Compliance library
Compliance frameworks and regulations
Practical, factually-grounded guides to the standards and regulations organizations actually have to meet — what each one requires, the evidence auditors expect, and what can reasonably be automated.
Information security
ISO 27001
What ISO 27001 is, who it applies to, its core requirements and Annex A controls, the evidence auditors expect, and what compliance work can be automated.
See how Isodora helpsData protection
GDPR
What the GDPR requires, who it applies to, the records and DPIAs you need, breach-notification timelines, and how to keep data-protection compliance continuous.
See how Isodora helpsCybersecurity regulation
NIS2
What the NIS2 Directive is, which essential and important entities it covers, its risk-management and incident-reporting duties, and how to operationalize them.
See how Isodora helpsFinancial resilience regulation
DORA
What DORA requires, which financial entities it covers, its five pillars including ICT third-party risk and resilience testing, and how to operationalize it.
See how Isodora helpsAI regulation
EU AI Act
What the EU AI Act requires, who it applies to, its risk-based tiers and high-risk obligations, the application timeline, and how to operationalize AI governance.
See how Isodora helpsAI management
ISO 42001
What ISO/IEC 42001 is, who it is for, its AI-specific requirements and Annex A controls, how it supports EU AI Act readiness, and how to run an AIMS continuously.
See how Isodora helpsAttestation report
SOC 2
What SOC 2 is, the difference between Type I and Type II, the Trust Services Criteria, the evidence auditors expect, and how it overlaps ISO 27001.
See how Isodora helpsQuality management
ISO 9001
What ISO 9001 is, who it is for, its process approach and core clauses, the evidence auditors expect, and how to run a quality management system continuously.
See how Isodora helpsHealth data protection
HIPAA
What HIPAA requires, who it applies to, the Privacy, Security and Breach Notification Rules, the safeguards and BAAs auditors expect, and how it overlaps ISO 27001.
See how Isodora helpsMedical devices
ISO 13485
What ISO 13485 is, who it is for, its medical-device QMS requirements (design controls, risk, traceability, CAPA), the evidence auditors expect, and how it links to ISO 9001.
See how Isodora helpsFull library
Every framework Isodora supports
Isodora supports 21 frameworks and regulations out of the box — plus your own custom frameworks. Cards marked “Guide” link to an in-depth explainer.
Information security & resilience
Data protection & privacy
Artificial intelligence
Quality & operations
Environment & sustainability
People & workplace
Don’t see your framework? Bring your own.
Beyond the standards above, Isodora supports custom frameworks — bring your own requirements (for example TISAX, an internal control framework or an industry-specific standard) and get the same analysis, evidence and continuous monitoring as the built-in frameworks.
Talk to us about custom frameworks