Proprietary methodology
CEPF — Compliance Estimation & Planning Framework
CEPF is a regulatory crossing catalogue: a mapping of regulatory regimes onto the operational obligations each one produces, and onto the points where those obligations overlap. It exists because organisations subject to several regimes at once do not face a sum of separate compliance programmes — they face one programme with shared controls, and the shared controls are where both the cost and the omissions concentrate.
The framework works on obligations, not on principles. Every regime is broken down into the deliverables it actually requires, the roles that produce them and the effort each one carries. Where two regimes demand the same control — access management, audit logging, change management, incident response — the control is stated once and documented against each regime, rather than built twice.
It is the instrument behind the exposure assessment.
CEPF v7 — 21 regimi — snapshot luglio 2026
This page hosts a reduced demo of the framework.
The interactive tool below covers nine of the twenty-one regimes in CEPF v7 and a subset of its planning functions. It is a working demonstration, not the complete framework. Its interface is in Italian.
Lo strumento è in italiano, e lo è anche l’assessment di esposizione: se stai leggendo la demo, quello è il percorso giusto.
Regimes covered by this demo
- SOX IT — Sarbanes-Oxley IT general controls — PCAOB AS 2201, COSO 2013
- NIS2 — Directive (EU) 2022/2555
- AI Act — Regulation (EU) 2024/1689
- GDPR — Regulation (EU) 2016/679
- DORA — Regulation (EU) 2022/2554
- ISO/IEC 27001:2022 — Information Security Management System
- ISO 56001:2024 — Innovation Management System
- ENS — Esquema Nacional de Seguridad — Real Decreto 311/2022
- GS1 — EPC/RFID and EPCIS 2.0 supply chain standards