Start a free trial
Menu

Standards · Cybersecurity

Which security standards and laws apply to you?

ISO/IEC 27001 and its family, the NIST and CIS frameworks, IEC 62443, SOC 2 and TISAX, and the EU laws that bind you directly: NIS2, DORA, the Cyber Resilience Act and GDPR. Explained in plain words, in one catalogue, with every entry linked to its source.

Overview

Three shapes of security requirement

A security requirement arrives as a standard, a framework or a law. Knowing which one you are looking at tells you who checks it and what evidence they want.

  1. A standard you certify against

    ISO/IEC 27001 is the management system a customer asks for. An accredited body audits it and issues the certificate; 27002, 27005, 27017, 27018 and 27701 are read on top of it.

  2. A framework you are assessed against

    NIST CSF 2.0 and SP 800-53, SP 800-171 for the US defence supply chain, the CIS Controls, IEC 62443 for industrial systems. SOC 2 and TISAX are the reports and labels built on the same idea.

  3. A law that binds you directly

    NIS2 and CER by sector, DORA for finance, the Cyber Resilience Act for products, GDPR for personal data. A supervisor enforces them whether or not a contract mentions them.

  4. One set of controls serves all three

    The measures the laws list are the controls a 27001 system runs. Build the system once, keep its evidence, and answer the auditor, the customer and the regulator from the same records.

  5. Find yours below

    Search the catalogue by name, browse it by family, or answer five questions about your situation. Each entry links to its source and can be requested in ComplyTrain.

Your customer's questionnaire, your regulator or the law itself names what you must show. A law binds you by who you are; a standard by what a contract says. MANAGEMENT SYSTEM (ISO/IEC) ISO/IEC 27001 the certifiable base for information security ISO/IEC 27002 · 27005 the controls · the risk method + 27017 cloud · 27018 · 27701 privacy Certifiable. A certification body audits you. FRAMEWORKS AND CONTROLS NIST CSF 2.0 six functions, Govern to Recover SP 800-53 · 800-171 the control catalogues underneath + CIS Controls · IEC 62443 (OT) · SOC 2 · TISAX Attested or assessed, not certified. EU LAW NIS2 · DORA resilience duties by sector and by entity CRA · GDPR products with digital elements · personal data + CER · eIDAS 2 · AI Act · Cybersecurity Act Binding. A supervisory authority enforces. maps to evidence for A 27001 certificate is the usual way to show a customer, and increasingly a regulator, that the controls the law asks for exist and are run. NIS2 and CER reach you through national law; DORA, the CRA and GDPR apply directly. Which ones is a question of sector, size and what you sell. HOW A SECURITY REQUIREMENT REACHES A COMPANY · COMPLYTRAIN BY SKYLEN
How a security requirement reaches a company: a customer's questionnaire, a regulator or the law names it; ISO/IEC 27001 is the certifiable management system; NIST, CIS, IEC 62443, SOC 2 and TISAX are the frameworks and controls; NIS2, DORA, the CRA and GDPR bind directly.

The standards, frameworks and laws behind a security requirement

A security requirement reaches a company in three shapes. A customer's questionnaire or contract asks for a standard, usually ISO/IEC 27001. A framework such as NIST's gives a programme its structure and a control catalogue to assess against. And a law binds you not because a contract says so but because of what you are and what you sell: NIS2, DORA, the Cyber Resilience Act, GDPR. This page explains the three, how they fit, and where the documents come from. The explorer below then finds the ones that match your situation.

Start with ISO/IEC 27001

ISO/IEC 27001 is the international standard for an information security management system, and the one a customer asks about first. It is certifiable, it is the same in every industry, and its main text lists no technical measures: it asks you to run a management system that knows what information you hold, assesses the risks to it, chooses controls and keeps evidence that they work. The 2022 edition's Annex A holds 93 controls in four themes, organisational, people, physical and technological. ISO/IEC 27002 explains each control and how to implement it, and ISO/IEC 27005 describes the risk assessment the standard requires but does not spell out. See ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27005.

