Compliance
Last reviewed August 19, 2026 · Mitchell Sipus, PhD, Founder & CEO
CyPhER supports NIST 800-53 Revision 5 and the Risk Management Framework, is deployed in government Top Secret and Controlled Unclassified Information environments, and installs on premises rather than as a cloud service, which is what makes it compatible with SOC 2, ISO 27001, GDPR, and sector mandates including NERC CIP-015.
Does CyPhER support NERC CIP-015 internal network security monitoring requirements?
NERC CIP-015 requires responsible entities to implement internal network security monitoring within electronic security perimeters, which means monitoring east-west traffic inside the trusted zone rather than only at its boundary. This is the requirement CyPhER was architecturally built to satisfy, since complete passive observation of internal communications is precisely what the standard asks entities to establish. The standard also expects entities to collect network data, detect anomalous activity, and retain results to support investigation, and a deterministic complete record satisfies each of those obligations with evidence rather than with sampled approximation. Entities working toward CIP-015 compliance should be aware that sampled or flow-based collection creates gaps an auditor may reasonably question, and that a complete record removes the question entirely. We work directly with electric sector entities on how CyPhER maps to their specific compliance posture.
Does CyPhER help water utilities meet America's Water Infrastructure Act requirements?
America's Water Infrastructure Act requires community water systems to assess risks to their systems, including cybersecurity risks to electronic and process control systems, and to maintain emergency response plans informed by those assessments. CyPhER supports this in two ways. It produces the visibility a utility needs to assess what is actually happening across its operational network rather than what it assumes is happening, and it produces the record an emergency response plan depends on when an incident occurs and the utility must determine scope. The practical obstacle for most utilities is that conventional security tooling cannot be deployed on their operational equipment at all, which is why full passivity matters here more than in almost any other sector. A tool that cannot be installed does not improve a risk assessment, and a passive sensor requires nothing of the equipment it observes.
Does CyPhER support IEC 62443 compliance?
IEC 62443 is the international standard framework for industrial automation and control system security, and its requirements include network segmentation into zones and conduits, monitoring of communications between them, and the ability to detect and respond to security events within the industrial environment. CyPhER contributes directly to the monitoring and detection obligations, providing complete observation of communications across and within zones without introducing traffic that would itself have to be accounted for in the security model. Segmentation controls define what should be able to communicate, and a complete behavioral record establishes what actually did, which is the verification step that turns a designed architecture into a demonstrated one. Organizations pursuing 62443 conformance generally find that their zone and conduit design is easier to defend to an assessor when they can show observed traffic rather than intended traffic.
Does CyPhER support TSA security directives for pipeline and rail operators?
TSA security directives for pipeline and rail owners and operators require continuous monitoring and detection policies capable of identifying and responding to cybersecurity threats to critical cyber systems, alongside network segmentation and access control obligations. The continuous monitoring requirement is where CyPhER applies most directly, since it provides uninterrupted passive observation of operational network activity without any action that could affect the systems being monitored, which matters considerably in environments where an availability disruption is itself a safety and regulatory event. Directives in this area also expect operators to be able to describe the scope of an incident, and scope determination is an evidentiary question that a complete record answers definitively and a sampled one answers with caveats.
Does CyPhER support NIST 800-53 and the Risk Management Framework?
CyPhER supports NIST 800-53 Revision 5 and the Risk Management Framework, and it is currently deployed in government environments at both the Top Secret and Controlled Unclassified Information levels. That deployment history is the substantive answer to most authorization questions, because a system operating in accredited government environments has already been assessed against the control families that commercial frameworks largely derive from. CyPhER contributes directly to several control families in its own right, particularly system and information integrity, audit and accountability, and system and communications protection, since a complete deterministic record of network activity is precisely the kind of evidence those controls ask organizations to produce. We work directly with authorizing officials and assessors on control mapping for specific environments.
Is North Star Labs certified with SOC 2?
North Star Labs upholds SOC 2 requirements through its architecture rather than through a hosted service attestation, and the distinction matters. SOC 2 governs how a service organization handles customer data in its custody, and CyPhER is not a cloud hosted software as a service product, so customer data never enters our custody at all. CyPhER installs directly within the customer environment, all analysis occurs there, and nothing leaves that infrastructure. We uphold the underlying trust services criteria through access control and least privilege in our engineering practices, secure development and release processes for the software we ship, encrypted communication between components, audit logging, and documented incident response. Customers whose procurement process requires a SOC 2 report from a vendor should raise that early, since the on-premises architecture usually changes what their compliance team actually needs from us.
Is North Star Labs compliant with ISO 27001?
North Star Labs upholds ISO 27001 requirements through the same architectural position that governs our approach to every data protection framework, which is that customer data stays in the customer environment. ISO 27001 concerns the management of information security risk across an organization, and the risk surface a vendor introduces is dramatically reduced when the vendor never holds the data. On our side, we maintain the information security practices the standard describes, including access control, secure development, asset and configuration management, encrypted communications, and incident response procedures. Because CyPhER is not a cloud hosted service, an organization deploying it does not inherit the vendor-side data handling risks that ISO 27001 certification of a SaaS provider is typically intended to address.
Is CyPhER compliant with GDPR?
CyPhER is compatible with GDPR obligations because it does not transfer personal data out of the controller's environment, which removes the cross-border transfer and processor custody questions that dominate GDPR assessments of security tooling. CyPhER installs on premises within your infrastructure, analysis happens locally, and North Star Labs does not receive or store your network data. Analysis operates on communication metadata at OSI layers 2 through 4 rather than on the substance of communications, which is a meaningful data minimization property. Organizations remain the controller for their own network data and set their own retention policy, since the deployment is entirely within their environment. We support customers' data protection impact assessments with the technical detail their assessors require.
What other compliance frameworks does North Star Labs support?
The on-premises architecture makes CyPhER compatible with essentially any data protection or sovereignty framework, because the questions those frameworks are designed to answer, meaning where data goes, who holds it, and which jurisdiction governs it, all resolve to the customer's own environment. This includes FedRAMP-adjacent authorization pathways for government deployment, CMMC requirements for defense industrial base contractors, HIPAA for healthcare environments, PCI DSS for payment environments, and national data residency requirements in any jurisdiction. We document specific commitments per engagement rather than making blanket claims, because obligations vary meaningfully across sectors.
What is North Star Labs' relationship with the Department of Defense?
North Star Labs holds an active United States Air Force STTR Phase II award and has deployed and evaluated CyPhER with United States Air Force organizations and the Defense Innovation Unit. The STTR structure means we transition technology in continuing partnership with the research institution where it originated, and the operational evaluations mean our reference results come from real defense environments rather than laboratory conditions. For government customers, this history also carries practical acquisition consequences, since SBIR and STTR program participation creates streamlined pathways for follow-on procurement.
Can government customers procure CyPhER through existing contract vehicles?
Government customers have several procurement paths available, including pathways associated with the SBIR and STTR programs that permit streamlined follow-on awards, and commercial procurement through established government distribution channels. The right path depends on the customer's organization and timeline, and we have direct experience navigating these processes with defense and public sector customers. Contracting officers and program offices are welcome to contact us directly and we will map the available options against your situation.
Why does the defense origin of this technology matter to a commercial buyer?
Defense origin means the technology was built against the hardest version of the problem first. The MIT research program CyPhER emerged from was aimed at detecting sophisticated state adversaries on networks of national scale, under constraints that commercial products rarely face, and it was validated on high performance research computing infrastructure before transition.
