Skip to main content
20% off — first 20 customers. See the offer →

Resources

Frameworks and regulations — all 31, at a glance

ISO 27001 and UK / EU GDPR essentials are in the core at every tier. The other 29 are optional modules that reuse the controls and evidence you already hold. Seven have full plain-English guides you can read online — use your browser's Print → Save as PDF to keep a copy. The rest are described in one line here and in more detail on the modules page.

Module list and what each gives youPricingFree ISO 27001 starter checklist

Information security and cyber

The ISMS itself and the security schemes buyers and government frameworks ask for.

ISO 27001 management system

In the core

Clauses 4–10 with editable narratives and approval history. Statement of Applicability across all 93 Annex A controls with owners and justification.

Read the full guide →

SOC 2 (Type I & II)

Module

Trust Services Criteria, system description, audit periods and guest auditor access for US enterprise deals.

~65% inherited from ISO 27001

Cyber Essentials

Module

The five technical control areas with a self-assessment scaffold and evidence pack.

~60% inherited

Cyber Essentials Plus

Module

Assessor verification records, sampling and certificate register on top of Cyber Essentials.

NCSC CAF v3.2

Module

Objectives A–D, 39 contributing outcomes and profile-based scoring for UK OES and GovAssure.

~65% inherited

NIST CSF 2.0 / 800-53

Module

CSF functions with an 800-53 Rev 5 crosswalk and evidence reuse.

~75% inherited

NIST 800-171 / CMMC 2.0

Module

Requirement families and CMMC level guidance for US defence supply chains.

~70% inherited

Defence Cyber Certification

Module

Def Stan 05-138 Issue 4 controls across Levels 0–3 for MOD suppliers, mapped to your Annex A controls.

ISO 27017 / 27018 (cloud)

Module

Cloud security and cloud PII extensions with shared-responsibility guidance.

CSA STAR (CCM v4 / CAIQ)

Module

Cloud Controls Matrix domains, STAR level guidance and a CAIQ-style coverage export.

EU Cyber Resilience Act

Module

Essential product requirements, vulnerability handling duties and reporting deadlines.

UK Cyber Security and Resilience Bill

Module

Duties tracked against your existing controls so you are ready before it commences.

Privacy and data protection

Personal data duties, from the GDPR core out to health data and cookies.

UK / EU GDPR essentials

In the core

Records of processing (ROPA) with lawful basis, retention and transfers. Data subject requests with statutory clocks and evidence.

Read the full guide →

ISO 27701 (privacy)

Module

Privacy information management as an extension of your ISMS, with controller and processor split.

~85% inherited

PECR & cookie consent records

Module

Cookie and tracker inventory, consent before non-essential cookies, marketing rules and demonstrable consent records.

~70% inherited

HIPAA

Module

Security, Privacy and Breach Notification rules with BAA tracking for health data.

Resilience and financial regulation

Operational resilience, continuity and the EU regimes with reporting clocks.

DORA

Module

Five pillars, register of information and 24h / 72h / 1 month reporting clocks for EU financial entities.

~70% inherited

Read the full guide →

NIS2

Module

Article 21 measures, management accountability records and incident reporting timers.

~70% inherited

Read the full guide →

ISO 22301 (continuity)

Module

Business continuity management using your BIA, continuity plans and restore tests.

FCA / PRA operational resilience

Module

Important business services, impact tolerances, scenario testing and SS2/21 outsourcing duties.

Sector, supply chain and governance

Scheme-specific and supply chain obligations that come up in tenders.

PCI DSS v4.0.1

Module

Requirements, SAQ guidance and readiness summaries for card data environments.

TISAX / VDA ISA 6

Module

Information security, prototype protection and data protection assessment groups for automotive.

NHS DSPT

Module

Standards, assertions and a submission-ready export for NHS providers and their sub-processors.

~70% inherited

ISO 27036 (supplier security)

Module

Supplier security across plan, agree, operate and exit, driven by your supplier register.

ISO 37002 (whistleblowing)

Module

Confidential reporting channels, impartial investigation, protection from retaliation and trend reporting to the board.

Modern Slavery & ESG

Module

Section 54 transparency statement, supply chain due diligence beyond tier one, labour standards and ESG governance.

Every module inherits the controls, evidence and registers already in your ISO 27001 core, so a second or third framework is a fraction of the work of the first. See the full module list or what the platform does.