New: ISO 42001 and NIS2 Supply Chain available in the Compliance Tool.View standards and requirements →Careers
Standards, laws & requirements

Manage standards, laws and customer requirements from a single common basis.

Many compliance obligations require similar controls: risk management, policies, supplier management, incidents, audits and improvement. The Compliance Tool lets you reuse what is already in place and record only the additional requirements for each framework, law or customer.

ISO 27001Information security
NEN 7510Healthcare information
NIS2Cyber resilience
ISO 42001AI Management
49frameworks in one
platform
ISO
27001
NIS2
GDPR
Shared
measures
Less duplicate work

Implement controls once. Support multiple obligations.

A supplier assessment may contribute simultaneously to ISO 27001, NEN 7510 and NIS2. The same applies to risk analysis, incident processes and internal audits.

  • Shared Action Library
  • Links between controls and requirements
  • Understanding additional requirements per standard or law
  • Consistent evidence towards auditors and customers
Library

49 standards, laws and customer-specific requirements in the Compliance Tool.

49 results found

Standard

ISO 27001:2022

Information security management system.

Standard

ISO 14001:2015

Environmental management and continuous improvement.

Standard

ISO 9001:2015

Quality management and process management.

Standard

NEN 7510-1:2017

Information security in care.

Standard

Authorised Economic Operator (AEO)

Customs programme for reliable operators.

Standard

AEO Security (AEO-S)

Security within the international trade chain.

Standard

AEO Customs simplifications (AEO-C)

Simplified customs procedures and control.

Standard

Combined authorisation AEO-S/AEO-C

Security and customs simplifications combined.

Customer specific

VodafoneZiggo

Specific customer and chain requirements.

Standard

Quality label Strong Social Work

Quality framework for social work.

Law

Youth Act

Legal requirements regarding youth assistance and implementation.

Standard

Hellios

Available in the Compliance Tool.

Standard

EcoVadis

Assessment framework for sustainability performance.

Law

RI&E

Risk inventory and assessment for working conditions.

Law

NIS2

Cyber resilience and administrative responsibility.

Customer specific

RVO

Specific customer and chain requirements.

Customer specific

Volksbank

Specific customer and chain requirements.

Standard

NEN 7510-1:2024

Current standard for information security in healthcare.

Standard

BRL9500-U

Assessment Directive for utility buildings.

Standard

BRL9500-W

Housing Assessment Directive.

Customer specific

Corporate Social Responsibility (CSR)

Customer-specific requirements for corporate responsibility.

Standard

ISO 42001:2023

Management system for responsible AI use.

Law

AI Regulation (AI Act)

European requirements for development and use of AI.

Standard

CIIO Staff

Information security and control review framework.

Law

Digital Operational Resilience Act (DORA)

Digital operational resilience in the financial sector.

Law

PGS 15

Safe storage of packaged hazardous substances.

Law

ADR

Requirements for the transport of dangerous goods by road.

Standard

NEN 4400-1:2023

Reliability of temporary agency and posting organisations.

Standard

SOC 1

Management of service providers relevant for financial reporting.

Standard

SOC 2

Control around security, availability and confidentiality.

Standard

ISO 27701:2019

Management system for privacy information.

Standard

ISO 27017:2021

Information security measures for cloud services.

Standard

ISO 27018:2020

Protection of personal data in public clouds.

Standard

BC 5701

Available in the Compliance Tool.

Standard

Good Practice Information Security (DNB)

Good practices of DNB for information security.

Law

Law protection whistleblowers

Requirements around reporting channels and protection of whistleblowers.

Law

Wwft

Customer due diligence, monitoring and reporting obligations.

Law

GDPR

Protection and lawful processing of personal data.

Law

Wtta

Admission system for companies supplying workers.

EU regulation

PPWR

European rules on packaging and packaging waste.

Standard

NIS2-SC10 Basic

Base level for NIS2 Supply Chain.

Standard

NIS2-SC20 Substantial

Substantial level for NIS2 Supply Chain.

Standard

NIS2-SC30 High

High level for NIS2 Supply Chain.

Standard

SURFaudit Review framework Information security

Review framework for information security in education and research.

Standard

SURF Review Framework Privacy

Review framework for privacy in education and research.

Standard

BRL9500-U/W:2026

Combined assessment framework for utility buildings and dwellings.

Standard

HKZ

Quality standards for care and wellbeing.

Standard

Safety Culture Ladder 2.0

Assessment framework for safety awareness and behaviour.

Standard

Baseline Information Security General government 2 (BIO2)

Baseline for information security within the government.

The library shows the standards, laws and customer requirements built into the Compliance Tool. Applicability is determined for each organisation.

Which route fits?

Start with a strong base and build logically.

Route A

ICT & SaaS

ISO 27001NIS2 / SOC 2ISO 42001

For organisations that want to combine customer confidence, security and AI governance.

Route B

Healthcare & health IT

ISO 27001NEN 7510GDPR

For organisations that want to manage healthcare information and privacy with demonstrable control.

Route C

Broad business operations

ISO 9001ISO 27001ISO 14001

For organisations that manage quality, security and sustainability in an integrated way.

Which requirements apply to your organisation?

The applicability check identifies the relevant laws, standards and customer requirements.

Interactive prototype