Standards and regulations

30 standards in one platform

From ISO 27001 and GDPR, through NIS 2 and the Polish cybersecurity act, to DORA, TISAX and KRI for public administration. All in one price, with no add-ons. Open a standard to read who it applies to and take a free readiness self-assessment without signing in.

Information security and European Union law

ISO 27001

ISO/IEC 27001 is the most widely recognised international standard for information security management.

NIS 2 (Polish KSC act)

NIS 2 is the EU cybersecurity directive (Directive (EU) 2022/2555) covering 18 sectors of the economy.

GDPR

The GDPR (Regulation (EU) 2016/679) is the EU data protection regulation which, since 25 May 2018, obliges organisations to process personal data…

DORA

DORA (Digital Operational Resilience Act) is EU Regulation 2022/2554 which, since 17 January 2025, imposes uniform digital resilience requirements…

MiCA

MiCA (EU Regulation 2023/1114 on Markets in Crypto-Assets) is the first comprehensive EU law governing crypto-assets.

ISO 27701

ISO/IEC 27701 is the international standard for privacy information management (PIMS).

ISO 22301

ISO 22301 is the international standard for business continuity management. It defines the requirements for a Business Continuity Management System…

KRI

The Polish National Interoperability Framework (KRI) is a Council of Ministers regulation of 12 April 2012 that obliges every entity performing…

BIO2

BIO2 (Baseline Informatiebeveiliging Overheid 2.0) is the Dutch government-wide information security baseline covering the entire public sector…

IEC 62443

IEC 62443 is a series of security standards for industrial automation and control systems (IACS/OT): production lines, power grids, water utilities…

US-market and industry standards

SOC 2

SOC 2 is a US attestation reporting standard developed by the AICPA — an independent CPA evaluates whether a service organization’s controls meet…

PCI DSS

PCI DSS (Payment Card Industry Data Security Standard) is the global security standard for payment card data, established by the PCI Security…

NIST CSF

The NIST Cybersecurity Framework (CSF) 2.0 is a voluntary cybersecurity risk management framework published by the US National Institute of…

NIST 800-53

NIST SP 800-53 Rev. 5 is the most comprehensive publicly available catalogue of security and privacy controls — over a thousand controls and…

HIPAA

HIPAA (Health Insurance Portability and Accountability Act) is a US federal law from 1996 that protects patients’ health data.

CMMC 2.0

CMMC 2.0 (Cybersecurity Maturity Model Certification) is the US Department of Defense program that verifies whether contractors and subcontractors…

Cyber Essentials

Cyber Essentials is the UK government-backed certification scheme for baseline cyber hygiene.

SOX ITGC

SOX ITGCs are the IT General Controls required under the US Sarbanes-Oxley Act: access to financial systems, change management, program development…

TISAX

TISAX is the automotive industry’s assessment and exchange mechanism for information security — based on the VDA ISA catalogue and governed by the…

ISO 21434

ISO/SAE 21434 is the road vehicle cybersecurity engineering standard — covering the full lifecycle of electrical and electronic (E/E) systems, from…

Quality, environment, artificial intelligence

ISO 9001

ISO 9001 is the most widely adopted management standard in the world. It defines the requirements for a Quality Management System (QMS) — a way of…

ISO 14001

ISO 14001 is the world’s most widely used environmental management standard.

ISO 45001

ISO 45001 is the international standard for occupational health and safety (OH&S) management.

ISO 42001 (AI)

ISO/IEC 42001 is the world’s first certifiable standard for an Artificial Intelligence Management System (AIMS).

EU AI Act

The EU AI Act — Regulation (EU) 2024/1689 of the European Parliament and of the Council — is the world’s first comprehensive regulation of…

Medical devices and healthcare

ISO 13485

ISO 13485 is the international quality management system (QMS) standard for medical devices.

IEC 62304

IEC 62304 is the international standard for medical device software life cycle processes — both software embedded in devices and standalone software…

MDR

The MDR — Regulation (EU) 2017/745 — is the EU law governing the placing of medical devices on the European market.

ISO 14971

ISO 14971:2019 is the international standard for risk management of medical devices.

DCB0129

DCB0129 is the NHS England standard for clinical risk management in the manufacture of health IT systems.

Let's talk about your organisation

Book a short call — we will show you the platform live and answer questions about the requirements that apply to your company.