From ISO 27001 and GDPR, through NIS 2 and the Polish cybersecurity act, to DORA, TISAX and KRI for public administration. All in one price, with no add-ons. Open a standard to read who it applies to and take a free readiness self-assessment without signing in.
ISO/IEC 27001 is the most widely recognised international standard for information security management.
NIS 2 is the EU cybersecurity directive (Directive (EU) 2022/2555) covering 18 sectors of the economy.
The GDPR (Regulation (EU) 2016/679) is the EU data protection regulation which, since 25 May 2018, obliges organisations to process personal data…
DORA (Digital Operational Resilience Act) is EU Regulation 2022/2554 which, since 17 January 2025, imposes uniform digital resilience requirements…
MiCA (EU Regulation 2023/1114 on Markets in Crypto-Assets) is the first comprehensive EU law governing crypto-assets.
ISO/IEC 27701 is the international standard for privacy information management (PIMS).
ISO 22301 is the international standard for business continuity management. It defines the requirements for a Business Continuity Management System…
The Polish National Interoperability Framework (KRI) is a Council of Ministers regulation of 12 April 2012 that obliges every entity performing…
BIO2 (Baseline Informatiebeveiliging Overheid 2.0) is the Dutch government-wide information security baseline covering the entire public sector…
IEC 62443 is a series of security standards for industrial automation and control systems (IACS/OT): production lines, power grids, water utilities…
SOC 2 is a US attestation reporting standard developed by the AICPA — an independent CPA evaluates whether a service organization’s controls meet…
PCI DSS (Payment Card Industry Data Security Standard) is the global security standard for payment card data, established by the PCI Security…
The NIST Cybersecurity Framework (CSF) 2.0 is a voluntary cybersecurity risk management framework published by the US National Institute of…
NIST SP 800-53 Rev. 5 is the most comprehensive publicly available catalogue of security and privacy controls — over a thousand controls and…
HIPAA (Health Insurance Portability and Accountability Act) is a US federal law from 1996 that protects patients’ health data.
CMMC 2.0 (Cybersecurity Maturity Model Certification) is the US Department of Defense program that verifies whether contractors and subcontractors…
Cyber Essentials is the UK government-backed certification scheme for baseline cyber hygiene.
SOX ITGCs are the IT General Controls required under the US Sarbanes-Oxley Act: access to financial systems, change management, program development…
TISAX is the automotive industry’s assessment and exchange mechanism for information security — based on the VDA ISA catalogue and governed by the…
ISO/SAE 21434 is the road vehicle cybersecurity engineering standard — covering the full lifecycle of electrical and electronic (E/E) systems, from…
ISO 9001 is the most widely adopted management standard in the world. It defines the requirements for a Quality Management System (QMS) — a way of…
ISO 14001 is the world’s most widely used environmental management standard.
ISO 45001 is the international standard for occupational health and safety (OH&S) management.
ISO/IEC 42001 is the world’s first certifiable standard for an Artificial Intelligence Management System (AIMS).
The EU AI Act — Regulation (EU) 2024/1689 of the European Parliament and of the Council — is the world’s first comprehensive regulation of…
ISO 13485 is the international quality management system (QMS) standard for medical devices.
IEC 62304 is the international standard for medical device software life cycle processes — both software embedded in devices and standalone software…
The MDR — Regulation (EU) 2017/745 — is the EU law governing the placing of medical devices on the European market.
ISO 14971:2019 is the international standard for risk management of medical devices.
DCB0129 is the NHS England standard for clinical risk management in the manufacture of health IT systems.
Book a short call — we will show you the platform live and answer questions about the requirements that apply to your company.