ISO 27001 · SOC 2 · NIS2 · DORA
Review ISO 27001 and SOC 2 without reading the whole report
Governly reads the vendor's certificate and audit report and answers the essentials: does the scope cover the service you're buying, is the certificate valid, are there exceptions, and how does it map to NIS2 and DORA?
What we look at
- Certificate validity and issuing body
- Scope vs the service you're buying
- Exceptions and qualified opinions
- Statement of Applicability and excluded controls
- Mapping to NIS2 and DORA
- Suggested follow-up questions for the vendor