Around that core sit the extensions a particular customer asks for. ISO/IEC 27017 adds controls for cloud services and ISO/IEC 27018 protects personal data in a public cloud; both are what a cloud provider is asked to show. ISO/IEC 27701 extends the management system to privacy, the shape a GDPR programme can be run in. ISO/IEC 27035 covers incident management, and ISO 22301 business continuity. None of them stands alone: each is read on top of a 27001 system. See ISO/IEC 27017 and ISO/IEC 27018.

Frameworks and control catalogues

A framework is not a certificate. It is a structure to organise a programme and a catalogue to assess it against, and it is what an auditor, an insurer or a US customer measures you with. The NIST Cybersecurity Framework 2.0, from 2024, has six functions, Govern, Identify, Protect, Detect, Respond and Recover, and maps to the catalogues underneath it. NIST SP 800-53 is the control catalogue US federal systems are assessed against and the one most other catalogues cross-reference. NIST SP 800-171 is the subset a supplier to the US Department of Defense meets to handle controlled unclassified information, and the basis of the CMMC certification programme. The CIS Controls are eighteen prioritised safeguard groups in three implementation groups by organisation size, and the usual first step when nothing formal exists yet.

Two frameworks are sector-specific. IEC 62443 is the security series for industrial automation and control systems: zones and conduits for the plant, a secure development life cycle for the product (part 4-1) and technical requirements for components (part 4-2). TISAX is the automotive industry's exchange of information security assessments against the VDA ISA catalogue, and what a supplier to a German car maker is asked for. And two are attestations rather than standards: a SOC 2 report is an auditor's opinion on a service organisation's controls against the AICPA Trust Services Criteria, the document a US customer asks a SaaS provider for; the EU Cybersecurity Act's certification schemes are the European counterpart, still being rolled out.

The EU laws

A standard binds you because a contract says so. A law binds you because of what you are. Five EU acts now carry security obligations directly, and each has its own scope.

NIS2, Directive (EU) 2022/2555, applies to essential and important entities in eighteen sectors, from energy and transport to digital infrastructure, manufacturing of critical products and public administration. It is transposed into national law, so the exact duties come from your own country's act, but the shape is the same everywhere: management accountability, risk-management measures on a fixed list, supply-chain security, and early warning of a significant incident within 24 hours. The CER Directive, 2022/2557, is its physical-resilience counterpart for critical entities.

DORA, Regulation (EU) 2022/2554, applies since January 2025 to financial entities and to their critical ICT third-party providers. It asks for ICT risk management, incident reporting, resilience testing including threat-led penetration testing for the largest, and a register of every ICT contract. It applies directly, with no national transposition.

The Cyber Resilience Act, Regulation (EU) 2024/2847, reaches products rather than organisations: hardware and software with digital elements placed on the EU market must be secure by design, handle vulnerabilities for their support period and carry the CE mark for it. Reporting of actively exploited vulnerabilities starts in September 2026 and the full obligations apply from December 2027. ETSI EN 303 645 is the baseline the consumer-IoT part of it draws on.

GDPR, Regulation (EU) 2016/679, is the oldest of the five and the one everybody already meets: security of processing appropriate to the risk, and breach notification to the supervisory authority within 72 hours. Two newer acts touch the edges: eIDAS 2, Regulation (EU) 2024/1183, for trust services and the European Digital Identity Wallet, and the AI Act, Regulation (EU) 2024/1689, whose high-risk systems need a risk management system and a quality management system of their own.

How a certificate and a law fit together

An ISO/IEC 27001 certificate does not by itself satisfy NIS2 or DORA; the laws have their own scope, their own reporting clocks and their own supervisors. But the measures they list, risk analysis, incident handling, business continuity, supply-chain security, access control, encryption, are the measures a 27001 system runs, and the national authorities and ENISA reference ISO/IEC 27001 and the NIST framework in their guidance. A certified management system is the usual way to show a supervisor that the measures exist and are run, and a risk register and an incident log are the evidence both a certification auditor and a regulator read.

