ISO 27001 · SOC 2 · NIS2 · DORA

Review ISO 27001 and SOC 2 without reading the whole report

Governly reads the vendor's certificate and audit report and answers the essentials: does the scope cover the service you're buying, is the certificate valid, are there exceptions, and how does it map to NIS2 and DORA?

What we look at

  • Certificate validity and issuing body
  • Scope vs the service you're buying
  • Exceptions and qualified opinions
  • Statement of Applicability and excluded controls
  • Mapping to NIS2 and DORA
  • Suggested follow-up questions for the vendor