Skip to main content

ADR-017 — Product compliance posture

1. Context

Distinct from ADR-016 (what we sell to customers as compliance value), this ADR covers what Noxys itself must comply with as a vendor — regulatory obligations applying to our company and our products, plus the certifications we pursue to unlock enterprise sales.

Two pressures push this forward:

  1. Regulatory cliff: Cyber Resilience Act mandatory 2027 for products with digital elements (extension + agent + proxy all qualify). NIS2 cascade obligations from clients in regulated sectors. DORA from financial-sector clients. GDPR Art 32 baseline.
  2. Sales gating: Enterprise deals (>1k seats) require ISO 27001 minimum, often SOC 2 Type II, increasingly ISO 42001 for AI products. French sovereign deals (gov, defense, OIV) require SecNumCloud. German enterprise gates via BSI C5 / AIC4.

We must sequence certifications to balance cost (~250-400k€ total over 2 years), audit readiness effort, and revenue unlock.

2. Decision summary

  • Trust Center public at noxys.eu/trust shipped M6 (June 2026) — pre-cert credibility surface.
  • Certifications timeline: ISO 27001 first (M9-12), SOC 2 Type II + ISO 42001 in parallel (M12-15 / M15-18), SecNumCloud H2 2027, BSI C5/AIC4 2028.
  • CRA pre-assessment for extension + agent in 2026 to be ready for 2027 mandatory date.
  • DPA + sub-processors public by M3 (already partially via legal page).
  • Vendor questionnaire pre-fills (CAIQ + SIG) maintained as living artefacts.

3. Regulatory obligations applicable to Noxys

RegulationWhy it appliesAction requiredOwner
GDPR (Reg. 2016/679)Process customer/end-user data in EUDPA, Art 30 register, Art 32 controls, DPIA, Art 35Jerome (DPO interim)
EU AI Act (Reg. 2024/1689)We provide AI security tooling — high-risk classification possibleSelf-assessment + technical documentationProduct
CRA (Reg. 2024/2847)Extension + agent + proxy = "products with digital elements", deadline 2027Conformity assessment + CE marking + SBOM + vuln handling processProduct + Infra
NIS2 (Dir. 2022/2555)Vendor cascade if customers are essential/important entitiesIncident reporting capacity 24h, supply-chain due diligenceInfra
DORA (Reg. 2022/2554)Financial-sector clients require ICT risk vendor obligationsResilience testing + incident reporting + sub-contractor registerInfra + Sales
ePrivacy DirCookies + tracking on noxys.eu and consoleBanner consent + audit trailConsole + Infra

4. Certifications roadmap

CertTarget windowEstimated costAuditor candidatesSales unlock
ISO 27001:2022M9-12 (Q4 2026)25-40k€LRQA / Bureau Veritas / SGSMost enterprise B2B
SOC 2 Type IIM12-15 (Q1 2027)40-60k€Drata + qualified CPAInternational, US-export
ISO/IEC 42001:2023M15-18 (Q1-Q2 2027)30-50k€LRQA / Bureau VeritasAI-specialized buyers, sovereignty narrative
SecNumCloud (ANSSI)H2 2027100-150k€ANSSI-accredited PASSI auditorFrench gov / defense / OIV
BSI C5 / AIC4202880-120k€Bird & Bird / Steria-pwc DEDE enterprise gating

Sequencing rationale:

  • ISO 27001 first = baseline almost everyone wants; foundation for everything else.
  • SOC 2 + ISO 42001 in parallel after 27001 — most controls overlap (ISMS basis).
  • SecNumCloud delayed to H2 2027 — high cost, narrow market, requires architectural investments (data localization audit, restricted personnel).
  • BSI 2028 only if we have material DE pipeline.

5. Trust Center public — noxys.eu/trust

Sub-pages:

  • /trust — overview, certifications status (badges with audit dates), key links
  • /trust/dpa — Data Processing Agreement template (downloadable PDF, FR + EN + DE)
  • /trust/subprocessors — sub-processor list with versioning + email-subscribe to changes
  • /trust/security — controls overview (encryption at rest/in transit, access management, MFA, retention)
  • /trust/disclosure — responsible-disclosure email + PGP key + scope statement + Hall of Fame
  • /trust/status — uptime page (Statuspage.io alt: BetterUptime, EU-hosted) — incidents past + ongoing
  • /trust/pen-tests — annual pentest executive summaries (full report under NDA)
  • /trust/questionnaires — CAIQ + SIG pre-filled, downloadable (gated by lead-form)
  • /trust/dpia-template — DPIA template referencing Noxys (pre-filled), customer-customizable

Implementation: noxys-website repo (Astro static site).

