# Isodora > Isodora is an AI-powered compliance platform that helps organizations implement, manage and continuously verify regulatory and certification requirements — including ISO 27001, GDPR, NIS2, DORA, SOC 2 and ISO 9001. Isodora is an AI-powered compliance platform based in Sweden and built for European regulatory depth. It helps organizations implement, manage and continuously verify regulatory and certification requirements — running automated controls in the background and building a regulator-grade audit trail. Content below is English (en-US); Swedish equivalents are available under /sv-SE. ## Core pages - [What is Isodora?](https://www.isodora.se/en-US/what-is-isodora): Canonical explanation of the product, who it is for, and how it differs from traditional tools - [Product](https://www.isodora.se/en-US/product): Fit/Gap analysis, integrated management system, supplier registry, reports - [Pricing](https://www.isodora.se/en-US/pricing): Modular, transparent pricing from a platform fee - [For Europe](https://www.isodora.se/en-US/for/europe): European regulatory depth: ISO, CSRD, NIS2, DORA, EU AI Act - [Switch from Vanta](https://www.isodora.se/en-US/switch): How Isodora keeps you compliant after certification - [About](https://www.isodora.se/en-US/about): Company background and mission - [Press release](https://www.isodora.se/en-US/news/isodora-opens-compliance-platform): Isodora opens its compliance platform to Swedish small businesses ## Free tools - [Does the Swedish Cybersecurity Act (NIS2) apply to you?](https://www.isodora.se/en-US/tools/nis2-omfattning): Indicative scope check: sector, size and size-independent entities, plus duties and timeline. Swedish version at /sv-SE/tools/nis2-omfattning ## Compliance frameworks - [ISO 27001](https://www.isodora.se/en-US/frameworks/iso-27001): What ISO 27001 is, who it applies to, its core requirements and Annex A controls, the evidence auditors expect, and what compliance work can be automated. - [GDPR](https://www.isodora.se/en-US/frameworks/gdpr): What the GDPR requires, who it applies to, the records and DPIAs you need, breach-notification timelines, and how to keep data-protection compliance continuous. - [NIS2](https://www.isodora.se/en-US/frameworks/nis2): What the NIS2 Directive is, which essential and important entities it covers, its risk-management and incident-reporting duties, and how to operationalize them. - [DORA](https://www.isodora.se/en-US/frameworks/dora): What DORA requires, which financial entities it covers, its five pillars including ICT third-party risk and resilience testing, and how to operationalize it. - [EU AI Act](https://www.isodora.se/en-US/frameworks/eu-ai-act): What the EU AI Act requires, who it applies to, its risk-based tiers and high-risk obligations, the application timeline, and how to operationalize AI governance. - [ISO 42001](https://www.isodora.se/en-US/frameworks/iso-42001): What ISO/IEC 42001 is, who it is for, its AI-specific requirements and Annex A controls, how it supports EU AI Act readiness, and how to run an AIMS continuously. - [SOC 2](https://www.isodora.se/en-US/frameworks/soc-2): What SOC 2 is, the difference between Type I and Type II, the Trust Services Criteria, the evidence auditors expect, and how it overlaps ISO 27001. - [ISO 9001](https://www.isodora.se/en-US/frameworks/iso-9001): What ISO 9001 is, who it is for, its process approach and core clauses, the evidence auditors expect, and how to run a quality management system continuously. - [HIPAA](https://www.isodora.se/en-US/frameworks/hipaa): What HIPAA requires, who it applies to, the Privacy, Security and Breach Notification Rules, the safeguards and BAAs auditors expect, and how it overlaps ISO 27001. - [ISO 13485](https://www.isodora.se/en-US/frameworks/iso-13485): What ISO 13485 is, who it is for, its medical-device QMS requirements (design controls, risk, traceability, CAPA), the evidence auditors expect, and how it links to ISO 9001. ## Use cases & concepts - [Compliance automation](https://www.isodora.se/en-US/use-cases/compliance-automation): Compliance automation uses software to reduce the manual work of implementing, monitoring and demonstrating compliance. Here is what it covers and how it works. - [AI compliance software](https://www.isodora.se/en-US/use-cases/ai-compliance): How