Start a free trial
Menu

Standards · Cybersecurity

Which security standards and laws apply to you?

ISO/IEC 27001 and its family, the NIST and CIS frameworks, IEC 62443, SOC 2 and TISAX, and the EU laws that bind you directly: NIS2, DORA, the Cyber Resilience Act and GDPR. Explained in plain words, in one catalogue, with every entry linked to its source.

Overview

Three shapes of security requirement

A security requirement arrives as a standard, a framework or a law. Knowing which one you are looking at tells you who checks it and what evidence they want.

  1. A standard you certify against

    ISO/IEC 27001 is the management system a customer asks for. An accredited body audits it and issues the certificate; 27002, 27005, 27017, 27018 and 27701 are read on top of it.

  2. A framework you are assessed against

    NIST CSF 2.0 and SP 800-53, SP 800-171 for the US defence supply chain, the CIS Controls, IEC 62443 for industrial systems. SOC 2 and TISAX are the reports and labels built on the same idea.

  3. A law that binds you directly

    NIS2 and CER by sector, DORA for finance, the Cyber Resilience Act for products, GDPR for personal data. A supervisor enforces them whether or not a contract mentions them.

  4. One set of controls serves all three

    The measures the laws list are the controls a 27001 system runs. Build the system once, keep its evidence, and answer the auditor, the customer and the regulator from the same records.

  5. Find yours below

    Search the catalogue by name, browse it by family, or answer five questions about your situation. Each entry links to its source and can be requested in ComplyTrain.

Your customer's questionnaire, your regulator or the law itself names what you must show. A law binds you by who you are; a standard by what a contract says. MANAGEMENT SYSTEM (ISO/IEC) ISO/IEC 27001 the certifiable base for information security ISO/IEC 27002 · 27005 the controls · the risk method + 27017 cloud · 27018 · 27701 privacy Certifiable. A certification body audits you. FRAMEWORKS AND CONTROLS NIST CSF 2.0 six functions, Govern to Recover SP 800-53 · 800-171 the control catalogues underneath + CIS Controls · IEC 62443 (OT) · SOC 2 · TISAX Attested or assessed, not certified. EU LAW NIS2 · DORA resilience duties by sector and by entity CRA · GDPR products with digital elements · personal data + CER · eIDAS 2 · AI Act · Cybersecurity Act Binding. A supervisory authority enforces. maps to evidence for A 27001 certificate is the usual way to show a customer, and increasingly a regulator, that the controls the law asks for exist and are run. NIS2 and CER reach you through national law; DORA, the CRA and GDPR apply directly. Which ones is a question of sector, size and what you sell. HOW A SECURITY REQUIREMENT REACHES A COMPANY · COMPLYTRAIN BY SKYLEN
How a security requirement reaches a company: a customer's questionnaire, a regulator or the law names it; ISO/IEC 27001 is the certifiable management system; NIST, CIS, IEC 62443, SOC 2 and TISAX are the frameworks and controls; NIS2, DORA, the CRA and GDPR bind directly.

The standards, frameworks and laws behind a security requirement

A security requirement reaches a company in three shapes. A customer's questionnaire or contract asks for a standard, usually ISO/IEC 27001. A framework such as NIST's gives a programme its structure and a control catalogue to assess against. And a law binds you not because a contract says so but because of what you are and what you sell: NIS2, DORA, the Cyber Resilience Act, GDPR. This page explains the three, how they fit, and where the documents come from. The explorer below then finds the ones that match your situation.

Start with ISO/IEC 27001

ISO/IEC 27001 is the international standard for an information security management system, and the one a customer asks about first. It is certifiable, it is the same in every industry, and its main text lists no technical measures: it asks you to run a management system that knows what information you hold, assesses the risks to it, chooses controls and keeps evidence that they work. The 2022 edition's Annex A holds 93 controls in four themes, organisational, people, physical and technological. ISO/IEC 27002 explains each control and how to implement it, and ISO/IEC 27005 describes the risk assessment the standard requires but does not spell out. See ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27005.

