Resources
Frameworks and regulations — all 31, at a glance
ISO 27001 and UK / EU GDPR essentials are in the core at every tier. The other 29 are optional modules that reuse the controls and evidence you already hold. Seven have full plain-English guides you can read online — use your browser's Print → Save as PDF to keep a copy. The rest are described in one line here and in more detail on the modules page.
Module list and what each gives youPricingFree ISO 27001 starter checklist
Information security and cyber
The ISMS itself and the security schemes buyers and government frameworks ask for.
ISO 27001 management system
In the coreClauses 4–10 with editable narratives and approval history. Statement of Applicability across all 93 Annex A controls with owners and justification.
Read the full guide →SOC 2 (Type I & II)
ModuleTrust Services Criteria, system description, audit periods and guest auditor access for US enterprise deals.
~65% inherited from ISO 27001
Cyber Essentials
ModuleThe five technical control areas with a self-assessment scaffold and evidence pack.
~60% inherited
Cyber Essentials Plus
ModuleAssessor verification records, sampling and certificate register on top of Cyber Essentials.
NCSC CAF v3.2
ModuleObjectives A–D, 39 contributing outcomes and profile-based scoring for UK OES and GovAssure.
~65% inherited
NIST CSF 2.0 / 800-53
ModuleCSF functions with an 800-53 Rev 5 crosswalk and evidence reuse.
~75% inherited
NIST 800-171 / CMMC 2.0
ModuleRequirement families and CMMC level guidance for US defence supply chains.
~70% inherited
Defence Cyber Certification
ModuleDef Stan 05-138 Issue 4 controls across Levels 0–3 for MOD suppliers, mapped to your Annex A controls.
ISO 27017 / 27018 (cloud)
ModuleCloud security and cloud PII extensions with shared-responsibility guidance.
CSA STAR (CCM v4 / CAIQ)
ModuleCloud Controls Matrix domains, STAR level guidance and a CAIQ-style coverage export.
EU Cyber Resilience Act
ModuleEssential product requirements, vulnerability handling duties and reporting deadlines.
UK Cyber Security and Resilience Bill
ModuleDuties tracked against your existing controls so you are ready before it commences.
Privacy and data protection
Personal data duties, from the GDPR core out to health data and cookies.
UK / EU GDPR essentials
In the coreRecords of processing (ROPA) with lawful basis, retention and transfers. Data subject requests with statutory clocks and evidence.
Read the full guide →ISO 27701 (privacy)
ModulePrivacy information management as an extension of your ISMS, with controller and processor split.
~85% inherited
PECR & cookie consent records
ModuleCookie and tracker inventory, consent before non-essential cookies, marketing rules and demonstrable consent records.
~70% inherited
HIPAA
ModuleSecurity, Privacy and Breach Notification rules with BAA tracking for health data.
AI, quality and service management
Management systems that sit alongside the ISMS and share its evidence.
ISO 42001 (AI management)
ModuleAI management system: clauses, Annex A AI controls, AI system register and impact assessments.
~45% inherited
Read the full guide →EU AI Act
ModuleRisk classification, Article 9–15 obligations and conformity evidence for AI providers and deployers.
~50% inherited
Read the full guide →ISO 9001 (quality)
ModuleQuality management system with shared management review and quality records.
~80% inherited
Read the full guide →ISO 20000-1 (service management)
ModuleService catalogue, service levels, capacity, availability, change, incident, problem and release management.
~60% inherited
Resilience and financial regulation
Operational resilience, continuity and the EU regimes with reporting clocks.
DORA
ModuleFive pillars, register of information and 24h / 72h / 1 month reporting clocks for EU financial entities.
~70% inherited
Read the full guide →NIS2
ModuleArticle 21 measures, management accountability records and incident reporting timers.
~70% inherited
Read the full guide →ISO 22301 (continuity)
ModuleBusiness continuity management using your BIA, continuity plans and restore tests.
FCA / PRA operational resilience
ModuleImportant business services, impact tolerances, scenario testing and SS2/21 outsourcing duties.
Sector, supply chain and governance
Scheme-specific and supply chain obligations that come up in tenders.
PCI DSS v4.0.1
ModuleRequirements, SAQ guidance and readiness summaries for card data environments.
TISAX / VDA ISA 6
ModuleInformation security, prototype protection and data protection assessment groups for automotive.
NHS DSPT
ModuleStandards, assertions and a submission-ready export for NHS providers and their sub-processors.
~70% inherited
ISO 27036 (supplier security)
ModuleSupplier security across plan, agree, operate and exit, driven by your supplier register.
ISO 37002 (whistleblowing)
ModuleConfidential reporting channels, impartial investigation, protection from retaliation and trend reporting to the board.
Modern Slavery & ESG
ModuleSection 54 transparency statement, supply chain due diligence beyond tier one, labour standards and ESG governance.
Every module inherits the controls, evidence and registers already in your ISO 27001 core, so a second or third framework is a fraction of the work of the first. See the full module list or what the platform does.