CloudTwyst Security Assess · EU SaaS

Cloud security compliance in minutes, not months.

CloudTwyst Security Assess is a SaaS platform that automatically assesses an organisation's cloud environment against NIS2, DORA, and ISO 27001. It connects read-only to your cloud tenants, evaluates live configuration and control evidence, and returns a mapped compliance posture with gaps and remediation guidance — in minutes rather than the months a traditional scoped assessment takes. Subscription-based, continuous, and audit-ready.

Read the security overview →
Minutes
Not months — results on demand
Multi-cloud
Azure, AWS & GCP
EU hosted
Azure West Europe data residency
GDPR
Privacy by design
CloudTwyst
Assessment Overview Assessed
Posture Score
78%
NIS2 Article 21
Open Gaps
34
6 critical
Control coverage by domain — NIS2
ISO 27001:2022
Annex A coverage
92 / 100
6 critical gaps ready for remediation — NIS2 Article 21
Azure · AWS · GCP
Role-based access control
Immutable audit trails
NIS2 · ISO 27001 · DORA · GDPR
Vendor-neutral by design
EU data residency · Azure West Europe
CloudTwyst

Two engines. One studio.

Subscription products for scale. Senior consulting for transformation.

🧪 Products

Studio

Enterprise products with production-ready defaults. Subscription, online, audit-ready.

Inside
🛡️ CloudTwyst Security Assess Preview Explore Studio →
🛠️ Services

CloudTwyst Services

Senior consulting for cloud strategy, sovereign AI, post-quantum readiness, and the work in between.

8 offerings
Explore Services →

Built by the same team. Backed by the same pillars: secure by design · AI-native & fast · human-reviewed.

Traditional security assessments were built for large budgets and long timelines.
Most SMEs couldn't afford either.

NIS2, DORA, and ISO 27001 now apply to businesses of every size across the EU. But the traditional assessment model — months of scoping, consulting engagements, and manual evidence collection — was never designed for SMEs. CloudTwyst Security Assess changes that.

Traditional security assessment
  • Months from scoping to sign-off
    A traditional NIS2 or ISO 27001 assessment typically runs 3–6 months — scoping workshops, evidence collection, consultant reviews, draft reports, revisions, and final sign-off.
  • Priced for large enterprises only
    Day-rate consulting engagements and bespoke tooling make proper security assessments inaccessible for SMEs — the exact businesses NIS2 and DORA now regulate.
  • Results are stale before they're delivered
    By the time a 6-month assessment is complete, the cloud environment has changed. The report reflects a point in time that no longer exists.
  • Manual evidence, no audit trail
    Compliance evidence is collected in spreadsheets and shared drives — difficult to verify, impossible to chain-hash, and a liability in any regulatory review.
CloudTwyst Security Assess
  • Results in minutes, not months
    Connect your cloud environment, run the assessment, and see your NIS2, DORA, or ISO 27001 posture score — with per-control findings and a prioritised remediation backlog — in minutes. Depending on environment size.
  • Subscription-based — accessible to mid-market and enterprise
    Flat-rate subscription pricing replaces day-rate consulting. Any regulated EU organisation can access a full NIS2, DORA, or ISO 27001 assessment online — no procurement cycle required.
  • Always current — re-assess any time
    Run a new assessment whenever your environment changes. Each engagement is independent, governed, and purged after sign-off — so there's no legacy data risk and no stale reports.
  • Automated evidence, immutable audit trail
    Evidence is collected automatically from your cloud environment. Every action in the assessment lifecycle is chain-hashed and logged — audit-ready from day one.

Four frameworks. Three cloud providers. One assessment platform — online.

CloudTwyst Security Assess automates the full assessment lifecycle — from connecting your cloud environment to delivering a board-ready compliance report — in a single governed SaaS workflow that replaces months of manual consulting work.

