gateTechStandards checks technical security standards, ISO 27001, NIST CSF, TISAX and SOC 2, as boolean flags. Not a standalone customer gate, but an architecture building block woven into other gates.
Every row is a hard boolean check, not probabilistic scoring. A critical failure leads to block, a high severity failure to warn, everything else to pass.
| Reference | Checks | Severity |
|---|---|---|
| Clause 4.3 | ISMS scope not defined | critical |
| Clause 6.1.2 | Information security risk assessment not performed | critical |
| Clause 6.1.3 | Risk treatment plan not documented | high |
| Clause 6.1.3(d) | Statement of Applicability not produced | high |
| Clause 8.3 | Annex A controls (93 controls) not fully implemented | critical |
| Clause 9.2 | Internal ISMS audit not performed | medium |
| Clause 9.3 | Management review not performed | medium |