Home/Frameworks
Framework guides
One page per framework: what it is, how you get assessed against it, and which documentation applies. Written for the person who has just been told 'we need to be compliant with this'.
ISO/IEC 27001:2022
International standard for an information security management system (ISMS). Certifiable by accredited bodies. The 2022 edition restructured Annex A into 93 controls across four themes (organisational, people, physical, technological) and added eleven new controls including threat intelligence, cloud services and data leakage prevention.
How assessment works
Clauses 4–10 define the management system: context, leadership, planning (risk), support, operation, evaluation and improvement. Annex A lists the controls; ISO/IEC 27002 explains them. Certification is a Stage 1 documentation review followed by a Stage 2 implementation audit, then annual surveillance.
What we provide
Policies and standards for all 93 controls, the clause 4–10 templates, a risk methodology and register, a Statement of Applicability, and internal audit and management review templates.
NIST CSF 2.0
Voluntary US framework, widely used internationally as a governance structure. Version 2.0 (February 2024) added the Govern function and extended the audience beyond critical infrastructure. It is an outcomes framework: 106 subcategories describe what good looks like without prescribing how.
How assessment works
Six functions: Govern, Identify, Protect, Detect, Respond, Recover. Organisations build a current profile and a target profile and use tiers (1–4) to describe rigour. There is no certification; it is used for self-assessment and customer assurance.
What we provide
Policies for the six functions, standards at subcategory level so each outcome becomes testable, profile and tier workbooks, and mappings to ISO 27002 and 800-53.
NIST SP 800-53 Rev 5
The US federal control catalogue: about 1,000 controls and enhancements across 20 families, with low, moderate and high baselines. Required for federal systems and FedRAMP; used contractually by many organisations that serve government.
How assessment works
Each family begins with a -1 control requiring documented policy and procedures. Many controls contain organisation-defined parameters (ODPs) that you must set. Assessment follows SP 800-53A.
What we provide
Family-level policies, control-level standards for the moderate baseline, an ODP workbook so parameters are set once, and a POA&M template.
- Policies & Standards — NIST SP 800-53 R5 (Moderate)
- Procedures Library
- Vulnerability & Patch Management Programme
NIST SP 800-171 R3 and CMMC
800-171 protects Controlled Unclassified Information in non-federal systems. Revision 3 (2024) has 97 requirements across 17 families, with organisation-defined parameters. CMMC 2.0 is the US Department of Defense's assessment programme: Level 1 (FAR basic safeguarding), Level 2 (800-171, self or C3PAO assessed), Level 3 (adds 800-172).
How assessment works
Assessors use the assessment objectives in 800-171A, not the requirement text. Every objective needs examine, interview or test evidence. The System Security Plan and POA&M are mandatory artefacts.
What we provide
The full programme: policies, standards and procedures per objective, SSP and POA&M templates, CUI scoping, a supply chain plan and an R2-to-R3 transition worksheet.
- NIST SP 800-171 R3 & CMMC Level 2 Programme
- Risk Management Programme
- Vulnerability & Patch Management Programme
- Incident Response & Business Continuity Programme
SOC 2
An attestation report under the AICPA Trust Services Criteria, produced by a CPA firm. Type I reports on control design at a point in time; Type II reports on operating effectiveness over a period (typically 6–12 months). Security is mandatory; Availability, Confidentiality, Processing Integrity and Privacy are optional.
How assessment works
The auditor tests the controls you describe in your system description. Documentation therefore has to exist before the observation period starts, and the controls have to operate consistently throughout it.
What we provide
Policies and standards for the Common Criteria and the four optional categories, a criteria-to-control matrix, and a system description outline.
PCI DSS v4.0.1
The card brands' standard for any organisation that stores, processes or transmits cardholder data. Twelve requirements. v4 (mandatory since March 2025) added targeted risk analyses, the customised approach, and stricter authentication and e-commerce script controls. v4.0.1 is a clarification release.
How assessment works
Scope is set by your Self-Assessment Questionnaire type (A through D) or by a QSA assessment. Every requirement expects documented policies and procedures, and several expect a documented targeted risk analysis to justify control frequency.
What we provide
Policies and standards for all twelve requirements, an SAQ applicability matrix, scoping and data-flow templates, targeted risk analysis templates and a compliance calendar.
UK GDPR and EU GDPR
Data protection law for personal data of people in the UK and EU respectively, with near-identical text. Applies to controllers and processors regardless of where they are based if they target or monitor those people. Requires demonstrable accountability: records, assessments and policies, not just compliance in practice.
