Compliance en beveiliging

80+ frameworks, one management system: how to find the right ones for your organisation

Being ISO 27001 compliant already covers 82% of NIS2. Learn how to use Cyberday's comparison tool, AI suggestions and assessments to plan your framework stack.

Inhoud van het artikel

ISO 27001 collectie
80+ frameworks, one management system: how to find the right ones for your organisation
NIS2-verzameling
80+ frameworks, one management system: how to find the right ones for your organisation
Cyberday blog
80+ frameworks, one management system: how to find the right ones for your organisation

Ten years ago, "being compliant" usually meant one thing. You picked a standard, you worked towards it, you got the certificate, and you put the logo in your sales deck.

That era is over. An EU-based organisation today can easily find itself in scope for NIS2, GDPR, the AI Act and the Cyber Resilience Act at the same time, while its largest customer asks for ISO 27001 certification in the next procurement round and a public-sector tender quietly requires a national framework nobody in the company has heard of. Each of these is manageable on its own. Together, they turn compliance into a scoping problem before it ever becomes a security problem.

That is the challenge our framework library is built to solve — and, in a nice bit of irony, it's also the reason the library itself needs a map.

With a total of over 80 frameworks available in Cyberday, it may be difficult to find the framework you are looking for; but rest assured that we have many tools that help you find the correct frameworks, compare framework contents and even suggest new frameworks you may be interested in. On both our website and in the app itself there is a full list of all the frameworks that are available, that can be filtered or searched by to find frameworks easily, but we also have other tools to help your search:

AI framework suggestions

Cyberday has several places where AI is utlised to suggest frameworks based on your specific situation and needs. When you initially set up Cyberday, in the second step of the onboarding, we suggest frameworks that we think are relevant and important for you. These suggestions are based on the company profile that you filled in the first step, and take into account your organisation's location, size, industry and any of your existing certifications. So for example if you are based in Finland, it will suggest relevant Finnish and EU frameworks with varying implementation strengths based on your pursued maturity (particularly in cases like iso 27001).

This functionality is also present on the main frameworks editing page outside of the onboarding phase.

Why this step matters more than it looks. Most organisations arrive with a single trigger in mind — a customer questionnaire, a board request, a tender they lost. The trigger is rarely the whole picture. A 40-person SaaS company selling into Finnish healthcare has a very different obligation set from a 40-person manufacturer selling connected devices across the EU, even though both would describe themselves as "a small tech company that needs to get compliant."

A practical tip: treat the suggestions as a scoping conversation rather than a shopping list. Read through what comes up, and pay particular attention to anything you didn't expect. Those are usually the frameworks that would have surfaced six months later in an audit, a due-diligence request or a supplier assessment — at a point where you have far less room to plan. Activating everything on day one isn't the goal either; the point is to know what's out there before you decide what to work on first.

Framework comparison tool

Since you can have multiple frameworks active at the same time in Cyberday, we created a tool that allows you to compare the requirement overlap between frameworks. This means that if you are already compliant with one framework, you can see how much more work needs to be done to comply with another framework you may be interested in. The tool works by comparing the overlap of tasks for each framework in Cyberday and calculating the difference in compliance scores based on the overlapping tasks. For example, being ISO 27001 compliant already covers 82% of the NIS2 directive, and you can also see in the tool how much each framework is involved with certain policies.

You can find the framework comparison tool here.

The overlap is the whole point. Different regulations were written by different bodies for different purposes, but they converge on a remarkably similar set of practices: governance and risk management, access control, supplier and third-party management, incident detection and reporting, business continuity, awareness training. The wrapping paper changes. The controls underneath mostly don't.

This is why the second framework is almost always cheaper than the first, and the fifth is cheaper still. A number like 82% isn't  trivia. It changes how you plan. It's the difference between "we need to run a NIS2 project" and "we need to close a specific gap in incident reporting and supply chain management, and we already have evidence for the rest."

Used well, the comparison tool answers three questions that come up constantly:

  • Which framework should be our anchor? Pick the one with the broadest overlap across everything else you're likely to need, build your management system around it, and treat the rest as extensions rather than separate projects.
  • What does a new customer requirement actually cost us? When sales comes back from a call asking whether you can commit to a framework you've never touched, you can give an answer grounded in your current state instead of a guess.
  • Where is the genuinely new work? The gap, not the total, is your project plan.

Framework assessments

If you already have some work done towards a specific framework, you can also use our Framework assessment tool to get a head start on the work in the management system. Each framework assessment has a set of questions where you gauge what level your current implementation of the most important policies in the framework is. After evaluating the policies, the framework assessment will give you a preview of your expected compliance score in Cyberday based on your answers. After reviewing this, the assessment allows you to create your Cyberday account with content prefilled to match the questions answered in the assessment.

You are almost never starting from zero. This is the single most common misconception we see. Organisations that have never run a formal compliance programme still have backups, access reviews, onboarding checklists, an incident process of some kind and a handful of policies written years ago by someone who has since left. The work exists, it just isn't documented, owned or connected to any requirement.

Starting from a realistic baseline changes the experience in two ways. Practically, you skip the blank-page problem: instead of an empty management system and 150 tasks to triage, you open a system that already reflects the state of your organisation and shows you what to do next. Politically — and this matters more than it should — a starting score of 45% is a much easier conversation with management than a starting score of 0%. It reframes the project from "we're failing" to "we're two-thirds of the way there, and here's the remaining third."

Can't find the framework you are looking for?

If you have a wish for a framework you'd like to see in Cyberday, we'd love to hear from you! We are always actively working on implementing the next most important framework in our catalogue, and you can suggest your framework ideas on our community page, where you can suggest your own and vote on framework ideas of other community members.

Our roadmap genuinely moves based on your input. Regulatory attention shifts fast, and national and sector-specific requirements often matter enormously to the organisations affected while staying invisible to everyone else. Voting is the fastest way to tell us that a framework is a priority for real teams, not just a line item in a legal update.

A simple order of operations

If you're just getting started and the list of 80+ feels like a lot, this sequence works for most organisations:

  1. Fill in your company profile properly. Location, size, industry and existing certifications are what drive every suggestion downstream. Five minutes here saves a lot of guesswork later.
  2. Review the AI suggestions and note the surprises. You're building a map of obligations, not committing to work yet.
  3. Choose one anchor framework. Usually the one that's either legally unavoidable or commercially most valuable.
  4. Run the framework assessment for it. Start from where you actually are.
  5. Use the comparison tool to plan what comes next. Add frameworks deliberately, once you can see what the incremental work really is.
  6. Vote or suggest in the community if something you need isn't there yet.

The goal isn't fewer frameworks — it's fewer silos

The organisations that struggle with overlapping requirements are rarely the ones with the most obligations. They're the ones running each obligation as a separate project, with its own spreadsheet, its own owner and its own evidence folder, duplicating the same access control review four times because four different auditors asked for it in four different formats.

The alternative is to do the work once, in one system, and map it to every framework that asks for it. That's what makes 80+ frameworks an asset rather than an overwhelming menu: not because you'll ever need all of them, but because whichever ones you do need are already speaking the same language underneath.

Ready to see where you stand? Start with the framework comparison tool — or just create an account and let the onboarding suggest a starting point.

Start je gratis proefabonnement van 14 dagen

Start vandaag nog je gratis proefabonnement. Geen creditcard nodig. Volledige toegang, geen risico. Op elk moment annuleren.

Gratis proef starten

Andere gerelateerde blogartikelen