01 — Cloud Connector
Azure, AWS & GCP — read-only, no agents
The connector runs inside the customer's own cloud environment, calls cloud provider APIs locally, and securely submits collected security posture data to CloudTwyst Assess via a single authenticated ingest endpoint. CloudTwyst never connects to the customer's cloud directly — no inbound connections, no persistent access.
Multi-cloud
02 — Framework Scoring
NIS2 · DORA · ISO 27001 · GDPR
Ingested cloud data is evaluated against four EU compliance frameworks. Per-control gap analysis with a posture score, findings list, and prioritised remediation backlog — generated automatically.
Compliance
03 — Assessment Lifecycle
From draft to sign-off — governed & auditable
A state machine takes each engagement from collecting through assessed, remediating, and report delivered to signed-off and purged. Two-step OTP sign-off and three automatic data retention paths built in.
Governance
04 — Report Engine
Word, PowerPoint & CSV — board-ready
Assessment findings exported as board-ready reports in Word, PowerPoint, and CSV. Azure DevOps work item creation maps each gap directly to your engineering backlog — no manual translation.
Reporting
05 — Enterprise Remediation
Automated fixes — inside your environment
Trigger remediation inside the customer's own cloud account via signed runbooks (Azure), SSM documents (AWS), or Cloud Run Jobs (GCP). CloudTwyst never holds write access to any customer environment.
Automation

Enterprise-grade capability, out of the box — no configuration marathon required.

CloudTwyst Security Assess ships with the framework mappings, connectors, runbooks, and report templates already built. You run your first assessment on day one, not month six.

4
Pre-mapped Compliance Frameworks
Controls pre-mapped to NIS2 Article 21, ISO 27001:2022 Annex A, DORA ICT risk, and GDPR technical safeguards. Per-control gap analysis with no manual mapping needed.
NIS2ISO 27001DORAGDPR
3
Report Formats — Board Ready
Assessment findings exported straight from the data: Word for the full findings narrative, PowerPoint for the executive deck, CSV for tooling import. No manual formatting after the engagement.
WordPowerPointCSV
Pre-built
Remediation Runbook Gallery
Signed remediation runbooks for all three clouds — Azure Automation Runbooks, AWS Systems Manager documents, GCP Cloud Run Jobs. Every one runs inside your own environment; CloudTwyst never holds write access.
AzureAWS SSMCloud Run
Gap to ticket
Azure DevOps Integration
One work item per identified gap, pushed into your Azure DevOps backlog at the end of the assessment — so remediation starts in the tooling your team already uses. Your PAT is never stored.
ADOWork itemsNo PAT storage
Governed
Engagement Lifecycle & Sign-Off
Every assessment runs a defined state machine from collecting through assessed, remediating and report delivered to signed off and purged — with two-step OTP sign-off and three automatic retention paths built in.
OTP sign-offAudit stubAuto-purge
3
Cloud Provider Connectors
Lightweight connectors for Azure, AWS, and GCP — deployed inside the customer's environment. Each connector collects security posture data locally and submits it to CloudTwyst via a short-lived authenticated token. No agents, no inbound connections.
AzureAWSGCP

From cloud environment to compliance posture score — in four steps, in minutes.

What used to take months of consulting engagement, manual evidence collection, and back-and-forth report revisions is now a governed, automated workflow. The same rigour — a fraction of the time.

Connect

Deploy the read-only connector to your cloud environment — Azure, AWS, or GCP. A short-lived engagement token scopes access to this assessment only. No agents, no write access, no persistent footprint.

Assess

CloudTwyst Security Assess evaluates your cloud security posture against NIS2, DORA, ISO 27001, and GDPR controls automatically. Per-control scoring, gap identification, and a prioritised remediation backlog — generated in minutes.

Remediate

Findings are tracked through a governed remediation lifecycle. Gaps map to your Azure DevOps backlog automatically. Enterprise customers can trigger remediation runbooks inside their own cloud environment — CloudTwyst never holds write access.

Sign off & purge

When remediation is complete, the customer signs off the engagement with a two-step OTP confirmation. Board-ready reports are exported in Word, PowerPoint, and CSV. All customer insight data is then purged — leaving only a tamper-evident audit stub.

Teams come to Assess through the deadline they need to hit.

The same assessment, arriving in minutes, answers five very different pressures — a regulatory clock, an auditor, a customer questionnaire, a board paper, or a remediation backlog nobody has scoped.

NIS2 deadline
Establish your NIS2 baseline
You are in scope and need to show where you stand against Article 21. Assess scores your live cloud configuration control by control and hands back the gaps, ranked.
Article 21Gap analysisMinutes
Audit prep
Walk into the audit with evidence
An ISO 27001 or DORA audit is scheduled and evidence collection is manual. Assess produces the control-by-control position and the export, without a scoping exercise first.
ISO 27001DORAEvidence export
Customer due diligence
Answer the security questionnaire
A prospect's procurement team wants proof of your cloud security posture. Turn a fortnight of questionnaire archaeology into a current, exportable assessment.
QuestionnairesPosture scoreRepeatable
Remediation
Turn findings into a worked backlog
Knowing the gaps is not closing them. Each finding becomes an ADO work item and, where one exists, a signed runbook your own team triggers inside your own environment.
ADO work itemsRunbooksTracked to close
Board reporting
Give the board a defensible number
Leadership needs a posture position they can put in a board pack and defend. Word narrative, PowerPoint deck and CSV, generated from the assessment rather than assembled by hand.
WordPowerPointCSV

Built for the sectors that NIS2 and DORA actually name.

