Skip to content

description: Kanonik runs ISO 27001:2022, SOC 2, GDPR, NIST CSF 2.0, HIPAA, and HIPAA today. Each loads as a versioned package onto the same substrate: the same canonical record, the same Verifier, the same approval gate, the same sealed export. Your first framework is included in Solo; each additional one is a $499 Framework Activation.

Five frameworks live today. One record underneath

Kanonik runs ISO 27001:2022, SOC 2, GDPR, NIST CSF 2.0, HIPAA, and HIPAA today. Each loads as a versioned package onto the same substrate: the same canonical record, the same Verifier, the same approval gate, the same sealed export. Your first framework is included in Solo; each additional one is a $499 Framework Activation.

What you get with each framework

ISO 27001:2022

The full requirement set and Annex A control taxonomy, end to end. Your AI drafts the Statement of Applicability and the control mapping; the Verifier checks each decision; you approve; the record seals it. The output is the artifact set an ISO auditor actually asks for, with the reasoning trail behind every applicability call.

SOC 2 (Trust Services Criteria)

The Trust Services Criteria load onto the same canonical record, so the controls and evidence you already recorded project onto SOC 2 rather than being retyped into it. You get the applicability statement, the criteria-to-control mapping, and sealed records that show who wrote, verified, and approved every entry.

GDPR

Records of Processing Activities under Article 30, DPIAs, and processing activities, recorded and verified continuously as part of Solo. When a regulator, a data protection authority, or an enterprise customer asks, a Sealed Audit Package produces the signed bundle. Their access to your workspace, if you grant it, is free and does not expire unless you set an end date.

NIST CSF 2.0

The CSF 2.0 functions and categories load as a package and map onto the controls you already hold in the canonical record. You get the profile-style applicability statement, the category-to-control mapping, and the same sealed chain behind every assessment your AI proposes and you approve.

HIPAA

The Administrative Simplification rules (45 CFR Part 164) load as a package covering the administrative, physical, technical, organizational, privacy and breach-notification families, with required and addressable implementation specifications distinguished as the rule distinguishes them. HIPAA is US federal regulation and therefore public domain: there is no text to buy and no licence to attest, so you can activate it and start immediately.

Your own licensed copy, where one is required

ISO 27001 and SOC 2 are copyrighted standards. Kanonik does not resell or redistribute their text: those frameworks run against your own licensed copy, and you attest to your licence when you activate the framework. Your licence, your relationship with the standards body, our substrate.

GDPR, NIST CSF 2.0 and HIPAA are public text. There is nothing to buy and nothing to attest; activate and go.

This is the same posture your auditor already expects: the organization under audit holds its own copy of the standard it certifies against.

ISO 27001:2022 and SOC 2

Bring your own licensed standard text. You attest to your licence at activation; Kanonik runs the framework package against your copy.

GDPR, NIST CSF 2.0 and HIPAA

Public text. No licence needed, no attestation step. Included the moment the framework is active.

Author once, map across frameworks

Adding a framework is a projection onto the record you already keep, which is why Framework Activation is a one-time $499 rather than a second subscription. The activation generates the new framework's Statement of Applicability and control mapping, runs them through the Verifier, and seals them.

Five frameworks, one record, one trust layer. Your first framework is included in Solo; activating another is a sealed, one-time event, not a second subscription.

Runs ISO 27001:2022, SOC 2, GDPR, NIST CSF 2.0, HIPAA, and HIPAA today.