ALL FRAMEWORKS

Compliance frameworks for every requirement that matters

Explore the compliance frameworks Secrato supports—from GDPR, NIS 2 and DORA to ISO 27001—in one connected, EU-first GRC platform.

FRAMEWORKS SECRATO SUPPORTS

Compliance frameworks that matter for Europe

Secrato is built for European businesses first, delivering seamless compliance coverage for critical EU regulations and global standards.

16+

FRAMEWORKS

1

CONTROL LIBRARY
Compliance frameworks supported by Secrato
EU REGULATIONS & DIRECTIVES

Binding obligations set by EU

NIS 2 DIRECTIVE

NIS 2

EU directive setting cybersecurity and incident-reporting obligations for essential and important entities. 

DATA PROTECTION

GDPR

EU regulation governing the protection of personal data and privacy for individuals in the EU.

RESILIENCE ACT

DORA

EU regulation setting ICT risk management and resilience requirements for the financial sector.

CYBER RESILIENCE ACT

CRA

EU regulation setting cybersecurity requirements for products with digital elements sold in the EU market.

INTERNATIONAL MANAGEMENT STANDARDS

Certifiable management systems across markets and sectors

ISMS

ISO 27001

International standard for establishing and maintaining an information security management system.

QMS

ISO 9001

International standard for quality management systems.

EMS

ISO 14001

International standard for environmental management systems.

AIMS

ISO/IEC 42001

International standard for management systems governing the responsible use of artificial intelligence.

BCMS

ISO 22301

International standard for business continuity management systems.

CYBERSECURITY FRAMEWORK

NIST CSF 2.0

Voluntary framework for managing and reducing cybersecurity risk, organised around core functions.

NATIONAL & REGIONAL SCHEMES

Country-specific requirements set by national cybersecurity authorities

CYBERFUNDAMENTALS

CYFUN

Belgian cybersecurity framework of baseline controls for organisations operating in Belgium.

FRENCH NAT'L SCHEME

ANSSI

Reference security requirements and certification schemes set by France’s national cybersecurity agency.

GERMAN NAT'L SCHEME

BSI

Reference security standards and certification schemes, including IT-Grundschutz, set by Germany’s federal cybersecurity agency.

INDUSTRY-SPECIFIC STANDARDS

Sector standards required for specific supply chains and industries

AUTOMOTIVE SECURITY

TISAX

Information security assessment and exchange standard used across the automotive industry.

PAYMENT CARD SECURITY

PCI DSS

Global security standard for organisations handling payment card data.

INDUSTRIAL CONTROL SECURITY

IEC 62443

International standard for security of industrial automation and control systems.

CUSTOM FRAMEWORKS

Don't see your framework? Ask Secrato to build it for you. Or create a custom one.

Combine requirements from any standard framework or your own internal policies into a framework built around your organisation, tracked the same way as everything else in the register. 

EU DATA SOVEREIGNTY

GRC data is processed on self-managed infrastructure in a Belgian datacentre, within the EU legal and regulatory environment.

Belgium · EU

Common questions

Which frameworks does Secrato support today?

Secrato covers 16+ frameworks across four groups: EU regulations and directives, international management standards, national and regional schemes, and industry-specific standards. The full set is listed in the register above and new frameworks are added regularly.

You can build it yourself. Alongside the supported frameworks, Secrato lets you compile controls from any standard framework or your own internal policies into a custom framework, tracked the same way as every other entry in the register.

No. When a control satisfies requirements across more than one framework, Secrato maps it once and reuses it everywhere it applies. Mapping a control for NIS2 that also counts toward ISO 27001 means the work carries across without being repeated.

Run your frameworks in Secrato

Request a demo and we’ll walk through the frameworks that apply to your organisation, and how Secrato maps them together.

Secrato