AI compliance tools work: what AI can genuinely automate in a compliance program, where human judgement is still required, and how to adopt it safely. - [Continuous compliance](https://www.isodora.se/en-US/use-cases/continuous-compliance): Continuous compliance means controls are verified and evidenced all year, not reconstructed before an audit. Here is what it means and why it matters. - [Compliance for startups](https://www.isodora.se/en-US/use-cases/compliance-for-startups): How startups and SMBs can reach ISO 27001, SOC 2 and GDPR compliance without a large team or six-figure consulting projects — and what to prioritize first. ## Answers to buyer questions - [Customer requires ISO 27001](https://www.isodora.se/en-US/answers/kund-kraver-iso-27001): Your biggest customer requires ISO 27001 certification. How a 10–100-person company gets from the requirement to a certificate in 3–6 months: what the customer actually requires, what you can promise today, timeline and cost. - [Answering a security annex](https://www.isodora.se/en-US/answers/svara-pa-sakerhetsbilaga): The customer sends a security annex or an 80-question supplier questionnaire. What they ask, how to answer without lying, which answers kill the deal, and how to build an answer bank you reuse. - [Does the AI Act apply to us?](https://www.isodora.se/en-US/answers/galler-ai-forordningen-oss): You use ChatGPT, shipped an AI feature in your product or bought an AI tool. How to decide whether the EU AI Act applies to you, in which role, which duties already apply and which arrive 2026–2028. - [What does ISO 27001 cost?](https://www.isodora.se/en-US/answers/iso-27001-kostnad): ISO 27001 certification costs SEK 150,000–700,000 in the first year for a Swedish company with 10–100 employees, depending on whether you hire a consultant, do it yourself or use a platform. Cost table per item, public sources and a calculator. ## Comparisons - [Isodora vs Vanta](https://www.isodora.se/en-US/compare/isodora-vs-vanta): Isodora and Vanta compared on price, frameworks, EU hosting, SIS licence, self-service and target customer. Vanta does not publish prices; Isodora starts at SEK 500/month. Updated September 2026. - [Isodora vs Kravklar](https://www.isodora.se/en-US/compare/isodora-vs-kravklar): Kravklar and Isodora are both Swedish, self-serve and built for small companies — but solve different problems. Kravklar: GDPR, work environment and pay transparency from SEK 2,395/year. Isodora: ISO 27001, NIS2 and certification from SEK 500/month. - [Isodora vs consultant vs Excel](https://www.isodora.se/en-US/compare/isodora-vs-konsult): The three real options when a customer requires ISO 27001: hire a consultant (SEK 80,000–300,000), do it yourself in Excel (400–800 hours) or use Isodora (SEK 20,400/year). Time, cost, risk and what happens after the certificate. - [Vanta alternatives in Europe](https://www.isodora.se/en-US/compare/vanta-alternatives-europe): Seven European alternatives to Vanta for ISO 27001, NIS2, GDPR and the EU AI Act: Isodora, Kertos, Secfix, Cyberday, ChainSec, Noru and Orbiq. Where each is based, what it focuses on, and who it suits. Updated September 2026. ## Swedish (sv-SE) — primary market - [Omfattas vi av cybersäkerhetslagen (NIS2)?](https://www.isodora.se/sv-SE/tools/nis2-omfattning): Gratis vägledande bedömning: sektor, storlek, undantag, skyldigheter och tidsplan - [Priser](https://www.isodora.se/sv-SE/pricing): Plattform 500 kr/mån, ramverksprojekt 1 200 kr/mån, exklusive moms - [Kunden kräver ISO 27001](https://www.isodora.se/sv-SE/answers/kund-kraver-iso-27001): Er största kund kräver ISO 27001-certifiering. Så tar ett företag med 10–100 anställda sig från kravet till certifikat på 3–6 månader: vad kunden faktiskt kräver, vad ni kan lova nu, tidsplan och kostnad. - [Svara på säkerhetsbilagan](https://www.isodora.se/sv-SE/answers/svara-pa-sakerhetsbilaga): Kunden skickar en säkerhetsbilaga eller ett leverantörsformulär med 80 frågor. Vad de frågar om, hur ni svarar utan att ljuga, vilka svar som stoppar affären och hur ni bygger en svarsbank ni återanvänder. - [Gäller AI-förordningen oss?](https://www.isodora.se/sv-SE/answers/galler-ai-forordningen-oss): Ni använder ChatGPT, har byggt en AI-funktion i produkten eller köpt ett