Skip to content

Solution

A second standard. Much of it is already done.

ISO 27001, NEN 7510 and ISO 9001 share the same management system structure. Once you have one, a large part of the next is already in place. Trustbird makes that overlap visible: your existing work is linked to the new standard, and you only work on what it adds.

  • Existing controls linked to the new requirements
  • Evidence supplied once, counted for both
  • One audit and review cycle for all standards

Why the second standard costs less in Trustbird

Without a link between standards, every new one feels like starting over. In Trustbird the standards are views on the same management system, so the second one builds on the first.

The overlap made visible

When you adopt a new standard, Trustbird shows per requirement what is already covered, by which document, control and evidence.

One policy, several standards

An access policy or incident procedure serves every standard it applies to. One version, one owner, one approval date.

Evidence that counts everywhere

Evidence is attached to the control, not to the standard. When a control covers requirements in both, the same evidence counts for both.

Only the gaps on your list

Your work list contains what the new standard adds, such as healthcare-specific controls for NEN 7510 or process and customer requirements for ISO 9001.

One Statement of Applicability

Controls are rows and each standard is a column. You keep one overview instead of two documents that drift apart.

Combined audits

Plan internal audits and the management review for all standards together, and hand the certification body one consistent file.

How you add a standard

  1. 01

    Adopt the new standard

    Switch it on next to what you already carry. Trustbird proposes links to your existing work straight away.

  2. 02

    Review what is covered

    Check the proposed links and confirm where existing controls and documents meet the new requirements.

  3. 03

    Work on what it adds

    Decide on the additional requirements, assign owners and attach evidence.

  4. 04

    Audit both together

    Include the new standard in your audit and review cycle and export one file for the auditor.

Frequently asked questions

Do I have to move my existing ISO 27001 work into Trustbird first?
Your existing management system is the starting point. You describe your organization and bring in your current policy, risks and controls, for example through a CSV import, and Trustbird proposes how they link to both standards.
Who confirms that an existing control meets a new requirement?
You do. Trustbird proposes the links, and a named person confirms them before they count. The auditor makes the final assessment.
Which standards can I combine?
ISO 27001, NEN 7510 and ISO 9001 share the same core. NIS2 and the GDPR can be linked to the same controls as sets of requirements.

See what Trustbird does for your organization

Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing. Apply as a design partner, or mail us with a question.