The fastest path to certification.
Standards overlap far more than they differ. Implement a control area once — access control, encryption, incident response — and it counts toward several certifications at the same time. Pick your targets below to see the shared foundation to build first, and what's uniquely left per standard.
Which standards are you targeting?
Your optimal build order
Highest-leverage controls first. With every standard selected, the phases below are the shortest route through all of them; deselect standards above and the plan and the matrix update to match.
Phase 1 — universal foundation
Controls almost every standard demands. Build these first: each one moves you forward on the most certifications at once.
Incident response & breach reporting
An incident response plan, defined severities, and the ability to detect, contain and report incidents to the right parties in time.
Risk assessment & treatment
A repeatable process to identify, rate and treat risks, with a risk register and treatment decisions on record.
Security governance & policies
Documented information-security policies, defined roles and management ownership of the security programme.
Encryption in transit & at rest
TLS everywhere, encryption of stored sensitive data, and sane key management.
Access control & least privilege
Role-based access, least privilege, and periodic access reviews across systems that hold sensitive data.
Asset & data inventory
A maintained inventory of systems, data and (where relevant) processing activities — you cannot protect what you have not listed.
Logging & monitoring
Centralised, tamper-resistant logging of security-relevant events, with alerting and retention.
Third-party & supply-chain risk
Due diligence on suppliers, security terms in contracts, and a maintained register of critical third parties.
Vulnerability & patch management
Regular scanning, a patch SLA, and a route for handling reported vulnerabilities.
Phase 2 — broadly shared
Still reused across many standards, but not quite universal.
Business continuity & backup
Tested backups and a business continuity / disaster recovery plan with defined recovery objectives.
Multi-factor authentication
MFA on remote access, admin accounts and access to sensitive systems.
Security awareness training
Onboarding and periodic security training for staff, with completion records.
Change management
Reviewed, approved and logged changes to production systems.
Data retention & secure disposal
Retention schedules and secure deletion / media sanitisation.
Personnel security
Background screening where lawful, plus joiner / mover / leaver controls tied to access.
Physical & environmental security
Controlled physical access to facilities and equipment holding sensitive data.
Phase 3 — standard-specific
The work that does not overlap — added only for the specific standards that require it.
AI governance: oversight & transparency
Human oversight, data governance for models and transparency duties — specific to AI systems.
Privacy: lawful basis & data-subject rights
Lawful basis, consent, DSAR handling and DPIAs — the data-protection-specific obligations.
Product security & vulnerability disclosure
Secure-by-design products, update support periods, CE marking and a disclosure route — specific to product makers.
Cardholder data scoping
Defining and minimising the cardholder data environment — specific to card payments.
Financial reporting controls (ICFR)
Controls over financial reporting and officer certifications — specific to public-company reporting.
Operational resilience testing
Threat-led penetration testing and resilience testing — specific to the financial-sector resilience regime.
Regulator & market disclosure
Materiality assessment and timely public / regulator disclosure of incidents — specific to securities regulation.
Coverage matrix
Where each control area counts. A dot means implementing that area helps satisfy that standard. Selected standards are highlighted.
This planner is indicative guidance, not a certification methodology. Overlaps are general — exact applicability depends on your scope, and each standard has requirements no other covers. Always confirm against the current text of the standard and, for formal certification, an accredited assessor.