Around that core sit the extensions a particular customer asks for. ISO/IEC 27017 adds controls for cloud services and ISO/IEC 27018 protects personal data in a public cloud; both are what a cloud provider is asked to show. ISO/IEC 27701 extends the management system to privacy, the shape a GDPR programme can be run in. ISO/IEC 27035 covers incident management, and ISO 22301 business continuity. None of them stands alone: each is read on top of a 27001 system. See ISO/IEC 27017 and ISO/IEC 27018.

Frameworks and control catalogues

A framework is not a certificate. It is a structure to organise a programme and a catalogue to assess it against, and it is what an auditor, an insurer or a US customer measures you with. The NIST Cybersecurity Framework 2.0, from 2024, has six functions, Govern, Identify, Protect, Detect, Respond and Recover, and maps to the catalogues underneath it. NIST SP 800-53 is the control catalogue US federal systems are assessed against and the one most other catalogues cross-reference. NIST SP 800-171 is the subset a supplier to the US Department of Defense meets to handle controlled unclassified information, and the basis of the CMMC certification programme. The CIS Controls are eighteen prioritised safeguard groups in three implementation groups by organisation size, and the usual first step when nothing formal exists yet.

Two frameworks are sector-specific. IEC 62443 is the security series for industrial automation and control systems: zones and conduits for the plant, a secure development life cycle for the product (part 4-1) and technical requirements for components (part 4-2). TISAX is the automotive industry's exchange of information security assessments against the VDA ISA catalogue, and what a supplier to a German car maker is asked for. And two are attestations rather than standards: a SOC 2 report is an auditor's opinion on a service organisation's controls against the AICPA Trust Services Criteria, the document a US customer asks a SaaS provider for; the EU Cybersecurity Act's certification schemes are the European counterpart, still being rolled out.

The EU laws

A standard binds you because a contract says so. A law binds you because of what you are. Five EU acts now carry security obligations directly, and each has its own scope.

NIS2, Directive (EU) 2022/2555, applies to essential and important entities in eighteen sectors, from energy and transport to digital infrastructure, manufacturing of critical products and public administration. It is transposed into national law, so the exact duties come from your own country's act, but the shape is the same everywhere: management accountability, risk-management measures on a fixed list, supply-chain security, and early warning of a significant incident within 24 hours. The CER Directive, 2022/2557, is its physical-resilience counterpart for critical entities.

DORA, Regulation (EU) 2022/2554, applies since January 2025 to financial entities and to their critical ICT third-party providers. It asks for ICT risk management, incident reporting, resilience testing including threat-led penetration testing for the largest, and a register of every ICT contract. It applies directly, with no national transposition.

The Cyber Resilience Act, Regulation (EU) 2024/2847, reaches products rather than organisations: hardware and software with digital elements placed on the EU market must be secure by design, handle vulnerabilities for their support period and carry the CE mark for it. Reporting of actively exploited vulnerabilities starts in September 2026 and the full obligations apply from December 2027. ETSI EN 303 645 is the baseline the consumer-IoT part of it draws on.

GDPR, Regulation (EU) 2016/679, is the oldest of the five and the one everybody already meets: security of processing appropriate to the risk, and breach notification to the supervisory authority within 72 hours. Two newer acts touch the edges: eIDAS 2, Regulation (EU) 2024/1183, for trust services and the European Digital Identity Wallet, and the AI Act, Regulation (EU) 2024/1689, whose high-risk systems need a risk management system and a quality management system of their own.

How a certificate and a law fit together

An ISO/IEC 27001 certificate does not by itself satisfy NIS2 or DORA; the laws have their own scope, their own reporting clocks and their own supervisors. But the measures they list, risk analysis, incident handling, business continuity, supply-chain security, access control, encryption, are the measures a 27001 system runs, and the national authorities and ENISA reference ISO/IEC 27001 and the NIST framework in their guidance. A certified management system is the usual way to show a supervisor that the measures exist and are run, and a risk register and an incident log are the evidence both a certification auditor and a regulator read.

Where the documents come from

ISO/IEC standards are bought from ISO, from IEC or from your national standards body. Every NIST publication is free from NIST's Computer Security Resource Center, and the CIS Controls are free with registration. The EU acts are free on EUR-Lex, and every regulation entry in the explorer links to the consolidated text there; the national transpositions of NIS2 and CER come from your own legislature. IEC 62443 is bought from IEC or ISA, SOC 2's criteria come from the AICPA, and TISAX from the ENX Association.

