Every UK & EU standard, one place

Vanta and Drata cover a US-first slice of the market. We cover the standards UK and EU buyers actually ask about — with concrete implementation guidance and how ISO-STANDARD.app helps you evidence each one.

Standards we cover

United Kingdom
UK GDPR (Data Protection Act 2018)

The UK GDPR sits alongside the Data Protection Act 2018 and is enforced by the ICO. Since Brexit it has diverged in small but real ways from the EU GDPR — most notably around international transfers (the UK IDTA) and the ICO's own guidance.

10 articles →
European Union
NIS2 Directive

NIS2 is the EU's expanded cybersecurity directive — replacing NIS from October 2024. It brings tens of thousands of new entities into scope, mandates board-level accountability, and sets tight incident reporting timelines (24 hours for early warning).

10 articles →
European Union
Digital Operational Resilience Act (DORA)

DORA became fully applicable on 17 January 2025. It creates a single, harmonised EU framework for ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing across the financial sector.

10 articles →
European Union
EU AI Act

The EU AI Act is the world's first comprehensive AI law. It classifies AI by risk tier, bans certain uses, imposes conformity assessment on high-risk systems, and creates specific obligations for general-purpose AI models. Prohibitions took effect February 2025; GPAI obligations August 2025; high-risk obligations largely August 2026.

10 articles →
United Kingdom
Cyber Essentials

Cyber Essentials is the UK government-backed baseline scheme run by IASME on behalf of the NCSC. Self-assessment covers five technical control areas. Certification is annual.

10 articles →
United Kingdom
Cyber Essentials Plus

Cyber Essentials Plus adds independent hands-on testing to the Cyber Essentials self-assessment. Same five control areas; higher assurance for buyers.

10 articles →
Germany / European automotive
TISAX (Trusted Information Security Assessment Exchange)

TISAX is the German automotive industry's information security assessment scheme, based on the VDA ISA questionnaire. Results are shared through the ENX portal. Common for suppliers to VW, BMW, Mercedes-Benz, Bosch, Continental and others.

10 articles →
International (heavily used in EU)
ISO/IEC 27017

ISO 27017 is a code of practice that adds cloud-specific implementation guidance to ISO 27002 controls, plus seven cloud-only controls. Certified as an extension to ISO 27001.

10 articles →
International (mandatory in many EU procurement)
ISO/IEC 27018

ISO 27018 is a code of practice for protecting PII in the public cloud when the provider acts as a processor. It's the international counterpart to GDPR processor obligations and is often required for EU customers.

10 articles →
International (widely required in EU/UK regulated sectors)
ISO 22301

ISO 22301 is the international standard for Business Continuity Management Systems (BCMS). It gives you a structured way to prepare for, respond to and recover from disruptive incidents.

10 articles →
International (heavily used in EU for GDPR alignment)
ISO/IEC 27701

ISO 27701 is an extension to ISO 27001 for privacy. It sets requirements and controls for a Privacy Information Management System (PIMS), aligned with GDPR and other privacy regimes. You must have ISO 27001 (or implement it in parallel) to certify to 27701.

10 articles →

Why one platform for every standard

UK and EU buyers rarely ask a single question. In a typical enterprise procurement cycle we see requests spanning ISO 27001, SOC 2 Type II, GDPR / UK GDPR Article 32, DORA operational resilience, NIS2 sector obligations, ISO 42001 AI governance and Cyber Essentials Plus — all inside the same security questionnaire. Running each of those on a separate spreadsheet or a US-first tool means the same evidence gets uploaded three times and the same control gets re-tested for every framework.

ISO-STANDARD.app is built for this reality. Controls, risks, assets, policies and evidence are stored once, then cross-walked into every standard you operate. When an auditor for one framework asks for a control, the same evidence is already attached — with owner, review cadence, next-review date and a full audit trail. That is what "one platform for every standard" actually means in practice, and it is why the standards library below matters more than a long feature list.

How each standard page is organised

  • Scope & applicability — who the standard applies to, thresholds, effective dates and enforcement bodies for UK and EU markets.
  • Clause / control map — plain-English summary of the mandatory requirements, mapped to the ISO-STANDARD.app control catalogue.
  • Evidence you'll need — the artefacts an auditor or regulator will typically ask for, and where each one lives in the app.
  • Common pitfalls — the failure modes that repeatedly come up in surveillance audits and enforcement actions.
  • Crosswalk to other standards — where controls overlap with ISO 27001, SOC 2, NIST CSF and other frameworks so you don't duplicate work.
  • Long-form articles — ten or more implementation deep-dives per standard, written for practitioners, not marketing.

Coverage by region

The library groups standards by the buyer base that asks for them: UK (Cyber Essentials, Cyber Essentials Plus, UK GDPR, DTAC, DCB0129), EU (GDPR, NIS2, DORA, EU AI Act, TISAX), international ISO (27001, 27017, 27018, 27701, 22301, 9001, 20000-1, 31000, 42001) and US-origin frameworks (SOC 2, HIPAA, PCI DSS). If you sell into more than one region — and most UK/EU SMEs do — the crosswalk is the single most valuable feature.

See it in your workspace

Pre-loaded controls, evidence vault, Trust Center and audit workflow — the same shape across every standard we cover. Start free, no sales call, no credit card until you subscribe.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.