Compliance & Regulation

Compliance frameworks – which are supported by ViVeSec Box by default

ViVeSec Box is not just a technical protection, but an auditable compliance platform. The requirements of the following frameworks are architecturally and documented in the product - not as an after-the-fact module.

NIS2 EU Directive

NIS2 – Network and Information Systems Security

The EU NIS2 Directive imposes strict cybersecurity requirements on critical and important organizations – with obligations for recovery, incident management and business continuity.

How ViVeSec Box helps

  • Immutable, ransomware-resistant backup (NIS2 Article 21 – risk management measures)
  • Business continuity and recovery capability with documented RTO
  • Incident management capability: rapid recovery after an attack with auditable steps
  • Access control (RBAC), 4-eye principle for critical operations
  • Tamper-evident audit log for supervisory investigations
GDPR EU · Regulation

GDPR – General Data Protection Regulation

GDPR is the EU's General Data Protection Regulation, which imposes obligations on controllers and processors of personal data - integrity, confidentiality, availability.

How ViVeSec Box helps

  • On-premise storage – data does not leave the customer's infrastructure
  • AES-256 encryption at rest and in transit
  • Exportable audit log of data processing operations
  • Auditable implementation of data erasure requests (“right to be forgotten”)
  • Rapid recovery after a data breach (Art. 32 – technical and organizational measures)
ISO 27001 International Standard

ISO/IEC 27001 – Information Security Management System

ISO 27001 is the leading international information security standard. With ViVeSec Box, a significant part of Annex A controls can be technically implemented.

How ViVeSec Box helps

  • A.8.13 Information backup – immutable backup with WORM storage
  • A.5.30 ICT readiness for business continuity – Instant Recovery
  • A.8.3 Information access restriction – RBAC + 4-eye principle
  • A.8.15 Logging – tamper-evident, exportable audit log
  • A.8.24 Use of cryptography – AES-256 + CRYSTALS-Dilithium (NIST PQC)
CE EU · Compliance

CE marking – placing on the EU market

The ViVeSec Box has a CE Declaration of Conformity – the legal basis for placing on the EU market and certain public procurement procedures.

How ViVeSec Box helps

  • EMC – electromagnetic compatibility
  • LVD – low voltage electrical equipment
  • RoHS – Restriction of Hazardous Substances
  • EU-MADE – supply chain transparency
CC International Certification

Common Criteria – Security Target

ViVeSec Box comes with a Security Target document prepared according to the principles of Common Criteria (ISO/IEC 15408), which formally describes the resources to be protected, threat models and security functions. The architecture is based on the principles of EAL 2 assessment level.

How ViVeSec Box helps

  • TOE (Target of Evaluation) and its boundaries are precisely defined
  • Threat Models and Security Objectives
  • Safety Functional Requirements (SFRs)
  • Hardware TPM root-of-trust with documented initialization
  • EAL 2-based design and testing practices
UK CE UK · Certificate

UK Cyber Essentials

The UK's basic cybersecurity certification, which requires 5 essential controls. ViVeSec Box also technically supports the following controls.

How ViVeSec Box helps

  • Firewalls and routers – out-of-band management, network segmentation
  • Secure configuration – closed, dedicated platform, reduced attack surface
  • User access control – RBAC + 4-eye principle
  • Malware protection – immutable storage, ransomware-resistant architecture
  • Patch management – priority security patches as part of the license
Certificates & documents

Compliance and transparency –

ViVeSec Box is built to not only meet compliance and security requirements, but also to prove it in a documented and verifiable way. All key documents are publicly available for download.

CE Declaration of Conformity CC Common Criteria – Security Target EU EU-MADE – supply chain NIS2 NIS2 Ready GDPR GDPR Ready

Security Target (Common Criteria principles)

Detailed documentation of the resources to be protected, threat models, and security features. EAL 2.

Download from the Downloads page

Are you preparing for an audit? Let's talk.

Our experts help you prepare for NIS2, GDPR, ISO 27001 or DORA audits - with specific controls that can be implemented with ViVeSec Box.

Book a meeting →