| Information security policy | SOC 2 CC5.3 |
| Risk assessment | SOC 2 CC3.2 |
| Independent audit and certification | SOC 2 CC4.1 |
| Multi-factor authentication | SOC 2 CC6.1 · PCI DSS 8.4.2 |
| Password policy | SOC 2 CC6.1 |
| Access provisioning and review | SOC 2 CC6.2 · PCI DSS 7.2.4 |
| Encryption at rest | SOC 2 CC6.1 · PCI DSS 3.5.1 · GDPR Art. 32 |
| Encryption in transit | PCI DSS 4.2.1 |
| Data retention and secure deletion | PCI DSS 3.2.1 · GDPR Art. 28 |
| Data location and transfers | GDPR Art. 44 · GDPR Art. 46 |
| Cardholder data and PCI DSSno ISO 27001 clause: beyond an ISO 27001 certificate | PCI DSS 3.2.1 · PCI DSS 12.5.2 |
| Logging and monitoring | SOC 2 CC7.2 · PCI DSS 10.4.1 |
| Vulnerability and patch management | SOC 2 CC7.1 · PCI DSS 6.3.3 · PCI DSS 11.3.1 |
| Penetration testing | PCI DSS 11.4.3 |
| Secure development and change | SOC 2 CC8.1 |
| Incident response plan | SOC 2 CC7.4 · PCI DSS 12.10.1 |
| Notifying the customer of an incident | SOC 2 CC7.4 · GDPR Art. 33 |
| Business continuity plan | SOC 2 A1.3 |
| Backup and disaster recovery | SOC 2 A1.2 |
| Subcontractors and subprocessors | SOC 2 CC9.2 · PCI DSS 12.8.1 · GDPR Art. 28 |
| Assessing your own suppliers | SOC 2 CC9.2 |
| Data subject requests | GDPR Art. 15 · GDPR Art. 28 |
| Lawful basis, consent and privacy notice | GDPR Art. 6 |
| Data processing agreement | GDPR Art. 28 |