AI-verktyg. Så avgör ni om EU:s AI-förordning gäller er, i vilken roll, vilka krav som gäller redan nu och vilka som kommer 2026–2028. - [Vad kostar ISO 27001?](https://www.isodora.se/sv-SE/answers/iso-27001-kostnad): ISO 27001-certifiering kostar 150 000–700 000 kr första året för ett svenskt företag med 10–100 anställda, beroende på om ni anlitar konsult, gör det själva eller använder en plattform. Kostnadstabell per post, publika källor och en kalkylator. - [Isodora vs Vanta](https://www.isodora.se/sv-SE/compare/isodora-vs-vanta): Isodora och Vanta jämförda på pris, ramverk, EU-anpassning, SIS-licens, självbetjäning och målgrupp. Vanta publicerar inte priser; Isodora kostar från 500 kr/mån. Uppdaterad september 2026. - [Isodora vs Kravklar](https://www.isodora.se/sv-SE/compare/isodora-vs-kravklar): Kravklar och Isodora är båda svenska, självbetjänade och byggda för småföretag — men löser olika problem. Kravklar: GDPR, arbetsmiljö och lönetransparens från 2 395 kr/år. Isodora: ISO 27001, NIS2 och certifiering från 500 kr/mån. - [Isodora vs konsult vs Excel](https://www.isodora.se/sv-SE/compare/isodora-vs-konsult): De tre verkliga alternativen när kunden kräver ISO 27001: anlita konsult (80 000–300 000 kr), göra det själv i Excel (400–800 timmar) eller använda Isodora (20 400 kr/år). Tid, kostnad, risk och vad som händer efter certifikatet. - [Vanta-alternativ i Europa](https://www.isodora.se/sv-SE/compare/vanta-alternatives-europe): Sju europeiska alternativ till Vanta för ISO 27001, NIS2, GDPR och AI-förordningen: Isodora, Kertos, Secfix, Cyberday, ChainSec, Noru och Orbiq. Var de finns, vad de fokuserar på och vilka de passar. Uppdaterad september 2026. - [ISO 27001](https://www.isodora.se/sv-SE/frameworks/iso-27001): Vad ISO 27001 är, vilka det gäller, kärnkraven och Annex A-kontrollerna, vilka bevis revisorer förväntar sig och vilket arbete som kan automatiseras. - [GDPR](https://www.isodora.se/sv-SE/frameworks/gdpr): Vad GDPR kräver, vilka det gäller, vilka register och konsekvensbedömningar som behövs, tidsfrister för incidentanmälan och hur dataskyddet hålls löpande. - [NIS2](https://www.isodora.se/sv-SE/frameworks/nis2): Vad NIS2-direktivet är, vilka väsentliga och viktiga verksamheter det omfattar, kraven på riskhantering och incidentrapportering och hur de operationaliseras. - [DORA](https://www.isodora.se/sv-SE/frameworks/dora): Vad DORA kräver, vilka finansiella entiteter det omfattar, dess fem pelare inklusive tredjepartsrisk och motståndskraftstester, och hur det operationaliseras. - [EU AI Act](https://www.isodora.se/sv-SE/frameworks/eu-ai-act): Vad EU:s AI-förordning kräver, vilka den gäller, dess riskbaserade nivåer och krav på högrisksystem, tillämpningstidslinjen och hur AI-styrning operationaliseras. - [ISO 42001](https://www.isodora.se/sv-SE/frameworks/iso-42001): Vad ISO/IEC 42001 är, vilka det är för, dess AI-specifika krav och Annex A-kontroller, hur det stödjer beredskap för EU:s AI-förordning och hur ett AIMS körs löpande. - [SOC 2](https://www.isodora.se/sv-SE/frameworks/soc-2): Vad SOC 2 är, skillnaden mellan Type I och Type II, Trust Services Criteria, vilka bevis revisorer förväntar sig och hur det överlappar ISO 27001. - [ISO 9001](https://www.isodora.se/sv-SE/frameworks/iso-9001): Vad ISO 9001 är, vilka det är för, processansatsen och kärnkapitlen, vilka bevis revisorer förväntar sig och hur ett kvalitetsledningssystem körs löpande. - [HIPAA](https://www.isodora.se/sv-SE/frameworks/hipaa): Vad HIPAA kräver, vilka det gäller, Privacy-, Security- och Breach Notification-reglerna, de skyddsåtgärder och BAA-avtal revisorer förväntar sig och hur det överlappar ISO 27001. - [ISO 13485](https://www.isodora.se/sv-SE/frameworks/iso-13485): Vad ISO 13485 är, vilka det är för, kraven på QMS för medicintekniska produkter (designstyrning, risk, spårbarhet, CAPA), vilka bevis revisorer förväntar sig och kopplingen till ISO 9001. ## Hubs - [Frameworks](https://www.isodora.se/en-US/frameworks) - [Resources](https://www.isodora.se/en-US/resources) ## Notes - Isodora helps prepare and maintain compliance programs. Certificates and attestation reports are issued by independent accredited bodies or auditors after their own examinations; no software guarantees a certificate. - Data can be stored and processed entirely in the EU.