Onwyn › Standards

Coverage

Standards we cover

Every framework below is live in the Semantic Compliance Engine as a guided, requirement-by-requirement program — not a checklist. Each requirement carries what to do, how to evidence it, what auditors commonly reject, and a senior consultant one click away.

22
Frameworks live
790
Requirements
401
Recommended documents
1
Subscription, all of them

Certifiable standards

ISO 22301:2019

ISO 22301 is the international standard for a business continuity management system (BCMS): a disciplined way of working out which of your activities the business cannot afford to lose, how fast they must be back, what it would take to get them there, and whether the plans actually work when tested.

38 requirements · 22 documents

ISO 9001:2015

ISO 9001 is the international standard for a quality management system: a structured way of understanding what your customers require, running the processes that deliver it under control, catching what goes wrong, and improving on the evidence.

48 requirements · 27 documents

ISO/IEC 27001:2022

ISO/IEC 27001 is the international standard for running an information security management system (ISMS): a repeatable way of deciding what to protect, treating the risks, and proving it works.

118 requirements · 32 documents

ISO/IEC 27701:2019

ISO/IEC 27701 turns an information security management system into a privacy information management system (PIMS): it adds privacy-specific management requirements on top of ISO/IEC 27001 and a set of controls for organizations that decide why personal data is processed (controllers) and for those that process it on someone else's instruction (processors).

66 requirements · 25 documents

ISO/IEC 42001:2023

ISO/IEC 42001 is the first certifiable management system standard for artificial intelligence: it structures how an organization governs the AI systems it develops or uses — responsibly, transparently, and with managed risk.

18 requirements · 15 documents

Regulations

DORA — Digital Operational Resilience Act (Regulation (EU) 2022/2554)

DORA is the EU's operational resilience law for the financial sector.

41 requirements · 25 documents

EU AI Act (Regulation (EU) 2024/1689)

The EU AI Act is the first comprehensive AI law: it applies to essentially every company that puts an AI system on the EU market or uses one in the EU — including ordinary businesses that merely deploy AI tools bought from vendors.

32 requirements · 15 documents

EU Cyber Resilience Act (Regulation (EU) 2024/2847)

The Cyber Resilience Act is EU product law for anything with digital elements — hardware, embedded devices, and software — placed on the EU market.

33 requirements · 16 documents

EU Data Act (Regulation (EU) 2023/2854)

The Data Act is the EU's horizontal law on who may use the data that connected products, related services and cloud platforms generate.

35 requirements · 23 documents

European Accessibility Act (Directive (EU) 2019/882) and EN 301 549

The European Accessibility Act sets accessibility requirements for a defined list of consumer products and services sold into the EU — e-commerce, consumer banking, electronic communications, audiovisual media access, passenger transport, e-books, self-service terminals, computer hardware, e-readers and consumer terminal equipment.

35 requirements · 15 documents

GDPR — Operational Compliance

The General Data Protection Regulation applies to essentially every company handling personal data of people in the EU — customers, users, employees, prospects.

21 requirements · 18 documents

NIS2 Directive (EU 2022/2555)

NIS2 is the EU's cybersecurity law for essential and important entities — energy, transport, health, digital infrastructure, manufacturing, digital providers, and more, generally from 50 employees or EUR 10M turnover in the listed sectors.

21 requirements · 16 documents

RED Cybersecurity (Directive 2014/53/EU, Art. 3(3)(d)-(f))

The cybersecurity requirements of the EU Radio Equipment Directive, in force for radio equipment placed on the EU market.

46 requirements · 22 documents

Scheme / frameworks

AI Impact Assessments (DPIA · FRIA · ISO/IEC 42005)

Three assessment instruments now converge on companies deploying AI in the EU: the GDPR data protection impact assessment (DPIA) where processing is high-risk for individuals, the AI Act fundamental rights impact assessment (FRIA) for certain deployers of high-risk AI, and the ISO/IEC 42005 AI system impact assessment as the management-system practice tying it together.

17 requirements · 10 documents

BSI C5 — Cloud Computing Compliance Criteria Catalogue

C5 is a criteria catalogue published by Germany's Federal Office for Information Security (BSI) that defines a minimum baseline of information security for professional cloud services.

42 requirements · 26 documents

NIST AI Risk Management Framework 1.0

The NIST AI Risk Management Framework is a voluntary, non-certifiable framework for managing the risks of designing, developing, deploying, and using AI systems — organized into four functions: Govern (the standing organizational machinery), Map (understanding each system in context), Measure (testing and tracking trustworthiness), and Manage (acting on what you find).

25 requirements · 12 documents

NIST Cybersecurity Framework 2.0

The NIST Cybersecurity Framework 2.0, published February 2024, organises cybersecurity outcomes into six functions, 22 categories and 106 subcategories.

24 requirements · 14 documents

PCI DSS v4.0.1

The Payment Card Industry Data Security Standard applies to every organisation that stores, processes or transmits cardholder data, and to service providers that can affect the security of a customer's cardholder data environment.

26 requirements · 12 documents

SOC 2 (AICPA Trust Services Criteria)

SOC 2 is a US-origin attestation scheme in which a CPA firm audits your controls against the AICPA Trust Services Criteria and issues a report your customers can rely on.

37 requirements · 23 documents

SWIFT Customer Security Programme (CSCF v2026)

The Customer Security Programme is SWIFT's mandatory security regime for every institution connected to the SWIFT network.

34 requirements · 12 documents

TISAX (VDA ISA 6.0)

TISAX is the automotive industry's information security assessment scheme, governed by the ENX Association and based on the VDA ISA catalogue.

26 requirements · 21 documents

VAPT / Security Testing

A practical security-testing checklist for EU-facing products: define the scope and authorization, confirm the attack surface, test safely, capture evidence, rate the findings, track remediation, and retest before closeout.

7 requirements · 0 documents

One subscription. Every framework on this page.

There is no per-framework pricing and never will be. Start with one, add another when you are ready — and the work you have already settled carries across where the frameworks overlap. Your first 30 days are free, with no card.