Auditen

The fastest path to certification.

Standards overlap far more than they differ. Implement a control area once — access control, encryption, incident response — and it counts toward several certifications at the same time. Pick your targets below to see the shared foundation to build first, and what's uniquely left per standard.

Which standards are you targeting?

Your optimal build order

Highest-leverage controls first. With every standard selected, the phases below are the shortest route through all of them; deselect standards above and the plan and the matrix update to match.

2

Phase 2 — broadly shared

Still reused across many standards, but not quite universal.

8 standards

Access control & least privilege

Role-based access, least privilege, and periodic access reviews across systems that hold sensitive data.

8 standards

Asset & data inventory

A maintained inventory of systems, data and (where relevant) processing activities — you cannot protect what you have not listed.

8 standards

Logging & monitoring

Centralised, tamper-resistant logging of security-relevant events, with alerting and retention.

8 standards

Third-party & supply-chain risk

Due diligence on suppliers, security terms in contracts, and a maintained register of critical third parties.

8 standards

Vulnerability & patch management

Regular scanning, a patch SLA, and a route for handling reported vulnerabilities.

7 standards

Business continuity & backup

Tested backups and a business continuity / disaster recovery plan with defined recovery objectives.

7 standards

Multi-factor authentication

MFA on remote access, admin accounts and access to sensitive systems.

7 standards

Security awareness training

Onboarding and periodic security training for staff, with completion records.

6 standards

Change management

Reviewed, approved and logged changes to production systems.

5 standards

Data retention & secure disposal

Retention schedules and secure deletion / media sanitisation.

5 standards

Personnel security

Background screening where lawful, plus joiner / mover / leaver controls tied to access.

4 standards

Physical & environmental security

Controlled physical access to facilities and equipment holding sensitive data.

Coverage matrix

Where each control area counts. A dot means implementing that area helps satisfy that standard. Selected standards are highlighted.

This planner is indicative guidance, not a certification methodology. Overlaps are general — exact applicability depends on your scope, and each standard has requirements no other covers. Always confirm against the current text of the standard and, for formal certification, an accredited assessor.