Who decides what applies to you

Not this page, and not us. A contract or a questionnaire names the standard; a law names its own scope, and whether you fall inside it is a question about your sector, your size and what you sell that your counsel answers. What the explorer can do is show you the whole map: search it by number or name, browse it by family, or answer five questions about your situation and see which areas companies like you are commonly asked about. Each entry links to its source, to its ComplyTrain page where one exists, and otherwise to a request. ComplyTrain holds a standard as a requirement tree with the evidence against each requirement. The certificate stays yours to earn.

Standards explorer

Find your security standards and laws

Search the ISO/IEC 27000 family, the NIST and CIS frameworks, IEC 62443, SOC 2 and TISAX, and the EU acts together, browse them by family, or answer five questions about your situation.

50 standards in the catalogue

Not sure where to start?

Five questions, pick everything that applies. Nothing is stored.

Question 1 of 5What do you run or sell?
Question 2 of 5Who is asking?
Question 3 of 5Which of these describe you?
Question 4 of 5What do you have today?
Question 5 of 5What are you asked to show?
ISO management systems14 standards
  1. EN 9100AS9100 and EN 9100: the aerospace quality standardRead moreOne aerospace quality standard published under three names: AS9100 in the Americas, EN 9100 in Europe, JISQ 9100 in Asia-Pacific. It contains ISO 9001 in full and adds the requirements aviation, space and defence put on top.↗
  2. ISO 10007Quality management - Guidelines for configuration managementRead moreQuality management - Guidelines for configuration management↗
  3. ISO 14001Environmental management systems - Requirements with guidance for useRead moreEnvironmental management systems - Requirements with guidance for use↗
  4. ISO 19443Quality management systems - Specific requirements for the application of ISO 9001:2015 by organizations in the supply chain of the nuclear energy sector supplying products and services important to nuclear safety (ITNS)Read moreQuality management systems - Specific requirements for the application of ISO 9001:2015 by organizations in the supply chain of the nuclear energy sector supplying products and services important to nuclear safety (ITNS)↗
  5. ISO 28000Security and resilience - Security management systems - RequirementsRead moreSecurity and resilience - Security management systems - Requirements↗
  6. ISO 37001Anti-bribery management systems - Requirements with guidance for useRead moreAnti-bribery management systems - Requirements with guidance for use↗
  7. ISO 37301Compliance management systems - Requirements with guidance for useRead moreCompliance management systems - Requirements with guidance for use↗
  8. ISO 45001Occupational health and safety management systems - Requirements with guidance for useRead moreOccupational health and safety management systems - Requirements with guidance for use↗
  9. ISO 50001Energy management systems - Requirements with guidance for useRead moreEnergy management systems - Requirements with guidance for use↗
  10. ISO 55001Asset management - Management systems - RequirementsRead moreAsset management - Management systems - Requirements↗
  11. ISO 9001ISO 9001 quality managementRead moreISO 9001 is the international standard for quality management systems. ComplyTrain is structured around its clause structure, so your QMS is audit-ready by design.↗
  12. ISO/IEC 17025General requirements for the competence of testing and calibration laboratoriesRead moreGeneral requirements for the competence of testing and calibration laboratories↗
  13. ISO/IEC 20000-1Information technology - Service management - Part 1: Service management system requirementsRead moreInformation technology - Service management - Part 1: Service management system requirements↗
  14. ISO/IEC 42001Information technology - Artificial intelligence - Management systemRead moreInformation technology - Artificial intelligence - Management system↗
Information security management (ISO/IEC 27000 family)7 standards
  1. ISO/IEC 27001ISO 27001 information security managementRead moreISO 27001 is the standard for an information security management system (ISMS). ComplyTrain gives you the framework to build, run and evidence your ISMS - the certificate stays yours to earn.↗
  2. ISO/IEC 27002ISO 27002 information security controlsRead moreISO 27002 is the implementation guidance for the information-security controls listed in ISO 27001 Annex A. ComplyTrain holds each control as a requirement with the evidence that shows it is operating - which is what an auditor samples.↗
  3. ISO/IEC 27005ISO 27005 information security risk managementRead moreISO 27005 is the guidance for managing information security risk - the assessment and treatment that ISO 27001 requires but does not describe. ComplyTrain runs it as a living register, not an annual document.↗
  4. ISO/IEC 27017ISO 27017 cloud security controlsRead moreISO 27017 extends the ISO 27002 controls to cloud services and adds controls specific to them. ComplyTrain holds each one as a requirement, including the ones that belong to your provider rather than to you.↗
  5. ISO/IEC 27018ISO 27018 personal data in the cloudRead moreISO 27018 extends ISO 27001 to the protection of personal data in public clouds. ComplyTrain gives you the framework to manage and evidence those controls.↗
  6. ISO/IEC 27035-1Information technology - Information security incident management - Part 1: Principles and processRead moreInformation technology - Information security incident management - Part 1: Principles and process↗
  7. ISO/IEC 27701Security techniques - Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management - Requirements and guidelinesRead moreSecurity techniques - Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management - Requirements and guidelines↗
