Skip to content
EN
Book a demo
Standards

Eleven standards, one coverage table.

For every standard we record which requirements it sets and which Complaica module covers them. You maintain the requirement itself only once.

Book a demo
01

Coverage at a glance

StandardVersionCoverageRequirementsStructure
ISO/IEC 27001 2022 ● complete 93 controls Information security management system
NIS2 / BSIG 2025 ● complete §30 BSIG Risk management measures for operators
TISAX / VDA ISA 6.0 ● complete 3 assessment objectives Information security in the automotive supply chain
DORA (EU) 2022/2554 ● complete ICT risk management Digital operational resilience in the financial sector
IT-Grundschutz Kompendium ● complete 10 layers BSI Standards 200-1 to 200-3
DSGVO (EU) 2016/679 ● complete Art. 30 RoPA Data protection management system
BCM BSI-Standard 200-4 ● complete Tiered model: reactive–standard Business continuity management
B3S §8a BSIG ● complete KRITIS Sector-specific security standards
ISO/IEC 27017 · 27018 2015 · 2019 ● complete Cloud-specific controls Cloud extensions to ISO/IEC 27002
Automotive SPICE 4.0 ● complete Process groups Process assessment in vehicle development
ISO 9001 2015 ● complete 10 clauses Quality management system

Figures on scope and edition must be reconciled with the version in force before publication.

02

Synergies instead of duplicated work

The matrix shows which requirement counts towards which standards. One row is one control in your ISMS.

Coverage matrix Hover a row
ISO/IEC27001:2022NIS2§30 BSIGTISAXVDA ISA 6.0DORA(EU) 2022/2554IT-Grund-schutz
A.5.1 counts towards ISO/IEC 27001:2022 counts towards NIS2 §30 BSIG counts towards TISAX VDA ISA 6.0 counts towards DORA (EU) 2022/2554 counts towards IT-Grund- schutz 5/5
A.5.7 counts towards ISO/IEC 27001:2022 counts towards NIS2 §30 BSIG counts towards TISAX VDA ISA 6.0 not applicable counts towards IT-Grund- schutz 4/5
A.5.23 counts towards ISO/IEC 27001:2022 not applicable counts towards TISAX VDA ISA 6.0 counts towards DORA (EU) 2022/2554 not applicable 3/5
A.6.3 counts towards ISO/IEC 27001:2022 counts towards NIS2 §30 BSIG counts towards TISAX VDA ISA 6.0 counts towards DORA (EU) 2022/2554 counts towards IT-Grund- schutz 5/5
A.8.8 counts towards ISO/IEC 27001:2022 counts towards NIS2 §30 BSIG counts towards TISAX VDA ISA 6.0 counts towards DORA (EU) 2022/2554 counts towards IT-Grund- schutz 5/5
A.8.16 counts towards ISO/IEC 27001:2022 counts towards NIS2 §30 BSIG not applicable counts towards DORA (EU) 2022/2554 counts towards IT-Grund- schutz 4/5
counts towards the standard not applicable
A.5.1 Information security policiesA.5.7 Threat intelligenceA.5.23 Information security for cloud servicesA.6.3 Awareness and trainingA.8.8 Management of technical vulnerabilitiesA.8.16 Monitoring activities
03

30 minutes, your standards, your scope.

No sales pitch
A demo on your use case, not on sample data
Reply within one business day
Your data is never passed to third parties

By submitting you agree to the privacy policy.

Book a demo