Provantis is anchored to FSCA / Prudential Authority Joint Standard 2 of 2024 (in force 1 June 2025). A 32-rule library across seven sub-domains, a 19-check automated trust score, a structured self-assessment with five maturity bands — and the differentiators an underwriter actually asks about.
Joint Standard 2 of 2024 took effect on 1 June 2025. It applies directly to the financial institutions defined in paragraph 2 — including insurers and insurance controlling companies, CIS managers, discretionary FSPs and administrative FSPs. A Category I FSP is included only where it provides investment fund administration services, so most independent non-life brokerages are not directly in scope in that capacity. Paragraphs 4.2.3, 7.2.3(a)(iii), 7.7.1(b) and 8.1.1(f) place third-party contracting, information protection, testing-assurance and access-control duties on the in-scope institution. An insurer may reflect those duties in a broker or UMA contract, but the standard does not itself make every intermediary directly subject to JS2. Provantis helps assemble readiness evidence for the requirements that apply to your entity and relationships; applicability remains for professional review.
JS2 of 2024 has been in force since 1 June 2025 for the institutions in its defined scope. Those institutions must be able to demonstrate the controls and oversight the standard requires.
JS2 binds the institutions defined in paragraph 2 — insurers among them. Most independent non-life Category I brokerages are not directly in scope in that capacity, but insurer contracts and oversight may require evidence from a broker or UMA where the service and risk justify it.
Insurance and due-diligence questionnaires may ask for documented control evidence. A structured pack makes the evidence easier to review; it does not guarantee acceptance, renewal or coverage.
The library is structured to mirror Joint Standard 2 governance language while staying operational for a broker or UMA. Every rule is citation-grade — traceable to a public regulatory instrument.
Cybersecurity strategy, board oversight, risk appetite, roles and responsibilities, policy framework.
HTTPS / HSTS, TLS posture, SPF / DKIM / DMARC, security headers, admin exposure, lookalike domains.
Multi-factor authentication, privileged access, password hygiene, joiner / mover / leaver controls.
Backup, disaster recovery, business continuity, incident response, recovery time and recovery point objectives.
Outsourcing register, vendor due diligence, concentration risk, contractual cyber clauses, exit strategy.
Awareness training, phishing-drill cadence, role-based education, insider risk, social-engineering posture.
Load-shedding resilience, MFA fallback, generator and UPS posture, failover ISP, SA cyber-threat-actor context.
19 automated checks run for free in 60 seconds. The 32-rule readiness self-assessment is the deeper, attested evidence layer for paid customers.
Every assessment lands you in one of five bands — with a description, a recommended action, and a clear path to the next level.
Critical controls absent. Immediate remediation and management attention required. This readiness band is not a legal compliance conclusion.
Basic controls exist but significant gaps remain. Prioritise critical safeguards and verify entity-specific regulatory and insurance requirements.
Core controls are in place, but governance, testing and third-party risk frameworks need strengthening. Some assessed controls map to JS2 themes.
Solid readiness posture with documented, tested controls and evidence of management oversight. Compliance still depends on entity scope and a full professional review.
Advanced readiness posture with proactive threat intelligence and continuous monitoring. This score does not certify JS2 compliance.
The capabilities that separate a generic cyber tool from one built for SA short-term insurance.
A board-ready IRP aligned to JS2 of 2024 and NIST SP 800-61 r2 — roles, escalation, comms tree, detection, containment, eradication, recovery, lessons learned. In minutes.
One executive PDF aggregating 90-day scan trend, latest readiness assessment, IRP, load-shedding attestation and vendor register — the underwriter walks in informed.
Alerts when your cyber posture changes between scans — new open ports, expired TLS, missing DMARC, dropped headers — before the underwriter notices.
Detects typo-squat and homoglyph domains targeting your brand — the social-engineering vector behind most claim-driving incidents in SA broking.
Structured business-continuity attestation for the SA operating context — UPS, generator, failover ISP, MFA fallback — included in the cyber-insurance pack.
Lightweight log of phishing exercises against your staff — campaign, click-rate, reporter-rate — surfaced in the human-risk view and the evidence pack.
Detects visible technology signals on your public surface and flags possible vendor concentration for further assessment.
Deeper authenticated scans require DNS TXT verification, providing a strong technical-control check and a guard against scope abuse.