Skip to main content
NOVACompliance

Frameworks

Activate the frameworks that apply to you

NOVA maps requirements from each framework onto a shared control set. Evidence collected once can support multiple frameworks where it genuinely satisfies the control.

Available now

Ready to activate

SOC 2

Available now

Service organisation reporting against the Trust Services Criteria, used widely in enterprise procurement.

Explore

ISO/IEC 27001

Available now

The international standard for an information security management system, certified by an accredited body.

Explore

Essential Eight

Available now

Eight prioritised mitigation strategies published by the Australian Cyber Security Centre, assessed by maturity level.

Explore

ISO/IEC 42001

Available now

The management system standard for artificial intelligence, covering governance of AI systems across their lifecycle.

Explore

Roadmap

Planned frameworks

NIST Cybersecurity Framework

Planned

A voluntary framework organising cybersecurity outcomes into functions, categories and subcategories.

Read more

HIPAA

Planned

United States requirements for safeguarding protected health information held by covered entities and business associates.

Read more

Australian Government Information Security Manual

Planned

A cybersecurity framework of controls published by the Australian Signals Directorate for government systems and their suppliers.

Read more

Global register

Planned frameworks by region

A regional view of the major compliance frameworks and regulatory regimes NOVA may support. Eredox is headquartered in Australia and its service scope is worldwide.

Global and cross border

Major frameworks and regimes encountered across every market. Confirm applicability for each customer engagement.

FrameworkJurisdictionPrimary subjectNOVA relevancePriority
ISO/IEC 27001:2022InternationalInformation security management system requirementsCore product framework for governance, controls, evidence, risk treatment and certification readiness.Core
ISO/IEC 27701InternationalPrivacy information management extension to ISO 27001Supports privacy control mapping, processor and controller accountability and global privacy operations.Core
ISO 22301InternationalBusiness continuity managementSupports continuity objectives, recovery plans, exercises and resilience evidence.Core
NIST Cybersecurity Framework 2.0International / US originCybersecurity risk governance and outcomesCrosswalk framework for customers using NIST terminology.Core
NIST SP 800-53 Rev 5International / US originSecurity and privacy controlsDetailed control library for implementation, inheritance and evidence mapping.Core
NIST SP 800-30 Rev 1International / US originInformation security risk assessmentMethod for threat, vulnerability, likelihood, impact and risk assessment.Core
CIS Controls v8.1InternationalPrioritised technical safeguardsPractical baseline for smaller customers and technical evidence collection.Core
SOC 2 Trust Services CriteriaInternational / AICPAService organisation controlsCustomer assurance and Trust Center evidence model. Not a government law.Core
COBIT 2019International / ISACAIT governance and management objectivesGovernance crosswalk for enterprise and audit customers.Reference
PCI DSS v4.0.1International / payment cardsProtection of payment card dataSector-triggered where cardholder data is stored, processed or transmitted.Sector
FATF RecommendationsInternational / AML CFTAnti-money laundering and counter-terrorist financingAnchor for AML and CTF content, risk assessment and customer due diligence.Sector
CSA Cloud Controls Matrix v4InternationalCloud security controls and shared responsibilityCloud provider and SaaS assurance crosswalk.Reference
Core

Cross-market or foundational. Prioritised in the catalogue, control library, crosswalks, evidence and reporting.

Sector

Triggered by sector or activity. Supported as an add-on with applicability assessment and sector evidence.

Reference

Voluntary or mapping aid. Used for crosswalks, procurement and assurance, never presented as certification.

This register is a product catalogue and discovery baseline, not a certification or legal opinion. Applicability depends on customer country, sector, data, service and contractual role.

Readiness

Illustrative readiness reporting

Illustrative interface concept. Values shown are examples, not customer data.

  • Controls mapped across activated frameworks
  • Evidence status shown by control and requirement
  • Gaps surfaced before an external assessment
  • Freshness expectations keep evidence current

Example readiness snapshot

SOC 295%

Readiness

ISO/IEC 2700185%

Readiness

Essential Eight90%

Maturity coverage

ISO/IEC 4200182%

Readiness

NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.

See NOVA against your own compliance obligations

Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.