Markets

Trust travels across borders.

ISO/IEC 42001, SOC 2, and ISO/IEC 27001 serve different buyer and governance needs across Europe, Australia, and Singapore. In Europe, NIS2 adds national cyber duties for covered entities.

Where the paths meet

Start with the outcome you need.

ISO/IEC 42001 governs AI management. SOC 2 reports on controls for a defined service. ISO/IEC 27001 provides information security management. NIS2 adds national cyber duties for covered EU entities. Shared controls can support these paths, while each scope and obligation stays explicit.

Explore the four priorities

Work with Normstone

Let’s build what stands up to scrutiny.

Tell us what you need to achieve. We’ll help define the right first step.

Start a conversation