Compliance & Audit Readiness
Which framework applies to your sector?
Six frameworks, eight industries — cross-referenced in one place, rather than making you check each page separately. Not every framework applies to every sector; the gaps below are deliberate, not missing content.
Applies Not applicable
| Framework | Financial Services | Insurance | Retail | Aviation | Manufacturing | Pharma | Telecoms | Public Sector |
|---|---|---|---|---|---|---|---|---|
| ISO 27001 | ||||||||
| GDPR | ||||||||
| NIST CSF | ||||||||
| Zero Trust | ||||||||
| SOC 2 | ||||||||
| DORA |
- ISO 27001, GDPR, NIST CSF, Zero Trust — apply broadly across every sector we work in.
- SOC 2 — scoped to where third-party/vendor trust attestation is typically requested: financial services, insurance, retail's SaaS estate, and telecoms' customer-facing platforms.
- DORA — an EU regulation scoped specifically to financial entities, including insurance and reinsurance undertakings. It genuinely doesn't apply outside financial services and insurance, and we're not going to pretend otherwise to fill a cell.
The eight sectors shown are where we have direct delivery experience — the same frameworks apply in similar ways elsewhere, so if yours isn't listed, talk to us about the specifics.