Choosing a GRC framework: what each instrument actually is
Certifiable standard, outcome framework, attestation report or sector standard: what each GRC instrument produces, and which one a given driver calls for.
Governance3 Sept 20269 min read
On this page
How to read this
Framework selection is usually presented as a comparison of scope, as though the instruments were competing products. They are not. They produce different artefacts, are issued by different parties, and answer to different drivers. This page sorts them by what an exercise against each one actually produces, then gives a decision table keyed to the driver that started the conversation. It is a starting point for a scoping decision, not a substitute for one, and it makes no claim that one instrument satisfies another.
The instruments, by what they produce
| Instrument | Official designation | Category | What the exercise produces |
|---|---|---|---|
| ISO 27001 | ISO/IEC 27001:2022 1 | Certifiable management-system standard | A certificate issued by a certification body, covering a stated scope |
| ISO 27002 | ISO/IEC 27002:2022 2 | Control guidance | Implementation guidance for the controls referenced from Annex A; nothing is certified against it |
| ISO 27701 | ISO/IEC 27701:2025 3 | Certifiable management-system standard | A privacy information management system, standalone since the 2025 edition |
| SOC 2 | 2017 Trust Services Criteria (With Revised Points of Focus – 2022) 4 | Attestation criteria | An attestation report signed by a CPA firm, addressed to the buyer's risk function |
| NIST CSF 2.0 | NIST CSWP 29 5 | Outcome framework | A current and target profile, self-assessed or assessed by a third party; no certificate |
| CIS Controls | CIS Critical Security Controls Version 8.1 6 | Prioritised control baseline | An implementation plan across 18 Controls, scoped by implementation group |
| COBIT | COBIT 2019 7 | Governance framework | A governance system design for enterprise information and technology; COBIT and related marks are trademarks of ISACA |
| IEC 62443 | IEC 62443-2-4:2023 8 and IEC 62443-4-1:2018 9 | Sector standards for industrial automation | Security programme requirements for service providers, and secure product development lifecycle requirements |
Four categories, four different outcomes
A certifiable management-system standard states requirements a management system must meet. ISO/IEC 27001:2022 is titled as a requirements standard, and the outcome of a successful audit is a certificate with a defined scope statement. The 2024 amendment adding climate-related wording applies to the same edition 10.
An attestation report is an opinion, not a certificate. AICPA describes SOC 2 as "a report on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy" 11. The report is written for the buyer's third-party risk function and expires with the period it covers.
An outcome framework describes what good looks like without prescribing how to get there. NIST states the position plainly: "The CSF does not prescribe how outcomes should be achieved" 5. CSF 2.0 organises its outcomes under six Functions, Govern, Identify, Protect, Detect, Respond and Recover, and produces a profile rather than an audited result.
A prioritised control baseline is an ordered implementation plan. Version 8.1 of the CIS Controls added alignment updates, revised asset classes and Safeguard descriptions, and the "Govern" security function introduced in NIST CSF 2.0 6. It is the fastest route to a defensible control set when no external driver has yet fixed the destination.
Sector standards apply where the operating environment, not the buyer, sets the requirement. The IEC 62443 series covers industrial automation and control systems, with separate parts for service providers and for product development.
Choosing the primary instrument
The driver that started the conversation determines the primary instrument. Everything else is a secondary layer built on the same evidence.