Cybersecurity frameworks and controls9 standards
  1. CIS Controls v8CIS Critical Security Controls, version 8.1Ed. 8.1Read moreCIS Critical Security Controls, version 8.1↗
  2. ETSI EN 303 645Cyber Security for Consumer Internet of Things: Baseline RequirementsRead moreCyber Security for Consumer Internet of Things: Baseline Requirements↗
  3. IEC 62443Security for industrial automation and control systems (IEC 62443 series)Read moreSecurity for industrial automation and control systems (IEC 62443 series)↗
  4. NIST CSF 2.0NIST Cybersecurity Framework (CSF) 2.0Ed. 2.0Read moreNIST's voluntary taxonomy of cybersecurity outcomes, Govern, Identify, Protect, Detect, Respond and Recover, that organisations use to assess their own risk posture and communicate it; there is no certification against it.↗
  5. NIST SP 800-171NIST SP 800-171 protecting Controlled Unclassified InformationEd. Rev. 3Read moreUS federal security requirements for protecting Controlled Unclassified Information on nonfederal systems, binding once a federal contract or agreement invokes them.↗
  6. NIST SP 800-53NIST SP 800-53 security and privacy controls for federal information systemsEd. Rev. 5Read moreNIST's catalogue of 20 families of security and privacy controls for federal information systems, mandatory under FISMA and OMB Circular A-130, with baselines and assessment procedures held in companion publications.↗
  7. NIST SP 800-61NIST SP 800-61 incident response recommendationsEd. Rev. 3Read moreNIST's voluntary CSF 2.0 Community Profile mapping incident response recommendations and considerations onto the Cybersecurity Framework's six Functions, replacing the 2012 Computer Security Incident Handling Guide.↗
  8. SOC 2SOC 2: Trust Services Criteria for security, availability, processing integrity, confidentiality and privacyRead moreSOC 2: Trust Services Criteria for security, availability, processing integrity, confidentiality and privacy↗
  9. TISAXTISAX: Trusted Information Security Assessment Exchange (VDA ISA)Read moreTISAX: Trusted Information Security Assessment Exchange (VDA ISA)↗
EU cybersecurity and data law8 standards
  1. CERDirective (EU) 2022/2557 on the resilience of critical entitiesRead moreDirective (EU) 2022/2557 on the resilience of critical entities↗
  2. CRARegulation (EU) 2024/2847, the Cyber Resilience ActRead moreRegulation (EU) 2024/2847, the Cyber Resilience Act↗
  3. DORARegulation (EU) 2022/2554 on digital operational resilience for the financial sectorRead moreRegulation (EU) 2022/2554 on digital operational resilience for the financial sector↗
  4. eIDAS 2Regulation (EU) 2024/1183 amending the framework for a European Digital IdentityRead moreRegulation (EU) 2024/1183 amending the framework for a European Digital Identity↗
  5. EU AI ActRegulation (EU) 2024/1689 laying down harmonised rules on artificial intelligenceRead moreRegulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence↗
  6. EU Cybersecurity ActRegulation (EU) 2019/881 on ENISA and on cybersecurity certificationRead moreRegulation (EU) 2019/881 on ENISA and on cybersecurity certification↗
  7. GDPRRegulation (EU) 2016/679, the General Data Protection RegulationRead moreRegulation (EU) 2016/679, the General Data Protection Regulation↗
  8. NIS2Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the UnionRead moreDirective (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union↗
Risk management standards and methods12 standards
  1. ISO 22301Security and resilience - Business continuity management systems - RequirementsRead moreSecurity and resilience - Business continuity management systems - Requirements↗
  2. ISO 31000ISO 31000 risk managementRead moreISO 31000 is the international guidance for managing risk. ComplyTrain’s risk management is structured around its process, so risk is a living framework across the organisation, not a spreadsheet reviewed once a year.↗
  3. ISO/IEC 23894Information technology - Artificial intelligence - Guidance on risk managementRead moreInformation technology - Artificial intelligence - Guidance on risk management↗
  4. FAIROpen FAIR Risk Analysis Standard (O-RA)Read moreOpen FAIR Risk Analysis Standard (O-RA)↗
  5. IEC 31010Risk management - Risk assessment techniquesRead moreRisk management - Risk assessment techniques↗
  6. IEC 60812Failure modes and effects analysis (FMEA and FMECA)Read moreFailure modes and effects analysis (FMEA and FMECA)↗
  7. IEC 61508Functional safety of electrical/electronic/programmable electronic safety-related systemsRead moreFunctional safety of electrical/electronic/programmable electronic safety-related systems↗
  8. IEC 61882Hazard and operability studies (HAZOP studies) - Application guideRead moreHazard and operability studies (HAZOP studies) - Application guide↗
  9. NIST AI RMFNIST AI RMF, a framework for managing AI system riskEd. 1.0Read moreA voluntary US framework of four functions, Govern, Map, Measure and Manage, for organizations to manage AI system risk, with no certification scheme.↗
  10. NIST SP 800-30NIST SP 800-30 information security risk assessmentsEd. Rev. 1Read moreNIST's guide to running an information security risk assessment, from threat sources and vulnerabilities through to a level of risk.↗
  11. NIST SP 800-37NIST SP 800-37 risk management framework for information systemsEd. Rev. 2Read moreNIST's seven-step Risk Management Framework for categorizing federal information systems, selecting and implementing security and privacy controls, and having an authorizing official decide whether the residual risk is acceptable.↗
  12. COSO ERMEnterprise Risk Management - Integrating with Strategy and PerformanceRead moreEnterprise Risk Management - Integrating with Strategy and Performance↗

