Skip to main content

FRAMEWORKS

Reference guides to the frameworks buyers ask about.

Goldline delivers ISO 42001 and ISO 27001 as headline programmes. These guides explain the wider framework landscape, where each one applies, and how it relates to the management systems we implement.

DELIVERED BY GOLDLINE

ISO 42001

The international standard for AI Management Systems.

TimelineAgreed at scoping

Best forProving AI Governance to Buyers, Investors and Regulators

View framework

ISO 27001

The international standard for Information Security Management Systems.

TimelineAgreed at scoping

Best forUnblocking UK and EU Enterprise Procurement

View framework

INFORMATION SECURITY AND PRIVACY

SOC 2

The US attestation report enterprise buyers request during vendor due diligence.

TimelineVaries by Type

Best forUS Enterprise Procurement

View framework

GDPR

The UK and EU data protection regime governing personal data processing.

TimelineOngoing Obligation

Best forAny Organisation Handling EU or UK Personal Data

View framework

ISO 27017

Cloud-specific security controls extending an ISO 27001 management system.

TimelineExtension to ISO 27001

Best forCloud Service Providers

View framework

ISO 27018

Protection of personally identifiable information in public cloud environments.

TimelineExtension to ISO 27001

Best forCloud Processors Handling Personal Data

View framework

ISO 27701

The privacy information management extension to ISO 27001.

TimelineExtension to ISO 27001

Best forDemonstrating Privacy Management Alongside Security

View framework

PCI DSS

The payment card industry standard for organisations handling cardholder data.

TimelineVaries by Merchant Level

Best forOrganisations Processing Payment Card Data

View framework

NHS DSPT

The Data Security and Protection Toolkit required of NHS suppliers and partners.

TimelineAnnual Submission

Best forNHS-Connected Organisations

View framework

AI GOVERNANCE

EU AI Act

The EU regulation classifying AI systems by risk and setting obligations for each tier.

TimelinePhased to 2027

Best forOrganisations Placing AI Systems on the EU Market

View framework

NIST AI RMF

The voluntary US framework for governing, mapping, measuring, and managing AI risk.

TimelineVoluntary Framework

Best forOrganisations Aligning to US AI Governance Expectations

View framework

SECTOR AND REGULATORY

DORA

The EU digital operational resilience regime for financial entities and their ICT providers.

TimelineIn Force

Best forEU Financial Services and Their ICT Suppliers

View framework

Cyber Essentials

The UK government-backed baseline of five technical controls.

TimelineAgreed at scoping

Best forUK Public Sector Tenders and Supply Chain Baseline

View framework

Cyber Essentials Plus

The independently audited version of the Cyber Essentials controls.

TimelineAgreed at scoping

Best forSupply Chains Requiring Independent Technical Audit

View framework

IASME Cyber Assurance

A broader UK assurance scheme covering fourteen governance and security themes.

TimelineVaries by Level

Best forCyber Resilience Beyond the Technical Baseline

View framework

Defence Cyber Certification

The MOD supply chain cyber requirement applied through Def Stan 05-138.

TimelineLevel 0 by 31 December 2026

Best forUK MOD Supply Chain Suppliers

View framework

DEFCON 658

The MOD contract condition that makes cyber risk assessment and supplier assurance contractual.

TimelineApplies at Contract Award

Best forSuppliers Holding MOD or Prime Contract Flowdown

View framework

Def Stan 05-138

The MOD standard grading contracts from Very Low to Very High risk and setting the control set for each.

TimelineIssue 4 Current

Best forEstablishing the Cyber Risk Level Behind DCC

View framework

GHANA PRACTICE

Goldline's Ghana practice serves Bank of Ghana regulated institutions, distinct from our UK programmes.

Bank of Ghana CISD

The Cyber and Information Security Directive for Bank of Ghana regulated institutions.

TimelineVaries by Institution

Best forBoG-Licensed Banks, SDIs, and Payment Service Providers

View framework

GDPR for Ghanaian companies

How EU and UK data protection duties reach Ghanaian organisations serving European clients.

TimelineOngoing Obligation

Best forGhanaian Organisations Serving UK or EU Data Subjects

View framework

Ghana Data Protection Act

The Data Protection Act 2012 and the duties it places on data controllers in Ghana.

TimelineOngoing Obligation

Best forAny Data Controller Operating in Ghana

View framework

Frameworks outside our headline delivery share substantial control overlap with ISO 42001 and ISO 27001. Where a framework sits outside our direct focus, we route to partner referral. Discussed at scoping.

Not sure which framework applies?

A free 45 minute diagnostic establishes which frameworks your buyers, regulator, or supply chain actually require. No sales pitch.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.