All frameworks
Everything Asiri maps, displays, or refuses.
Twenty-three frameworks in four groups. The group a framework sits in decides what Asiri will claim about it — and the last group exists because some claims cannot honestly be made at all.
Managed
Mapped requirement by requirement onto your controls. Coverage is computed from control state, never stored — so it cannot drift from the evidence behind it.
NDPA 2023
The law you answer to. Everything else is a mapping over the same evidence.
GAID 2025
The directive that fixes tiers, filing routes and what counts as a high-risk decision.
GDPR
Applies to the customers you serve in the EU. Most of it is already satisfied by NDPA work.
ISO 27001
Security controls enterprise customers ask for. Overlaps the Act on protection, not on rights.
ISO 27701
The privacy extension to 27001, and the closest international standard to the Act itself.
SOC 2
What US partners ask for. An attestation, not a certification — and narrower than it sounds.
ISO 42001
AI management. Worth carrying early both ways — including for Eri, under GAID’s own AI expectations.
PCI DSS
Card data. Scope boundary first: Asiri sits outside the cardholder data environment.
Recognised
Displayed on your Trust Center with the expiry tracked, and no control mapping behind them. Quality management does not read across to data protection, and a coverage figure here would imply it did.
NaDPAP
The NDPC’s own ten-metric adequacy programme.
CBN RBCF
Risk-based cybersecurity. Mandatory for banks and payment service providers.
ISO 22301
Business continuity. Common among banks and ICT providers.
ISO 9001
Quality management. The most widely held certificate in Nigeria.
ISO 37001
Anti-bribery. Increasingly expected in public procurement.
ISO 45001
Health and safety. Common in oil and gas, and in construction.
ISO 14001
Environmental management.
ISO/IEC 20000-1
IT service management.
ISO 22000
Food safety management.
ISO 50001
Energy management.
ISO 13485
Medical devices quality management.
ISO/IEC 17025
Testing and calibration laboratories.
NITDA
NITDA guidelines.
NCC
NCC licensing conditions.
NAICOM
NAICOM requirements.
SEC
SEC Nigeria requirements.
Extensions
Assessed against an existing ISO 27001 certificate rather than on their own. Asiri models them as extensions so neither can be displayed standalone.
ISO/IEC 27017
Cloud security controls. Assessed as an extension to a 27001 certificate, so it can only be shown alongside one.
Only alongside ISO 27001ISO/IEC 27018
Personal data in public clouds. Same rule — it is not certified on its own.
Only alongside ISO 27001What Asiri will not let you claim
No certification scheme exists for these. Asiri refuses the claim and offers the wording that is true instead — because getting it wrong is the kind of mistake that surfaces in the middle of a deal.
“NIST CSF certified”
A framework, not a standard. Nothing certifies against it.
Say instead
Aligned to NIST CSF — self-declared.
“ISO 31000 certified”
Risk management guidance, with no certification scheme.
Say instead
Aligned to ISO 31000.
“ISO 26000 certified”
Social responsibility — explicitly not intended for certification.
Say instead
Guided by ISO 26000.
“ISO 27002 certified”
Control guidance supporting 27001. It is 27001 that is certifiable.
Say instead
ISO/IEC 27001:2022 certified.
One control satisfies many of these at once. See what you already hold before you buy anything.
Start free →