Standards coverage
Which Vernax check groups contribute to which security and privacy standards. This is an orientation aid for coverage — not a certification and no substitute for a full audit.
DSGVO / GDPR
| Art. 32 (integrity/confidentiality) | |
| SSL/TLS | Art. 32 (encryption) |
| Web Security | Art. 32 (security of processing) |
| Exposure | Art. 32 (confidentiality) |
| Privacy | Art. 6/7 (consent) · Art. 25 · Art. 44 (third country) |
ISO/IEC 27001:2022 (Annex A)
| A.8.24 Cryptography · A.5.7 Threat intelligence | |
| SSL/TLS | A.8.24 Cryptography |
| DNS | A.8.20/8.21 Network security · A.8.16 Monitoring |
| Domain | A.5.9 Inventory of assets · A.8.8 Vulnerabilities |
| Certificate Transparency | A.8.8 Vulnerability management · A.8.16 Monitoring |
| Web Security | A.8.26/8.27 Application security · A.8.24 Cryptography |
| Reputation | A.5.7 Threat intelligence |
| Exposure | A.8.9 Configuration management · A.8.12 Data leakage |
| Privacy | A.5.34 Privacy & PII |
BSI IT-Grundschutz
| SSL/TLS | CON.1 Crypto concept |
| DNS | NET.1 Network architecture |
| Web Security | APP.3.1 Web applications |
| Exposure | OPS.1.1 Operations · CON.8 Software development |
NIS2 (Art. 21)
| Art. 21 (2) h (cryptography) | |
| SSL/TLS | Art. 21 (2) h |
| DNS | Art. 21 (2) g (cyber hygiene) |
| Domain | Art. 21 (2) a (risk analysis) |
| Certificate Transparency | Art. 21 (2) e (security in development) |
| Web Security | Art. 21 (2) e |
| Reputation | Art. 21 (2) b (incident handling) |
| Exposure | Art. 21 (2) g (cyber hygiene) |
See also Scoring methodology and Compliance & data processing.