Data protection
Responsibilities, records of processing, legal bases, minimisation, rights, processors, security and breach management.
Goal: governed processing and well-managed processors.
Audit & compliance
The IKNSA Audit & compliance practice covers GDPR, NIS2, HDS, the AI Act, DORA, the CRA and related frameworks. It establishes the scope, assesses the situation, builds the trajectory and prepares the demonstrable elements.
Operational compliance
The assessment determines the applicable scope, the priority gaps and the evidence already available. Common requirements are pooled without creating artificial equivalence between the texts.
Responsibilities, records of processing, legal bases, minimisation, rights, processors, security and breach management.
Goal: governed processing and well-managed processors.
Risk governance, security measures, continuity, supply chain, incident management and notification.
Goal: prepare the scope and the evidence expected in France.
Qualification of the need, sharing of responsibilities, target architecture and migration to HDS-certified hosting services.
Goal: use a certified scope with no ambiguity of roles.
Inventory, legal role, classification, transparency, supplier control, human oversight and monitoring.
ICT risk framework, incidents, testing, register of critical third parties, concentration and exit strategies.
Product risk, security by design, components, support, vulnerabilities and the conformity file.
IKNSA does not claim HDS certification. We design and support architectures on certified offerings, with a documented sharing of responsibilities. Any hosting or managed-services activity falling within the HDS scope must be carried by a certified perimeter.

Our approach
Compliance becomes durable when it joins investment decisions, changes, operations and vendor contracts.
Entities, activities, data, critical services, applicable texts and stakeholders.
Risks, existing controls, gaps, dependencies and available evidence.
Roadmap, technical measures, processes, contracts and support.
Evidence files, exercises, management reviews and audit preparation.
Demonstrability
Controls must produce dated, attributable, reviewable elements: decisions, test results, incidents, exceptions, reviews and action plans. We build this chain of evidence with the teams who actually operate the information system.
| Control | Examples of evidence |
|---|---|
| Risk management | Mapping, owners, decisions, treatment plans |
| Identities & access | Reviews, entitlement records, privileged accounts, leavers |
| Vulnerabilities | Inventory, scans, remediation times, exceptions and acceptances |
| Continuity | Plans, restore tests, exercises, observed RPO and RTO |
| Suppliers | Evaluation, clauses, subcontractors, service levels, exit |
Who does what
We define the roles before the engagement to avoid any ambiguous promise or conflict of interest. The Audit & compliance practice is distinct from the Cybersecurity practice: they can contribute to the same programme, but their mandates, people and deliverables remain identified.
Certification bodies, regulated auditors, DPOs and technical providers keep their own responsibilities. Where formal independence is required, implementation and evaluation are not entrusted to the same actor.
Management approves the scope, the priorities and the residual risks.
Qualification, assessment, roadmap, coordination and evidence preparation under the mandate.
A certification body, qualified auditor or independent adviser acts within its own framework.
The Cyber practice and the operations teams implement, test and improve the controls that fall under their mandate.
Frequently asked questions
First conversation
A project to frame, operations to take over, compliance to demonstrate? Describe the context. You will get a first considered reading — not a generic brochure.