Home/Frameworks

Framework guides

One page per framework: what it is, how you get assessed against it, and which documentation applies. Written for the person who has just been told 'we need to be compliant with this'.

ISO/IEC 27001:2022

International standard for an information security management system (ISMS). Certifiable by accredited bodies. The 2022 edition restructured Annex A into 93 controls across four themes (organisational, people, physical, technological) and added eleven new controls including threat intelligence, cloud services and data leakage prevention.

How assessment works

Clauses 4–10 define the management system: context, leadership, planning (risk), support, operation, evaluation and improvement. Annex A lists the controls; ISO/IEC 27002 explains them. Certification is a Stage 1 documentation review followed by a Stage 2 implementation audit, then annual surveillance.

What we provide

Policies and standards for all 93 controls, the clause 4–10 templates, a risk methodology and register, a Statement of Applicability, and internal audit and management review templates.


NIST CSF 2.0

Voluntary US framework, widely used internationally as a governance structure. Version 2.0 (February 2024) added the Govern function and extended the audience beyond critical infrastructure. It is an outcomes framework: 106 subcategories describe what good looks like without prescribing how.

How assessment works

Six functions: Govern, Identify, Protect, Detect, Respond, Recover. Organisations build a current profile and a target profile and use tiers (1–4) to describe rigour. There is no certification; it is used for self-assessment and customer assurance.

What we provide

Policies for the six functions, standards at subcategory level so each outcome becomes testable, profile and tier workbooks, and mappings to ISO 27002 and 800-53.


NIST SP 800-53 Rev 5

The US federal control catalogue: about 1,000 controls and enhancements across 20 families, with low, moderate and high baselines. Required for federal systems and FedRAMP; used contractually by many organisations that serve government.

How assessment works

Each family begins with a -1 control requiring documented policy and procedures. Many controls contain organisation-defined parameters (ODPs) that you must set. Assessment follows SP 800-53A.

What we provide

Family-level policies, control-level standards for the moderate baseline, an ODP workbook so parameters are set once, and a POA&M template.


NIST SP 800-171 R3 and CMMC

800-171 protects Controlled Unclassified Information in non-federal systems. Revision 3 (2024) has 97 requirements across 17 families, with organisation-defined parameters. CMMC 2.0 is the US Department of Defense's assessment programme: Level 1 (FAR basic safeguarding), Level 2 (800-171, self or C3PAO assessed), Level 3 (adds 800-172).

How assessment works

Assessors use the assessment objectives in 800-171A, not the requirement text. Every objective needs examine, interview or test evidence. The System Security Plan and POA&M are mandatory artefacts.

What we provide

The full programme: policies, standards and procedures per objective, SSP and POA&M templates, CUI scoping, a supply chain plan and an R2-to-R3 transition worksheet.


SOC 2

An attestation report under the AICPA Trust Services Criteria, produced by a CPA firm. Type I reports on control design at a point in time; Type II reports on operating effectiveness over a period (typically 6–12 months). Security is mandatory; Availability, Confidentiality, Processing Integrity and Privacy are optional.

How assessment works

The auditor tests the controls you describe in your system description. Documentation therefore has to exist before the observation period starts, and the controls have to operate consistently throughout it.

What we provide

Policies and standards for the Common Criteria and the four optional categories, a criteria-to-control matrix, and a system description outline.


PCI DSS v4.0.1

The card brands' standard for any organisation that stores, processes or transmits cardholder data. Twelve requirements. v4 (mandatory since March 2025) added targeted risk analyses, the customised approach, and stricter authentication and e-commerce script controls. v4.0.1 is a clarification release.

How assessment works

Scope is set by your Self-Assessment Questionnaire type (A through D) or by a QSA assessment. Every requirement expects documented policies and procedures, and several expect a documented targeted risk analysis to justify control frequency.

What we provide

Policies and standards for all twelve requirements, an SAQ applicability matrix, scoping and data-flow templates, targeted risk analysis templates and a compliance calendar.