CloudTwyst Security Assess is designed for organisations with a regulatory obligation to evidence their cloud security posture — where a misconfiguration is a reportable risk, not just an inconvenience.

Financial Services
Banking, Insurance & Capital Markets
DORA ICT risk and resilience controls scored against your live cloud configuration, with the evidence and gap backlog your regulator expects — without a six-month audit engagement.
DORANIS2ISO 27001
Healthcare & Life Sciences
Hospitals, Pharma & MedTech
NIS2 applies directly to health sector entities. Assess scores your cloud estate against Article 21 controls and GDPR technical safeguards, with findings mapped control by control.
NIS2GDPRISO 27001
Public Sector
Government & Public Services
Public administration is in scope for NIS2. Assess gives agencies a repeatable, evidence-backed posture assessment across Azure, AWS and GCP — with all data purged at sign-off.
NIS2ISO 27001EU residency
Technology & SaaS
Scale-ups, ISVs & Platform Engineering
Digital providers and ICT service managers fall under NIS2. Assess turns a customer security questionnaire from a scramble into an export — ISO 27001 and NIS2 posture on demand.
NIS2ISO 27001Azure · AWS · GCP
Retail & E-commerce
Retail Chains & Online Platforms
Online platforms are treated as digital providers under NIS2. Assess scores the cloud environment behind the storefront and hands back a prioritised remediation backlog.
NIS2GDPRISO 27001
Telecommunications
Telcos & Network Operators
Digital infrastructure is a core NIS2 sector. Assess evaluates cloud configuration and control evidence against Article 21 and returns posture, gaps, and remediation runbooks.
NIS2DORAISO 27001

Six stages, from read-only collection to signed-off and purged.

Each stage is independently testable; together they form a governed assessment pipeline that starts inside your environment and ends with your data deleted.

Stage 1
Cloud Connector
Azure, AWS, GCP — security posture data collected inside the customer's environment and submitted via connector
Stage 2
Framework Scoring
NIS2, ISO 27001, DORA and GDPR — per-control gap analysis and posture score
Stage 3
Assessment Lifecycle
State machine from draft through assessed and remediating to signed off
Stage 4
Report Engine
Word, PowerPoint and CSV output, plus one ADO work item per gap
Stage 5
Enterprise Remediation
Signed runbooks triggered inside your environment — never by us
Stage 6
Data Custody
Transient custody, encryption, then purge — leaving a tamper-evident audit stub

Security is a platform characteristic, not a feature layer.

CloudTwyst is built from the ground up for enterprise security requirements — from access control to data handling to integration standards.

  • Role-based access control
    Granular permission models at the workspace, module, and resource level. Every user sees only what their role permits — enforced by the platform, not by trust.
  • Immutable audit trails
    Every action, approval, exception, and configuration change is logged with timestamp, actor, and context. Tamper-evident records for audit and regulatory evidence.
  • Policy-driven access control
    Zero-standing-access patterns. Time-bound entitlements, just-in-time approval, and automated access expiry enforced through the governance engine.
  • Secure integrations
    OAuth 2.0, SAML, and OIDC for identity federation. Encrypted at rest and in transit. Supports BYOK encryption for regulated environments.
Security posture — live
Platform score
92/100
4 open exceptions · 0 critical
Pass RBAC enforcement All 47 accounts
Pass MFA coverage 100%
Active Audit trail collection Real-time
Review Privileged access review Due in 3 days
Pass Encryption in transit TLS 1.3
Minutes
Assessment results — not months
NIS2 · DORA
ISO 27001
EU frameworks scored automatically
EU SaaS
Subscription · online · export-ready
Zero
Customer data retained after sign-off
NIS2, DORA, and ISO 27001 compliance — assessed in minutes.

CloudTwyst Security Assess is online, subscription-based, and available to any EU SME today. Book a demo and see your cloud security posture score before the call ends.

Not ready for a demo? Read the security overview.