Titles belong to their publishers. The one-line summaries are ours.

Request access to work with this standard in ComplyTrain

Shortlist

Security standards with their own page

Each page sets out what the standard asks of you and how a ComplyTrain workspace is organised around it. The catalogue above holds far more than these, and any entry in it can be requested. Adding a standard to a workspace is usually a matter of days, not a project.

  • ISO/IEC 27001

    ISO 27001 information security management

    ISO 27001 is the standard for an information security management system (ISMS). ComplyTrain gives you the framework to build, run and evidence your ISMS - the certificate stays yours to earn.

  • ISO/IEC 27002

    ISO 27002 information security controls

    ISO 27002 is the implementation guidance for the information-security controls listed in ISO 27001 Annex A. ComplyTrain holds each control as a requirement with the evidence that shows it is operating - which is what an auditor samples.

  • ISO/IEC 27005

    ISO 27005 information security risk management

    ISO 27005 is the guidance for managing information security risk - the assessment and treatment that ISO 27001 requires but does not describe. ComplyTrain runs it as a living register, not an annual document.

  • ISO/IEC 27017

    ISO 27017 cloud security controls

    ISO 27017 extends the ISO 27002 controls to cloud services and adds controls specific to them. ComplyTrain holds each one as a requirement, including the ones that belong to your provider rather than to you.

  • ISO/IEC 27018

    ISO 27018 personal data in the cloud

    ISO 27018 extends ISO 27001 to the protection of personal data in public clouds. ComplyTrain gives you the framework to manage and evidence those controls.

