Skip to main content

For teams certifying against more than one framework

Cross-framework compliance, organized once. Reused across every framework you need.

One evidence library. One upload satisfies controls across ISO 27001, NIST CSF, ISO 22301, DPTM, MAS TRM, and the rest.

No credit card · Encrypted at rest and in transit · Cancel anytime

Built-in AI

From blank page to reviewed draft—without leaving VeraKey.

AI that knows your frameworks and your data. Drafts your starting evidence. Answers your compliance questions. Nothing is auto-approved—you review every draft and every answer.

Evidence drafting

Start from a reviewed draft, not a blank page.

After you pick your frameworks and answer a few onboarding questions, VeraKey auto-drafts your starting policies and procedures. Each draft lands in your Evidence Library, pre-mapped to the control it satisfies—moving that control from “not started” to “in progress” automatically. The right model is chosen per framework, so quality stays high and cost stays sane. Nothing is auto-approved; you stay in control.

access-control-policy.docx
AI-generated — needs review

This Access Control Policy applies to all systems operated by [Organisation Name] and establishes requirements for granting, reviewing, and revoking access to information assets.

Access rights shall be reviewed at intervals not exceeding [Review Frequency, e.g. quarterly] by [Role, e.g. IT Manager].

↓ Fill the bracketed placeholders, re-upload, mark reviewed.

ISO 27001 · A.5.15not startedin progress
auto-mapped on draft
Compliance assistant

Instant answers, grounded in your data—not the open web.

Ask your in-app assistant about your organisation’s own compliance posture: which controls you’re missing, which evidence maps to which framework, where your audit readiness gaps are. It reads only your tenant’s data—enforced by row-level security—has zero internet access, and every question is audit-logged. Instant answers, no hallucination surface, nothing leaves your tenant.

Compliance assistantowner · admin
youWhen there's an incident, who do I contact?
verakey aiYour Incident Response Plan (v2.0) names the Security Lead as first responder, escalating to the IR Manager within 1 hour and the CISO for any data breach. It's mapped to ISO 22301 §8.2 and MAS TRM 7.1.
youWhat's my password policy?
verakey aiYour Access Control Policy (v3.2) sets a 12-character minimum, MFA on every admin account, and 90-day rotation. It satisfies ISO 27001 A.5.17 and NIST CSF PR.AA-01.
reads your data onlyno internet accessaudit-logged

Most teams do compliance the slow way.

Same evidence, seven uploads.

Your DR plan is asked for in ISO 27001, ISO 22301, NIST CSF, DPTM, MAS TRM, CTM, and CEM. You upload it seven times.

Spreadsheets and Dropbox links.

Auditors ask “where’s the latest?” You’re not sure either.

Every new cert restarts the clock.

New framework, new spreadsheet, new evidence hunt. The 80% you've already done doesn't transfer.

Four steps to certified.

Pick frameworks. Upload evidence once. Scope your auditor’s access. Export a signed packet.

Catalog
Choose your frameworks
6 available
ISO 27001
Annex A controls
NIST CSF
5 functions
DPTM
9 chapters
ISO 42001
AI controls
MAS TRM
TRM Guidelines
ISO 22301
BCM
6 frameworks adopted · ready for evidenceContinue →
Step 01

Pick your frameworks

Adopt one or all from the catalog — ISO 27001, NIST CSF, DPTM, and more.

Scroll to advance · click any dot to jump

Audit readiness

Know where you stand, every day.

A live score per framework, recomputed the moment a control flips green or new evidence lands. See your gaps now — not in the panic week before your audit.

