NIS2, DORA and SOC 2 all ask the same three questions about email: is the top attack vector protected, can you prove it continuously, and do you detect incidents fast enough to report them on time?
No product makes you compliant with NIS2, DORA or SOC 2, and you should distrust any that claims to. Compliance lives in your governance, processes and documentation. But every framework requires technical controls, and email is where the requirements converge, because it is where most incidents begin. Sentaro is that control layer, plus the evidence that it operates, plus the detection your reporting deadlines depend on.
NIS2 requires risk-management measures against exactly the attacks that arrive by email, supply-chain vigilance, and incident reporting on a 24h / 72h / one-month clock. Sentaro contributes the protection measure, flags compromised vendor mailboxes in your mail flow, and starts the reporting chain with detection and evidence instead of an empty page.
For financial entities, DORA demands ICT risk management, major-incident reporting on fixed timelines, and control of third-party ICT dependencies. Sentaro covers the detect-and-monitor expectations at the mailbox, supplies the who/what/when/scope that incident classification requires, and surfaces every third-party and AI service holding OAuth access to mail and files.
SOC 2 is won or lost on evidence: controls that demonstrably operated all period. Sentaro maps to the Common Criteria where they touch email (threat detection and monitoring, incident records, logical access via OAuth visibility, third-party insight) and generates the continuous logs your auditor tests, for the whole observation window.
The same controls and evidence extend to ISO 27001, GDPR and its 72-hour breach clock, the EU AI Act, and ISO 42001.
Auditors and supervisors have stopped accepting screenshots and intentions. What passes is continuous operation: logs that cover the whole period, alerts with dispositions, and reports generated by the system rather than assembled the week before the audit. Because Sentaro monitors continuously, the evidence exists as a by-product of protection, including the awkward parts other tools miss, like which AI services your employees connected to company mailboxes and which grants held what access when.
This page is general guidance, not legal or audit advice.
The incident reporting chain, from detection to deadline
| What happens | Who owns it | |
|---|---|---|
| Detection | Sentaro identifies the email-borne attack in real time | Sentaro |
| Facts | Who was targeted, what was blocked or delivered, when, and how far it spread | Sentaro |
| Assessment | Is this significant or major under your framework? | You, with Sentaro’s evidence |
| Report | 24h/72h notifications (NIS2), timeline reports (DORA), incident records (SOC 2) | You, with Sentaro’s evidence |
| Post-incident | Final reports, lessons learned, control adjustments | You |
No product does, and claims otherwise are a red flag. Compliance is your governance, processes and documentation. Sentaro provides the email-layer controls, continuous evidence and incident detection those frameworks require.
For email-borne incidents it provides the detection that triggers your process and the facts (targets, actions, timestamps, scope) that early warnings and notifications must contain, so NIS2’s 24/72-hour clocks and DORA’s timelines start with evidence.
Continuous logs of threat detection and disposition, OAuth grant and access visibility, and monitoring reports spanning the observation period, mapped with your auditor to the relevant Common Criteria.
Yes, indirectly. Covered entities must manage supply-chain security and increasingly push requirements onto suppliers. Demonstrable email security and incident detection is one of the most commonly requested controls.
Yes. GRC tools manage the program: policies, tasks, evidence collection across all domains. Sentaro is one of the actual controls the program depends on, and a source of the evidence it collects.
Connect Google Workspace or Microsoft 365 in four minutes and the protection, monitoring and evidence start immediately.