Back to insights
    Reference

    Choosing a GRC framework: what each instrument actually is

    Certifiable standard, outcome framework, attestation report or sector standard: what each GRC instrument produces, and which one a given driver calls for.

    Governance3 Sept 20269 min read

    2017 Trust Services Criteria (With Revised Points of Focus – 2022)CIS Critical Security Controls Version 8.1COBIT 2019IEC 62443-2-4:2023IEC 62443-4-1:2018ISO/IEC 27001:2022ISO/IEC 27701:2025NIST CSWP 29
    On this page

    How to read this

    Framework selection is usually presented as a comparison of scope, as though the instruments were competing products. They are not. They produce different artefacts, are issued by different parties, and answer to different drivers. This page sorts them by what an exercise against each one actually produces, then gives a decision table keyed to the driver that started the conversation. It is a starting point for a scoping decision, not a substitute for one, and it makes no claim that one instrument satisfies another.

    The instruments, by what they produce

    InstrumentOfficial designationCategoryWhat the exercise produces
    ISO 27001ISO/IEC 27001:2022 1Certifiable management-system standardA certificate issued by a certification body, covering a stated scope
    ISO 27002ISO/IEC 27002:2022 2Control guidanceImplementation guidance for the controls referenced from Annex A; nothing is certified against it
    ISO 27701ISO/IEC 27701:2025 3Certifiable management-system standardA privacy information management system, standalone since the 2025 edition
    SOC 22017 Trust Services Criteria (With Revised Points of Focus – 2022) 4Attestation criteriaAn attestation report signed by a CPA firm, addressed to the buyer's risk function
    NIST CSF 2.0NIST CSWP 29 5Outcome frameworkA current and target profile, self-assessed or assessed by a third party; no certificate
    CIS ControlsCIS Critical Security Controls Version 8.1 6Prioritised control baselineAn implementation plan across 18 Controls, scoped by implementation group
    COBITCOBIT 2019 7Governance frameworkA governance system design for enterprise information and technology; COBIT and related marks are trademarks of ISACA
    IEC 62443IEC 62443-2-4:2023 8 and IEC 62443-4-1:2018 9Sector standards for industrial automationSecurity programme requirements for service providers, and secure product development lifecycle requirements

    Four categories, four different outcomes

    A certifiable management-system standard states requirements a management system must meet. ISO/IEC 27001:2022 is titled as a requirements standard, and the outcome of a successful audit is a certificate with a defined scope statement. The 2024 amendment adding climate-related wording applies to the same edition 10.

    An attestation report is an opinion, not a certificate. AICPA describes SOC 2 as "a report on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy" 11. The report is written for the buyer's third-party risk function and expires with the period it covers.

    An outcome framework describes what good looks like without prescribing how to get there. NIST states the position plainly: "The CSF does not prescribe how outcomes should be achieved" 5. CSF 2.0 organises its outcomes under six Functions, Govern, Identify, Protect, Detect, Respond and Recover, and produces a profile rather than an audited result.

    A prioritised control baseline is an ordered implementation plan. Version 8.1 of the CIS Controls added alignment updates, revised asset classes and Safeguard descriptions, and the "Govern" security function introduced in NIST CSF 2.0 6. It is the fastest route to a defensible control set when no external driver has yet fixed the destination.

    Sector standards apply where the operating environment, not the buyer, sets the requirement. The IEC 62443 series covers industrial automation and control systems, with separate parts for service providers and for product development.

    Choosing the primary instrument

    The driver that started the conversation determines the primary instrument. Everything else is a secondary layer built on the same evidence.

