Resources · Standards and frameworks

STANDARDS AND FRAMEWORKS

ISO/IEC 27001, CIS Controls, NIST CSF, SOC 2 and NÚKIB guidance. Each serves a different purpose — here is how to decide between them.

Get your bearings first

A standard, a framework, an attestation and legislation are four different things

A certifiable standard, a catalogue of controls, a management framework and an attestation report are evidenced in different ways, and none of them replaces legislation. The guide explains how they differ and what each one is good for; the FAQ answers the situations in which the decision gets stuck.

Guide · 20 min read

Guide to standards and frameworks

What is actually certified under ISO/IEC 27001 and what the certificate evidences. CIS Controls Implementation Groups, the six NIST CSF functions, SOC 2 as a report instead of a stamp, the status of NÚKIB guidance, and where security ends and personal data protection begins.

Open the guide →
FAQ · common questions

FAQ on standards and frameworks

A customer wants ISO — do we have to have it? Are CIS Controls enough? Will certification cover the Cybersecurity Act or the GDPR? What it means when a supplier sends a SOC 2 report, how type 1 differs from type 2 and how such a report is read.

Open the FAQ →

From reading to managing

When you want to run it, not just read up on it

A framework on its own solves nothing. The work starts where you find out where you stand, and where the result has to hold until the next audit. For continuous management we have our own platform; for a one-off picture of the current state, a service with a deadline and a deliverable. Both lead outside the Resources section.

Observa · our GRC platform

Frameworks in one tool instead of a spreadsheet

Observa connects requirements across eleven frameworks — the Czech Cybersecurity Act, NIS2, ISO 27001, DORA, NIST and others — and keeps records of assets, risks, suppliers, policies and incidents in one place; all eleven frameworks at once are on the Enterprise plan. Seven-day free trial, no payment card and no commitment, in limited scope; pricing from CZK 2 990 per month.

Open Observa →
Service · Security Assessment

An independent view of where you stand today

A maturity assessment against NIST CSF, ISO/IEC 27001 or CIS Controls and a regulatory gap analysis against the Cybersecurity Act, DORA or a standard. The output is a map of requirements, the gaps found and a prioritised plan, not a score. A rapid assessment takes one to two weeks; a regulatory gap analysis depends on the framework and the scope — for the Cybersecurity Act, two to three weeks in the lower regime and four to six in the higher one.

Open the service →
Content valid as of 8 August 2026

Where we can help

One management system,
several addressees.

Picking a framework is a decision that takes hours; implementing it is months of work — and most of that work can be done once for several addressees at the same time. We run maturity assessments against the chosen framework, gap analyses against the decrees, and we set records up so that one control and one piece of evidence serve the standard, the legislation and a customer questionnaire alike. Write to us with what you need to evidence and to whom; we will scope it from there.