Skip to content

Frameworks

Which framework, and in what order

What each standard actually proves, who asks for it by name, how long it takes, and which one to do first. Reference pages for each, written for practitioners.

In short

Security and AI frameworks differ in what they prove and who recognises them. ISO 27001 certifies an information security management system; SOC 2 attests that controls operated over a window; Cyber Essentials verifies five technical controls; ISO 42001 certifies AI governance. The right one is normally whichever your customers are asking for by name.

Comparison

Six frameworks, compared honestly

Including where a framework is irrelevant to you, which most comparison tables leave out.

Security and AI governance frameworks compared by what they prove, who asks for them, elapsed time to achieve, ongoing audit burden and market recognition
FrameworkWhat it provesWho asks for itElapsed timeOngoing burdenRecognition
ISO 27001A whole information security management system, risk-assessed and auditedUK and European enterprise buyers, investors, regulated customers6-9 monthsTwo-stage audit, then annual surveillance, recertification at 3 yearsInternational, and the default ask in the UK and EU
SOC 2That defined controls operated effectively across an observation windowNorth American enterprise buyers, almost always by name6-9 months (Type II)Observation window of 3-12 months, then annualDominant in the US, less recognised in UK procurement
Cyber EssentialsFive specific technical controls are in placeUK central government and MOD contracts, increasingly insurers4-8 weeksAnnual reassessment against a question set that changes yearlyUK only, and mandatory for many public contracts
ISO 42001That AI is governed systematically across its lifecycleEnterprise and public sector buyers procuring AI, increasingly6-12 months, or 4-7 with an existing ISMSTwo-stage audit, then annual surveillanceNew but rising fast, and the clearest AI governance evidence available
PCI DSSCardholder data is handled to the card schemes' requirementsYour acquiring bank, contractually rather than legally4 weeks to 9 months, entirely dependent on scopeAnnual validation plus quarterly ASV scanningMandatory if you touch card data, irrelevant if you do not
GDPRNothing on its own - it is law, not a certificateThe ICO, data subjects, and every customer's DPA reviewOngoing, not a project with an endContinuous accountability, DPIAs, records, subject rightsLegal obligation across the UK and EU

Cost is deliberately not in this table yet. Indicative figures are being confirmed against delivered engagements before publication: cost and internal effort per framework · Q15 An invented cost range on a comparison table is exactly the number that gets quoted back at you in a negotiation.

Reference

One page per framework, written for practitioners

FAQ

Choosing between frameworks

Which security certification should we get first?

Get the one your pipeline is asking for by name. If deals are stalling on a specific requirement, that requirement is the answer regardless of what is theoretically better. Absent that signal: UK organisations selling to enterprise usually want ISO 27001, US-facing companies usually want SOC 2, UK public sector suppliers need Cyber Essentials, and organisations deploying AI at scale should look at ISO 42001. Cyber Essentials is a sensible first step in almost every case because it is weeks rather than months and closes real technical gaps.

Do we need both ISO 27001 and SOC 2?

Only if you sell into both UK/European and North American enterprise markets, which is when you will eventually be asked for both. The underlying control work overlaps by roughly seventy per cent and most evidence serves both, so running one control programme with two validation tracks is far cheaper than two programmes. Doing both when only one market asks is spending money to answer a question nobody is putting.

Does a certification make us secure?

No, and treating it as though it does is how certified organisations get breached. A certificate evidences that a management system existed and operated at a point in time within a defined scope. It says nothing about what sits outside that scope, and nothing about the day after the audit. The value is real - it forces structure, ownership and evidence - and it is not a substitute for continuous assurance.

How much do security certifications cost?

Cost has two components: the certification body's or auditor's fees, driven by scope and headcount, and the internal or consulting effort to build and operate the system, which is usually the larger figure by some margin. Cloudgap publishes indicative figures only where they reflect delivered engagements, and those are being confirmed with the practice before publication rather than estimated.