How assessment works
Article 30 records of processing, Article 35 impact assessments, Article 28 processor contracts, Article 33 breach notification within 72 hours, and Articles 12–22 data subject rights are the documentary core.
What we provide
The Data Privacy Programme covers the internal records and the external notices, and connects privacy to the security controls in the ISMS.
NIS2
EU directive on cybersecurity for essential and important entities across 18 sectors, transposed into member-state law from October 2024. Management bodies must approve and oversee risk measures and can be held personally liable. Article 21 lists ten minimum measure areas including supply chain, incident handling and business continuity.
How assessment works
Incident reporting to the national CSIRT: early warning within 24 hours, notification within 72 hours, final report within one month. Supervision and fines vary by member state.
What we provide
The NIS2 and DORA set is organised by article so you can show which document satisfies which obligation.
- NIS2 & DORA Documentation Set
- Supply Chain Risk Management Plan
- Incident Response & Business Continuity Programme
DORA
EU regulation on digital operational resilience for financial entities and their critical ICT third-party providers, applying from January 2025. Five pillars: ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing. Detailed regulatory technical standards specify the content of the ICT risk framework, incident classification and contract provisions.
How assessment works
Major incident reporting to the competent authority: initial notification within 4 hours of classification (and 24 hours of detection), intermediate within 72 hours, final within one month. A register of information on ICT third parties must be maintained and submitted.
What we provide
The NIS2 and DORA set includes the ICT risk framework, classification and reporting procedure, third-party register and testing programme.
- NIS2 & DORA Documentation Set
- Supply Chain Risk Management Plan
- Incident Response & Business Continuity Programme
ISO/IEC 42001 and the EU AI Act
ISO/IEC 42001 (2023) is a certifiable management-system standard for AI, structured like ISO 27001 with an Annex A of AI-specific controls. The EU AI Act (in force August 2024, obligations phasing in through 2027) attaches legal duties to providers and deployers of AI systems according to risk tier, with prohibited practices, high-risk requirements and transparency rules.
How assessment works
Both expect an inventory of AI systems, impact assessments, human oversight, data governance and documentation of decisions. The Act's high-risk obligations include technical documentation, logging, and conformity assessment.
What we provide
The AI Governance Programme gives you the management-system structure, inventory, impact assessment and obligations map, reusing your ISMS where possible.
Cyber Essentials
UK government-backed certification of five basic control areas: firewalls, secure configuration, access control, malware protection and patch management. Cyber Essentials is a self-assessment verified by an assessor; Cyber Essentials Plus adds a technical audit. Required for many UK public-sector contracts.
How assessment works
The assessment is questionnaire-based and asks for policy in several areas (for example password and device policies). Patching within 14 days of a critical or high vulnerability is the most-failed requirement.
What we provide
The Core Fundamentals set maps to the five control themes; the Vulnerability and Patch Management Programme documents the patching rule.
Side by side
| Framework | Mandatory? | Certifiable? | Structure | Best used as |
|---|---|---|---|---|
| ISO 27001 | No (contractual) | Yes | Management system + 93 controls | The backbone for most organisations |
| NIST CSF 2.0 | No | No | 6 functions, 106 outcomes | Governance structure and board language |
| NIST 800-53 | Federal systems | Via FedRAMP/ATO | 20 families, baselines | Control catalogue when depth is required |
| 800-171 / CMMC | US DoD supply chain | Yes (CMMC) | 17 families, 97 requirements | Non-negotiable if you hold CUI |
| SOC 2 | No (contractual) | Attestation | Trust Services Criteria | Assurance for US enterprise customers |
| PCI DSS | If you handle cards | Yes (SAQ/ROC) | 12 requirements | Scoped to the card environment |
| GDPR | Yes (law) | No | Principles + obligations | Privacy layer over any security framework |
| NIS2 | Yes (law, in scope) | No | Article 21 measures | Usually satisfied via ISO 27001 + gap set |
| DORA | Yes (law, financial) | No | 5 pillars + RTS | Prescriptive; document by article |
| ISO 42001 / AI Act | AI Act: yes (law) | 42001: yes | Management system + AI controls | Extension of the ISMS to AI |
| Cyber Essentials | UK public contracts | Yes | 5 control themes | Small-organisation baseline |
The framework guides on this page are general summaries for orientation, current to October 2026. They are not legal advice. Check the primary source for your obligations.