Frameworks

Every framework,
one control set.

Map your controls once and reuse them across every standard you need. Start with a plain-language guide to the framework you're working on — what it asks for, and how teams keep it audit-ready between audits.

Book a conversation
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
Guides

Start with your framework.

In-depth, plain-language walkthroughs of each standard. More are on the way — every framework below is supported today from one control set.

ISO/IEC 27001

The international standard for an ISMS — certification, Annex A controls, the Statement of Applicability and staying audit-ready.

Read the guide

ISO/IEC 27002

The reference catalogue of 93 information security controls behind ISO/IEC 27001 Annex A: the four themes, the five attributes, and how to use it as the how-to layer of an ISMS

Read the guide

SOC 2

The AICPA attestation report SaaS vendors use to prove security — Trust Services Criteria, Type I vs Type II, and the observation period.

Read the guide

SOC 1

The AICPA attestation report on the controls at a service organization that affect a customer’s financial reporting — control objectives, Type 1 vs Type 2, and who actually reads it.

Read the guide

GDPR

The EU data protection law explained plainly — lawful bases, data subject rights, RoPA, DPIAs and the 72-hour breach clock.

Read the guide

HIPAA

The US law that protects health information — PHI and ePHI, the Privacy, Security and Breach Notification Rules, business associates and BAAs.

Read the guide

PCI DSS v4.0.1

The payment-card data security standard — the 12 requirements, scope and segmentation, SAQ vs ROC, and staying compliant as business-as-usual.

Read the guide

NIST CSF 2.0

The voluntary US cybersecurity framework — six Functions, Implementation Tiers and Current-to-Target Profiles, with no certificate to chase.

Read the guide

EU AI Act

The first comprehensive law on AI — risk tiers, high-risk obligations, the GPAI rules, conformity assessment and the phased timeline.

Read the guide

NIS2 Directive

The EU cybersecurity directive for essential and important entities — risk-management measures, incident reporting and management accountability.

Read the guide

DORA

The EU regulation on digital operational resilience for financial entities — ICT risk, incident reporting, resilience testing and third-party risk.

Read the guide

OWASP

The open body of application-security resources — the OWASP Top 10, the ASVS, SAMM and the API Security Top 10 that teams build and verify secure software against.

Read the guide

ISO/IEC 42001

The international standard for an AI management system — certifiable, with AI risk and impact assessments and lifecycle governance.

Read the guide

CIS Controls

The prioritized, voluntary set of cybersecurity safeguards — the 18 Controls, their Safeguards and the IG1 to IG3 implementation groups.

Read the guide

Cloud Controls Matrix

The CSA cloud-security control framework — domains, the CAIQ, the STAR program and answering customer security reviews.

Read the guide

ISO/IEC 27017 & 27018

The cloud extensions to ISO/IEC 27001 — cloud security guidance (27017) and PII protection in public clouds (27018), added as scope.

Read the guide

ISO/IEC 27701

The privacy information management standard, standalone since 2025: PIMS clauses 4 to 10 and 78 Annex A controls split between PII controllers, PII processors and both

Read the guide

ISO 9001

The certifiable quality management standard: clauses 4 to 10, risk-based thinking, documented information and the same three-year audit cycle as ISO 27001.

Read the guide

ISO 14001

The certifiable environmental management standard, revised in 2026: clauses 4 to 10, environmental aspects, compliance obligations, a life cycle perspective and the same three-year audit cycle as ISO 9001

Read the guide

ISO 45001

The certifiable occupational health and safety standard: clauses 4 to 10, worker consultation and participation, hazard identification, the hierarchy of controls and the same three-year audit cycle as ISO 9001

Read the guide

Swiss nFADP

Switzerland’s revised data-protection law (revFADP / nDSG) explained — the principles, records, DPIAs, breach notification and how it lines up with the GDPR.

Read the guide

Custom frameworks

Author your own framework and controls when the official ones aren’t enough.

Read the guide

Working toward a standard we haven't written up yet? Book a conversation and we'll walk through yours.

Bring your frameworks into one workspace.

Map your controls once, reuse the evidence across every standard, and keep each one audit-ready between audits.

Book a conversation
Sign in
Start for free
Book a conversationStart for free