Frameworks & Standards
The 26+ frameworks our services map to. Where they overlap, we implement the control once and evidence it against every framework that requires it.
Framework library
| Framework | Domain | What it covers |
|---|---|---|
| ISO/IEC 27001:2022 | Information security management | 93 controls across 4 themes. The global baseline for information security certification. |
| ISO/IEC 42001:2023 | AI management systems | The first certifiable AI governance standard. Increasingly requested of AI vendors. |
| ISO 9001:2015 | Quality management | Process consistency and continual improvement across the organisation. |
| ISO/IEC 20000-1:2018 | IT service management | Service delivery, incident, change and capacity management. |
| ISO 22301:2019 | Business continuity | Continuity planning, RTO/RPO definition and tested recovery. |
| ISO/IEC 27701:2019 | Privacy information management | Extends ISO 27001 to privacy, mapping to GDPR obligations. |
| SOC 2 Type II | Trust Services Criteria | Attestation over a period, most often demanded of SaaS providers. |
| NIST CSF 2.0 | Cyber security framework | Govern, Identify, Protect, Detect, Respond, Recover. |
| GDPR | EU data protection | Lawful basis, data subject rights, processor obligations, breach notification. |
| DPDP Act 2023 | India data protection | Consent, data principal rights, significant data fiduciary duties. |
| PCI DSS 4.0 | Payment card security | Twelve requirements for anyone handling cardholder data. |
| HIPAA | US healthcare privacy | Security, privacy and breach notification rules for PHI. |
Why crosswalking matters
ISO 27001, SOC 2 and the DPDP Act ask overlapping questions in different language. Implemented separately, you build three control sets, three evidence trails and three audit cycles.
Our control library maps every control to all applicable frameworks, so an access-review control answers ISO 27001 A.5.18, SOC 2 CC6.2 and DPDP security safeguards simultaneously — one implementation, one evidence artefact, three satisfied requirements.
Which frameworks apply to you?
Send us your customer questionnaires or regulatory obligations and we will produce a mapped scope in a single session.
Book a Consultation