Standards coverage

Which Vernax check groups contribute to which security and privacy standards. This is an orientation aid for coverage — not a certification and no substitute for a full audit.

DSGVO / GDPR

MailArt. 32 (integrity/confidentiality)
SSL/TLSArt. 32 (encryption)
Web SecurityArt. 32 (security of processing)
ExposureArt. 32 (confidentiality)
PrivacyArt. 6/7 (consent) · Art. 25 · Art. 44 (third country)

ISO/IEC 27001:2022 (Annex A)

MailA.8.24 Cryptography · A.5.7 Threat intelligence
SSL/TLSA.8.24 Cryptography
DNSA.8.20/8.21 Network security · A.8.16 Monitoring
DomainA.5.9 Inventory of assets · A.8.8 Vulnerabilities
Certificate TransparencyA.8.8 Vulnerability management · A.8.16 Monitoring
Web SecurityA.8.26/8.27 Application security · A.8.24 Cryptography
ReputationA.5.7 Threat intelligence
ExposureA.8.9 Configuration management · A.8.12 Data leakage
PrivacyA.5.34 Privacy & PII

BSI IT-Grundschutz

SSL/TLSCON.1 Crypto concept
DNSNET.1 Network architecture
Web SecurityAPP.3.1 Web applications
ExposureOPS.1.1 Operations · CON.8 Software development

NIS2 (Art. 21)

MailArt. 21 (2) h (cryptography)
SSL/TLSArt. 21 (2) h
DNSArt. 21 (2) g (cyber hygiene)
DomainArt. 21 (2) a (risk analysis)
Certificate TransparencyArt. 21 (2) e (security in development)
Web SecurityArt. 21 (2) e
ReputationArt. 21 (2) b (incident handling)
ExposureArt. 21 (2) g (cyber hygiene)

See also Scoring methodology and Compliance & data processing.