Organizations that need to demonstrate compliance to a regulator, a client, or an insurer — often against several frameworks at the same time.
Last updated — August 22, 2026
A client, a regulator, or an insurer asks for proof of compliance, sometimes against several frameworks at once — ISO 27001 for a tender, law 05-20 for operations in Morocco, GDPR for European citizens' data. Treating each framework in isolation multiplies the work without a proportional reduction in risk.
—
Gap diagnosis report
—
Risk register and treatment plan
—
Documentation set (policies, procedures)
—
UCM mapping of controls shared across the relevant frameworks
—
Certification-audit preparation file
—
Documented responses to client security questionnaires
Varies with the number of frameworks and starting maturity — from a few weeks for a targeted upgrade to several months for full certification preparation
Typical duration
No — that is exactly the purpose of the UCM (Unified Control Mapping) methodology: a single control set is implemented once, then mapped onto each relevant framework (ISO 27001, NIS2, law 05-20, NESA, NCA ECC, GDPR). An organization subject to several frameworks implements once and demonstrates compliance several times. Full methodology at /approche/ucm.
No. The decision to certify belongs exclusively to the accredited certification body, which conducts an independent audit. The engagement prepares the organization for that audit but cannot replace it or guarantee its outcome.
It depends on the organization's actual perimeter (sector, countries of operation, clients). The frameworks applied are listed above; the initial diagnosis determines which ones actually apply to your situation.