Skip to content
BastionSec
Contact us
Standards

The standards, explained without the hype.

Informational guides to ISO 27001, SOC 2, ISO 42001 and GDPR: what each one is, how it works, what it takes, typical timelines and costs. No selling: understand first, then decide.

  • Certification (ISO) vs attestation (SOC 2): the difference, explained well.
  • GDPR is law, not a certification: there's no “GDPR certificate”.
  • Honest timelines and firm boundaries: we support you, we don't certify you.

The standard guides

Informational pages to understand each framework. When you're ready to act, each guide links to the related service.

ISO/IEC 27001

The international standard for information security management (ISMS). What it is, the 93 Annex A controls, the certification process, timelines and costs.

Read the guide

SOC 2

The AICPA attestation report (not a certification). Trust Services Criteria, Type I vs Type II, the observation period: the US market's trust lever.

Read the guide
New

ISO/IEC 42001

The first certifiable standard for an AI Management System (AIMS). What it is, how it relates to the EU AI Act (and how it doesn't overlap), requirements and timelines.

Read the guide

GDPR

Regulation (EU) 2016/679: principles, legal bases, data subject rights, fines and extraterritorial reach. It's law, not a certification.

Read the guide

Frequently asked about standards

What's the difference between the Standard pages and the Services pages?

Standard pages explain what a standard is and how it works. Services pages say what we do to get you there. To understand, start with Standards; to do it, start with Services.

Are certification and attestation the same thing?

No. ISO 27001 and ISO 42001 are certifications, issued by an independent accredited body. SOC 2 is an attestation: a report signed by a CPA. GDPR is neither: it's law.

Which standard do I need?

It depends on your market and trigger: ISO 27001 carries weight in the EU and globally, SOC 2 in the US, ISO 42001 if you run AI, GDPR if you process EU residents' data. Write to us and we'll clarify it together.

Figured out what you need? Let's do it together.

Write to us and we'll turn theory into a concrete path.