Trusterio

Coverage

Do the work once. Count it everywhere.

Seven frameworks, one control library. A reading of your cloud that satisfies ISO 27001 also satisfies the SOC 2 criterion, the NIS2 measure and the DORA requirement that ask the same question — so the second certification is mostly already done.

Framework by framework

What each one actually asks of you

Written out rather than shown as a wall of certification marks — partly because those marks are licensed and we do not hold the licences, and partly because a logo does not tell you whether the thing applies to your company.

ISO/IEC 27001

Information security management

Most European B2B software companies, usually because a customer asked.

The full Annex A control set, with the statement of applicability derived from what you selected rather than maintained beside it. Exclusions carry your reason and are visible next to the score they moved.

  • Annex A controls
  • Statement of applicability
  • Management review
  • Internal audit

NIS2

Network and information security, second directive

Essential and important entities — and, increasingly, their suppliers.

Article 21 measures mapped onto the same controls you already run for ISO 27001, plus the incident reporting timetable, which is the part that catches people out.

  • Art. 21 measures
  • Incident reporting clocks
  • Supply chain
  • Management accountability

GDPR

General Data Protection Regulation

Anybody processing personal data in or from the EU. So: you.

Including the Article 30 record of processing activities as a real record — purposes, legal bases, categories, recipients, retention — checked against what your Trust Center says you hold.

  • Art. 30 record
  • Legal bases
  • Subprocessors and transfers
  • Retention

SOC 2

Trust services criteria

Companies selling into the United States.

The common criteria and the optional categories, mapped to the same controls as ISO 27001 — which is most of why running both costs far less than twice as much.

  • Common criteria
  • Availability
  • Confidentiality
  • Evidence periods

DORA

Digital Operational Resilience Act

Financial entities in the EU, and the ICT providers who serve them.

ICT risk management, incident classification and the register of information about third-party arrangements, which draws on the same subprocessor records your Trust Center publishes.

  • ICT risk management
  • Incident classification
  • Third-party register
  • Resilience testing

ISO/IEC 42001

AI management systems

Companies shipping AI features and being asked how they govern them.

The management system for AI, mapped onto the same structure as 27001 so the overlap is counted once rather than rebuilt.

  • AI policy
  • Impact assessment
  • Data governance
  • Human oversight

EU AI Act

Regulation (EU) 2024/1689

Providers and deployers of AI systems placed on the EU market.

Risk classification and the obligations that follow from it, kept beside the AI management system rather than in a separate document nobody opens.

  • Risk classification
  • Technical documentation
  • Transparency
  • Post-market monitoring

How the mapping works

The second framework is mostly already done

Frameworks overlap far more than their table of contents suggests. Trusterio keeps one control library and points requirements at it, so adding a framework mostly reveals evidence you already had.

One library
Controls belong to you, not to a framework. A requirement points at one.
One reading
Evidence collected for one requirement is counted against every requirement pointing at the same control.
One score per framework
Each framework reports its own readiness from the controls that actually apply to it.
Gaps, not duplicates
Adding a framework shows you what is genuinely new — usually a short list.

Next: what it costs

Fourteen days. The whole thing.

No card, no sales call, no demo you have to sit through. Your data stays in the EU.

Start free
Frameworks — ISO 27001, NIS2, GDPR, SOC 2, DORA and the EU AI Act