Eleven frameworks, ready to work
Switch on a framework and its controls arrive as recurring work. Each comes with a description, a recommendation and a default review cadence, so nobody starts from a blank page. Frameworks sit side by side in one workspace: add ISO 27001 first, then GDPR, then NIS2, without rebuilding anything.
| Framework | Controls in Dazr | Plan |
|---|---|---|
| ISO 27001:2022 | 118 (93 Annex A controls plus clauses 4-10) | All plans |
| GDPR | 36 | All plans |
| NIS2 | 21 | All plans |
| NEN 7510, ISO 27701, ISO 22301, SOC 2 | 20, 36, 25 and 51 | Pro and Enterprise |
| DORA, EU AI Act, BIO, PCI DSS | 27, 27, 15 and 35 | Enterprise |
Free includes one of ISO 27001, GDPR or NIS2, Basic two, Pro five and Enterprise all eleven.
Recurring controls with owners
- Assign an owner and a due date. The owner gets an email when the control is assigned, 7 days before it is due and weekly while it is overdue.
- Pick a cadence: once, every month, every 3 months, every 6 months or every year. Enterprise sets its own interval per control.
- Completing a control locks its evidence and schedules the next cycle, so the history of every review stays intact.
- Comments per control keep the discussion next to the evidence; external auditors can comment too.
- Add your own tasks next to the framework controls from Basic, for work that no standard prescribes.
Evidence that does not quietly expire
Attach evidence as a note, a link or a file of up to 25 MB, and give it a valid-until date. A control only counts as covered while its evidence is valid. Before evidence lapses, the owner hears about it in one daily digest email, together with vendor reviews that are due. Evidence validity and expiry alerts are included from Basic.
Statement of Applicability
Mark each ISO 27001 control applicable or not, give the reason (risk assessment, legal or contractual requirement, business requirement or best practice) and record the implementation status: implemented, partial, planned or not implemented. Excluding a control requires a justification, as clause 6.1.3 d expects. Excluded controls drop out of your control list and coverage.
Approve a version when the SoA is ready: Dazr keeps every approved version with who approved it and when, and exports it as PDF or XLSX. Included from Basic.
Controls, risks, policies and processes, linked
Everything in the workspace can point to everything else: controls, risks, policies, processes, assets, vendors and processing activities. A risk shows the controls that treat it, a policy shows the controls it supports, and a process shows the controls, risks and assets it depends on. Links show up for auditors too, read-only.
The process register (Pro and Enterprise) lists your business processes with a description, a criticality and an owner, up to 500 per workspace, so continuity and risk work hangs off the processes that matter.
A dashboard that shows the trend
- Controls covered per framework: how many controls have valid evidence, with the change over the last 30 days.
- What needs you now: overdue and due-soon controls, policies, evidence and vendor reviews in one list, oldest first.
- Daily coverage snapshots draw the trend, so you see whether the programme is improving or drifting.
- On Enterprise an audit-readiness card from Prepare for Audit sits next to it.