Where the documents come from

ISO/IEC standards are bought from ISO, from IEC or from your national standards body. Every NIST publication is free from NIST's Computer Security Resource Center, and the CIS Controls are free with registration. The EU acts are free on EUR-Lex, and every regulation entry in the explorer links to the consolidated text there; the national transpositions of NIS2 and CER come from your own legislature. IEC 62443 is bought from IEC or ISA, SOC 2's criteria come from the AICPA, and TISAX from the ENX Association.

Who decides what applies to you

Not this page, and not us. A contract or a questionnaire names the standard; a law names its own scope, and whether you fall inside it is a question about your sector, your size and what you sell that your counsel answers. What the explorer can do is show you the whole map: search it by number or name, browse it by family, or answer five questions about your situation and see which areas companies like you are commonly asked about. Each entry links to its source, to its ComplyTrain page where one exists, and otherwise to a request. ComplyTrain holds a standard as a requirement tree with the evidence against each requirement. The certificate stays yours to earn.

Standards explorer

Find your security standards and laws

Search the ISO/IEC 27000 family, the NIST and CIS frameworks, IEC 62443, SOC 2 and TISAX, and the EU acts together, browse them by family, or answer five questions about your situation.

50 standards in the catalogue

Not sure where to start?

Five questions, pick everything that applies. Nothing is stored.

