Framework guides

Organise evidence against each framework's control library

One guide per supported framework — its full control library as a versioned, change-controlled catalogue. 10 frameworks, 523 requirement-level criteria.

ISO/IEC 27001

Security

ISO/IEC 27001:2022

The full Annex A control library (93 controls) plus clauses 4–10, versioned and change-controlled.

Free readiness kit
93 criteriaOpen guide

SOC 2

Security

SOC 2 — Trust Services Criteria

A catalogue of the Trust Services Criteria (57), organised by the five trust services categories.

Free readiness kit
57 criteriaOpen guide

GDPR

Privacy

Regulation (EU) 2016/679

A catalogue of GDPR obligations (48) across Articles 5–49, versioned with provenance.

Free readiness kit
48 criteriaOpen guide

NIST CSF 2.0

Security

NIST Cybersecurity Framework 2.0

The full CSF 2.0 subcategory library (106) across the Govern, Identify, Protect, Detect, Respond, Recover functions.

Free readiness kit
106 criteriaOpen guide

DORA

Financial

Digital Operational Resilience Act

An article-level requirement library (37) across DORA's five resilience pillars.

37 criteriaOpen guide

MiCA

Financial

Markets in Crypto-Assets Regulation

Obligation libraries (45) for both token issuers and crypto-asset service providers (CASPs).

45 criteriaOpen guide

Essential Eight

Security

ACSC Essential Eight Maturity Model

The eight ACSC mitigation strategies as a curated, maturity-aware control library.

8 criteriaOpen guide

APRA CPS 234

Financial

APRA Prudential Standard CPS 234

A requirement library (24) covering CPS 234 information-security obligations for APRA-regulated entities.

Interactive self-assessment
24 criteriaOpen guide

NIST AI RMF

AI governance

NIST AI Risk Management Framework 1.0

The AI RMF subcategory library (72) across the Govern, Map, Measure, Manage functions.

72 criteriaOpen guide

EU AI Act

AI governance

Regulation (EU) 2024/1689

An obligation library (33) addressing EU AI Act requirements for high-risk and GPAI obligations.

33 criteriaOpen guide

Four frameworks come with a free, downloadable readiness kit of templates and registers; APRA CPS 234 has an interactive self-assessment. Whatever you collect, the evidence-quality guide explains what makes it sufficient.

These are catalogue-depth guides — how to organise evidence against each framework's controls and obligations today. ISO 42001 is not a supported framework and is not counted in the ten; where relevant it is informed-by only, never “supported.”

Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. Where the boundary sits.

See a readiness export

Framework libraries are how you organise evidence. A readiness export is what you hand to a stakeholder or assessor.