Resources · Standards and frameworks
ISO/IEC 27001, CIS Controls, NIST CSF, SOC 2 and NÚKIB guidance. Each serves a different purpose — here is how to decide between them.
Get your bearings first
A certifiable standard, a catalogue of controls, a management framework and an attestation report are evidenced in different ways, and none of them replaces legislation. The guide explains how they differ and what each one is good for; the FAQ answers the situations in which the decision gets stuck.
What is actually certified under ISO/IEC 27001 and what the certificate evidences. CIS Controls Implementation Groups, the six NIST CSF functions, SOC 2 as a report instead of a stamp, the status of NÚKIB guidance, and where security ends and personal data protection begins.
Open the guide → FAQ · common questionsA customer wants ISO — do we have to have it? Are CIS Controls enough? Will certification cover the Cybersecurity Act or the GDPR? What it means when a supplier sends a SOC 2 report, how type 1 differs from type 2 and how such a report is read.
Open the FAQ →From reading to managing
A framework on its own solves nothing. The work starts where you find out where you stand, and where the result has to hold until the next audit. For continuous management we have our own platform; for a one-off picture of the current state, a service with a deadline and a deliverable. Both lead outside the Resources section.
Observa connects requirements across eleven frameworks — the Czech Cybersecurity Act, NIS2, ISO 27001, DORA, NIST and others — and keeps records of assets, risks, suppliers, policies and incidents in one place; all eleven frameworks at once are on the Enterprise plan. Seven-day free trial, no payment card and no commitment, in limited scope; pricing from CZK 2 990 per month.
Open Observa → Service · Security AssessmentA maturity assessment against NIST CSF, ISO/IEC 27001 or CIS Controls and a regulatory gap analysis against the Cybersecurity Act, DORA or a standard. The output is a map of requirements, the gaps found and a prioritised plan, not a score. A rapid assessment takes one to two weeks; a regulatory gap analysis depends on the framework and the scope — for the Cybersecurity Act, two to three weeks in the lower regime and four to six in the higher one.
Open the service →Where we can help
Picking a framework is a decision that takes hours; implementing it is months of work — and most of that work can be done once for several addressees at the same time. We run maturity assessments against the chosen framework, gap analyses against the decrees, and we set records up so that one control and one piece of evidence serve the standard, the legislation and a customer questionnaire alike. Write to us with what you need to evidence and to whom; we will scope it from there.