Supported frameworks
The standards and regulations projects can be posted for, what kind of engagement each usually needs, and where to read more.
A posting names the framework the audit is for. Auditors list the frameworks they work in, at what level, so a posting reaches the right bidders. The public site carries a guide per framework: what it requires, who it reaches, and what an audit checks.
| Framework | What it covers | Typical engagements |
|---|---|---|
| ISO 27001 | Information security management system | Gap assessment, internal audit, stage 1 and 2 readiness, surveillance |
| SOC 2 | Trust services criteria, Type I or Type II | Readiness assessment, control testing before the examination |
| GDPR | EU data protection | Programme review, DPIA support, records of processing |
| NIS2 | EU cybersecurity risk management for essential and important entities | Applicability, gap assessment against the measures, incident readiness |
| DORA | Digital operational resilience for financial entities and their ICT providers | ICT risk framework review, third-party register, testing programme |
| EU AI Act | Obligations for providers and deployers of AI systems | Risk classification, high-risk obligations, technical documentation |
| ISO 42001 | AI management system | Gap assessment, internal audit, certification readiness |
| HIPAA | US health information privacy and security | Risk analysis, safeguards review |
| PCI DSS | Cardholder data environment | Scoping, gap assessment, readiness for a QSA assessment |
| CRA | EU cybersecurity requirements for products with digital elements | Applicability, conformity assessment readiness |
| ISO 27701 | Privacy information management, extending ISO 27001 | Gap assessment, internal audit |
| ISO 22301 | Business continuity management | Gap assessment, exercise review |
A posting can also name another standard; write it in and describe what the audit must cover.
Which rules apply to you #
Not sure? The rules finder sorts twelve frameworks and laws into required by law, required by contract, expected by buyers and worth considering, from ten questions about your market, sector, data and products. The readiness check scores twenty things an auditor tests in the first week.
Deadlines #
Regulatory dates for NIS2, DORA, the AI Act and the CRA are kept on one deadlines page.