Skip to content
Compliflux

Frameworks

Eleven frameworks, one control set.

Most requirements overlap. The platform brings them together on a shared control set, so a single piece of evidence satisfies several obligations.

ISO 27001

The international standard for information security management systems. It requires a risk-based approach and the 93 controls of Annex A. The platform uses this as the basis for aligning the other frameworks.

NIS2

The EU directive on network and information security significantly widens the range of affected entities and mandates risk management, reporting channels and evidence obligations. National transposition specifies deadlines and supervision.

GDPR

The General Data Protection Regulation requires technical and organisational measures to protect personal data. Records of processing, data-subject rights and breach-notification duties can be evidenced with the platform's registers and records.

DORA

The Digital Operational Resilience Act applies to the financial sector and governs digital operational stability - including ICT risk management, incident reporting and third-party oversight. The vendor and incident registers address these requirements directly.

KRITIS

The German transposition of NIS2 into the BSIG places specific duties on operators of critical infrastructure, with its own registration, reporting and evidence regime. Its requirements are mapped both to ISO 27001 and directly to NIS2, so an operator carries one control set rather than two.

TISAX

The automotive industry's assessment and exchange mechanism carries information-security requirements into the supply chain. Anyone supplying manufacturers demonstrates maturity against a shared catalogue.

BSI IT-Grundschutz

The methodology of Germany's Federal Office for Information Security links modules to concrete measures. It can be combined with ISO 27001 and is an established path for public authorities and operators of critical infrastructure.

SOC 2

The assurance standard for service providers demonstrates to customers that controls for security, availability and confidentiality are effective. Evidence packages and control records support preparation for Type I and Type II.

CRA

The Cyber Resilience Act sets requirements for the security of products with digital elements across their entire life cycle - from vulnerability management to update obligations. Relevant for manufacturers and those placing products on the market.

AI Act

The EU's AI regulation tiers obligations by risk class. Providers and deployers of AI systems document risk management, data governance and oversight - topics that fit into existing registers.

CSRD

The sustainability reporting directive requires assured disclosures, including on governance and risks. Evidence of effective controls and the consolidated view across units support the reporting obligation.

Framework packs

Frameworks, bundled the way you adopt them.

Every plan starts with ISO 27001 as the shared control set. Add the packs that match your regulatory footprint - they are independent of the plan tier, so you only carry what applies to you.

Foundation

ISO 27001

The shared control set. Always included - every other framework maps back to it.

Germany Industry

BSI IT-Grundschutz, TISAX

For public-sector work and automotive supply chains.

EU Critical & Finance

NIS2, DORA, KRITIS

For essential entities, operators of critical infrastructure and the regulated financial sector.

EU Product & Data

GDPR, AI Act, CRA

For personal data, AI systems and products with digital elements.

International SaaS

SOC 2

The assurance report your customers ask for.

Sustainability add-on

CSRD

Add reporting duties on demand, the moment they apply to you.

Cross-mapping

Implement once, evidence many times.

A control required by ISO 27001 often covers NIS2, DORA or TISAX at the same time. The platform maintains this mapping, shows overlaps and makes visible where a single measure satisfies several obligations.