Skip to content
DM11AI TRUST & IT RISK PROTECTION
StandardsProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • SastAction®
  • NosConformes®
  • Cyber Antifrágil®
  • All products

Company

  • About Us
  • Case Studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000
  • Standards and certifications
  • Comparisons between standards

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption
  1. Home
  2. COMPARISONS

COMPARISONS

Which one is your customer actually asking for

Most of the doubt before signing fits into a single question: do these two acronyms do the same thing? Each comparison below answers that in its first paragraph, then lays out in a table who requires what.

AI governance

  • ISO 42001 vs EU AI Act

    ISO/IEC 42001 is a standard that earns a certificate; the EU AI Act is binding law. They don't compete: ISO 42001 helps you comply with the AI Act. See the comparison, the deadlines and where to start.

    Read
  • ISO 42001 vs NIST AI RMF

    ISO/IEC 42001 is an AI standard that earns a certificate; the NIST AI RMF is a free framework for handling AI risk. See the differences, when to use each, and how they fit together.

    Read

Information security

  • SOC 2 vs ISO 27001

    SOC 2 is an audit report strong in the United States; ISO/IEC 27001 is an international information-security certification. See the differences, what each customer recognizes, and how one accelerates the other.

    Read
  • SOC 2 Type 1 vs Type 2

    Type 1 is a snapshot of a single day; Type 2 proves controls worked for months. See the difference, timelines, cost and why buyers nearly always ask for Type 2.

    Read
  • ISO 27001 vs NIST CSF

    ISO/IEC 27001 is an international security certification; the NIST CSF is a free framework for organizing your defense. See the differences, when to use each, and how they fit together.

    Read
  • CIS Controls vs ISO 27001

    CIS Controls tell you what to configure; ISO 27001 organizes management and earns a certificate. See the difference, where CIS Benchmarks fit, and how to use both.

    Read
  • CSA STAR vs ISO 27001

    CSA STAR does not replace ISO 27001: Level 2 is built on top of it. See how the STAR levels work, where ISO 27017 fits and what the right order is.

    Read
  • NIS2 vs ISO 27001

    NIS2 is EU law with fines and personal liability for directors; ISO 27001 is a certifiable standard. See what the standard already solves, what it does not, and who is in scope.

    Read
  • TISAX vs ISO 27001

    ISO/IEC 27001 is an international information-security certification; TISAX is the automotive industry's assessment. See the differences, what each carmaker asks for, and how one accelerates the other.

    Read

Privacy and data protection

  • GDPR vs LGPD

    GDPR (Europe) and LGPD (Brazil) start from the same principles but differ on the fine, the notice deadline, the legal bases and the authority. See the comparison and what changes for companies serving both countries.

    Read
  • ISO 27701 vs LGPD

    Nobody gets certified in LGPD, because it is a law. ISO 27701 is the privacy standard that earns a certificate, and since 2025 it no longer depends on ISO 27001.

    Read

Business continuity

  • BCP vs DRP

    A BCP (Business Continuity Plan) keeps the company running in a crisis; a DRP (Disaster Recovery Plan) restores IT systems. See the difference, why you need both, and how to build them.

    Read

Security testing

  • Pentest vs Vulnerability Assessment

    A vulnerability assessment finds and lists the flaws; a pentest tries to exploit them to prove the real risk. See the difference, when to use each, and why compliance often asks for both.

    Read

Still unsure which path fits your company?

Tell us what your customer asked for and we will say which standard answers it, and what you already have in house that counts toward it.

Talk to a specialist