Audit readiness
0/ 100
+0 pts vs 30d
Cyber Essentials Markv2.0
0
Cyber Trust Mark2025
0
ISO 270012022
0
Data Protection TrustmarkSS 714:2025
0
Data Protection Essentials2024
0
Needs your attention0 gaps
  • 0Non-Compliantce.A.1.4(e) · ctm.B.7.2
  • 0No evidence5 suggestions ready
Residual risk map8 controls plotted · hover to reveal
Impact →
V.HighHighMedLowV.Low
8.2
Protect-3
A.5.15
7.1
GV.SC-1
4.2
A.17.1.1
A.6.3
V.LowLowMedHighV.High
Likelihood →
lowmedhighcritical

Organizational risk

Spot the gaps that will hurt.

Score residual risk per control on the standard 5×5 matrix. Plot exposure by likelihood and impact, assign owners, set target dates, and watch the matrix shift as gaps close.

Proof on Demand

Hand auditors a verified evidence packet in minutes, not weeks.

Every control links to versioned, attributed evidence with a tamper-evident chain. When an audit or a customer security review asks “show me,” you export a signed packet instantly.

audit-packet — 2026-Q2.zip
generating
access-control-policy.pdfv3.2
j.tan·sha a7c1f9·ISO 27001 · A.5.15DPTM · Protect-3
incident-response-plan.pdfv2.0
m.koh·sha 9e22b4·ISO 22301 · 8.2MAS TRM · 7.1
vendor-risk-register.xlsxv5.1
r.lim·sha 0d5f8a·ISO 27001 · A.5.19NIST CSF · GV.SC-1
awareness-training-2026Q1.pdfv1.0
j.tan·sha 3b6e21·ISO 27001 · A.6.3DPTM · Protect-1
Signed manifest
sha256 · 2026-04-12T09:14:22+08:00 · 47 controls satisfied
verified

Built-in audit trust

Your auditor, consultant, and client — each with exactly the access you grant.

Framework-scoped external access. Shareable read-only links for clients. Append-only audit log that captures every view, edit, and export. Revoke any of them in one click.

Internal team
Owner · Admin · Editor
Consultant
ISO 27001 + DPTM — write
Auditor
DPTM — read-only · exp 30 Jun
Client view
Shareable link · read-only
Acme Pte Ltd
Audit logappend-only · live
  1. 09:08:11editor · k.wong  uploaded evidence  Awareness-Q1 v1.0
  2. 09:14:22consultant · m.koh  added evidence  DR-Plan v3.2
  3. 09:18:07auditor · j.key@certbody  viewed control  DPTM · Protect-3
  4. 09:22:41owner · j.tan  shared with client  Acme Holdings
  5. 09:31:55admin · s.lim  rotated link  client-view #c42b
  6. 09:40:03consultant · m.koh  mapped evidence  ISO 27001 · A.5.15
  7. 09:48:17owner · j.tan  exported packet  audit-2026-Q2.zip
  8. 09:55:30editor · k.wong  updated control  CTM · 4.2 (compliant)
  9. 10:03:42admin · s.lim  invited member  r.lim · editor
  10. 10:12:19system  snapshot built  readiness 73 → 74

Cross-framework mapping

One file. Every framework it satisfies.

Hand-mapped across every major compliance framework. Upload one piece of evidence and watch what it satisfies.

0controls satisfied
DR-Plan.pdf
Access-Policy.pdf
Vendor-Risk.xlsx
Awareness-Training.pdf
ISO 27001
A.5.15
CTM
4.2
DPTM
Protect-3
MAS TRM
7.1
NIST CSF
GV.SC-1
ISO 22301
8.2.2
DPE
8.1
ISO 42001
8.3
CEM
A.4(d)
ISO 27001
A.17.1.1
MAS TRM
7.4
DPTM
Protect-1
NIST CSF
ID.RA-1
ISO 27001
A.6.3
DPTM
Govern-2
DPE
9.2
ISO 42001
6.1.4
CTM
5.1

Four files. Eight frameworks. 47 controls satisfied. Drawn from 120+ hand-curated cross-framework mappings — the table is the product.

Start free for 30 days. No card.

Full Team tier. After your trial, pick the plan that fits.