Skip to main content
Frameworks & Regulations

Different requirements. One program of controls and evidence.

We do not treat each standard as a separate universe.Where requirements overlap, we reuse controls, risks and evidence without confusing legal or audit obligations.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2

Assurance & certification

Two assurance paths, two different types of outcome.

SOC2 and ISO/IEC 27001 can reuse a significant portion of controls and evidence, but auditor engagement and final outcome are not the same.

Regulatory & privacy

The framework does not change the technical reality of the organization.

GDPR, NIS2 and accessibility require different contexts, but all require processes that can be operated and demonstrated — not just documents created for review.

Mapping between Frameworks and Controls

Cross-framework

You reuse work without pretending that standards are equivalent.

The same access review, risk treatment, or evidence can support multiple requirements when mapping is justified.

How the platform works

Don’t see the framework you need?

We can evaluate the requirement and mapping before adding a new program to the scope.

Talk to ZBTKEEP
ZebraByte

Managed frameworks Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Not seeing the framework you are looking for?
Reach out — we may already support it in the programme.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert