You will get a full EU AI Act risk classification and compliance gap analysis
Project details
You will get a clear picture of where your AI systems stand against the EU AI Act (Regulation 2024/1689), with each system classified by risk tier and every gap mapped to the exact article it falls under. As an IAPP AI Governance Professional (AIGP) and fractional CISO, I bring both the regulatory fluency and the technical background to assess real systems, not just policy documents. You will receive a prioritized, plain-English gap report, a documentation checklist auditors and regulators will expect to see, and a compliance roadmap sequenced against the Act's phased enforcement deadlines, so you know exactly what to fix first and by when.
Cybersecurity Expertise
AI Compliance, AI Governance, Gap AnalysisTechnology Type
IaaS, Computer Network, SaaSCybersecurity Regulation
GDPR, ISO, HIPAAWhat's included
| Service Tiers |
Starter
$650
|
Standard
$1,300
|
Advanced
$2,600
|
|---|---|---|---|
| Delivery Time | 5 days | 8 days | 12 days |
Compliance Plan | - | - | - |
Gap Analysis | - | - | - |
Implementation | - | - | - |
Frequently asked questions
2 reviews
(2)
(0)
(0)
(0)
(0)
This project doesn't have any reviews.
KV
Kris V.
Dec 29, 2022
advice installing landing zone in new datacenter (AD / site configuration / DNS / DHCP / etc)
BG
Bradley G.
Nov 16, 2022
Ubiquity Unifi 802.1x MAC-Based RADIUS Authentication Issue
Great working with Damir very professional and knowledgeable
About Damir
Fractional CISO · Information Security Architect · Cloud Security
Maasmechelen, Belgium - 4:49 pm local time
I set security direction and personally deliver it — cloud guardrails, Kubernetes and CI/CD pipeline security, identity and secrets management, security monitoring and incident command, vulnerability management, and the technical controls behind PCI DSS, ISO 27001, SOC 2, and PSD2/DORA-style regulation.
Key engagements:
• CISO — Verizon Benelux: stood up the security function, delivered board-level risk governance and ISO 27001 compliance across EMEA operations
• CISO — Punch Powertrain: built the security programme from scratch in a high-pressure Tier-1 automotive environment
• CISO — ITAF ICT Services Belgrade: established security governance and controls for a regional ICT provider
• Security Architect / Team Lead — Dataplan Belgrade: built the security standard applied to 600+ SMB customers; delivered the Intune MDM programme
• Lead Security Architect — Belfius (PSD2 / Open Banking), BNP Paribas Fortis (cloud transformation), ING Belgium & Netherlands (PCI DSS compliance and network segregation)
• SecOps Lead — Federation of Notaries Belgium: owned SIEM/SOAR, vulnerability lifecycle, incident response, and Python automation for the sovereign real-estate clearing authority
Core capabilities:
→ Cloud security (Azure, GCP, AWS): identity, network segmentation, encryption, secrets, configuration baselines
→ Kubernetes & microservices: multi-cluster hardening, OPA/Gatekeeper, Falco, SPIFFE/SPIRE, mTLS, image signing
→ Secure SDLC & CI/CD: pipeline security gates, SBOM, supply-chain controls, threat modeling (STRIDE)
→ IAM & zero-trust: OAuth 2.0 / OIDC / SAML, HashiCorp Vault, HSM-backed KMS, certificate lifecycle
→ SecOps & IR: SIEM/SOAR engineering, detection rules, vulnerability lifecycle, penetration test coordination, incident command
→ Compliance: PCI DSS, ISO 27001 (Lead Auditor), SOC 2, NIST CSF, PSD2, MiCA, GDPR
→ AI security: OWASP Top 10 for LLMs, securing agentic applications, AI-assisted security tooling (IAPP AIGP certified)
Certifications: CISSP · CISM · CISA · ISO 27001 Lead Auditor · CCIE R&S · AZ-500 / SC-100 · CEH v13 · CASP+ · IAPP AIGP / CIPM
Available for fractional CISO engagements, security architecture reviews, ISO 27001 / SOC 2 / PCI DSS advisory, Kubernetes and cloud-native security, and incident response retainers. Remote, EU timezone, fluent English and Dutch.
Steps for completing your project
After purchasing the project, send requirements so Damir can start the project.
Delivery time starts when Damir receives requirements from you.
Damir works on your project following the steps below.
Revisions may occur after the delivery date.
AI Inventory and Risk Classification
Every AI/ML system and use case is catalogued and classified against the EU AI Act risk tiers: unacceptable, high-risk, limited, and minimal.
Control-by-Control Gap Analysis
High-risk systems are assessed against Title III obligations: risk management, data governance, technical documentation, transparency, and human oversight.