Five laws affect the same systems. CAISSON\u2122 brings them together in a single assessment and ties that assessment to the design of the installation. What you end up with is not only which obligations apply, but which zone, which interface and which measure they translate into.
CAISSON stands for Compliance Assured In Scope, System, Organisation and Norm. It is a method resting on four pillars. Those pillars are not phases but dimensions: every engagement is tested against all four, whichever phase it is in.
Organisations running critical or operational technology do not face one law but possibly five at once. The Critical Entities Resilience Act determines whether an organisation is designated. The Cyber Security Act imposes the duty of care and the duty to report. The GDPR applies wherever personal data is involved. Public bodies must add the Open Government Act and the Archives Act. The Archives Act 2026 replaces it on 1 January 2027. Those interests do not always point the same way: the Open Government Act pushes towards disclosure, the GDPR towards restriction and the Archives Act towards retention, while the duty of care calls for shielding. Where those requirements contradict each other, an explicit trade-off is needed.
These legal frameworks affect the same systems, the same processes and the same people, yet in practice they are assessed separately. The result is duplicated work, conflicting measures and a scope that shifts from one engagement to the next. And what is almost always missing: the translation into the installation itself, where the risk becomes physical and safety can be at stake.
CAISSON brings those five frameworks into a single assessment, establishes what is genuinely required, and carries that outcome through into the design of the operational environment. From statute to zone.
The method consists of four phases that run in sequence, with an explicit gate between phase 1 and phase 2. No work on measures begins while the scope is still open.
For CAISSON it does not matter which documentation already exists: a management system for IT, a group policy or separate OT procedures. The matrix of three domains (GEN shared, OT and IT) and six functions1 is laid over the existing documentation. For each cell one decision is made: keep, extend or add.
A second set of documents is never built alongside the existing one. The organisation's own numbering stays leading, and every requirement remains traceable to statute and standard.
Phased approaches to NIS2 are not rare. Two things are, and the combination of them certainly is.
The first is determining scope across five frameworks in a single assessment. Public self-assessments cover one act; control frameworks issued by professional bodies explicitly exclude privacy. Yet the cascade is precisely where things go wrong: designation under one act pulls obligations from another along with it.
The second is depth in operational technology. Zone and conduit design with a target security level per zone is the language of IEC 62443, and that language is rarely spoken by parties who also master the legal side. See also OT security.
Added to that is role clarity. We sell no software, no licences and no certificates, and therefore have no interest in the heaviest possible programme.
1 Govern, Identify, Protect, Detect, Respond and Recover: the layout of the NIST Cybersecurity Framework 2.0. Chosen because Govern gives board responsibility under the Dutch Cyber Security Act its own place, and because the other five are also the cybersecurity concepts attribute of ISO/IEC 27002, the catalogue of controls that belongs to ISO 27001. Existing IT controls can therefore be placed directly.
The first question is not which measures you must take, but whether and for what you are obliged. That is where CAISSON begins. Schedule an introductory call.
Schedule an introductory call