NIS2 Principles · CRA Principles · IEC 62443 Guided · ISO 27001 Guided
Security & Compliance
Every Nordic IoT system is designed with security principles and regulatory readiness from day one. We don't bolt security on at the end. It shapes how we select hardware, write software, and handle data.
NIS2
NIS2 Directive
The NIS2 Directive (2022/2555) applies to operators of essential and important services across energy, transport, manufacturing, health, water, and digital infrastructure. Article 21 requires risk management measures including supply chain security, encryption, access controls, vulnerability handling, and incident response. Article 23 requires significant incidents to be reported within 24 hours (early warning) and 72 hours (full report). Penalties reach up to 10 million EUR or 2% of global annual turnover for essential entities. Our architecture is designed so that the IoT layer does not become your NIS2 gap. We handle connectivity and gateway security so your IoT infrastructure supports your compliance posture rather than creating new obligations.
IEC 62443
IEC 62443
International standard for industrial automation and control systems security. Our hardware and software architecture follows IEC 62443 security principles including network segmentation between OT and IT networks, role-based access control, system hardening with minimal attack surfaces, and defence-in-depth across device, network, and platform layers.
ISO 27001
ISO 27001/27002
Information security management system standards. Our operational practices and data handling follow ISO 27001/27002 controls including access management, encryption of data at rest and in transit, audit logging, incident response procedures, and supply chain transparency.
CRA
Cyber Resilience Act
EU regulation on cybersecurity requirements for products with digital elements. Our hardware platform ships with secure boot, automatic security updates, signed firmware, and a documented software bill of materials, addressing CRA requirements for security-by-design and security-by-default.
EU Sovereign
EU Data Sovereignty
Nordic IoT runs on Hetzner infrastructure in German and Finnish data centres. Every provider in the chain is EU-based and operates under EU law and GDPR, so your data stays within the EU, on infrastructure we operate. This gives you genuine EU data residency and data sovereignty. Our platform is open-source and auditable, so you can verify where your data lives.
Questions about compliance?
We can walk you through how our systems are designed with your regulatory requirements in mind.
