ADR-017 — Product compliance posture
1. Context
Distinct from ADR-016 (what we sell to customers as compliance value), this ADR covers what Noxys itself must comply with as a vendor — regulatory obligations applying to our company and our products, plus the certifications we pursue to unlock enterprise sales.
Two pressures push this forward:
- Regulatory cliff: Cyber Resilience Act mandatory 2027 for products with digital elements (extension + agent + proxy all qualify). NIS2 cascade obligations from clients in regulated sectors. DORA from financial-sector clients. GDPR Art 32 baseline.
- Sales gating: Enterprise deals (>1k seats) require ISO 27001 minimum, often SOC 2 Type II, increasingly ISO 42001 for AI products. French sovereign deals (gov, defense, OIV) require SecNumCloud. German enterprise gates via BSI C5 / AIC4.
We must sequence certifications to balance cost (~250-400k€ total over 2 years), audit readiness effort, and revenue unlock.
2. Decision summary
- Trust Center public at
noxys.eu/trustshipped M6 (June 2026) — pre-cert credibility surface. - Certifications timeline: ISO 27001 first (M9-12), SOC 2 Type II + ISO 42001 in parallel (M12-15 / M15-18), SecNumCloud H2 2027, BSI C5/AIC4 2028.
- CRA pre-assessment for extension + agent in 2026 to be ready for 2027 mandatory date.
- DPA + sub-processors public by M3 (already partially via legal page).
- Vendor questionnaire pre-fills (CAIQ + SIG) maintained as living artefacts.
3. Regulatory obligations applicable to Noxys
| Regulation | Why it applies | Action required | Owner |
|---|---|---|---|
| GDPR (Reg. 2016/679) | Process customer/end-user data in EU | DPA, Art 30 register, Art 32 controls, DPIA, Art 35 | Jerome (DPO interim) |
| EU AI Act (Reg. 2024/1689) | We provide AI security tooling — high-risk classification possible | Self-assessment + technical documentation | Product |
| CRA (Reg. 2024/2847) | Extension + agent + proxy = "products with digital elements", deadline 2027 | Conformity assessment + CE marking + SBOM + vuln handling process | Product + Infra |
| NIS2 (Dir. 2022/2555) | Vendor cascade if customers are essential/important entities | Incident reporting capacity 24h, supply-chain due diligence | Infra |
| DORA (Reg. 2022/2554) | Financial-sector clients require ICT risk vendor obligations | Resilience testing + incident reporting + sub-contractor register | Infra + Sales |
| ePrivacy Dir | Cookies + tracking on noxys.eu and console | Banner consent + audit trail | Console + Infra |
4. Certifications roadmap
| Cert | Target window | Estimated cost | Auditor candidates | Sales unlock |
|---|---|---|---|---|
| ISO 27001:2022 | M9-12 (Q4 2026) | 25-40k€ | LRQA / Bureau Veritas / SGS | Most enterprise B2B |
| SOC 2 Type II | M12-15 (Q1 2027) | 40-60k€ | Drata + qualified CPA | International, US-export |
| ISO/IEC 42001:2023 | M15-18 (Q1-Q2 2027) | 30-50k€ | LRQA / Bureau Veritas | AI-specialized buyers, sovereignty narrative |
| SecNumCloud (ANSSI) | H2 2027 | 100-150k€ | ANSSI-accredited PASSI auditor | French gov / defense / OIV |
| BSI C5 / AIC4 | 2028 | 80-120k€ | Bird & Bird / Steria-pwc DE | DE enterprise gating |
Sequencing rationale:
- ISO 27001 first = baseline almost everyone wants; foundation for everything else.
- SOC 2 + ISO 42001 in parallel after 27001 — most controls overlap (ISMS basis).
- SecNumCloud delayed to H2 2027 — high cost, narrow market, requires architectural investments (data localization audit, restricted personnel).
- BSI 2028 only if we have material DE pipeline.
5. Trust Center public — noxys.eu/trust
Sub-pages:
/trust— overview, certifications status (badges with audit dates), key links/trust/dpa— Data Processing Agreement template (downloadable PDF, FR + EN + DE)/trust/subprocessors— sub-processor list with versioning + email-subscribe to changes/trust/security— controls overview (encryption at rest/in transit, access management, MFA, retention)/trust/disclosure— responsible-disclosure email + PGP key + scope statement + Hall of Fame/trust/status— uptime page (Statuspage.io alt: BetterUptime, EU-hosted) — incidents past + ongoing/trust/pen-tests— annual pentest executive summaries (full report under NDA)/trust/questionnaires— CAIQ + SIG pre-filled, downloadable (gated by lead-form)/trust/dpia-template— DPIA template referencing Noxys (pre-filled), customer-customizable
Implementation: noxys-website repo (Astro static site).
