Framework by framework
What each one actually asks of you
Written out rather than shown as a wall of certification marks — partly because those marks are licensed and we do not hold the licences, and partly because a logo does not tell you whether the thing applies to your company.
ISO/IEC 27001
Information security managementMost European B2B software companies, usually because a customer asked.
The full Annex A control set, with the statement of applicability derived from what you selected rather than maintained beside it. Exclusions carry your reason and are visible next to the score they moved.
- Annex A controls
- Statement of applicability
- Management review
- Internal audit
NIS2
Network and information security, second directiveEssential and important entities — and, increasingly, their suppliers.
Article 21 measures mapped onto the same controls you already run for ISO 27001, plus the incident reporting timetable, which is the part that catches people out.
- Art. 21 measures
- Incident reporting clocks
- Supply chain
- Management accountability
GDPR
General Data Protection RegulationAnybody processing personal data in or from the EU. So: you.
Including the Article 30 record of processing activities as a real record — purposes, legal bases, categories, recipients, retention — checked against what your Trust Center says you hold.
- Art. 30 record
- Legal bases
- Subprocessors and transfers
- Retention
SOC 2
Trust services criteriaCompanies selling into the United States.
The common criteria and the optional categories, mapped to the same controls as ISO 27001 — which is most of why running both costs far less than twice as much.
- Common criteria
- Availability
- Confidentiality
- Evidence periods
DORA
Digital Operational Resilience ActFinancial entities in the EU, and the ICT providers who serve them.
ICT risk management, incident classification and the register of information about third-party arrangements, which draws on the same subprocessor records your Trust Center publishes.
- ICT risk management
- Incident classification
- Third-party register
- Resilience testing
ISO/IEC 42001
AI management systemsCompanies shipping AI features and being asked how they govern them.
The management system for AI, mapped onto the same structure as 27001 so the overlap is counted once rather than rebuilt.
- AI policy
- Impact assessment
- Data governance
- Human oversight
EU AI Act
Regulation (EU) 2024/1689Providers and deployers of AI systems placed on the EU market.
Risk classification and the obligations that follow from it, kept beside the AI management system rather than in a separate document nobody opens.
- Risk classification
- Technical documentation
- Transparency
- Post-market monitoring