Standards & Frameworks

29 standards.
None of them an upsell.

Every one with mapped controls, guided assessments, AI document generation and its own training course — included in the single platform price.

29
Standards & frameworks
1,109
Mapped controls
1,967
Guided questions
723
Document templates

Four families, one platform

10

ISO Standards

27001 · 42001 · 22301 · 31000 · 37001 · 37301 · 45001 · 27017 · 27018 · 27701

6

Regulatory & Certification

GDPR · SOC 2 · PCI DSS · NIST CSF 2.0 · DORA · HIPAA

6

UK Cyber & Assurance

Cyber Essentials · CE Plus · IASME CA · IASME MSP · DCC Level 1 · NCSC CAF

7

ESG & Sustainability

GRI · CSRD/ESRS · TCFD · CDP · ISSB · SASB · UN SDGs

Shared controls

Do the work once. Satisfy several standards.

Access control appears in ISO 27001, SOC 2, PCI DSS, Cyber Essentials, NIST CSF and DORA. In most tools that means evidencing it six times, on six schedules — and discovering during an audit that three copies have drifted apart.

  • Controls map across frameworks. Evidence attached once satisfies every standard that requires it.
  • Completion state updates everywhere at the same moment.
  • Your second framework costs a fraction of the effort of the first.
  • Every standard ships a training course — 29 courses across 337 modules.
See how controls work

Every standard, and what ships with it

Control counts are the mapped control library. Questions drive the guided assessment. Templates are the AI-generated documents available for that framework.

Standard / frameworkControlsQuestionsTemplates
ISO/IEC 27001 — Information Security11615030
ISO/IEC 42001 — AI Management6516032
ISO 22301 — Business Continuity464740
ISO 31000 — Risk Management394035
ISO 37001 — Anti-Bribery644842
ISO 37301 — Compliance Management624540
ISO 45001 — Occupational H&S4112148
ISO/IEC 27017 — Cloud Security7459
ISO/IEC 27018 — Cloud Privacy53030
ISO/IEC 27701 — Privacy Information Management134736
GDPR6715030
SOC 26120540
PCI DSS v4.0.17517033
NIST Cybersecurity Framework 2.09516234
DORA — Regulation (EU) 2022/2554465618
HIPAA675418
Cyber Essentials v3.3283621
Cyber Essentials Plus v3.1152018
IASME Cyber Assurance v755637
Defence Cyber Certification Level 11482213
NCSC Cyber Assessment Framework v4.0415818
IASME MSP — coming soon1010
GRI Standards 20216326
CSRD / ESRS3314
TCFD Recommendations2510
CDP Questionnaires2712
ISSB — IFRS S1 & S2188
SASB Standards2410
UN Sustainable Development Goals2510

— means no mapped control pack: those frameworks are delivered through guided assessments and document templates rather than a control library. Counts verified against the production platform on 11 August 2026.

Beyond the framework list

Two regimes that do not fit a control library get purpose-built modules instead.

EU AI Act

A guided obligations wizard that takes a system from classification through to the requirements that actually apply, tied into the AI portfolio and model registry.

Explore AI governance

UK Corporate Governance Code — Provision 29

Board-level declaration on material controls: principal risks register, oversight tracking, effectiveness testing and AI annual report generation.

Provision 29 overview

Adding a standard should not mean
adding a line to the invoice.

All 29, from day one, for the same price.