Frameworks · Three available today

One questionnaire, several standards covered.

ISO 27001, NIST CSF, Cyber-Safe — you answer once in business language, and we generate your conformity in each framework your customers require. No double entry, no technical jargon, just the right answers in the right place.

Filter by profile
Disponible
01 — International standard

ISO/IEC 27001

The world's reference standard for information security management systems. Required by major buyers, it's the ticket to working with financial, pharmaceutical and industrial groups.

SME under enterprise obligationLarge groupMulti-sector
iso.org/standard/27001
Controls
93
Domains
14
Average SME duration
8–12 h over 4 wks
Difficulty
High
Typical case: subcontractor of a large watchmaking group or private bank.
Disponible
02 — US framework

NIST CSF v2.0

NIST's Cybersecurity Framework, structured around six functions: Govern, Identify, Protect, Detect, Respond, Recover. Highly demanded by US groups and their European subsidiaries — particularly pharma and defence.

Large US / international groupPharma · DefenceSubsidiaries of US groups
nist.gov/cyberframework
Sub-categories
108
Functions
6
Average SME duration
10–14 h over 4–6 wks
Difficulty
High
Typical case: supplier to a US pharma group that requires Govern + Detect as priority.
Disponible
03 — Swiss SME label

Cyber-Safe (Switzerland)

The Swiss label designed for SMEs. Three progressive levels (1 / 2 / 3) that allow a simple start and gradual maturity gain without redoing everything. Designed in partnership with French- and German-speaking Swiss business associations.

Swiss SMEProgressive startFR · DE · IT
cyber-safe.ch
Controls
42
Levels
3
Average SME duration
2–4 h over 1 wk
Difficulty
Accessible
Typical case: a 12-person SME in French-speaking Switzerland that wants to prove its diligence to its customers.
The decisive argument

One answer, several standards covered.

You answer only once, in business language. Our engine projects your answer onto the equivalent controls of each framework. When a customer requires NIST, we have the answer. When another requires ISO, we have the same answer — properly phrased.

SME question · business language

“Do you keep an inventory of your team's work computers and phones?”

Domain · AssetsQuestion Q-014
ISO 27001
Asset inventoryA.8.1.1 · Identification of assets
Exact match
NIST CSF
Asset Management — HardwareID.AM-1 · Physical devices catalogued
Exact match
Cyber-Safe
Device managementN1.4 · List of work devices
Exact match
FINMA
IT system mappingCircular 2023/01 · §42
Roadmap
More than 800 equivalences validated by our analysts across the three live frameworks.
Automatic updates: when a framework evolves, your report updates by itself.
Full transparency: every equivalence is traceable, the auditor sees the mapping.
Questionnaire preview

A typical question, in business language.

No jargon. No acronyms. A question an SME executive can understand, with a clear scale and an evidence request at the end. Click an option to see the progress bar move.

Cyber-Safe · Level 1 / Section 3 — Identities & access
14 / 42
Question 14 · Authentication

Do your employees enable two-factor authentication on their work accounts?

Two-factor authentication (2FA, MFA) requires a second factor in addition to the password — a code, an app notification, a physical key. Indicate the level that matches your reality today, not your goal.

Attach a screenshot of your MFA console (optional)

Compare at a glance.

Three frameworks, six criteria. The “Recommended for” line guides you — but every SME is unique; ask us if you hesitate.

ISO 27001
Origin
Reference issuer
InternationalISO/IEC
Volume of controls
To assess in the SME
93 controls14 domains
Average duration
For an SME of ~20 people
8–12 h4 weeks
Difficulty
Required level of expertise
High● ● ●
External recognition
To answer a customer
WorldwideBanking, pharma, industry
Recommended for
Our default advice
SME subcontracting a large group.If customer = industry
NIST CSF
Origin
Reference issuer
United StatesNIST
Volume of controls
To assess in the SME
108 sub-cat.6 functions
Average duration
For an SME of ~20 people
10–14 h4–6 weeks
Difficulty
Required level of expertise
High● ● ●
External recognition
To answer a customer
Strong (US)US groups and subsidiaries
Recommended for
Our default advice
Subsidiaries of US groups.If customer = US / Pharma
Cyber-Safe
Origin
Reference issuer
Switzerlandcyber-safe.ch
Volume of controls
To assess in the SME
42 controls3 levels
Average duration
For an SME of ~20 people
2–4 h1 week
Difficulty
Required level of expertise
Accessible● ○ ○
External recognition
To answer a customer
SwitzerlandGrowing in CH
Recommended for
Our default advice
Get started with confidence.If I'm starting out
Roadmap

Four frameworks on the way.

FINMA

Circulars from the Swiss financial authority. For private banks, wealth managers and regulated fintechs.

NIS2

European directive on network security. Mandatory for essential and important entities in the EU.

GDPR & nFADP

Data protection — European and Swiss. Dedicated module with a record of processing activities and DPIA.

SOC 2

Type I and Type II. For Swiss SaaS vendors that want to sell to American companies.

Choose your framework. Or let us guide you.

Start for free with one framework. If your customers require another tomorrow, your answers are already mapped — you start nothing over.

Get started for free