Cryptographic Posture Management — discover, grade & remediate your whole cryptographic estate
Sovereign Certificate Authority for enterprise-grade certificate issuance & management
Certificate Lifecycle Management, discovery, governance & automation
DNS-agnostic Domain Control Validation, ready for 47-day TLS certificates
The 27 cryptography questions auditors ask, and the evidence that satisfies each one. Grouped by theme, referenced article by article, with a scorecard to fill in before the audit.
The PDF lands in your inbox within a minute, in the language of your choice.
NIS2, DORA and PCI-DSS 4.0 converge on cryptography. The same evidence answers all three, provided you know which one you will be asked for.
Know which themes the next audit will spend its time on, and show up with a trajectory instead of a spreadsheet.
Every question traced to its article (NIS2 Art. 21, DORA RTS Art. 7, PCI 12.3.3) and to the exact evidence that closes it.
Three concrete questions to ask the team each week, per theme, to find the gaps before the auditor does.
Do you have a written cryptography policy that names algorithms, is reviewed, and has an owner? Questions 01 to 05.
The most-failed theme: certificates, keys, protocols, declared scope and dependencies. Questions 06 to 12.
Does what you run match what you wrote, and what was your posture last quarter? Questions 13 to 18.
Prioritisation, owners, verification in production, rotation, post-quantum plan. Questions 19 to 23.
Can you prove it, for a given date, without a project? The theme that decides how the audit ends. Questions 24 to 27.
All 27 questions on one page, ticked Have, Partial or Missing. Anything Partial in themes 2, 3 and 5 is where the audit will spend its time.
Download the checklist in English or French, then run the scorecard with your team this week.