Govexa

The frameworks and regulations your compliance program runs on

Govexa ships control libraries and mappings for the standards organizations are most often measured against.

ISO 27001

Information security management — the foundation for most information security programs.

ISO 42001

AI management systems — governance for organizations building or deploying AI.

SOC 2

Trust services criteria commonly required by North American and international customers.

GDPR

The EU's general data protection regulation — mapped to controls, not just documented.

KVKK

Türkiye's data protection law, for organizations operating in or serving the Turkish market.

NIS2

The EU network and information security directive for essential and important entities.

DORA

The EU's digital operational resilience act for financial entities and their ICT providers.

NIST CSF

A widely used risk-based cybersecurity framework, useful alongside ISO and SOC 2.

ISO 9001

Quality management systems — the internationally recognized standard for consistent process control and customer satisfaction.

ISO 22301

Business continuity management — plan for, respond to, and recover from disruptions that threaten critical operations.

ISO/IEC 27017

Cloud security controls — extends ISO 27001 with implementation guidance for the shared responsibility between cloud provider and customer.

ISO/IEC 27018

PII protection in public cloud — code of practice for providers acting as data processors of personal data.

ISO/IEC 20000-1

IT service management — the standard for structured, auditable service delivery and change control.

TS 13298

Türkiye's national standard for electronic records management, built for public-sector document governance.

European regulations reshaping compliance

NIS2

Expands cybersecurity obligations to more sectors, with board-level accountability and stricter incident reporting timelines.

DORA

Requires financial entities to manage ICT risk, test resilience, and oversee critical third-party providers.

GDPR

Sets the baseline for how personal data is collected, processed and protected across the EU.

See Govexa on your own data

A working session with your assets, your frameworks, your risk model — not a generic slide deck.

Request a demo
Request a demo