Frameworks
Meet your next requirement.
Choose a framework to manage in Kaamos, or explore a guide to understand a customer requirement. Available catalogs include controls, ownership, status and linked evidence.
Find what applies to youBinding EU regulations
DORA
BindingEU regulation for ICT risk management and operational resilience in the financial sector.
Supported in KaamosEU AI Act
BindingEU regulation for AI providers and deployers, with stronger duties for high-risk and general-purpose AI systems.
Information onlyGDPR
BindingEU privacy regulation governing personal data processing, security, accountability, and data-subject rights.
Supported in KaamosNIS2
BindingEU cybersecurity directive for essential and important entities, including many digital providers and ICT service companies.
Supported in KaamosCRA
BindingCRA product scope and reporting from 11 September 2026: 24-hour and 72-hour notifications, separate final-report deadlines and a reporting-day checklist.
Supported in KaamosMDR / IVDR
BindingEU medical device and in vitro diagnostic regulations, including requirements for qualifying software.
Information onlyDSA
BindingEU regulation for intermediary, hosting, and online platform services offered to EU users.
Information onlyePrivacy
BindingEU rules for cookies, tracking, electronic marketing, and confidentiality of electronic communications.
Information onlyMiCA
BindingEU regulation for crypto-asset issuers and crypto-asset service providers.
Information onlyPSD2
BindingEU directive for payment services, strong customer authentication, open banking, and operational requirements.
Information onlyeIDAS 2.0
BindingEU digital identity and trust-services regulation expanding the European Digital Identity framework.
Information only
Voluntary security frameworks
ISO 27001
VoluntaryInternational standard for building and certifying an information security management system.
Supported in KaamosISO 42001
VoluntaryInternational management-system standard for organizations developing or using AI systems.
Supported in KaamosSOC 2
VoluntaryAICPA attestation used by enterprise buyers to evaluate security, availability, confidentiality, processing integrity, and privacy controls.
Supported in KaamosBSI C5
VoluntaryCloud-security criteria used by providers, auditors and customers to assess a cloud service’s controls.
Supported in KaamosISO 27701
VoluntaryA standalone privacy information management system for controllers and processors of personal data.
Supported in KaamosTISAX
VoluntaryInformation-security assessment requirements for organizations working with automotive customers.
Supported in KaamosCyber Essentials
VoluntaryUK cybersecurity certification focused on core technical controls.
Information onlyNIST CSF
VoluntaryCybersecurity framework commonly used as a shared vocabulary for risk, controls, and maturity.
Supported in Kaamos
Public-sector and contractual criteria
PCI DSS
BindingPayment-card security standard required by card networks for environments that store, process, or transmit cardholder data.
Supported in KaamosJulkri
BindingFinnish public-administration security criteria for non-classified information and public-sector procurement.
Information onlyKatakri
BindingFinnish national security audit criteria used for classified information and high-assurance public-sector work.
Information only
Going deeper
- ISO 27001 compliance automation: what a tool can and cannot do
Which parts of the standard software can genuinely take off your hands, and which stay a management decision.
- SOC 2 compliance automation: what software does, and cannot
Why a Type 2 observation period is the strongest case for automating evidence, and why the opinion stays with a CPA firm.
- ISO 27001 vs SOC 2: which one your buyer is actually asking for
A certification and a CPA’s attestation prove different things to different buyers. Most of the evidence serves both.
- Vanta alternatives, including the open-source option
Seven platforms compared, what moves the price, and an honest answer on self-hosting.
Start with your requirements.
Answer five questions about size, sector and customers to find your shortlist.