Standards & methodologies
OCPL is not an accreditation or certification body — SOC 2 reports and ISO 27001 certificates are issued by independent auditors and accredited certification bodies. The standards below are the frameworks OCPL's own methodology draws on and prepares clients to meet.
SOC 2 (AICPA Trust Services Criteria)
The most commonly requested framework in B2B SaaS enterprise deals. See SOC 2 readiness.
ISO/IEC 27001
The certifiable management-system standard most often required by European and multinational customers. See ISO 27001 readiness.
NIST Cybersecurity Framework
A reference structure for organizing risk and control work, used to inform prioritization even outside a formal certification path.
OWASP
The reference point for common application and API security failure modes, informing application and API security reviews.
CIS Controls
A practical baseline for foundational technical controls, used to inform vulnerability assessment and cloud/network security work.
The methodology behind it
Every engagement — regardless of which standard applies — runs on the same six-step methodology: Understand, Assess, Prioritize, Build, Validate, Strengthen.
Not sure which standard applies to you?
Tell us what your customers or regulators are asking for and we'll help you figure out where to start.