Skip to content
ASIRI

All frameworks

Everything Asiri maps, displays, or refuses.

Twenty-three frameworks in four groups. The group a framework sits in decides what Asiri will claim about it — and the last group exists because some claims cannot honestly be made at all.

7Managed16Recognised2Extensions4Refused

Recognised

Displayed on your Trust Center with the expiry tracked, and no control mapping behind them. Quality management does not read across to data protection, and a coverage figure here would imply it did.

NaDPAP

The NDPC’s own ten-metric adequacy programme.

Recognised

CBN RBCF

Risk-based cybersecurity. Mandatory for banks and payment service providers.

Recognised

ISO 22301

Business continuity. Common among banks and ICT providers.

Recognised

ISO 9001

Quality management. The most widely held certificate in Nigeria.

Recognised

ISO 37001

Anti-bribery. Increasingly expected in public procurement.

Recognised

ISO 45001

Health and safety. Common in oil and gas, and in construction.

Recognised

ISO 14001

Environmental management.

Recognised

ISO/IEC 20000-1

IT service management.

Recognised

ISO 22000

Food safety management.

Recognised

ISO 50001

Energy management.

Recognised

ISO 13485

Medical devices quality management.

Recognised

ISO/IEC 17025

Testing and calibration laboratories.

Recognised

NITDA

NITDA guidelines.

Recognised

NCC

NCC licensing conditions.

Recognised

NAICOM

NAICOM requirements.

Recognised

SEC

SEC Nigeria requirements.

Recognised

Extensions

Assessed against an existing ISO 27001 certificate rather than on their own. Asiri models them as extensions so neither can be displayed standalone.

ISO/IEC 27017

Cloud security controls. Assessed as an extension to a 27001 certificate, so it can only be shown alongside one.

Only alongside ISO 27001

ISO/IEC 27018

Personal data in public clouds. Same rule — it is not certified on its own.

Only alongside ISO 27001

What Asiri will not let you claim

No certification scheme exists for these. Asiri refuses the claim and offers the wording that is true instead — because getting it wrong is the kind of mistake that surfaces in the middle of a deal.

“NIST CSF certified”

A framework, not a standard. Nothing certifies against it.

Say instead
Aligned to NIST CSF — self-declared.

Not certifiable

“ISO 31000 certified”

Risk management guidance, with no certification scheme.

Say instead
Aligned to ISO 31000.

Not certifiable

“ISO 26000 certified”

Social responsibility — explicitly not intended for certification.

Say instead
Guided by ISO 26000.

Not certifiable

“ISO 27002 certified”

Control guidance supporting 27001. It is 27001 that is certifiable.

Say instead
ISO/IEC 27001:2022 certified.

Not certifiable

One control satisfies many of these at once. See what you already hold before you buy anything.

Start free →