Frameworks
Activate the frameworks that apply to you
NOVA maps requirements from each framework onto a shared control set. Evidence collected once can support multiple frameworks where it genuinely satisfies the control.
Available now
Ready to activate
SOC 2
Available nowService organisation reporting against the Trust Services Criteria, used widely in enterprise procurement.
ExploreISO/IEC 27001
Available nowThe international standard for an information security management system, certified by an accredited body.
ExploreEssential Eight
Available nowEight prioritised mitigation strategies published by the Australian Cyber Security Centre, assessed by maturity level.
ExploreISO/IEC 42001
Available nowThe management system standard for artificial intelligence, covering governance of AI systems across their lifecycle.
ExploreRoadmap
Planned frameworks
NIST Cybersecurity Framework
PlannedA voluntary framework organising cybersecurity outcomes into functions, categories and subcategories.
Read moreHIPAA
PlannedUnited States requirements for safeguarding protected health information held by covered entities and business associates.
Read moreAustralian Government Information Security Manual
PlannedA cybersecurity framework of controls published by the Australian Signals Directorate for government systems and their suppliers.
Read moreGlobal register
Planned frameworks by region
A regional view of the major compliance frameworks and regulatory regimes NOVA may support. Eredox is headquartered in Australia and its service scope is worldwide.
Global and cross border
Major frameworks and regimes encountered across every market. Confirm applicability for each customer engagement.
| Framework | Jurisdiction | Primary subject | NOVA relevance | Priority |
|---|---|---|---|---|
| ISO/IEC 27001:2022 | International | Information security management system requirements | Core product framework for governance, controls, evidence, risk treatment and certification readiness. | Core |
| ISO/IEC 27701 | International | Privacy information management extension to ISO 27001 | Supports privacy control mapping, processor and controller accountability and global privacy operations. | Core |
| ISO 22301 | International | Business continuity management | Supports continuity objectives, recovery plans, exercises and resilience evidence. | Core |
| NIST Cybersecurity Framework 2.0 | International / US origin | Cybersecurity risk governance and outcomes | Crosswalk framework for customers using NIST terminology. | Core |
| NIST SP 800-53 Rev 5 | International / US origin | Security and privacy controls | Detailed control library for implementation, inheritance and evidence mapping. | Core |
| NIST SP 800-30 Rev 1 | International / US origin | Information security risk assessment | Method for threat, vulnerability, likelihood, impact and risk assessment. | Core |
| CIS Controls v8.1 | International | Prioritised technical safeguards | Practical baseline for smaller customers and technical evidence collection. | Core |
| SOC 2 Trust Services Criteria | International / AICPA | Service organisation controls | Customer assurance and Trust Center evidence model. Not a government law. | Core |
| COBIT 2019 | International / ISACA | IT governance and management objectives | Governance crosswalk for enterprise and audit customers. | Reference |
| PCI DSS v4.0.1 | International / payment cards | Protection of payment card data | Sector-triggered where cardholder data is stored, processed or transmitted. | Sector |
| FATF Recommendations | International / AML CFT | Anti-money laundering and counter-terrorist financing | Anchor for AML and CTF content, risk assessment and customer due diligence. | Sector |
| CSA Cloud Controls Matrix v4 | International | Cloud security controls and shared responsibility | Cloud provider and SaaS assurance crosswalk. | Reference |
Cross-market or foundational. Prioritised in the catalogue, control library, crosswalks, evidence and reporting.
Triggered by sector or activity. Supported as an add-on with applicability assessment and sector evidence.
Voluntary or mapping aid. Used for crosswalks, procurement and assurance, never presented as certification.
This register is a product catalogue and discovery baseline, not a certification or legal opinion. Applicability depends on customer country, sector, data, service and contractual role.
Readiness
Illustrative readiness reporting
Illustrative interface concept. Values shown are examples, not customer data.
- Controls mapped across activated frameworks
- Evidence status shown by control and requirement
- Gaps surfaced before an external assessment
- Freshness expectations keep evidence current
Example readiness snapshot
Readiness
Readiness
Maturity coverage
Readiness
NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.
See NOVA against your own compliance obligations
Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.