UK GDPR and EU GDPR

Data protection law for personal data of people in the UK and EU respectively, with near-identical text. Applies to controllers and processors regardless of where they are based if they target or monitor those people. Requires demonstrable accountability: records, assessments and policies, not just compliance in practice.

How assessment works

Article 30 records of processing, Article 35 impact assessments, Article 28 processor contracts, Article 33 breach notification within 72 hours, and Articles 12–22 data subject rights are the documentary core.

What we provide

The Data Privacy Programme covers the internal records and the external notices, and connects privacy to the security controls in the ISMS.


NIS2

EU directive on cybersecurity for essential and important entities across 18 sectors, transposed into member-state law from October 2024. Management bodies must approve and oversee risk measures and can be held personally liable. Article 21 lists ten minimum measure areas including supply chain, incident handling and business continuity.

How assessment works

Incident reporting to the national CSIRT: early warning within 24 hours, notification within 72 hours, final report within one month. Supervision and fines vary by member state.

What we provide

The NIS2 and DORA set is organised by article so you can show which document satisfies which obligation.


DORA

EU regulation on digital operational resilience for financial entities and their critical ICT third-party providers, applying from January 2025. Five pillars: ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing. Detailed regulatory technical standards specify the content of the ICT risk framework, incident classification and contract provisions.

How assessment works

Major incident reporting to the competent authority: initial notification within 4 hours of classification (and 24 hours of detection), intermediate within 72 hours, final within one month. A register of information on ICT third parties must be maintained and submitted.

What we provide

The NIS2 and DORA set includes the ICT risk framework, classification and reporting procedure, third-party register and testing programme.


ISO/IEC 42001 and the EU AI Act

ISO/IEC 42001 (2023) is a certifiable management-system standard for AI, structured like ISO 27001 with an Annex A of AI-specific controls. The EU AI Act (in force August 2024, obligations phasing in through 2027) attaches legal duties to providers and deployers of AI systems according to risk tier, with prohibited practices, high-risk requirements and transparency rules.

How assessment works

Both expect an inventory of AI systems, impact assessments, human oversight, data governance and documentation of decisions. The Act's high-risk obligations include technical documentation, logging, and conformity assessment.

What we provide

The AI Governance Programme gives you the management-system structure, inventory, impact assessment and obligations map, reusing your ISMS where possible.


Cyber Essentials

UK government-backed certification of five basic control areas: firewalls, secure configuration, access control, malware protection and patch management. Cyber Essentials is a self-assessment verified by an assessor; Cyber Essentials Plus adds a technical audit. Required for many UK public-sector contracts.

How assessment works

The assessment is questionnaire-based and asks for policy in several areas (for example password and device policies). Patching within 14 days of a critical or high vulnerability is the most-failed requirement.

What we provide

The Core Fundamentals set maps to the five control themes; the Vulnerability and Patch Management Programme documents the patching rule.


Side by side

FrameworkMandatory?Certifiable?StructureBest used as
ISO 27001No (contractual)YesManagement system + 93 controlsThe backbone for most organisations
NIST CSF 2.0NoNo6 functions, 106 outcomesGovernance structure and board language
NIST 800-53Federal systemsVia FedRAMP/ATO20 families, baselinesControl catalogue when depth is required
800-171 / CMMCUS DoD supply chainYes (CMMC)17 families, 97 requirementsNon-negotiable if you hold CUI
SOC 2No (contractual)AttestationTrust Services CriteriaAssurance for US enterprise customers
PCI DSSIf you handle cardsYes (SAQ/ROC)12 requirementsScoped to the card environment
GDPRYes (law)NoPrinciples + obligationsPrivacy layer over any security framework
NIS2Yes (law, in scope)NoArticle 21 measuresUsually satisfied via ISO 27001 + gap set
DORAYes (law, financial)No5 pillars + RTSPrescriptive; document by article
ISO 42001 / AI ActAI Act: yes (law)42001: yesManagement system + AI controlsExtension of the ISMS to AI
Cyber EssentialsUK public contractsYes5 control themesSmall-organisation baseline

The framework guides on this page are general summaries for orientation, current to October 2026. They are not legal advice. Check the primary source for your obligations.