| Driver | Primary instrument | Secondary layer | Why this order |
|---|---|---|---|
| Procurement questionnaires from enterprise buyers, mostly North American | SOC 2, security category only | ISO/IEC 27001:2022 when European buyers follow | The report is what the buyer's risk function files; the management system can follow it |
| Enterprise buyers in Europe, or a global buyer list | ISO/IEC 27001:2022 certification | SOC 2 report reusing the same control evidence | A certificate travels across markets; a report is read one buyer at a time |
| Regulator: NIS2 essential or important entity | ISO/IEC 27001:2022 as the management-system spine | National transposition measures, plus a CSF 2.0 profile for gap tracking | The directive sets obligations, not a control catalogue; the ISMS carries the evidence |
| Regulator: financial entity in scope of DORA | ISO/IEC 27001:2022 spine, extended for ICT risk and third-party registers | Sector guidance from the supervisory authority | The regulation adds requirements the ISMS scope must absorb rather than replace |
| Sector: industrial automation asset owner or supplier | IEC 62443 parts matching the role | ISO/IEC 27001:2022 for the corporate estate | Plant and product requirements do not fit an office-centric control set |
| Product with digital elements placed on the EU market | Secure development lifecycle to IEC 62443-4-1:2018 | Conformity work under the Cyber Resilience Act | Development-lifecycle evidence is what a product assessment examines |
| Privacy obligations dominate the risk picture | ISO/IEC 27701:2025 | ISO/IEC 27001:2022 where information security is also in scope | The 2025 edition is standalone, so it no longer requires the ISMS underneath it |
| Board asks for governance of technology overall | COBIT 2019 | ISO/IEC 27001:2022 for the security management system | Governance design and management-system certification answer different questions |
| No external driver yet, small team | CIS Critical Security Controls Version 8.1, implementation group 1 | Whichever instrument the first real driver names | A control baseline is never wasted work; a premature certification often is |
How the rest hangs off ISO 27001
Where more than one instrument is in play, one of them has to hold the scope, the risk assessment and the record of decisions. In most mixed cases that is the ISO 27001 management system, and the others attach to it as layers rather than parallel programmes.
| Layer | Instrument | Relationship to the management system |
|---|---|---|
| Management-system spine | ISO/IEC 27001:2022 | Owns scope, risk assessment, statement of applicability, internal audit and management review |
| Control guidance | ISO/IEC 27002:2022 | Explains the controls the Annex A reference set names; not separately certified |
| Control baseline | CIS Critical Security Controls Version 8.1 | Sequences implementation for teams that need an order of work, not another catalogue |
| Outcome measurement | NIST CSWP 29 | Expresses the same estate as current and target profiles, useful for board reporting |
| Customer assurance | 2017 Trust Services Criteria | Re-presents management-system evidence as criteria-aligned controls for an examination |
| Privacy extension | ISO/IEC 27701:2025 | Adds privacy processing obligations; standalone from the 2025 edition onward |
| Industrial scope | IEC 62443-2-4:2023 | Carries the plant and service-provider requirements the ISMS scope statement excludes |
| Governance layer | COBIT 2019 | Frames technology governance above the ISMS; COBIT and related marks are trademarks of ISACA |
What changes in evidence
The instrument chosen changes the evidence work more than it changes the controls.
- Certification puts the management system itself under audit. The records that matter are the scope statement, the risk assessment and treatment plan, the statement of applicability, internal audit results, management review minutes, and corrective actions closed with proof.
- Attestation puts named controls under examination against criteria. The evidence is instance-level: one access review, one change, one joiner, one leaver, one restore test, each traceable to a date inside the report period.
- An outcome profile puts the organisation's own judgement on record. The evidence is the assessment method and the gap list, and the value comes from repeating it on a fixed cadence rather than from an external signature.
- A control baseline puts implementation coverage on record. The evidence is a plan with owners and dates, plus the tooling output that shows a Safeguard is live across the asset population.
- Sector standards put role-specific requirements on record. The evidence follows the role: development lifecycle artefacts for a product supplier, security programme documentation for a service provider.
An organisation that runs two instruments should collect evidence once and present it twice. Duplicating the register, the vendor inventory or the access-review record is how a second instrument doubles the cost of the first.
Where the choice is constrained
Three EU instruments remove the choice rather than inform it, and each names obligations instead of a control catalogue.
- NIS2 is Directive (EU) 2022/2555, which sets measures for a high common level of cybersecurity across the Union 12. It applies through national transposition, so the applicable text is the member-state law rather than the directive alone.
