Frameworks
Which framework, and in what order
What each standard actually proves, who asks for it by name, how long it takes, and which one to do first. Reference pages for each, written for practitioners.
In short
Security and AI frameworks differ in what they prove and who recognises them. ISO 27001 certifies an information security management system; SOC 2 attests that controls operated over a window; Cyber Essentials verifies five technical controls; ISO 42001 certifies AI governance. The right one is normally whichever your customers are asking for by name.
Comparison
Six frameworks, compared honestly
Including where a framework is irrelevant to you, which most comparison tables leave out.
| Framework | What it proves | Who asks for it | Elapsed time | Ongoing burden | Recognition |
|---|---|---|---|---|---|
| ISO 27001 | A whole information security management system, risk-assessed and audited | UK and European enterprise buyers, investors, regulated customers | 6-9 months | Two-stage audit, then annual surveillance, recertification at 3 years | International, and the default ask in the UK and EU |
| SOC 2 | That defined controls operated effectively across an observation window | North American enterprise buyers, almost always by name | 6-9 months (Type II) | Observation window of 3-12 months, then annual | Dominant in the US, less recognised in UK procurement |
| Cyber Essentials | Five specific technical controls are in place | UK central government and MOD contracts, increasingly insurers | 4-8 weeks | Annual reassessment against a question set that changes yearly | UK only, and mandatory for many public contracts |
| ISO 42001 | That AI is governed systematically across its lifecycle | Enterprise and public sector buyers procuring AI, increasingly | 6-12 months, or 4-7 with an existing ISMS | Two-stage audit, then annual surveillance | New but rising fast, and the clearest AI governance evidence available |
| PCI DSS | Cardholder data is handled to the card schemes' requirements | Your acquiring bank, contractually rather than legally | 4 weeks to 9 months, entirely dependent on scope | Annual validation plus quarterly ASV scanning | Mandatory if you touch card data, irrelevant if you do not |
| GDPR | Nothing on its own - it is law, not a certificate | The ICO, data subjects, and every customer's DPA review | Ongoing, not a project with an end | Continuous accountability, DPIAs, records, subject rights | Legal obligation across the UK and EU |
Cost is deliberately not in this table yet. Indicative figures are being confirmed against delivered engagements before publication: cost and internal effort per framework · Q15 An invented cost range on a comparison table is exactly the number that gets quoted back at you in a negotiation.
Reference
One page per framework, written for practitioners
- ISO 27001ISO 27001, the information security management standardWhat ISO 27001 requires, a realistic certification timeline, and the specific things that cause a failed Stage 2 audit.
- ISO 42001ISO 42001, the AI management system standardWhat ISO 42001 requires, who needs it, and a realistic certification timeline, for teams that must evidence AI governance to a regulator or a customer.
- SOC 2SOC 2, the North American assurance reportHow SOC 2 works, the difference between Type I and Type II, and what causes exceptions in the report. Written for teams facing their first observation window.
- NIST AI RMFThe NIST AI Risk Management FrameworkHow the NIST AI Risk Management Framework works, what its four functions require in practice, and how it maps onto ISO 42001 and the EU AI Act.
- NIST 800-53NIST SP 800-53, the federal control catalogueHow NIST SP 800-53 control baselines work, when a UK organisation genuinely needs it, and how it relates to the NIST Cybersecurity Framework.
- Cyber EssentialsCyber Essentials, the UK baseline certificationWhat the five Cyber Essentials controls require, what changed in the April 2026 update, and why organisations fail the Plus assessment.
- PCI DSSPCI DSS, the payment card security standardHow PCI DSS v4.x works, which SAQ applies to you, and the future-dated requirements that became mandatory in March 2025.
- GDPRUK GDPR and data protection complianceWhat UK GDPR requires in practice, where compliance programmes fail, and how data protection intersects with AI deployment and supplier risk.
FAQ
Choosing between frameworks
Which security certification should we get first?
Do we need both ISO 27001 and SOC 2?
Does a certification make us secure?
How much do security certifications cost?
Start
Three ways in, depending on how close the deadline is.
- Book it
Book a discovery call
Thirty minutes, no deck. We work out whether there is a real engagement here, and say so if there is not.
- Go
Check the EU AI Act applies
Six questions, a dated list of the obligations that reach you, and a calendar file so the deadlines land somewhere you will see them again.
- Go
Request a roadmap
You know the obligation and the deadline. We scope the sprints, the deliverables and the dates.
Or just email a human: hello@cloudgap.ai
We reply within24 hours