Standards & frameworks

Assessed against thestandards that matter

We don't invent our own yardstick. Every assessment is anchored to internationally recognised frameworks, so your results are credible to auditors, regulators, insurers and your own board.

Framework families

Coverage across governance, security & resilience

Information security

Management systems and control catalogues for enterprise security.

ISO/IEC 27001 NIST CSF 2.0 NIST SP 800-53 CIS Controls

Governance & IT service

Technology governance, value delivery and service management maturity.

COBIT 2019 ITIL 4 ISO/IEC 20000

Cyber resilience

Continuity, disaster recovery and the ability to withstand disruption.

ISO 22301 NIST SP 800-34 ISO/IEC 27031

OT & industrial

Security for control systems, IT/OT boundaries and critical infrastructure.

ISA/IEC 62443 NIST SP 800-82

Application & technical

Secure development, testing and adversary-informed technical assurance.

OWASP ASVS OWASP Top 10 MITRE ATT&CK

Regulatory & privacy

EU regulatory obligations for data protection, security and operational resilience.

GDPR NIS2 DORA
How we use them

Standards as a shared language, not a checkbox

We map each control we assess to one or more recognised frameworks. That means your scores are comparable over time, defensible in an audit, and portable across the tools and teams you already use.

Where several frameworks overlap, we assess once and report against each — so a single engagement can support ISO certification readiness, NIS2 alignment and board risk reporting at the same time.

Standards referenced across our catalogue
ISO/IEC 27001 ISO/IEC 27002 ISO/IEC 27005 ISO/IEC 27031 ISO/IEC 27017 ISO/IEC 27018 ISO 22301 ISO/IEC 20000 ISO/IEC 42001 NIST CSF 2.0 NIST SP 800-53 NIST SP 800-82 NIST SP 800-34 NIST SP 800-171 COBIT 2019 ITIL 4 CIS Controls v8 ISA/IEC 62443 OWASP ASVS OWASP Top 10 MITRE ATT&CK GDPR NIS2 DORA PCI DSS SOC 2

…and the specific control clauses within each, mapped assessment by assessment.