Framework guides
Organise evidence against each framework's control library
One guide per supported framework — its full control library as a versioned, change-controlled catalogue. 10 frameworks, 523 requirement-level criteria.
ISO/IEC 27001
SecurityISO/IEC 27001:2022
The full Annex A control library (93 controls) plus clauses 4–10, versioned and change-controlled.
Free readiness kitSOC 2
SecuritySOC 2 — Trust Services Criteria
A catalogue of the Trust Services Criteria (57), organised by the five trust services categories.
Free readiness kitGDPR
PrivacyRegulation (EU) 2016/679
A catalogue of GDPR obligations (48) across Articles 5–49, versioned with provenance.
Free readiness kitNIST CSF 2.0
SecurityNIST Cybersecurity Framework 2.0
The full CSF 2.0 subcategory library (106) across the Govern, Identify, Protect, Detect, Respond, Recover functions.
Free readiness kitDORA
FinancialDigital Operational Resilience Act
An article-level requirement library (37) across DORA's five resilience pillars.
MiCA
FinancialMarkets in Crypto-Assets Regulation
Obligation libraries (45) for both token issuers and crypto-asset service providers (CASPs).
Essential Eight
SecurityACSC Essential Eight Maturity Model
The eight ACSC mitigation strategies as a curated, maturity-aware control library.
APRA CPS 234
FinancialAPRA Prudential Standard CPS 234
A requirement library (24) covering CPS 234 information-security obligations for APRA-regulated entities.
Interactive self-assessmentNIST AI RMF
AI governanceNIST AI Risk Management Framework 1.0
The AI RMF subcategory library (72) across the Govern, Map, Measure, Manage functions.
EU AI Act
AI governanceRegulation (EU) 2024/1689
An obligation library (33) addressing EU AI Act requirements for high-risk and GPAI obligations.
Four frameworks come with a free, downloadable readiness kit of templates and registers; APRA CPS 234 has an interactive self-assessment. Whatever you collect, the evidence-quality guide explains what makes it sufficient.
These are catalogue-depth guides — how to organise evidence against each framework's controls and obligations today. ISO 42001 is not a supported framework and is not counted in the ten; where relevant it is informed-by only, never “supported.”
Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. Where the boundary sits.
See a readiness export
Framework libraries are how you organise evidence. A readiness export is what you hand to a stakeholder or assessor.