Live workspace. Durable storage schema active — live connectors, billing, and AI automation are activation-gated.View Activation Status
Signed out
Sign in as the approved QA user before running RLS-bound QA.
Sign in
Step 2 of 8: Choose framework and scope
Compliance Journey
Preview only

Choose framework and scope

Select ISO 27001, SOC 2, or others and define your boundary.

View Home
Browser fallback active

Frameworks & Scope

Select your target frameworks and define your assessment scope as the first step in your compliance execution journey.

Choose your compliance path

Select a framework to map out your organization's security and governance goals.

Recommended starting point
ISO 27001 & SOC 2 Core Security
Establish foundational security controls before tackling AI-specific or regional privacy regulations.
What this means:ZAGOS will focus on access controls, encryption, and basic vendor security to build your core posture.
What happens next:We will guide you through setting your business scope, mapping your current systems, and collecting initial evidence.

Scope setup explanation

Before collecting evidence, we define the "scope" of your audit. This answers:

  • Which business area are we assessing? (e.g. Entire company vs. specific product line)
  • Which systems/tools are included? (e.g. AWS, GitHub, Google Workspace)
  • Which framework are we preparing for? (e.g. SOC 2 or ISO 27001)
  • What evidence do we already have? (Existing policies, past audits)
  • What is blocked until setup? (Live integrations and automated control tests remain blocked until scope is confirmed)

Available frameworks

ISO 42001 — AI management system
Purpose:Build a responsible AI management system.
Best for:Companies building or heavily using AI.
ZAGOS checks:AI policies, system inventories, risk impact assessments.
Status
Preview only
Review framework scope
ISO 27001 — information security controls
Purpose:Standardize your information security management.
Best for:Global B2B companies needing recognized security assurance.
ZAGOS checks:Access controls, cryptography, supplier security.
Status
Preview only
Review framework scope
SOC 2 — trust and security assurance
Purpose:Prove your security and availability to customers.
Best for:SaaS companies selling to enterprise customers.
ZAGOS checks:Logical access, monitoring, incident response.
Status
Guided setup
Start guided assessment
EU AI Act — AI risk and regulatory readiness
Purpose:Comply with European AI regulations.
Best for:Companies deploying AI systems in the EU market.
ZAGOS checks:High-risk system logs, human oversight, transparency docs.
Status
Preview only
Review framework scope
UK GDPR / GDPR — privacy and data protection
Purpose:Protect personal data and privacy rights.
Best for:Any company handling European or UK citizen data.
ZAGOS checks:Data retention limits, RoPA, breach notification processes.
Status
Preview only
Review framework scope
NIST AI RMF / NIST CSF — risk management and security structure
Purpose:Voluntary risk management framework.
Best for:US federal contractors and security-mature organizations.
ZAGOS checks:AI risk governance policies, accountability matrices.
Status
Planned
Back to dashboard