Cloud & SaaS

Cloud vendor assessment, on evidence

SaaS, IaaS and PaaS vendors publish a lot of documentation — SOC 2, ISO 27001, CSA CAIQ/STAR, DPAs, security white papers and architecture docs. Governly maps your requirements to that evidence and turns it into a traceable assessment that supports NIS2 and DORA expectations.

Typical evidence we review

  • SOC 2 Type II reports
  • ISO 27001 certificate and SoA
  • CSA CAIQ / STAR self-assessment
  • Data Processing Agreement (DPA)
  • Security white paper & architecture
  • Sub-processor list and transfer mechanisms
  • Penetration test summary
  • Business continuity & DR plans