Onwyn › Standards
CoverageStandards we cover
Every framework below is live in the Semantic Compliance Engine as a guided, requirement-by-requirement program — not a checklist. Each requirement carries what to do, how to evidence it, what auditors commonly reject, and a senior consultant one click away.
Certifiable standards
ISO 22301:2019
ISO 22301 is the international standard for a business continuity management system (BCMS): a disciplined way of working out which of your activities the business cannot afford to lose, how fast they must be back, what it would take to get them there, and whether the plans actually work when tested.
ISO 9001:2015
ISO 9001 is the international standard for a quality management system: a structured way of understanding what your customers require, running the processes that deliver it under control, catching what goes wrong, and improving on the evidence.
ISO/IEC 27001:2022
ISO/IEC 27001 is the international standard for running an information security management system (ISMS): a repeatable way of deciding what to protect, treating the risks, and proving it works.
ISO/IEC 27701:2019
ISO/IEC 27701 turns an information security management system into a privacy information management system (PIMS): it adds privacy-specific management requirements on top of ISO/IEC 27001 and a set of controls for organizations that decide why personal data is processed (controllers) and for those that process it on someone else's instruction (processors).
ISO/IEC 42001:2023
ISO/IEC 42001 is the first certifiable management system standard for artificial intelligence: it structures how an organization governs the AI systems it develops or uses — responsibly, transparently, and with managed risk.
Regulations
DORA — Digital Operational Resilience Act (Regulation (EU) 2022/2554)
DORA is the EU's operational resilience law for the financial sector.
EU AI Act (Regulation (EU) 2024/1689)
The EU AI Act is the first comprehensive AI law: it applies to essentially every company that puts an AI system on the EU market or uses one in the EU — including ordinary businesses that merely deploy AI tools bought from vendors.
EU Cyber Resilience Act (Regulation (EU) 2024/2847)
The Cyber Resilience Act is EU product law for anything with digital elements — hardware, embedded devices, and software — placed on the EU market.
EU Data Act (Regulation (EU) 2023/2854)
The Data Act is the EU's horizontal law on who may use the data that connected products, related services and cloud platforms generate.
European Accessibility Act (Directive (EU) 2019/882) and EN 301 549
The European Accessibility Act sets accessibility requirements for a defined list of consumer products and services sold into the EU — e-commerce, consumer banking, electronic communications, audiovisual media access, passenger transport, e-books, self-service terminals, computer hardware, e-readers and consumer terminal equipment.
GDPR — Operational Compliance
The General Data Protection Regulation applies to essentially every company handling personal data of people in the EU — customers, users, employees, prospects.
NIS2 Directive (EU 2022/2555)
NIS2 is the EU's cybersecurity law for essential and important entities — energy, transport, health, digital infrastructure, manufacturing, digital providers, and more, generally from 50 employees or EUR 10M turnover in the listed sectors.
RED Cybersecurity (Directive 2014/53/EU, Art. 3(3)(d)-(f))
The cybersecurity requirements of the EU Radio Equipment Directive, in force for radio equipment placed on the EU market.
Scheme / frameworks
AI Impact Assessments (DPIA · FRIA · ISO/IEC 42005)
Three assessment instruments now converge on companies deploying AI in the EU: the GDPR data protection impact assessment (DPIA) where processing is high-risk for individuals, the AI Act fundamental rights impact assessment (FRIA) for certain deployers of high-risk AI, and the ISO/IEC 42005 AI system impact assessment as the management-system practice tying it together.
BSI C5 — Cloud Computing Compliance Criteria Catalogue
C5 is a criteria catalogue published by Germany's Federal Office for Information Security (BSI) that defines a minimum baseline of information security for professional cloud services.
NIST AI Risk Management Framework 1.0
The NIST AI Risk Management Framework is a voluntary, non-certifiable framework for managing the risks of designing, developing, deploying, and using AI systems — organized into four functions: Govern (the standing organizational machinery), Map (understanding each system in context), Measure (testing and tracking trustworthiness), and Manage (acting on what you find).
NIST Cybersecurity Framework 2.0
The NIST Cybersecurity Framework 2.0, published February 2024, organises cybersecurity outcomes into six functions, 22 categories and 106 subcategories.
PCI DSS v4.0.1
The Payment Card Industry Data Security Standard applies to every organisation that stores, processes or transmits cardholder data, and to service providers that can affect the security of a customer's cardholder data environment.
SOC 2 (AICPA Trust Services Criteria)
SOC 2 is a US-origin attestation scheme in which a CPA firm audits your controls against the AICPA Trust Services Criteria and issues a report your customers can rely on.
SWIFT Customer Security Programme (CSCF v2026)
The Customer Security Programme is SWIFT's mandatory security regime for every institution connected to the SWIFT network.
TISAX (VDA ISA 6.0)
TISAX is the automotive industry's information security assessment scheme, governed by the ENX Association and based on the VDA ISA catalogue.
VAPT / Security Testing
A practical security-testing checklist for EU-facing products: define the scope and authorization, confirm the attack surface, test safely, capture evidence, rate the findings, track remediation, and retest before closeout.
One subscription. Every framework on this page.
There is no per-framework pricing and never will be. Start with one, add another when you are ready — and the work you have already settled carries across where the frameworks overlap. Your first 30 days are free, with no card.