Different requirements. One program of controls and evidence.
We do not treat each standard as a separate universe.Where requirements overlap, we reuse controls, risks and evidence without confusing legal or audit obligations.
Assurance & certification
Two assurance paths, two different types of outcome.
SOC2 and ISO/IEC 27001 can reuse a significant portion of controls and evidence, but auditor engagement and final outcome are not the same.
Regulatory & privacy
The framework does not change the technical reality of the organization.
GDPR, NIS2 and accessibility require different contexts, but all require processes that can be operated and demonstrated — not just documents created for review.
01
GDPR & Privacy
Data mapping, RoPA, DPIA, TIA, rights requests, third parties and technical measures related to the privacy program.
02
NIS2
Governance, cyber risk, incident readiness, supply chain security and resilience for organizations in scope.
03
Accessibility
Assessment, remediation and ongoing management of digital accessibility as part of the compliance program.
Cross-framework
You reuse work without pretending that standards are equivalent.
The same access review, risk treatment, or evidence can support multiple requirements when mapping is justified.
How the platform worksDon’t see the framework you need?
We can evaluate the requirement and mapping before adding a new program to the scope.
Talk to ZBTKEEP