Question 1 of 5What do you run or sell?
Question 2 of 5Who is asking?
Question 3 of 5Which of these describe you?
Question 4 of 5What do you have today?
Question 5 of 5What are you asked to show?
ISO management systems14 standards
  1. EN 9100Quality Management Systems - Requirements for Aviation, Space and Defence OrganizationsEd. 2018How ComplyTrain supports itISO 9001 plus the aerospace and defence supply chain's additional requirements (AS9100 in the Americas).
  2. ISO 10007Quality management - Guidelines for configuration managementEd. 2017Configuration management guidance, the civil counterpart to ACMP-2000 series.
  3. ISO 14001Environmental management systems - Requirements with guidance for useEd. 2015Environmental management: how an organisation controls its environmental impact and obligations.
  4. ISO 19443Quality management systems - Specific requirements for the application of ISO 9001:2015 by organizations in the supply chain of the nuclear energy sector supplying products and services important to nuclear safety (ITNS)Ed. 2018ISO 9001 with the additional requirements of the nuclear supply chain.
  5. ISO 28000Security and resilience - Security management systems - RequirementsEd. 2022Security management across the supply chain.
  6. ISO 37001Anti-bribery management systems - Requirements with guidance for useEd. 2016Anti-bribery controls, often asked for in public procurement and export markets.
  7. ISO 37301Compliance management systems - Requirements with guidance for useEd. 2021A management system for meeting legal and contractual compliance obligations.
  8. ISO 45001Occupational health and safety management systems - Requirements with guidance for useEd. 2018Occupational health and safety management, the successor to OHSAS 18001.
  9. ISO 50001Energy management systems - Requirements with guidance for useEd. 2018Energy management: measuring and improving energy performance.
  10. ISO 55001Asset management - Management systems - RequirementsEd. 2014Managing physical assets over their life cycle.
  11. ISO 9001Quality management systems - RequirementsEd. 2015How ComplyTrain supports itThe general-purpose quality management system standard most defence and industrial contracts start from.
  12. ISO/IEC 17025General requirements for the competence of testing and calibration laboratoriesEd. 2017Competence requirements for test and calibration laboratories.
  13. ISO/IEC 20000-1Information technology - Service management - Part 1: Service management system requirementsEd. 2018IT service management, the certifiable counterpart to ITIL.
  14. ISO/IEC 42001Information technology - Artificial intelligence - Management systemEd. 2023The first management system standard for organisations that build or use AI.
Information security management (ISO/IEC 27000 family)7 standards
  1. ISO/IEC 27001Information security, cybersecurity and privacy protection - Information security management systems - RequirementsEd. 2022How ComplyTrain supports itThe information security management system standard behind most security questionnaires and tenders.
  2. ISO/IEC 27002Information security, cybersecurity and privacy protection - Information security controlsEd. 2022How ComplyTrain supports itThe catalogue of information security controls ISO/IEC 27001 refers to.
  3. ISO/IEC 27005Information security, cybersecurity and privacy protection - Guidance on managing information security risksEd. 2022How ComplyTrain supports itThe risk assessment and treatment that ISO/IEC 27001 requires but does not describe.
  4. ISO/IEC 27017Information technology - Security techniques - Code of practice for information security controls based on ISO/IEC 27002 for cloud servicesEd. 2015How ComplyTrain supports itInformation security controls for cloud service providers and their customers.
  5. ISO/IEC 27018Information technology - Security techniques - Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processorsEd. 2019How ComplyTrain supports itProtecting personal data in public clouds, for providers acting as processors.
  6. ISO/IEC 27035-1Information technology - Information security incident management - Part 1: Principles and processEd. 2023How to plan, detect, report and learn from information security incidents.
  7. ISO/IEC 27701Security techniques - Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management - Requirements and guidelinesEd. 2019A privacy information management system layered on ISO/IEC 27001.
Cybersecurity frameworks and controls9 standards
  1. CIS Controls v8CIS Critical Security Controls, version 8.1Ed. 2024Eighteen prioritised safeguards, grouped in three implementation groups by organisation size.
  2. ETSI EN 303 645Cyber Security for Consumer Internet of Things: Baseline RequirementsEd. 2024The baseline security requirements for consumer connected products, referenced by the Cyber Resilience Act.
  3. IEC 62443Security for industrial automation and control systems (IEC 62443 series)Ed. 2024The security series for operational technology: zones and conduits, product development life cycle (62443-4-1) and component requirements (62443-4-2).
  4. NIST CSF 2.0The NIST Cybersecurity Framework 2.0Ed. 2024Six functions, Govern to Recover, that organise a security programme and map to the control catalogues underneath.
  5. NIST SP 800-171Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (Rev. 3)Ed. 2024The requirements a supplier to the US Department of Defense meets to handle controlled unclassified information; the basis of CMMC.
  6. NIST SP 800-53Security and Privacy Controls for Information Systems and Organizations (Rev. 5)Ed. 2020The control catalogue US federal systems are assessed against, and the reference many other frameworks map to.
  7. NIST SP 800-61Incident Response Recommendations and Considerations for Cybersecurity Risk Management (Rev. 3)Ed. 2025How to run incident response as part of a risk programme, aligned with CSF 2.0.
  8. SOC 2SOC 2: Trust Services Criteria for security, availability, processing integrity, confidentiality and privacyEd. 2017An attestation report on a service organisation's controls, the one US customers ask a SaaS provider for.
  9. TISAXTISAX: Trusted Information Security Assessment Exchange (VDA ISA)Ed. 2024The automotive industry's shared information security assessment, based on the VDA ISA catalogue.
EU cybersecurity and data law8 standards
  1. CERDirective (EU) 2022/2557 on the resilience of critical entitiesEd. 2022The physical and organisational resilience counterpart to NIS2 for critical entities in eleven sectors, transposed into national law.
  2. CRARegulation (EU) 2024/2847, the Cyber Resilience ActEd. 2024Cybersecurity requirements for products with digital elements placed on the EU market: secure by design, vulnerability handling and reporting, CE marking.
  3. DORARegulation (EU) 2022/2554 on digital operational resilience for the financial sectorEd. 2022Applies from January 2025 to financial entities and their critical ICT providers: ICT risk management, incident reporting, resilience testing and third-party risk.
  4. eIDAS 2Regulation (EU) 2024/1183 amending the framework for a European Digital IdentityEd. 2024Electronic identification, trust services and the European Digital Identity Wallet.
  5. EU AI ActRegulation (EU) 2024/1689 laying down harmonised rules on artificial intelligenceEd. 2024Risk-based obligations for providers and deployers of AI systems, with high-risk systems needing a quality and risk management system.
  6. EU Cybersecurity ActRegulation (EU) 2019/881 on ENISA and on cybersecurity certificationEd. 2019Establishes the EU cybersecurity certification framework for products, services and processes.
  7. GDPRRegulation (EU) 2016/679, the General Data Protection RegulationEd. 2016The rules for processing personal data in the EU, including the security of processing and breach notification.
  8. NIS2Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the UnionEd. 2022The security and incident-reporting obligations for essential and important entities in eighteen sectors, transposed into national law.
Risk management standards and methods12 standards
  1. ISO 22301Security and resilience - Business continuity management systems - RequirementsEd. 2019Business continuity management: keeping the organisation running through disruption.
  2. ISO 31000Risk management - GuidelinesEd. 2018How ComplyTrain supports itPrinciples and a framework for managing risk. Guidance, not a certifiable requirement set.
  3. ISO/IEC 23894Information technology - Artificial intelligence - Guidance on risk managementEd. 2023ISO 31000 applied to AI systems: the sources of risk particular to them and how to manage them across the life cycle.
  4. FAIROpen FAIR Risk Analysis Standard (O-RA)Ed. 2021Factor Analysis of Information Risk: quantifying cyber risk in loss event frequency and magnitude rather than colours.
  5. IEC 31010Risk management - Risk assessment techniquesEd. 2019The catalogue of risk assessment techniques, from brainstorming and checklists to FMEA, HAZOP, bow-tie and Monte Carlo, and when each fits.
  6. IEC 60812Failure modes and effects analysis (FMEA and FMECA)Ed. 2018The method standard for FMEA and FMECA, used in reliability, safety and process risk work.
  7. IEC 61508Functional safety of electrical/electronic/programmable electronic safety-related systemsEd. 2010The umbrella functional safety standard: safety integrity levels and the safety life cycle that sector standards derive from.
  8. IEC 61882Hazard and operability studies (HAZOP studies) - Application guideEd. 2016The structured team study that finds deviations in a process design and their consequences.
  9. NIST AI RMFArtificial Intelligence Risk Management Framework (AI RMF 1.0)Ed. 2023Four functions, Govern, Map, Measure and Manage, for the risks of AI systems, voluntary and sector-neutral.
  10. NIST SP 800-30Guide for Conducting Risk Assessments (Rev. 1)Ed. 2012How to run an information security risk assessment: threat sources, events, vulnerabilities, likelihood and impact.
  11. NIST SP 800-37Risk Management Framework for Information Systems and Organizations (Rev. 2)Ed. 2018The seven-step framework, Prepare to Monitor, that ties categorisation, control selection, assessment and authorisation together.
  12. COSO ERMEnterprise Risk Management - Integrating with Strategy and PerformanceEd. 2017The enterprise risk management framework used in corporate governance and financial reporting.

