Onwyn › Standards
CoverageStandards we cover
Every framework below is live in the Compliance Engine as a guided, requirement-by-requirement program — not a checklist. Each requirement carries what to do, how to evidence it, what auditors commonly reject, and a senior consultant one click away.
Certifiable standards
ISO 22301:2019
ISO 22301 is the international standard for a business continuity management system (BCMS): a disciplined way of working out which of your activities the business cannot afford to lose, how fast they must be back, what it would take to get them there, and whether the plans actually work when tested.
ISO 9001:2015
ISO 9001 is the international standard for a quality management system: a structured way of understanding what your customers require, running the processes that deliver it under control, catching what goes wrong, and improving on the evidence.
ISO/IEC 27001:2022
ISO/IEC 27001 is the international standard for running an information security management system (ISMS): a repeatable way of deciding what to protect, treating the risks, and proving it works.
ISO/IEC 27701:2019
ISO/IEC 27701 turns an information security management system into a privacy information management system (PIMS): it adds privacy-specific management requirements on top of ISO/IEC 27001 and a set of controls for organizations that decide why personal data is processed (controllers) and for those that process it on someone else's instruction (processors).
ISO/IEC 42001:2023
ISO/IEC 42001 is the first certifiable management system standard for artificial intelligence: it structures how an organization governs the AI systems it develops or uses — responsibly, transparently, and with managed risk.
Regulations
DORA — Digital Operational Resilience Act (Regulation (EU) 2022/2554)
DORA is the EU's operational resilience law for the financial sector.
EU AI Act (Regulation (EU) 2024/1689)
The EU AI Act is the first comprehensive AI law: it applies to essentially every company that puts an AI system on the EU market or uses one in the EU — including ordinary businesses that merely deploy AI tools bought from vendors.
EU Cyber Resilience Act (Regulation (EU) 2024/2847)
The Cyber Resilience Act is EU product law for anything with digital elements — hardware, embedded devices, and software — placed on the EU market.
GDPR — Operational Compliance
The General Data Protection Regulation applies to essentially every company handling personal data of people in the EU — customers, users, employees, prospects.
NIS2 Directive (EU 2022/2555)
NIS2 is the EU's cybersecurity law for essential and important entities — energy, transport, health, digital infrastructure, manufacturing, digital providers, and more, generally from 50 employees or EUR 10M turnover in the listed sectors.
Scheme / frameworks
AI Impact Assessments (DPIA · FRIA · ISO/IEC 42005)
Three assessment instruments now converge on companies deploying AI in the EU: the GDPR data protection impact assessment (DPIA) where processing is high-risk for individuals, the AI Act fundamental rights impact assessment (FRIA) for certain deployers of high-risk AI, and the ISO/IEC 42005 AI system impact assessment as the management-system practice tying it together.
BSI C5 — Cloud Computing Compliance Criteria Catalogue
C5 is a criteria catalogue published by Germany's Federal Office for Information Security (BSI) that defines a minimum baseline of information security for professional cloud services.
NIST AI Risk Management Framework 1.0
The NIST AI Risk Management Framework is a voluntary, non-certifiable framework for managing the risks of designing, developing, deploying, and using AI systems — organized into four functions: Govern (the standing organizational machinery), Map (understanding each system in context), Measure (testing and tracking trustworthiness), and Manage (acting on what you find).
SOC 2 (AICPA Trust Services Criteria)
SOC 2 is a US-origin attestation scheme in which a CPA firm audits your controls against the AICPA Trust Services Criteria and issues a report your customers can rely on.
TISAX (VDA ISA 6.0)
TISAX is the automotive industry's information security assessment scheme, governed by the ENX Association and based on the VDA ISA catalogue.
One subscription. Every framework on this page.
There is no per-framework pricing and never will be. Start with one, add another when you are ready — and the work you have already settled carries across where the frameworks overlap. Your first 30 days are free, with no card.