contribution Applies identity and access policies to agents and records automated actions that read, change or move customer information. |
|---|
| FrameworkSOC 2SaaS, BPO and cloud providers | CapabilitiesIGA | What it expectsCC6.2Control the registration and authorisation of new internal and external users. CC6.3Apply role-based access and update or remove rights promptly when responsibilities change. | Contribution Creates a controlled, dated identity lifecycle across the audit period, reducing manual account reconciliation. |
|---|
| FrameworkSOC 2SaaS, BPO and cloud providers | CapabilitiesAuthentication & SSO | What it expectsCC6.1Identify and authenticate users before they access protected information assets. CC6.7Restrict unauthorised transmission, movement and removal of information outside the system boundary. | Contribution Centralises MFA and session policies across the SaaS estate, giving auditors a consistent authentication control to assess. |
|---|
| FrameworkEU GDPRPersonal data processing | CapabilitiesZTNA | What it expectsArt. 32(1)(b)Protect the confidentiality of systems processing personal data. Art. 28 + Chapter VControl, log and geographically govern processor and sub-processor access. Data protection controlsKeep personal data from being stored on unmanaged endpoints. | Contribution Brokers third-party access, keeps protected systems away from direct public exposure and limits local copies of personal data on external devices. |
|---|
| FrameworkEU GDPRPersonal data processing | CapabilitiesPAM | What it expectsArt. 32Make administrator access to personal data controlled and accountable. Arts. 33–34Maintain enough evidence to determine what data was accessed during a breach and support notification obligations. Transparency requirementsApply appropriate information, proportionality and retention controls to recorded administrators. | Contribution Records privileged sessions and actions so teams can determine which personal data was viewed, changed or accessed during an incident. |
|---|
| FrameworkEU GDPRPersonal data processing | CapabilitiesAgentic AI | What it expectsArt. 5(1)(c)Limit the personal data an agent may read to what is necessary for its purpose. Art. 22Apply appropriate human involvement to automated decisions with legal or similarly significant effects. Art. 5(2) + Art. 30Maintain records showing which personal data an agent processed. | Contribution Limits each agent's data and tool access, applies human approval to sensitive actions and records what personal data the agent processed. |
|---|
| FrameworkEU GDPRPersonal data processing | CapabilitiesIGA | What it expectsArt. 25Apply data protection by design and by default, including minimising access before personal data is touched. Art. 32(1)(b) + 32(4)Maintain a demonstrable need-to-know model showing who may access personal data and under whose authority. Art. 5(2) + Art. 30Keep accountable records showing how access rights are governed and reviewed. | Contribution Enforces least privilege at the entitlement layer and records who received access, why it was approved and when it was reviewed or withdrawn. |
|---|
| FrameworkEU GDPRPersonal data processing | CapabilitiesAuthentication & SSO | What it expectsArt. 32(1)(b)Use authentication controls proportionate to the risk and sensitivity of the personal data. Art. 35Carry out a DPIA where biometric or behavioural authentication creates high privacy risk. Art. 33Reduce credential-related breach risk through stronger password and authentication practices. | Contribution Applies risk-based authentication and reduces password exposure through SSO, MFA and credential injection. |
|---|