6. Sub-processor list (initial — to be maintained)

VendorServiceRegionCustomer dataSensitive
OVHcloudHosting (api, db, workers)EU (Roubaix/Strasbourg)yeshigh
CloudflareCDN + Pages (console + website)EU edge (Paris/Frankfurt)metadatamedium
Mistral AILLM inference (default)EU (Paris)redacted aggregatesmedium
AnthropicLLM fallback (opt-in)US/EUredacted aggregatesmedium
GitHubCode hostingUSsource codelow
StripeBillingEU + USbilling datamedium
Resend / PostmarkTransactional emailEUemail metadatalow
SentryError trackingEU (sentry.io EU)error tracesmedium

Maintained at noxys-website/content/subprocessors.json (versioned, build-time injected). Subscriber list notified on changes.

7. CRA pre-assessment for extension + agent

CRA (Reg. 2024/2847) effective Dec 2027 mandates for products with digital elements:

  • Conformity assessment (self-attestation possible for our risk class)
  • Technical documentation (architecture, threat model, security functions)
  • SBOM in machine-readable format (CycloneDX) — covered by Sprint BOM-1
  • Vulnerability handling process (intake, triage, patch, disclosure)
  • 24h incident reporting to ENISA on actively exploited vulns
  • 5-year support obligation post-launch

Pre-assessment sprint COMP-PROD-5 (W27-28, 3d) maps Noxys extension + agent to CRA Annex I requirements, identifies gaps, schedules remediation before 2027.

8. Vendor questionnaires

Pre-fill and maintain as living docs:

  • CAIQ v4 (Cloud Security Alliance) — 261 questions, pre-fill ~80% from existing controls
  • SIG Lite (Shared Assessments) — pre-fill subset
  • Custom large-customer questionnaires — answer once, store reusable answers in ~docs/sales-questionnaires/

Owner: Jerome (security) + Vincent (sales).

9. DPO + Trust roles

  • DPO interim: Jerome until M12, then external DPO contract (~6-10k€/year)
  • Security Officer: Jerome (post-ISO 27001, formalize with role doc)
  • Trust Officer (sales-facing): Vincent (handles customer questionnaires, maintains questionnaire library)

10. Sprint plan

5 sprints, 11 days. W23-24 → W27-28.

IDTitleRepoWindowEffortPriority
COMP-PROD-1Trust Center public pages (DPA, sub-processors, security, disclosure)noxys-websiteW23-242dP1
COMP-PROD-2ISO 27001 readiness gap analysis + remediation roadmapdocs (gov)W25-263dP1
COMP-PROD-3DPA template + GDPR Art 32 documentation packdocsW23-241dP0
COMP-PROD-4CAIQ + SIG questionnaires pre-fill + repo structuredocs (sales)W25-262dP1
COMP-PROD-5CRA pre-assessment for extension + agent (gap analysis vs Annex I)docs (gov)W27-283dP2

Follow-up sprints (post-W30, not in current plan):

  • COMP-PROD-6: ISO 27001 ISMS implementation + audit prep (M9-12, ~30d)
  • COMP-PROD-7: SOC 2 Type II via Drata onboarding (M12-15, ~15d)
  • COMP-PROD-8: ISO 42001 implementation (M15-18, ~25d)

11. Risk mitigations

  • Audit cost shock: stage payments, leverage Drata-style automation tools (~10-15k€/year, halves auditor hours)
  • Solo-DPO conflict-of-interest: external DPO from M12 mandatory if Jerome stays CEO
  • CRA deadline slip: pre-assessment now, full conformity assessment Q3 2027, CE marking before Dec 2027
  • Cert auditor selection bias: get 3 quotes per cert, prefer EU-headquartered auditors for narrative coherence

12. Non-goals

  • ISO 9001 (quality management) — not relevant for SaaS at our stage
  • HITRUST — US healthcare-specific, not our market
  • FedRAMP — US gov only, anti-narrative
  • PCI DSS — we don't handle card data directly (Stripe handles)

13. Refs

  • ADR-016 Customer-facing compliance frameworks
  • ADR-013 Extension versioning (CRA SBOM dependency)
  • Sprint BOM-1 (AI-BOM data source for CRA SBOM requirement)
  • Memory: project_pricing_tiers.md
  • Memory: feedback_three_deployment_methods.md