Markets
Trust travels across borders.
ISO/IEC 42001, SOC 2, and ISO/IEC 27001 serve different buyer and governance needs across Europe, Australia, and Singapore. In Europe, NIS2 adds national cyber duties for covered entities.
Global standards. Specific decisions.
We focus on practical assurance questions for technology and service organizations serving regional and international customers. These guides distinguish customer requests, independent assessment, and local obligations.
Where the paths meet
Start with the outcome you need.
ISO/IEC 42001 governs AI management. SOC 2 reports on controls for a defined service. ISO/IEC 27001 provides information security management. NIS2 adds national cyber duties for covered EU entities. Shared controls can support these paths, while each scope and obligation stays explicit.
Explore the four prioritiesWork with Normstone
Let’s build what stands up to scrutiny.
Tell us what you need to achieve. We’ll help define the right first step.