Frameworks & regulations

One application. Six obligations. Mapped, not multiplied.

Each control you implement is mapped across frameworks, so a single policy can satisfy ISO, NIST, GDPR and NIS2 at once. No double work, no contradictory evidence.

NIST SP 800-53

The US federal control catalogue

The US federal control catalogue — now the de facto language for security questionnaires, supply-chain assurance and cyber-insurance underwriting worldwide.

What it demands

  • 20 control families covering access, audit, risk, supply chain and AI
  • Documented controls with assigned owners and tested effectiveness
  • Continuous monitoring and evidence retention

How the app accelerates you

  • Pre-mapped policy set covering the moderate baseline
  • Evidence prompts and review cadences baked into the plan
  • Maturity scoring out of the box, exportable for buyers and insurers
ISO/IEC 27001:2022

ISO 27001 — The global certification standard

ISO 27001 is the certification clients ask for by name. The 2022 update reorganised Annex A into 93 controls — our templates already use the new structure.

What it demands

  • A documented ISMS with scope, leadership and risk treatment
  • Statement of Applicability across all 93 Annex A controls
  • Internal audit, management review and continual improvement

How the app accelerates you

  • Full ISMS pack — policy, scope, SoA, risk register — ready to edit
  • Guided internal audit workflow with evidence capture
  • Annex A coverage visualised so you spot gaps before the auditor does
GDPR

EU & UK data protection

GDPR is the baseline for any firm handling personal data of EU or UK residents. Fines reach 4% of global turnover; reputational damage often costs more.

What it demands

  • Lawful basis, transparency and data-subject rights handling
  • Record of Processing Activities (Art. 30) and DPIAs for high-risk processing (Art. 35)
  • Appropriate technical and organisational measures (Art. 32) and breach notification within 72 hours

How the app accelerates you

  • RoPA and DPIA templates pre-populated for common SME processing
  • Breach response runbook with a 72-hour clock built in
  • Article 32 controls cross-mapped to ISO and NIST, no duplicated work
EU AI Act

The world's first horizontal AI law

If you build, integrate or deploy AI systems serving the EU market, the AI Act applies. High-risk systems carry obligations close to medical-device conformity.

What it demands

  • Classify each AI system as prohibited, high-risk, limited or minimal risk
  • For high-risk: risk management, data governance, technical documentation, logging, human oversight and post-market monitoring
  • Conformity assessment and EU Database registration before deployment

How the app accelerates you

  • AI inventory and risk-classification questionnaire
  • Annex IV technical documentation template, ready to complete
  • Post-market monitoring plan and incident reporting workflow
NIS2 Directive

Cybersecurity for essential & important entities

NIS2 captures medium-sized firms across 18 sectors — including digital providers, manufacturing, food, waste and managed services. Management is personally accountable.

What it demands

  • Risk-management measures across 10 minimum areas (Art. 21)
  • Incident reporting in 24h / 72h / one-month tiers
  • Management body training and accountability for cyber governance

How the app accelerates you

  • NIS2 Art. 21 control set mapped to your existing ISO/NIST work
  • Incident timer and notification templates aligned to national CSIRTs
  • Board-ready governance pack so directors can sign with confidence
WCAG 2.2 AA · EN 301 549

Digital accessibility

The European Accessibility Act made WCAG 2.2 AA effectively mandatory for digital products serving EU consumers from June 2025. Public-sector contracts already require it.

What it demands

  • Perceivable, operable, understandable and robust digital interfaces
  • Documented accessibility conformance report (ACR / VPAT)
  • Remediation roadmap for known issues

How the app accelerates you

  • Accessibility audit checklist mapped to WCAG 2.2 success criteria
  • ACR / EN 301 549 conformance template ready to publish
  • Remediation tracker integrated with the main project plan

Every framework, one control catalogue.

Buy a template, or the complete bundle, get app access and start closing gaps from day one.