Skip to main content

Knowledge centre

Standards and framework document library.

Every standard our assessors work against, 122 of them, each with the practitioner view rather than a restatement of the text. What it is, who it binds, what an assessor actually looks for, and how to get ready.

122 of 122

Security frameworks33

The control catalogues and models an assessment is run against. Pick the one your customers or your regulator names, not the one with the most controls.

Certifications and attestations24

Standards you can be certified or attested against, where the deliverable is a certificate or a report somebody else will read.

Data privacy laws10

Statutory obligations that attach to personal data. These bind you whether or not anyone asks for a certificate.

India regulatory33

Directions and frameworks issued by Indian regulators. Most organisations we assess are inside more than one of these at once.

Regional and national frameworks22

Country and region specific requirements, relevant where you operate, hold data or serve customers there.

Not sure which one applies?

Most organisations are inside more than one of these at once, and the overlap is larger than it looks: the same access review, the same log retention and the same incident record can satisfy three frameworks if you build the control once. A thirty minute call with an assessor will usually shorten your list rather than lengthen it.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.