Guides and reference for every module and framework in the platform.
First-time setup, navigation, and core concepts to get you up and running with Venvera.
5 articlesIdentify, assess, treat and monitor risk across every domain: the risk register, KRIs, ICT assets, controls, risk appetite and board reporting.
10 articlesAssess and monitor your ICT third-party providers: the provider register, DORA Article 31 concentration analysis, and vendor questionnaire campaigns.
6 articlesCross-framework modules including incident management, policy management, and control propagation that apply across all enabled frameworks.
6 articlesBoard reports, audit trail, regulatory updates, company profile, and user management.
15 articlesConnect Venvera to your cloud and identity providers for automated posture evidence, push tasks to Jira, and enrol endpoints with the Windows agent.
7 articlesCross-framework task management - auto-generated compliance work items, framework assignments, manual tasks, and team workload tracking.
8 articlesDeep dives into Venvera's key features including AI-powered compliance tools, framework controls, and cross-framework automation.
8 articlesControl evidence that closes the crosswalk, evidence freshness and renewal, the reusable evidence library, and the AI evidence assistant.
6 articlesDigital Operational Resilience Act - overview, gap assessments, and resilience testing for EU financial entities.
3 articlesThe Register of Information required by DORA Article 28(3): ICT providers, contractual arrangements, business functions and the xBRL-CSV export.
9 articlesDetailed control-by-control mapping tables showing how each compliance framework's requirements map to every other framework supported by Venvera.
31 articlesNetwork and Information Security Directive: gap assessments, management training, incident readiness and effectiveness KPIs for both entity classes.
6 articlesInternational ISMS standard: scope, statement of applicability, internal audits, nonconformities, management reviews and risk treatment.
12 articlesGeneral Data Protection Regulation - processing activities, DPIAs, data subject requests, breach management, DPAs, and international transfers.
8 articlesArtificial Intelligence Act - AI systems inventory, risk classification, gap assessments, technical documentation, conformity assessment, and CE marking.
11 articlesUK government-backed cybersecurity certification - 5 core technical controls, gap assessments, evidence collection, CE Plus testing, and certification tracking.
10 articlesNigeria Data Protection Act 2023: gap assessments, processing activities, DPIAs, data subject requests, breach management and cross-border transfers.
8 articlesUAE Information Assurance Standards - security governance, risk management, security controls, compliance audits, incident management, and CNI assessment.
7 articlesCybersecurity Maturity Model Certification: practices and domains, gap assessment, SPRS score, evidence, POA&Ms and assessment preparation.
9 articlesHealth Insurance Portability and Accountability Act: PHI inventory, safeguards, risk analysis, business associates and breach notification.
9 articlesPayment Card Industry Data Security Standard: cardholder data protection, network security, vulnerability management, access control and monitoring.
9 articlesEssential Cybersecurity Controls from the Saudi National Cybersecurity Authority: gap assessments, control tracking, evidence and NCA audit prep.
8 articlesSaudi Central Bank Cyber Security Framework: sub-control library, maturity and implementation tracking, evidence and SAMA audit preparation.
4 articlesSystem of Governance for EU insurers: board responsibility, the ORSA process, the four key functions, fit and proper, and outsourcing.
1 articleEU digital identity under Regulation (EU) 2024/1183: relying-party duties, wallet acceptance by December 2027 and data minimisation.
1 articleCrypto-asset markets under Regulation (EU) 2023/1114: authorisation of service providers and issuers, client asset protection and prudential rules.
1 articleProduct security under the Cyber Resilience Act, Regulation (EU) 2024/2847: essential requirements, vulnerability handling, SBOM and reporting duties.
1 articleAPRA Prudential Standard CPS 234 Information Security: the 24 requirements from paragraphs 13 to 36, evidence guidance, the gap assessment and both APRA notification clocks.
3 articles