How can we help?

Find guides, tutorials, and answers for every Venvera module.

πŸš€

Getting Started

First-time setup, navigation, and core concepts to get you up and running with Venvera.

5 articles
πŸ›‘οΈ

Risk Management

Identify, assess, treat and monitor risk across every domain: the risk register, KRIs, ICT assets, controls, risk appetite and board reporting.

8 articles
🏒

Third Party Risk Management (TPRM)

Assess and monitor your ICT third-party providers: the provider register, DORA Article 31 concentration analysis, and vendor questionnaire campaigns.

5 articles
πŸ›οΈ

DORA

Digital Operational Resilience Act - overview, gap assessments, and resilience testing for EU financial entities.

3 articles
πŸ“‘

DORA - Register of Information

Complete guide to the Register of Information (RoI) required by DORA Art. 28(3) - ICT providers, contractual arrangements, business functions, risk assessments, branches, sub-outsourcing, concentration risk, and XBRL/CSV export.

9 articles
πŸ”—

Shared Modules

Cross-framework modules including incident management, policy management, and control propagation that apply across all enabled frameworks.

5 articles
πŸ—ΊοΈ

Security Controls Mapping Across Frameworks

Detailed control-by-control mapping tables showing how each compliance framework's requirements map to every other framework supported by Venvera.

31 articles
πŸ›‘οΈ

NIS2

Network and Information Security Directive - gap assessments, management training, incident readiness, and effectiveness KPIs for essential and important entities.

6 articles
πŸ“‹

ISO 27001

International ISMS standard - scope, statement of applicability, internal audits, nonconformities, management reviews, risk treatment, and certification tracking.

12 articles
πŸ”’

GDPR

General Data Protection Regulation - processing activities, DPIAs, data subject requests, breach management, DPAs, and international transfers.

8 articles
πŸ€–

EU AI Act

Artificial Intelligence Act - AI systems inventory, risk classification, gap assessments, technical documentation, conformity assessment, and CE marking.

11 articles
πŸ“Š

Reports & Settings

Board reports, audit trail, regulatory updates, company profile, and user management.

12 articles
πŸ”Œ

Integrations

Connect Venvera to your cloud and identity providers for automated posture evidence, push tasks to Jira, and enrol endpoints with the Windows agent.

6 articles
βœ…

Tasks

Cross-framework task management - auto-generated compliance work items, framework assignments, manual tasks, and team workload tracking.

6 articles
πŸ”‘

Cyber Essentials

UK government-backed cybersecurity certification - 5 core technical controls, gap assessments, evidence collection, CE Plus testing, and certification tracking.

10 articles
πŸ‡³πŸ‡¬

NDPA

Nigeria Data Protection Act 2023 - gap assessments, processing activities, DPIAs, data subject requests, breach management, cross-border transfers, and compliance audit returns.

8 articles
πŸ‡¦πŸ‡ͺ

UAE IA

UAE Information Assurance Standards - security governance, risk management, security controls, compliance audits, incident management, and CNI assessment.

7 articles
πŸ›‘οΈ

CMMC 2.0

Cybersecurity Maturity Model Certification - practices & domains, controls, gap assessment & SPRS score, evidence, POA&Ms, assessments, management reviews, and certification readiness.

9 articles
πŸ₯

HIPAA

Health Insurance Portability and Accountability Act - PHI inventory, safeguards, risk analysis, business associates, breach notification, gap assessment, training, and policies.

9 articles
πŸ’³

PCI-DSS

Payment Card Industry Data Security Standard - cardholder data protection, network security, vulnerability management, access control, monitoring, and compliance documentation.

9 articles
✨

Features

Deep dives into Venvera's key features including AI-powered compliance tools, framework controls, and cross-framework automation.

7 articles
πŸ‡ΈπŸ‡¦

Saudi NCA ECC

Essential Cybersecurity Controls from the Saudi National Cybersecurity Authority. Gap assessments, control tracking, evidence management, and NCA audit preparation.

8 articles
🏦

SAMA CSF

Saudi Central Bank (SAMA) Cyber Security Framework. Sub-control library, maturity and implementation tracking, evidence, and SAMA audit preparation with findings management.

4 articles
πŸ›οΈ

Solvency II (Pillar 2)

System of Governance for EU insurers: board responsibility, ORSA process, the four key functions, fit and proper, and outsourcing under Directive 2009/138/EC Articles 40 to 49. Pillar 2 only.

1 article
πŸͺͺ

eIDAS 2.0

EU Digital Identity and trust services under Regulation (EU) 2024/1183: relying-party duties, wallet acceptance by 24 December 2027, data minimisation, and trust service provider obligations.

1 article
πŸͺ™

MiCA (Markets in Crypto-Assets)

EU regulation of crypto-asset markets under Regulation (EU) 2023/1114: authorisation of crypto-asset service providers and token issuers, protection of client crypto-assets, conduct, market integrity and reporting.

1 article
πŸ›‘οΈ

Cyber Resilience Act

EU cybersecurity requirements for products with digital elements under Regulation (EU) 2024/2847: essential requirements, vulnerability handling, SBOM, conformity and CE marking, and 24h/72h reporting from 11 September 2026, with full application on 11 December 2027.

1 article
πŸ—‚οΈ

Company Groups & Evidence

Newer capabilities: control evidence that closes the crosswalk, evidence freshness and renewal, the reusable evidence library, the AI evidence assistant, policy-to-control mapping, and Company Groups for multi-tenant policy sharing.

6 articles