Frameworks
Eleven frameworks, one control set.
Most requirements overlap. The platform brings them together on a shared control set, so a single piece of evidence satisfies several obligations.
ISO 27001
The international standard for information security management systems. It requires a risk-based approach and the 93 controls of Annex A. The platform uses this as the basis for aligning the other frameworks.
NIS2
The EU directive on network and information security significantly widens the range of affected entities and mandates risk management, reporting channels and evidence obligations. National transposition specifies deadlines and supervision.
GDPR
The General Data Protection Regulation requires technical and organisational measures to protect personal data. Records of processing, data-subject rights and breach-notification duties can be evidenced with the platform's registers and records.
DORA
The Digital Operational Resilience Act applies to the financial sector and governs digital operational stability - including ICT risk management, incident reporting and third-party oversight. The vendor and incident registers address these requirements directly.
KRITIS
The German transposition of NIS2 into the BSIG places specific duties on operators of critical infrastructure, with its own registration, reporting and evidence regime. Its requirements are mapped both to ISO 27001 and directly to NIS2, so an operator carries one control set rather than two.
TISAX
The automotive industry's assessment and exchange mechanism carries information-security requirements into the supply chain. Anyone supplying manufacturers demonstrates maturity against a shared catalogue.
BSI IT-Grundschutz
The methodology of Germany's Federal Office for Information Security links modules to concrete measures. It can be combined with ISO 27001 and is an established path for public authorities and operators of critical infrastructure.
SOC 2
The assurance standard for service providers demonstrates to customers that controls for security, availability and confidentiality are effective. Evidence packages and control records support preparation for Type I and Type II.
CRA
The Cyber Resilience Act sets requirements for the security of products with digital elements across their entire life cycle - from vulnerability management to update obligations. Relevant for manufacturers and those placing products on the market.
AI Act
The EU's AI regulation tiers obligations by risk class. Providers and deployers of AI systems document risk management, data governance and oversight - topics that fit into existing registers.
CSRD
The sustainability reporting directive requires assured disclosures, including on governance and risks. Evidence of effective controls and the consolidated view across units support the reporting obligation.
Framework packs
Frameworks, bundled the way you adopt them.
Every plan starts with ISO 27001 as the shared control set. Add the packs that match your regulatory footprint - they are independent of the plan tier, so you only carry what applies to you.
Foundation
ISO 27001
The shared control set. Always included - every other framework maps back to it.
Germany Industry
BSI IT-Grundschutz, TISAX
For public-sector work and automotive supply chains.
EU Critical & Finance
NIS2, DORA, KRITIS
For essential entities, operators of critical infrastructure and the regulated financial sector.
EU Product & Data
GDPR, AI Act, CRA
For personal data, AI systems and products with digital elements.
International SaaS
SOC 2
The assurance report your customers ask for.
Sustainability add-on
CSRD
Add reporting duties on demand, the moment they apply to you.
Cross-mapping
Implement once, evidence many times.
A control required by ISO 27001 often covers NIS2, DORA or TISAX at the same time. The platform maintains this mapping, shows overlaps and makes visible where a single measure satisfies several obligations.