Your auditors are asking for automated evidence.
We generate it automatically.

OPSEC Scrub is purpose-built for the April 2026 Cyber Essentials Plus v3.3 update, DORA compliance, and UK GDPR Article 25. Every sanitization event generates audit-ready evidence.

CE+ v3.3DORA Art. 9–19UK GDPR Art. 25NCSC GuidanceIASME Certified

Four frameworks. One solution.

CRITICAL
CE+

Cyber Essentials Plus v3.3

Effective: April 2026

The April 2026 update to Cyber Essentials Plus v3.3 introduces mandatory automated metadata sanitization requirements. Manual processes are explicitly excluded.

ACTIVE
DORA

Digital Operational Resilience Act

Effective: January 2025

DORA requires documented evidence of data sanitization processes, immutable audit trails, and automated ICT risk controls for all regulated financial entities.

ACTIVE
GDPR

UK GDPR — Article 25

Effective: In Force

Data Protection by Design requires that personal data embedded in documents is removed before external transmission. Metadata is explicitly classified as personal data under UK GDPR.

GUIDANCE
NCSC

NCSC Guidance — Document Metadata

Effective: Current

NCSC's official guidance on document metadata risks explicitly recommends automated sanitization tools and warns against manual processes for organisations handling sensitive data.

Manual cleaning is no longer compliant.

The April 2026 update explicitly requires automated tooling. Here is how OPSEC Scrub maps to each new requirement.

ReferenceRequirementManual ProcessOPSEC Scrub
CE+ 3.3 §4.1
Automated removal of metadata from outbound files
Manual processes are explicitly excluded from v3.3 compliance. Automated tooling is required.
CE+ 3.3 §4.2
Immutable audit log of all sanitization events
Logs must be cryptographically signed and stored in an append-only system.
CE+ 3.3 §5.1
PII detection prior to external transmission
Requires automated NLP/NER-based detection, not keyword matching.
CE+ 3.3 §5.3
Network-level interception (not endpoint-dependent)
Endpoint agents are insufficient; network proxy required for full coverage.
CE+ 3.3 §6.1
Evidence trail exportable for IASME auditors
Reports must be generated on-demand in auditor-readable format.

DORA Readiness: Articles 9–19

For financial entities subject to DORA, OPSEC Scrub provides the documented ICT risk controls and operational resilience evidence the regulation demands.

Art. 9Covered

ICT Risk Management

OPSEC Scrub's immutable logs satisfy DORA's requirement for documented ICT risk controls with evidence of continuous operation.

Art. 11Covered

Data Integrity Controls

Cryptographic file hashing (before/after sanitization) provides the data integrity verification DORA mandates for outbound data flows.

Art. 13Covered

Operational Resilience Testing

OPSEC Scrub's API enables automated testing of sanitization coverage as part of your DORA resilience testing programme.

Art. 19Covered

ICT Incident Reporting

Sanitization failure events are automatically escalated to your SIEM, supporting DORA's 4-hour incident notification requirement.

Certified by IASME
Cyber Assurance Level 2
UK GDPR Compliant
Article 25 — Privacy by Design
NCSC Aligned
In Association Programme
Cyber Essentials Plus
v3.3 Ready — April 2026

Audit-ready in 30 minutes.

Deploy OPSEC Scrub and your compliance team will have the evidence trail they need for the next audit cycle — automatically generated, cryptographically signed.