Regulatory compliance
Compliance frameworks
Ten frameworks, three different ways of proving them, and one question that matters: which one applies to you.
What a compliance framework is
A compliance framework is a set of requirements about how you manage security, privacy or risk. Some are international standards you adopt voluntarily. Others are laws that bind you because of what you do and where you do it.
The difference matters more than it looks, because it determines what you can show. A certifiable standard ends in a certificate issued by a third party. A legal obligation ends in nothing you can frame: it ends in documentation you produce when you are asked for it.
Certificate, report or obligation
It is the most widespread confusion in the sector, and it is worth settling before going further.
Third-party certification
An accredited body, independent of you, audits your management system and issues a certificate with a date and a scope.
- ISO 27001
- ISO 27701
- ISO 42001
- ENS Media/Alta
Auditor attestation
An audit firm examines your controls and issues a report with its opinion. It is not a certificate and there is no seal. SOC 2 works this way, which is why "SOC 2 certified" describes badly what you actually hold.
- SOC 2
Legal obligation
A law applies to you and an authority supervises it. No certificate attests compliance. GDPR, NIS2, the EU AI Act, DORA and HIPAA are obligations, and anyone selling you a compliance seal for any of them is selling you something else.
- GDPR
- NIS2
- EU AI Act
- DORA
- HIPAA
Which one applies to you
You almost never choose it. It is chosen by whoever has something you want.
- ISO 27001An enterprise customer asking for ISO 27001 during procurement.
- SOC 2 TYPE IIA United States buyer who wants a SOC 2 Type II.
- ENSA Spanish public administration whose contract carries the ENS with it.
- DORAA European bank passing DORA down to you because you are its supplier.
- NIS2An entire sector entering NIS2 and discovering that its supply chain does too.
And some apply without anyone asking. If you process personal data in Europe, the GDPR already applies to you. If your product uses AI and is used in the EU, so does the AI Act.
The ten frameworks
The market asks for it
4 frameworksVoluntary by law and mandatory by commercial contract. You adopt them because your customer, your investor or your procurement process requires them.
- CertificateINTERNATIONALISO 27001International security certificationSee the framework
- ReportUNITED STATESSOC 2Trust for the US marketSee the framework
- CertificateINTERNATIONALISO 27701Privacy information managementSee the framework
- CertificateINTERNATIONALISO 42001AI management systemsSee the framework
The law requires it
6 frameworksThey apply because of what you do and where you do it, not because you choose them. HIPAA is the particular case: a European company is reached by contract, through an agreement with a covered US entity.
- ObligationEUGDPREU personal data protectionSee the framework
- ObligationEUNIS2Cybersecurity for essential sectorsSee the framework
- ObligationEUEU AI ActObligations for AI systems in the EUSee the framework
- ObligationEUDORAFinancial sector operational resilienceSee the framework
- CertificateSPAINENSSpanish public-sector requirementSee the framework
- ObligationUNITED STATESHIPAAUS healthcare privacySee the framework
One single platform
With Zerod
Frameworks overlap more than they appear to. The risk analysis you do for ISO 27001 feeds the one NIS2 asks of you. The access controls you document for the ENS are the same ones a SOC 2 looks at.
In Zerod you activate the frameworks that apply to you and do the work once. Documentation, controls and evidence live in one place, not in a folder per standard.
Zerod is certified to ISO/IEC 27001:2022.
SHARED WORK
- Risk analysisISO 27001NIS2
- Access controlsENSSOC 2
- Supplier managementDORANIS2
- Record of processing activitiesGDPRISO 27701
Frequently asked questions
Where do I start if I have never certified anything?
With whichever one is blocking something. It is almost always ISO 27001 if you sell in Europe, or SOC 2 if you sell in the United States. Starting with the one nobody asked you for is work nobody pays for.
Can I cover several frameworks at once?
Yes, and it usually costs less than doing them in sequence, because they share a good part of the underlying work. What they do not share are the conformity schemes: each certificate, report or obligation is demonstrated on its own.