Frameworks
Framework libraries built for evidence-based readiness
10 framework libraries available today — 523 curated, versioned, change-controlled control entries to organise your evidence around, under a clear readiness‑not‑certification boundary.
Evidence tools help you collect and organise documents. Netallion is built to assess the evidential basis of a readiness conclusion — requirement by requirement.
See how that compares10 frameworks
523 control library entries
Versioned & change-controlled
Readiness, not certification
How readiness is reached
From framework to a defensible readiness conclusion
The libraries are the foundation; the value is what happens once evidence arrives — see the methodology.
By your regulatory context
Find the framework that matters to you
Each links to its framework page. The count shown is that framework's number of requirement entries — proof of depth, not the proposition itself.
Security & assurance
ISO/IEC 27001
ISO/IEC 27001:2022
Find evidence weaknesses before the certification audit does.
93 requirement entries · versioned & change-controlled
SOC 2
SOC 2 — Trust Services Criteria
Walk into your SOC 2 examination knowing your evidence holds up.
57 requirement entries · versioned & change-controlled
NIST CSF 2.0
NIST Cybersecurity Framework 2.0
See which CSF outcomes your evidence actually supports — and which don’t.
106 requirement entries · versioned & change-controlled
Essential Eight
ACSC Essential Eight Maturity Model
Prove the Essential Eight maturity you can actually substantiate.
8 requirement entries · versioned & change-controlled
Financial & regulatory
GDPR
Regulation (EU) 2016/679
Turn scattered privacy records into an evidence-backed view of readiness.
48 requirement entries · versioned & change-controlled
DORA
Digital Operational Resilience Act
Know which operational-resilience obligations are evidenced before supervisory scrutiny exposes the gaps.
37 requirement entries · versioned & change-controlled
MiCA
Markets in Crypto-Assets Regulation
Evidence your MiCA obligations before the competent authority asks.
45 requirement entries · versioned & change-controlled
APRA CPS 234
APRA Prudential Standard CPS 234
Evidence-based CPS 234 readiness — before APRA looks.
24 requirement entries · versioned & change-controlled
AI governance
NIST AI RMF
NIST AI Risk Management Framework 1.0
Move from AI-governance principles to evidence you can actually defend.
72 requirement entries · versioned & change-controlled
EU AI Act
Regulation (EU) 2024/1689
Turn EU AI Act obligations into evidence you can show a regulator.
33 requirement entries · versioned & change-controlled
SOC 2 note. Netallion carries SOC 2 to catalogue depth (57 Trust Services Criteria); we do not claim evidence-guidance parity beyond what that criteria set carries. ISO 42001 is not one of the 10 — for AI governance today, see NIST AI RMF and the EU AI Act.
Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. Where the boundary sits.
See what your evidence proves
Pick the framework that matters to you and see how Netallion assesses whether your evidence is sufficient — with explicit blockers and traceable readiness.