Insights
Notes on getting compliance right
Practical analysis on regulatory mapping, third-party risk and the methodology behind gap analysis you can actually defend.
gap analysis RAG grounding assurance AI NIS2 NIST CSF cross-framework controls mapping DORA
NIS2 22 May 2026 · 3 min read
Mapping NIS2 to NIST CSF 2.0 without losing the thread
NIS2 sets obligations; NIST CSF 2.0 organises controls. Here's how to bridge the two so an EU directive and a US framework reinforce each other instead of duplicating work.
Read → DORA 12 May 2026 · 3 min read
DORA and ICT third-party risk: what the register of information really asks of you
A practical read on how DORA reframes vendor management around ICT concentration risk, and why a static spreadsheet of suppliers no longer cuts it.
Read →Want this applied to your frameworks?
RunCompliance turns these ideas into working gap analysis across 130+ frameworks.
Request early access