Titles belong to their publishers. The one-line summaries are ours.

Request access to work with this standard in ComplyTrain

Shortlist

Security standards with their own page

Each page sets out what the standard asks of you and how a ComplyTrain workspace is organised around it. The catalogue above holds far more than these, and any entry in it can be requested. Adding a standard to a workspace is usually a matter of days, not a project.

  • ISO 27001

    ISO 27001 information security management

    ISO 27001 is the standard for an information security management system (ISMS). ComplyTrain gives you the framework to build, run and evidence your ISMS - the certificate stays yours to earn.

  • ISO 27002

    ISO 27002 information security controls

    ISO 27002 is the implementation guidance for the information-security controls listed in ISO 27001 Annex A. ComplyTrain holds each control as a requirement with the evidence that shows it is operating - which is what an auditor samples.

  • ISO 27005

    ISO 27005 information security risk management

    ISO 27005 is the guidance for managing information security risk - the assessment and treatment that ISO 27001 requires but does not describe. ComplyTrain runs it as a living register, not an annual document.

  • ISO 27017

    ISO 27017 cloud security controls

    ISO 27017 extends the ISO 27002 controls to cloud services and adds controls specific to them. ComplyTrain holds each one as a requirement, including the ones that belong to your provider rather than to you.

  • ISO 27018

    ISO 27018 personal data in the cloud

    ISO 27018 extends ISO 27001 to the protection of personal data in public clouds. ComplyTrain gives you the framework to manage and evidence those controls.

If you need to get there and have no quality function

A standard usually arrives as a contract condition or a regulator's letter rather than a project anyone planned for, and often at a company with no quality manager. Software is half the answer. Skylen's consultants are the other half, and because they build on ComplyTrain from day one you keep a live system your team owns rather than a binder and a departed consultant.

  • Gap assessment

    A clause-by-clause read of where you stand against the standard your contract or your regulator cites, turned into a prioritised plan you could act on with us or alone.

    What an assessment covers
  • Guided implementation

    Our consultants build the system with your team - procedures, document control, the records you need to keep and the review cadence - and prepare you for the audit or the inspection.

    How an engagement works
  • Full-service quality function

    We run and maintain the system for you, so a small team can reach and hold a standard without hiring a quality manager.

    What full-service means

Questions people ask about security standards and laws

Does an ISO/IEC 27001 certificate make us NIS2 compliant?

No, and nothing does on its own. NIS2 is transposed into national law with its own scope, its own list of measures and its own reporting deadlines, and a supervisor checks you against that act, not against a certificate. A 27001 system does run the measures the law lists, so the certificate and the system's records are the usual way to show a supervisor that they exist. Read your national act for the duties and the deadlines.

Which of these are certifications, and which are not?

ISO/IEC 27001 is a certification: an accredited body audits you and issues a certificate. ISO/IEC 27017, 27018 and 27701 are audited as extensions of it. SOC 2 is an attestation report, an opinion an auditor writes, not a certificate. TISAX is an assessment with a label shared through the ENX platform. The NIST framework, SP 800-53 and the CIS Controls are frameworks you assess against, with CMMC as the certification programme built on SP 800-171. IEC 62443 has product and process certification schemes run by third parties. A law is none of these: you comply with it, and a supervisor enforces it.

What is the difference between ISO/IEC 27001 and 27002?

ISO/IEC 27001 is the requirements standard, the one you are certified against: it says what a management system must do and lists the controls in Annex A. ISO/IEC 27002 is the guidance: it takes each of those controls and explains what it means and how to implement it. You cannot be certified against 27002. See ISO/IEC 27001 and ISO/IEC 27002.

We sell to a US customer. Do we need SOC 2 or ISO/IEC 27001?

Ask the customer, because it is their procurement that decides. A US enterprise buyer usually asks a SaaS provider for a SOC 2 Type II report; a European or a public-sector buyer usually asks for ISO/IEC 27001. The two overlap heavily and many companies hold both, running one set of controls and having it audited twice. A supplier to the US Department of Defense is asked for NIST SP 800-171 and, increasingly, CMMC.

Does the Cyber Resilience Act apply to our software?

If you place a product with digital elements on the EU market, hardware or software, it applies unless the product is covered by a sector act that already regulates its security, such as medical devices or vehicles. Open-source software offered outside a commercial activity is outside it. What the act asks depends on the product class; the reporting duties start in September 2026 and the rest in December 2027. Whether your product is in scope is a legal question for your counsel.

Does ComplyTrain certify us against a standard?

No. Certification is issued by an accredited certification body, a licence by your authority, and government quality assurance is exercised by the acquisition authority. ComplyTrain is the system you build, run and evidence your compliance in, and Skylen's consultants can take you through the work. The certificate stays yours to earn.

Can I get a standard added to ComplyTrain?

Yes, and that is what the Request access button on every entry is for. Tell us which standard and where the requirement comes from, and we come back to you on what holding it in your workspace involves, usually within one business day. Adding a standard to a workspace is usually a matter of days, not a project. ComplyTrain holds a standard as a requirement tree with your evidence against each requirement, and the tree is what we build.

Request access to work with a standard or a regulation

Name the standard, framework or act and where the requirement comes from, and we come back to you on what holding it in your workspace involves.

See ComplyTrain on your own security requirement

Book a 30-minute demo with your security or compliance lead - the product organised around the standard or the act you answer to.