Every UK & EU standard, one place
Vanta and Drata cover a US-first slice of the market. We cover the standards UK and EU buyers actually ask about — with concrete implementation guidance and how ISO-STANDARD.app helps you evidence each one.
Standards we cover
The UK GDPR sits alongside the Data Protection Act 2018 and is enforced by the ICO. Since Brexit it has diverged in small but real ways from the EU GDPR — most notably around international transfers (the UK IDTA) and the ICO's own guidance.
NIS2 is the EU's expanded cybersecurity directive — replacing NIS from October 2024. It brings tens of thousands of new entities into scope, mandates board-level accountability, and sets tight incident reporting timelines (24 hours for early warning).
DORA became fully applicable on 17 January 2025. It creates a single, harmonised EU framework for ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing across the financial sector.
The EU AI Act is the world's first comprehensive AI law. It classifies AI by risk tier, bans certain uses, imposes conformity assessment on high-risk systems, and creates specific obligations for general-purpose AI models. Prohibitions took effect February 2025; GPAI obligations August 2025; high-risk obligations largely August 2026.
Cyber Essentials is the UK government-backed baseline scheme run by IASME on behalf of the NCSC. Self-assessment covers five technical control areas. Certification is annual.
Cyber Essentials Plus adds independent hands-on testing to the Cyber Essentials self-assessment. Same five control areas; higher assurance for buyers.
TISAX is the German automotive industry's information security assessment scheme, based on the VDA ISA questionnaire. Results are shared through the ENX portal. Common for suppliers to VW, BMW, Mercedes-Benz, Bosch, Continental and others.
ISO 27017 is a code of practice that adds cloud-specific implementation guidance to ISO 27002 controls, plus seven cloud-only controls. Certified as an extension to ISO 27001.
ISO 27018 is a code of practice for protecting PII in the public cloud when the provider acts as a processor. It's the international counterpart to GDPR processor obligations and is often required for EU customers.
ISO 22301 is the international standard for Business Continuity Management Systems (BCMS). It gives you a structured way to prepare for, respond to and recover from disruptive incidents.
ISO 27701 is an extension to ISO 27001 for privacy. It sets requirements and controls for a Privacy Information Management System (PIMS), aligned with GDPR and other privacy regimes. You must have ISO 27001 (or implement it in parallel) to certify to 27701.
Why one platform for every standard
UK and EU buyers rarely ask a single question. In a typical enterprise procurement cycle we see requests spanning ISO 27001, SOC 2 Type II, GDPR / UK GDPR Article 32, DORA operational resilience, NIS2 sector obligations, ISO 42001 AI governance and Cyber Essentials Plus — all inside the same security questionnaire. Running each of those on a separate spreadsheet or a US-first tool means the same evidence gets uploaded three times and the same control gets re-tested for every framework.
ISO-STANDARD.app is built for this reality. Controls, risks, assets, policies and evidence are stored once, then cross-walked into every standard you operate. When an auditor for one framework asks for a control, the same evidence is already attached — with owner, review cadence, next-review date and a full audit trail. That is what "one platform for every standard" actually means in practice, and it is why the standards library below matters more than a long feature list.
How each standard page is organised
- Scope & applicability — who the standard applies to, thresholds, effective dates and enforcement bodies for UK and EU markets.
- Clause / control map — plain-English summary of the mandatory requirements, mapped to the ISO-STANDARD.app control catalogue.
- Evidence you'll need — the artefacts an auditor or regulator will typically ask for, and where each one lives in the app.
- Common pitfalls — the failure modes that repeatedly come up in surveillance audits and enforcement actions.
- Crosswalk to other standards — where controls overlap with ISO 27001, SOC 2, NIST CSF and other frameworks so you don't duplicate work.
- Long-form articles — ten or more implementation deep-dives per standard, written for practitioners, not marketing.
Coverage by region
The library groups standards by the buyer base that asks for them: UK (Cyber Essentials, Cyber Essentials Plus, UK GDPR, DTAC, DCB0129), EU (GDPR, NIS2, DORA, EU AI Act, TISAX), international ISO (27001, 27017, 27018, 27701, 22301, 9001, 20000-1, 31000, 42001) and US-origin frameworks (SOC 2, HIPAA, PCI DSS). If you sell into more than one region — and most UK/EU SMEs do — the crosswalk is the single most valuable feature.
See it in your workspace
Pre-loaded controls, evidence vault, Trust Center and audit workflow — the same shape across every standard we cover. Start free, no sales call, no credit card until you subscribe.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.