Skip to content

Regulatory compliance

Compliance frameworks

Ten frameworks, three different ways of proving them, and one question that matters: which one applies to you.

What a compliance framework is

A compliance framework is a set of requirements about how you manage security, privacy or risk. Some are international standards you adopt voluntarily. Others are laws that bind you because of what you do and where you do it.

The difference matters more than it looks, because it determines what you can show. A certifiable standard ends in a certificate issued by a third party. A legal obligation ends in nothing you can frame: it ends in documentation you produce when you are asked for it.

Certificate, report or obligation

It is the most widespread confusion in the sector, and it is worth settling before going further.

  • Third-party certification

    An accredited body, independent of you, audits your management system and issues a certificate with a date and a scope.

    • ISO 27001
    • ISO 27701
    • ISO 42001
    • ENS Media/Alta
  • Auditor attestation

    An audit firm examines your controls and issues a report with its opinion. It is not a certificate and there is no seal. SOC 2 works this way, which is why "SOC 2 certified" describes badly what you actually hold.

    • SOC 2
  • Legal obligation

    A law applies to you and an authority supervises it. No certificate attests compliance. GDPR, NIS2, the EU AI Act, DORA and HIPAA are obligations, and anyone selling you a compliance seal for any of them is selling you something else.

    • GDPR
    • NIS2
    • EU AI Act
    • DORA
    • HIPAA

Which one applies to you

You almost never choose it. It is chosen by whoever has something you want.

  • ISO 27001An enterprise customer asking for ISO 27001 during procurement.
  • SOC 2 TYPE IIA United States buyer who wants a SOC 2 Type II.
  • ENSA Spanish public administration whose contract carries the ENS with it.
  • DORAA European bank passing DORA down to you because you are its supplier.
  • NIS2An entire sector entering NIS2 and discovering that its supply chain does too.

And some apply without anyone asking. If you process personal data in Europe, the GDPR already applies to you. If your product uses AI and is used in the EU, so does the AI Act.

One single platform

With Zerod

Frameworks overlap more than they appear to. The risk analysis you do for ISO 27001 feeds the one NIS2 asks of you. The access controls you document for the ENS are the same ones a SOC 2 looks at.

In Zerod you activate the frameworks that apply to you and do the work once. Documentation, controls and evidence live in one place, not in a folder per standard.

Zerod is certified to ISO/IEC 27001:2022.

SHARED WORK

  • Risk analysisISO 27001NIS2
  • Access controlsENSSOC 2
  • Supplier managementDORANIS2
  • Record of processing activitiesGDPRISO 27701

Frequently asked questions

Where do I start if I have never certified anything?

With whichever one is blocking something. It is almost always ISO 27001 if you sell in Europe, or SOC 2 if you sell in the United States. Starting with the one nobody asked you for is work nobody pays for.

Can I cover several frameworks at once?

Yes, and it usually costs less than doing them in sequence, because they share a good part of the underlying work. What they do not share are the conformity schemes: each certificate, report or obligation is demonstrated on its own.

Get compliant. Prove your security.

Compliance frameworks · Zerod