The frameworks and regulations your compliance program runs on
Govexa ships control libraries and mappings for the standards organizations are most often measured against.
ISO 27001
Information security management — the foundation for most information security programs.
ISO 42001
AI management systems — governance for organizations building or deploying AI.
SOC 2
Trust services criteria commonly required by North American and international customers.
GDPR
The EU's general data protection regulation — mapped to controls, not just documented.
KVKK
Türkiye's data protection law, for organizations operating in or serving the Turkish market.
NIS2
The EU network and information security directive for essential and important entities.
DORA
The EU's digital operational resilience act for financial entities and their ICT providers.
NIST CSF
A widely used risk-based cybersecurity framework, useful alongside ISO and SOC 2.
ISO 9001
Quality management systems — the internationally recognized standard for consistent process control and customer satisfaction.
ISO 22301
Business continuity management — plan for, respond to, and recover from disruptions that threaten critical operations.
ISO/IEC 27017
Cloud security controls — extends ISO 27001 with implementation guidance for the shared responsibility between cloud provider and customer.
ISO/IEC 27018
PII protection in public cloud — code of practice for providers acting as data processors of personal data.
ISO/IEC 20000-1
IT service management — the standard for structured, auditable service delivery and change control.
TS 13298
Türkiye's national standard for electronic records management, built for public-sector document governance.
European regulations reshaping compliance
NIS2
Expands cybersecurity obligations to more sectors, with board-level accountability and stricter incident reporting timelines.
DORA
Requires financial entities to manage ICT risk, test resilience, and oversee critical third-party providers.
GDPR
Sets the baseline for how personal data is collected, processed and protected across the EU.
See Govexa on your own data
A working session with your assets, your frameworks, your risk model — not a generic slide deck.
Request a demo