Independent publication. General information only: not an auditor, certification body, law firm or standards body.
Baseline ReadySecurity & Compliance Intelligence Check your readiness

Resources

Resources and authoritative sources

Go to the source. These are the bodies behind the frameworks we cover, plus our own free data.

Authoritative sources

AICPA: Trust Services Criteria

The criteria SOC 2 examinations are measured against.

2017 TSC (revised points of focus, 2022)

ISO: ISO/IEC 27001

The information security management system standard.

ISO/IEC 27001:2022

NIST Cybersecurity Framework 2.0

Released in February 2024 with six functions, including the new Govern function.

NIST CSF 2.0 announcement

CISA for small businesses

Starting points for small and medium organisations.

Cyber Essentials · Performance Goals · MFA

Our free data

How we work