AAuditly
For everyoneUpdated 7 September 2026

Supported frameworks

The standards and regulations projects can be posted for, what kind of engagement each usually needs, and where to read more.

A posting names the framework the audit is for. Auditors list the frameworks they work in, at what level, so a posting reaches the right bidders. The public site carries a guide per framework: what it requires, who it reaches, and what an audit checks.

Framework What it covers Typical engagements
ISO 27001 Information security management system Gap assessment, internal audit, stage 1 and 2 readiness, surveillance
SOC 2 Trust services criteria, Type I or Type II Readiness assessment, control testing before the examination
GDPR EU data protection Programme review, DPIA support, records of processing
NIS2 EU cybersecurity risk management for essential and important entities Applicability, gap assessment against the measures, incident readiness
DORA Digital operational resilience for financial entities and their ICT providers ICT risk framework review, third-party register, testing programme
EU AI Act Obligations for providers and deployers of AI systems Risk classification, high-risk obligations, technical documentation
ISO 42001 AI management system Gap assessment, internal audit, certification readiness
HIPAA US health information privacy and security Risk analysis, safeguards review
PCI DSS Cardholder data environment Scoping, gap assessment, readiness for a QSA assessment
CRA EU cybersecurity requirements for products with digital elements Applicability, conformity assessment readiness
ISO 27701 Privacy information management, extending ISO 27001 Gap assessment, internal audit
ISO 22301 Business continuity management Gap assessment, exercise review

A posting can also name another standard; write it in and describe what the audit must cover.

Which rules apply to you #

Not sure? The rules finder sorts twelve frameworks and laws into required by law, required by contract, expected by buyers and worth considering, from ten questions about your market, sector, data and products. The readiness check scores twenty things an auditor tests in the first week.

Deadlines #

Regulatory dates for NIS2, DORA, the AI Act and the CRA are kept on one deadlines page.