    DriverPrimary instrumentSecondary layerWhy this order
    Procurement questionnaires from enterprise buyers, mostly North AmericanSOC 2, security category onlyISO/IEC 27001:2022 when European buyers followThe report is what the buyer's risk function files; the management system can follow it
    Enterprise buyers in Europe, or a global buyer listISO/IEC 27001:2022 certificationSOC 2 report reusing the same control evidenceA certificate travels across markets; a report is read one buyer at a time
    Regulator: NIS2 essential or important entityISO/IEC 27001:2022 as the management-system spineNational transposition measures, plus a CSF 2.0 profile for gap trackingThe directive sets obligations, not a control catalogue; the ISMS carries the evidence
    Regulator: financial entity in scope of DORAISO/IEC 27001:2022 spine, extended for ICT risk and third-party registersSector guidance from the supervisory authorityThe regulation adds requirements the ISMS scope must absorb rather than replace
    Sector: industrial automation asset owner or supplierIEC 62443 parts matching the roleISO/IEC 27001:2022 for the corporate estatePlant and product requirements do not fit an office-centric control set
    Product with digital elements placed on the EU marketSecure development lifecycle to IEC 62443-4-1:2018Conformity work under the Cyber Resilience ActDevelopment-lifecycle evidence is what a product assessment examines
    Privacy obligations dominate the risk pictureISO/IEC 27701:2025ISO/IEC 27001:2022 where information security is also in scopeThe 2025 edition is standalone, so it no longer requires the ISMS underneath it
    Board asks for governance of technology overallCOBIT 2019ISO/IEC 27001:2022 for the security management systemGovernance design and management-system certification answer different questions
    No external driver yet, small teamCIS Critical Security Controls Version 8.1, implementation group 1Whichever instrument the first real driver namesA control baseline is never wasted work; a premature certification often is
    Driver to primary instrument, with the layer that usually follows

    How the rest hangs off ISO 27001

    Where more than one instrument is in play, one of them has to hold the scope, the risk assessment and the record of decisions. In most mixed cases that is the ISO 27001 management system, and the others attach to it as layers rather than parallel programmes.

    LayerInstrumentRelationship to the management system
    Management-system spineISO/IEC 27001:2022Owns scope, risk assessment, statement of applicability, internal audit and management review
    Control guidanceISO/IEC 27002:2022Explains the controls the Annex A reference set names; not separately certified
    Control baselineCIS Critical Security Controls Version 8.1Sequences implementation for teams that need an order of work, not another catalogue
    Outcome measurementNIST CSWP 29Expresses the same estate as current and target profiles, useful for board reporting
    Customer assurance2017 Trust Services CriteriaRe-presents management-system evidence as criteria-aligned controls for an examination
    Privacy extensionISO/IEC 27701:2025Adds privacy processing obligations; standalone from the 2025 edition onward
    Industrial scopeIEC 62443-2-4:2023Carries the plant and service-provider requirements the ISMS scope statement excludes
    Governance layerCOBIT 2019Frames technology governance above the ISMS; COBIT and related marks are trademarks of ISACA

    What changes in evidence

    The instrument chosen changes the evidence work more than it changes the controls.

    • Certification puts the management system itself under audit. The records that matter are the scope statement, the risk assessment and treatment plan, the statement of applicability, internal audit results, management review minutes, and corrective actions closed with proof.
    • Attestation puts named controls under examination against criteria. The evidence is instance-level: one access review, one change, one joiner, one leaver, one restore test, each traceable to a date inside the report period.
    • An outcome profile puts the organisation's own judgement on record. The evidence is the assessment method and the gap list, and the value comes from repeating it on a fixed cadence rather than from an external signature.
    • A control baseline puts implementation coverage on record. The evidence is a plan with owners and dates, plus the tooling output that shows a Safeguard is live across the asset population.
    • Sector standards put role-specific requirements on record. The evidence follows the role: development lifecycle artefacts for a product supplier, security programme documentation for a service provider.

    An organisation that runs two instruments should collect evidence once and present it twice. Duplicating the register, the vendor inventory or the access-review record is how a second instrument doubles the cost of the first.

    Where the choice is constrained

    Three EU instruments remove the choice rather than inform it, and each names obligations instead of a control catalogue.

