Artifacts

GRC Artifact Index

Find the right page for your regulation, framework, or control program. Filter by topic, search by keyword, and open the artifact that matches your scope.

Explore artifacts
EU AI Act timeline artifact preview
Featured
Living Timeline

Regulatory deadlines in one living timeline.

Compare deadlines across CRA, NIS2, DORA, the EU AI Act, and other supported frameworks. Open the free universal view or build a timeline limited to the rules, systems, and deadlines that apply to your organisation.

Free universal timeline - broad coverage. Custom timelines can be scoped to your stack.

Sorena regulatory universal timeline preview
Product
Read

ESPR Timeline and Compliance Guide

ESPR guide covering scope, delegated acts, ecodesign requirements, DPP readiness, unsold-goods duties, evidence, and implementation dates.

Sorena AIArtifactsEUEcodesign For Sustainable Products Regulation
Read ESPR Timeline and Compliance Guide
GLOBAL
Read

ETSI EN 303 645 Implementation Guide

Apply the voluntary ETSI EN 303 645 consumer IoT security baseline, including its scope, provisions, implementation evidence, assessments, and claim limits.

Sorena AIArtifactsGlobalEtsi En 303 645
Read ETSI EN 303 645 Implementation Guide
GLOBAL
Read

ETSI EN 319 401 Implementation Guide

Plain-language guidance for trust service provider scope, common EN 319 401 controls, operating evidence, assessment boundaries, and eIDAS mapping.

Sorena AIArtifactsGlobalEtsi En 319 401
Read ETSI EN 319 401 Implementation Guide
GLOBAL
Read

ETSI EN 319 411-1 Certificate Service Guide

Navigate certificate policy profiles, TSP and CA/RA roles, subscriber validation, certificate lifecycle controls, revocation status, CA keys, and assessment evidence.

Sorena AIArtifactsGlobalEtsi En 319 411 1
Read ETSI EN 319 411-1 Certificate Service Guide
GLOBAL
Read

ETSI EN 319 411-2 Qualified Certificate Guide

Guide to V2.6.1 qualified certificate policy profiles, EN 319 411-1 dependencies, identity proofing, QSCD routes, lifecycle controls, trusted-list reliance, and the separate eIDAS qualified-status context.

Sorena AIArtifactsGlobalEtsi En 319 411 2
Read ETSI EN 319 411-2 Qualified Certificate Guide
GLOBAL
Read

FIPS Cryptographic Algorithms Guide

Choose FIPS algorithms and separate algorithm approval, CAVP testing, CMVP module validation, approved use, transitions, and procurement evidence.

Sorena AIArtifactsGlobalFips Crypto Algorithms
Read FIPS Cryptographic Algorithms Guide
GLOBAL
Read

ISO 22301 Implementation Guide

Plan BCMS scope, BIA, disruption risk, recovery strategy, exercises, conformity evidence, and optional certification under ISO 22301:2019.

Sorena AIArtifactsGlobalISO 22301
Read ISO 22301 Implementation Guide
GLOBAL
Read

ISO/IEC 27001 Implementation Guide

Plan ISMS scope, risk treatment, the Statement of Applicability, Annex A evidence, internal audits, management review, and certification.

Sorena AIArtifactsGlobalISO 27001
Read ISO/IEC 27001 Implementation Guide
GLOBAL
Read

ISO/IEC 27005 Risk Management Guide

ISO/IEC 27005:2022 guidance for risk criteria, scenario-based assessment, treatment, residual-risk decisions, and reviewable ISMS evidence.

Sorena AIArtifactsGlobalISO 27005
Read ISO/IEC 27005 Risk Management Guide

Guidance tailored to your needs

Get guidance tailored to your organisation, systems, and deadlines, with specific actions for the teams responsible.

Talk to an expert