- DORA is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector 13. It reaches ICT third-party arrangements directly, which changes what a vendor register has to hold.
- The Cyber Resilience Act is Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements 14. It attaches to the product placed on the market, not to the organisation that sells it.
In each case the management system is where the obligation is evidenced, and the framework question becomes which spine carries it.
Change log
| Date | Change |
|---|---|
| 2026-09-03 | First publication. Every designation and edition re-checked against the publisher's own catalogue or resource page. |
References
<!-- The rendered Sources block is generated from the verification markers above (ArticleShell). This list carries the publisher, official title and URL behind each of those markers. -->- ISO. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements. https://www.iso.org/standard/27001 1
- ISO. ISO/IEC 27001:2022/Amd 1:2024 — Climate action changes. https://www.iso.org/standard/88435.html 10
- ISO. ISO/IEC 27002:2022 — Information security controls. https://www.iso.org/standard/75652.html 2
- ISO. ISO/IEC 27701:2025 — Privacy information management systems — Requirements and guidance. https://www.iso.org/standard/85819.html 3
- AICPA & CIMA. 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (With Revised Points of Focus – 2022). https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 4
- AICPA & CIMA. SOC 2® — SOC for Service Organizations: Trust Services Criteria. https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2/ 11
- National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, 2024-02-26. https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final 5
- Center for Internet Security. CIS Critical Security Controls Version 8.1, and The 18 CIS Critical Security Controls. https://www.cisecurity.org/controls/v8-1 and https://www.cisecurity.org/controls/cis-controls-list 6
- ISACA. COBIT — governance and management of enterprise IT. https://www.isaca.org/resources/cobit — COBIT and related marks are trademarks of ISACA 7
- IEC. IEC 62443-2-4:2023 — Security for industrial automation and control systems - Part 2-4: Security program requirements for IACS service providers. Edition 2.0. https://webstore.iec.ch/en/publication/67631 8
- IEC. IEC 62443-4-1:2018 — Security for industrial automation and control systems - Part 4-1: Secure product development lifecycle requirements. Edition 1.0, 2018-01-15. https://webstore.iec.ch/en/publication/33615 9
- European Parliament and Council. Directive (EU) 2022/2555 (NIS 2 Directive). https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng 12
- European Parliament and Council. Regulation (EU) 2022/2554 (DORA). https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng 13
- European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng 14
Sources
- 1iso.org, ISO/IEC 27001:2022 catalogue entry · verified 2026-09-03
- 2iso.org, ISO/IEC 27002:2022 catalogue entry · verified 2026-09-03
- 3iso.org, ISO/IEC 27701:2025 catalogue entry · verified 2026-09-03
- 4AICPA & CIMA, 2017 Trust Services Criteria · verified 2026-09-03
- 5csrc.nist.gov, NIST CSWP 29 · verified 2026-09-03
- 6cisecurity.org, CIS Controls v8.1 · verified 2026-09-03
- 7isaca.org, COBIT resource page · verified 2026-09-03
- 8webstore.iec.ch, IEC 62443-2-4:2023 · verified 2026-09-03
- 9webstore.iec.ch, IEC 62443-4-1:2018 · verified 2026-09-03
- 10iso.org, ISO/IEC 27001:2022/Amd 1:2024 · verified 2026-09-03
- 11AICPA & CIMA, SOC 2 topic page · verified 2026-09-03
- 12eur-lex.europa.eu, Directive (EU) 2022/2555 · verified 2026-09-03
- 13eur-lex.europa.eu, Regulation (EU) 2022/2554 · verified 2026-09-03
- 14eur-lex.europa.eu, Regulation (EU) 2024/2847 · verified 2026-09-03
Related
- AI governance stand-up under the EU AI Act
Engagement pattern
- Building an ISMS people actually use
Playbook