Frameworks
Plain-English guides to the five frameworks the assessment covers: what each one asks for, who asks for it, and where they overlap.
Certifiable standard
ISO 27001
The international standard for an information security management system, or ISMS: how you run security, not just which tools you use.
Updated 1st October 2026
Certifiable standard
ISO 42001
The international standard for an AI management system: how you govern the AI you build or use, from risk to human oversight.
Updated 1st October 2026
Attestation report
SOC 2
An independent auditor’s report on how your security controls are designed and how they actually work over time.
Updated 1st October 2026
EU regulation
GDPR
EU law on how you collect, use and protect personal data, with fines of up to 4% of global annual turnover.
Updated 1st October 2026
EU regulation
EU AI Act
EU law on AI systems, sorted by risk: some uses are banned, high-risk ones carry strict duties, and chatbots must say they are AI.
Updated 1st October 2026