Standards and Regulations
Standard X covers key international standards and European regulations. When requirements overlap, you do the work once and cover multiple standards at the same time.
ISO 27001 — Information Security Management
Information security management system. A legal obligation for a large number of Montenegrin organizations by mid-2027 under the Law on Information Security. Standard X covers the entire PDCA cycle: context, policies, risk assessment, SoA with 93 Annex A controls, internal audits, management review, corrective actions.
ISO 9001 — Quality Management
Quality management system. If you already have 9001 established, Standard X connects it with 27001 through a shared organizational context — no duplication of policies, procedures, or training.
ISO 22301 — Business Continuity
Business continuity. BIA analyses, recovery plans, DRP scenarios, testing. Standard X uses the same risk register for BCM assessment.
ISO 14001 — Environmental Management
Environmental management system. Aspect analysis, impacts, objectives, monitoring — integrated with other standards through a shared framework.
ISO 42001 — AI Management System
The newest standard for managing AI systems (2023). Standard X covers AI risk assessment, transparency, bias control, and post-deployment monitoring. Critical for organizations that use or develop AI solutions.
GDPR — General Data Protection Regulation
Record of processing activities (RoPA), data protection impact assessments (DPIA), privacy policies, data processing agreements (DPA), data subject rights procedures, incident records with a 72-hour deadline. When GDPR and ISO 27001 requirements overlap — Standard X knows it.
EU AI Act
The first comprehensive EU regulation on AI, in force since August 2024. Risk classification of AI systems, transparency, technical documentation, human oversight. Standard X helps organizations map the AI systems they use and prepare the required documentation.
NIS2 — Network and Information Security
EU directive on cybersecurity for critical sectors. Activity register, vulnerability management, incident response, CSIRT notification within 24 hours. Becoming relevant for Montenegrin companies within the supply chain of EU clients.
DORA — Digital Operational Resilience Act
Regulation on the digital operational resilience of the EU financial sector. ICT risk management, resilience testing, third-party management, incident reporting. Standard X covers this once a financial organization falls under the regulated framework.
New Standards on Request
Does your industry require a standard that is not on the list? We plan our expansion through a roadmap — get in touch with us.