    • NIS2 is Directive (EU) 2022/2555, which sets measures for a high common level of cybersecurity across the Union 12. It applies through national transposition, so the applicable text is the member-state law rather than the directive alone.
    • DORA is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector 13. It reaches ICT third-party arrangements directly, which changes what a vendor register has to hold.
    • The Cyber Resilience Act is Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements 14. It attaches to the product placed on the market, not to the organisation that sells it.

    In each case the management system is where the obligation is evidenced, and the framework question becomes which spine carries it.

    Change log

    DateChange
    2026-09-03First publication. Every designation and edition re-checked against the publisher's own catalogue or resource page.

    References

    <!-- The rendered Sources block is generated from the verification markers above (ArticleShell). This list carries the publisher, official title and URL behind each of those markers. -->
    1. ISO. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements. https://www.iso.org/standard/27001 1
    2. ISO. ISO/IEC 27001:2022/Amd 1:2024 — Climate action changes. https://www.iso.org/standard/88435.html 10
    3. ISO. ISO/IEC 27002:2022 — Information security controls. https://www.iso.org/standard/75652.html 2
    4. ISO. ISO/IEC 27701:2025 — Privacy information management systems — Requirements and guidance. https://www.iso.org/standard/85819.html 3
    5. AICPA & CIMA. 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (With Revised Points of Focus – 2022). https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 4
    6. AICPA & CIMA. SOC 2® — SOC for Service Organizations: Trust Services Criteria. https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2/ 11
    7. National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, 2024-02-26. https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final 5
    8. Center for Internet Security. CIS Critical Security Controls Version 8.1, and The 18 CIS Critical Security Controls. https://www.cisecurity.org/controls/v8-1 and https://www.cisecurity.org/controls/cis-controls-list 6
    9. ISACA. COBIT — governance and management of enterprise IT. https://www.isaca.org/resources/cobit — COBIT and related marks are trademarks of ISACA 7
    10. IEC. IEC 62443-2-4:2023 — Security for industrial automation and control systems - Part 2-4: Security program requirements for IACS service providers. Edition 2.0. https://webstore.iec.ch/en/publication/67631 8
    11. IEC. IEC 62443-4-1:2018 — Security for industrial automation and control systems - Part 4-1: Secure product development lifecycle requirements. Edition 1.0, 2018-01-15. https://webstore.iec.ch/en/publication/33615 9
    12. European Parliament and Council. Directive (EU) 2022/2555 (NIS 2 Directive). https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng 12
    13. European Parliament and Council. Regulation (EU) 2022/2554 (DORA). https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng 13
    14. European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng 14

    Sources

    1. 1iso.org, ISO/IEC 27001:2022 catalogue entry · verified 2026-09-03
    2. 2iso.org, ISO/IEC 27002:2022 catalogue entry · verified 2026-09-03
    3. 3iso.org, ISO/IEC 27701:2025 catalogue entry · verified 2026-09-03
    4. 4AICPA & CIMA, 2017 Trust Services Criteria · verified 2026-09-03
    5. 5csrc.nist.gov, NIST CSWP 29 · verified 2026-09-03
    6. 6cisecurity.org, CIS Controls v8.1 · verified 2026-09-03
    7. 7isaca.org, COBIT resource page · verified 2026-09-03
    8. 8webstore.iec.ch, IEC 62443-2-4:2023 · verified 2026-09-03
    9. 9webstore.iec.ch, IEC 62443-4-1:2018 · verified 2026-09-03
    10. 10iso.org, ISO/IEC 27001:2022/Amd 1:2024 · verified 2026-09-03
    11. 11AICPA & CIMA, SOC 2 topic page · verified 2026-09-03
    12. 12eur-lex.europa.eu, Directive (EU) 2022/2555 · verified 2026-09-03
    13. 13eur-lex.europa.eu, Regulation (EU) 2022/2554 · verified 2026-09-03
    14. 14eur-lex.europa.eu, Regulation (EU) 2024/2847 · verified 2026-09-03