If you need to get there and have no quality function

A standard usually arrives as a contract condition or a regulator's letter rather than a project anyone planned for, and often at a company with no quality manager. Software is half the answer. Skylen's consultants are the other half, and because they build on ComplyTrain from day one you keep a live system your team owns rather than a binder and a departed consultant.

  • Gap assessment

    A clause-by-clause read of where you stand against the standard your contract or your regulator cites, turned into a prioritised plan you could act on with us or alone.

    What an assessment covers
  • Guided implementation

    Our consultants build the system with your team - procedures, document control, the records you need to keep and the review cadence - and prepare you for the audit or the inspection.

    How an engagement works
  • Full-service quality function

    We run and maintain the system for you, so a small team can reach and hold a standard without hiring a quality manager.

    What full-service means

Questions people ask about security standards and laws

Does an ISO/IEC 27001 certificate make us NIS2 compliant?

No, and nothing does on its own. NIS2 is transposed into national law with its own scope, its own list of measures and its own reporting deadlines, and a supervisor checks you against that act, not against a certificate. A 27001 system does run the measures the law lists, so the certificate and the system's records are the usual way to show a supervisor that they exist. Read your national act for the duties and the deadlines.

Which of these are certifications, and which are not?

ISO/IEC 27001 is a certification: an accredited body audits you and issues a certificate. ISO/IEC 27017, 27018 and 27701 are audited as extensions of it. SOC 2 is an attestation report, an opinion an auditor writes, not a certificate. TISAX is an assessment with a label shared through the ENX platform. The NIST framework, SP 800-53 and the CIS Controls are frameworks you assess against, with CMMC as the certification programme built on SP 800-171. IEC 62443 has product and process certification schemes run by third parties. A law is none of these: you comply with it, and a supervisor enforces it.

What is the difference between ISO/IEC 27001 and 27002?

ISO/IEC 27001 is the requirements standard, the one you are certified against: it says what a management system must do and lists the controls in Annex A. ISO/IEC 27002 is the guidance: it takes each of those controls and explains what it means and how to implement it. You cannot be certified against 27002. See ISO/IEC 27001 and ISO/IEC 27002.

We sell to a US customer. Do we need SOC 2 or ISO/IEC 27001?

Ask the customer, because it is their procurement that decides. A US enterprise buyer usually asks a SaaS provider for a SOC 2 Type II report; a European or a public-sector buyer usually asks for ISO/IEC 27001. The two overlap heavily and many companies hold both, running one set of controls and having it audited twice. A supplier to the US Department of Defense is asked for NIST SP 800-171 and, increasingly, CMMC.

Does the Cyber Resilience Act apply to our software?

If you place a product with digital elements on the EU market, hardware or software, it applies unless the product is covered by a sector act that already regulates its security, such as medical devices or vehicles. Open-source software offered outside a commercial activity is outside it. What the act asks depends on the product class; the reporting duties start in September 2026 and the rest in December 2027. Whether your product is in scope is a legal question for your counsel.

Does ComplyTrain certify us against a standard?

No. Certification is issued by an accredited certification body, a licence by your authority, and government quality assurance is exercised by the acquisition authority. ComplyTrain is the system you build, run and evidence your compliance in, and Skylen's consultants can take you through the work. The certificate stays yours to earn.

Can I get a standard added to ComplyTrain?

Yes, and that is what the Request access button on every entry is for. Tell us which standard and where the requirement comes from, and we come back to you on what holding it in your workspace involves, usually within one business day. Adding a standard to a workspace is usually a matter of days, not a project. ComplyTrain holds a standard as a requirement tree with your evidence against each requirement, and the tree is what we build.

Request access to work with a standard or a regulation

Some of these documents are sold by the bodies that publish them, and some are law or guidance you can read for free. We write a page only where we have read the document, so one is missing from this site either because we have not written it up yet, or because it is licensed and not ours to republish. Name the standard, framework or act and where the requirement comes from, and we come back to you on what holding it in your workspace involves.

See ComplyTrain on your own security requirement

Book a 30-minute demo with your security or compliance lead - the product organised around the standard or the act you answer to.