6. Sub-processor list (initial — to be maintained)
| Vendor | Service | Region | Customer data | Sensitive |
|---|---|---|---|---|
| OVHcloud | Hosting (api, db, workers) | EU (Roubaix/Strasbourg) | yes | high |
| Cloudflare | CDN + Pages (console + website) | EU edge (Paris/Frankfurt) | metadata | medium |
| Mistral AI | LLM inference (default) | EU (Paris) | redacted aggregates | medium |
| Anthropic | LLM fallback (opt-in) | US/EU | redacted aggregates | medium |
| GitHub | Code hosting | US | source code | low |
| Stripe | Billing | EU + US | billing data | medium |
| Resend / Postmark | Transactional email | EU | email metadata | low |
| Sentry | Error tracking | EU (sentry.io EU) | error traces | medium |
Maintained at noxys-website/content/subprocessors.json (versioned, build-time injected). Subscriber list notified on changes.
7. CRA pre-assessment for extension + agent
CRA (Reg. 2024/2847) effective Dec 2027 mandates for products with digital elements:
- Conformity assessment (self-attestation possible for our risk class)
- Technical documentation (architecture, threat model, security functions)
- SBOM in machine-readable format (CycloneDX) — covered by Sprint BOM-1
- Vulnerability handling process (intake, triage, patch, disclosure)
- 24h incident reporting to ENISA on actively exploited vulns
- 5-year support obligation post-launch
Pre-assessment sprint COMP-PROD-5 (W27-28, 3d) maps Noxys extension + agent to CRA Annex I requirements, identifies gaps, schedules remediation before 2027.
8. Vendor questionnaires
Pre-fill and maintain as living docs:
- CAIQ v4 (Cloud Security Alliance) — 261 questions, pre-fill ~80% from existing controls
- SIG Lite (Shared Assessments) — pre-fill subset
- Custom large-customer questionnaires — answer once, store reusable answers in
~docs/sales-questionnaires/
Owner: Jerome (security) + Vincent (sales).
9. DPO + Trust roles
- DPO interim: Jerome until M12, then external DPO contract (~6-10k€/year)
- Security Officer: Jerome (post-ISO 27001, formalize with role doc)
- Trust Officer (sales-facing): Vincent (handles customer questionnaires, maintains questionnaire library)
10. Sprint plan
5 sprints, 11 days. W23-24 → W27-28.
| ID | Title | Repo | Window | Effort | Priority |
|---|---|---|---|---|---|
| COMP-PROD-1 | Trust Center public pages (DPA, sub-processors, security, disclosure) | noxys-website | W23-24 | 2d | P1 |
| COMP-PROD-2 | ISO 27001 readiness gap analysis + remediation roadmap | docs (gov) | W25-26 | 3d | P1 |
| COMP-PROD-3 | DPA template + GDPR Art 32 documentation pack | docs | W23-24 | 1d | P0 |
| COMP-PROD-4 | CAIQ + SIG questionnaires pre-fill + repo structure | docs (sales) | W25-26 | 2d | P1 |
| COMP-PROD-5 | CRA pre-assessment for extension + agent (gap analysis vs Annex I) | docs (gov) | W27-28 | 3d | P2 |
Follow-up sprints (post-W30, not in current plan):
- COMP-PROD-6: ISO 27001 ISMS implementation + audit prep (M9-12, ~30d)
- COMP-PROD-7: SOC 2 Type II via Drata onboarding (M12-15, ~15d)
- COMP-PROD-8: ISO 42001 implementation (M15-18, ~25d)
11. Risk mitigations
- Audit cost shock: stage payments, leverage Drata-style automation tools (~10-15k€/year, halves auditor hours)
- Solo-DPO conflict-of-interest: external DPO from M12 mandatory if Jerome stays CEO
- CRA deadline slip: pre-assessment now, full conformity assessment Q3 2027, CE marking before Dec 2027
- Cert auditor selection bias: get 3 quotes per cert, prefer EU-headquartered auditors for narrative coherence
12. Non-goals
- ISO 9001 (quality management) — not relevant for SaaS at our stage
- HITRUST — US healthcare-specific, not our market
- FedRAMP — US gov only, anti-narrative
- PCI DSS — we don't handle card data directly (Stripe handles)
13. Refs
- ADR-016 Customer-facing compliance frameworks
- ADR-013 Extension versioning (CRA SBOM dependency)
- Sprint BOM-1 (AI-BOM data source for CRA SBOM requirement)
- Memory:
project_pricing_tiers.md - Memory:
feedback_three_deployment_methods.md