All Frameworks

Explore Every Framework in One Place

Every compliance journey starts with the right framework. Secrato brings together EU and global standards — from ISO 27001 to GDPR and more — in one seamless experience where you can align controls, automate tracking, and prove compliance readiness faster than ever.

SECRATO GRC PLATFORM NIS2 EU Directive ISO 27001 Info Security GDPR Data Protection ANSSI French Cyber ISO 22301 Business Continuity DORA Digital Resilience TISAX Automotive CyFUN 2025 Belgian Cyber EU CRA Cyber Resilience BSI German Cyber ISO 9001 Quality Mgmt ISO 42001 AI Governance NIST CSF 2.0 Cybersecurity PCI DSS v4.0 Payment Security

Comprehensive Framework for Europe

Secrato is built for European businesses first, delivering seamless compliance coverage for critical EU regulations and global standards.

Secrato’s Essential Frameworks
Built for European regulations first with global compliance coverage

GDPR
EU Regulation
GDPR
General Data Protection Regulation

The foundational EU law for privacy and personal data rights across all sectors.

Explore framework →
NIS 2
EU Regulation
NIS 2
Network and Information Security Directive 2

Mandatory cybersecurity requirements for essential and important entities across the EU.

Explore framework →
DORA
EU Regulation
DORA
Digital Operational Resilience Act

ICT risk management and operational resilience requirements for financial institutions.

Explore framework →
CRA
EU Regulation
CRA
EU Cyber Resilience Act

Mandatory cybersecurity requirements for products with digital elements sold in the EU.

Explore framework →
EU AI Act
EU Regulation
EU AI Act
European Artificial Intelligence Act

The world's first comprehensive AI regulation — risk-based governance for AI development and deployment.

Explore framework →
CSA
EU Regulation
CSA
EU Cybersecurity Act

Establishes ENISA's permanent mandate and an EU-wide cybersecurity certification framework for ICT products and services.

Explore framework →
ISO 27001
International Standard
ISO 27001:2022
Information Security Management System

The world's leading ISMS standard — latest edition adds controls for cloud security, threat intelligence, and data masking.

Explore framework →
ISO 27701
International Standard
ISO 27701:2019
Privacy Information Management System

Extends ISO 27001 with GDPR-aligned privacy controls for both data controllers and processors.

Explore framework →
ISO 9001
International Standard
ISO 9001:2015
Quality Management System

The world's most widely adopted quality management standard — consistent products, services, and customer satisfaction.

Explore framework →
ISO 14001
International Standard
ISO 14001:2015
Environmental Management System

Environmental management and sustainability compliance — structured governance to reduce environmental impact.

Explore framework →
ISO 22301
International Standard
ISO 22301:2019
Business Continuity Management System

Helps organisations prepare for, respond to, and recover from disruptive incidents with structured continuity management.

Explore framework →
42001
International Standard
ISO/IEC 42001:2023
AI Management System

Governance framework for responsible AI development, deployment, and use — complementary to the EU AI Act.

Explore framework →
NIST CSF 2.0
International Standard
NIST CSF 2.0
NIST Cybersecurity Framework 2.0

Updated 2024 release adds a new Govern function and expanded supply chain risk guidance for organisations of all sizes.

Explore framework →
IEC 62443
International Standard
IEC 62443
Industrial Cybersecurity Standard

Cybersecurity standard for operational technology (OT) and industrial control systems — critical for manufacturing and infrastructure.

Explore framework →
PCI DSS v4.0
Industry-Specific
PCI DSS v4.0
Payment Card Industry Data Security Standard

Updated 2022 standard for protecting cardholder data — introduces a customised approach for mature organisations.

Explore framework →
PCI PIN
Industry-Specific
PCI PIN
PCI PIN Security Standard

Controls for secure management, processing, and transmission of PINs at ATMs and point-of-sale terminals.

Explore framework →
TISAX
Industry-Specific
TISAX
Trusted Information Security Assessment Exchange

Automotive industry information security standard for OEMs, suppliers, and service providers handling sensitive data.

Explore framework →
CYFUN 2025
Industry-Specific
CYFUN 2025
Belgian Cyber Fundamentals 2025

Updated 2025 edition with Basic, Essential, and Important tiers — aligned to NIS2 obligations for Belgian organisations.

Explore framework →
CYFUN 2023
Industry-Specific
CYFUN 2023
Belgian Cyber Fundamentals 2023

Foundational cybersecurity baseline for Belgian organisations — maintained alongside the updated 2025 version.

Explore framework →
ANSSI
Industry-Specific
ANSSI
Agence Nationale de la Sécurité des Systèmes d'Information

French national cybersecurity agency guidelines and certification schemes for critical operators and digital service providers.

Explore framework →
BSI
Industry-Specific
BSI
Bundesamt für Sicherheit in der Informationstechnik

German Federal Office for Information Security — IT-Grundschutz methodology and certification for public and private sector organisations.

Explore framework →

Features That Work For You

Framework Library
Every major framework, ready to use.

Natively supports the frameworks that matter most to European enterprises — ISO 27001, NIS2, CYFUN, GDPR, CRA, and more — with continuous coverage expansion.

Control Management
Define once. Apply across every framework.

Map, tag, group, and manage controls across frameworks in a structured environment — eliminating duplication and keeping governance consistent at scale.

Assessments Engine
Evaluate status, track readiness.

Run Y/N and maturity-based assessments (0–3, 0–5, or custom) across multiple frameworks simultaneously — without managing each one in isolation.

Evidence Management
Attach once, validate everywhere.

Manage evidence through manual uploads and automated API-based collection. Secrato recognises where evidence satisfies requirements across frameworks automatically.

Policy Linking & Versioning
Full traceability from policy to control.

Link policies directly to controls and requirements with version control for full traceability — keeping governance connected from documentation to execution.

API & Integrations
Connect your entire compliance ecosystem.

Connect with internal and external systems — Microsoft 365, cloud platforms, security tools, and more — to support smoother, more reliable evidence automation across all frameworks.

Secrato