Skip to content

Compliance

Regulatory frameworks

Where a supervisor is asking the question, the assessment has to be structured the way the supervisor reads it — not translated afterwards from a generic control report.

Assess once, report several times

Organisations subject to more than one framework routinely run parallel assessments that ask the same people the same questions. Where several frameworks apply, we build a consolidated control set, collect evidence once, and report separately in each framework's own structure. On multi-framework engagements this is usually the single largest cost saving available.

Free tool · no sign-up

Not sure which of these apply to you?

Six questions, about ninety seconds. Runs in your browser — nothing is sent to us.

Open the framework finder
ISO 27001 SAMA CSF NCA ECC Shared evidence Assess once, reportseparately Usually the largest savingavailable on a multi-frameworkengagement.
Where several frameworks apply, we build one consolidated control set, collect evidence once, and report separately in each framework's own structure.

Pakistan

Gulf — Saudi Arabia and the UAE

Global frameworks

Frameworks and standards we audit against

ISACA ITAF COBIT 2019 ISO/IEC 27001:2022 ISO 22301:2019 NIST CSF 2.0 OWASP ASVS PCI DSS IIA Standards

Need an independent view?

Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.

Request a proposal
Top