Controls are cross-mapped between frameworks, so evidence you collect once counts everywhere it applies. Activating a new framework starts from the controls you already have; your plan determines how many you can have active at the same time. Not sure which apply to you? Book a free gap analysis.
NIS2
The Swedish Cybersecurity Act, built from the legal text and MSBFS. Full MSB incident flow included.
DORA
For financial institutions and their ICT providers, with a supervisor-ready ICT contract register
GDPR
Records of processing, data protection controls, and the 72-hour IMY breach flow
ISO 27001:2022
The full control catalog with continuous evidence collection and an auditor portal
EU AI Act
Scoping for high-risk AI systems and the requirements phasing in through 2027
CRA
Security requirements for products with digital elements sold in the EU. The next wave after NIS2.
SOC 2
The leading standard for B2B deals with US buyers, mapped to your existing controls
ISO 27701
Extend ISO 27001 with privacy controls that align with GDPR
ISO 22301
An auditable business continuity system, covering the continuity NIS2 also demands
TISAX
The automotive industry's security standard, required by European OEMs and their supply chains