ESG & Sustainability
Available nowESG Essentials · 1.1
ESG Essentials is a pragmatic starter set of Environmental, Social, and Governance disclosures: the questions investors, customers, and partners increasingly ask, without the weight of a full ESG audit. It is Keel-authored content, every requirement written in Keel’s own words, whose social-responsibility coverage was checked against the core subjects of ISO 26000:2010, ISO’s guidance on social responsibility, used as a checklist for what a responsible-business baseline should think about. ISO 26000 states no requirements of its own, so nobody is ever certified against it; ESG Essentials gives you requirements you can evidence and score.
Is ISO 26000 certifiable? Why there is nothing to certify against, and what to run instead
49
requirements in Keel’s authored baseline
Premium
Access
Add-on from $19/mo
Scope
How much of the standard Keel models
This is a Keel-defined composite rather than a published standard, so there is no external leaf count it could be complete or incomplete against. Keel sets the scope, and the requirement count below is Keel’s own baseline.
- Authored in Keel
- 49 requirements
- Defined by the standard
- Not applicable: no external standard
What Keel scores here, and what it does not
Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework
Who it is for
Who needs ESG Essentials?
- Companies fielding ESG questions in procurement or diligence
- Teams building a credible baseline before a formal framework
- Founders who want governance and sustainability documented, not improvised
What Keel does
How Keel helps with ESG Essentials
- A curated ESG disclosure set you can adopt incrementally
- The same evidence engine you use for security, applied to ESG
- A shareable posture so you can answer ESG asks quickly
Collect once, comply everywhere
ESG Essentials shares canonical controls with SOC 2, SOX (Sarbanes-Oxley) Section 404 and ISO/IEC 27001 and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding ESG Essentials rarely means starting from scratch.
- ISO/IEC 27001 shares canonical controls
- CIS Critical Security Controls shares canonical controls
- PCI DSS shares canonical controls
- SOC 2 shares canonical controls
- SOX (Sarbanes-Oxley) Section 404 shares canonical controls
- NIST Cybersecurity Framework shares canonical controls
- NIST SP 800-53 shares canonical controls
- FedRAMP Rev5 Class B shares canonical controls
- FedRAMP Rev5 Class C shares canonical controls
- FedRAMP Rev5 Class D shares canonical controls
- FedRAMP 20x shares canonical controls
- FedRAMP Consolidated Rules no shared canonical controls
- NIST SP 800-171 shares canonical controls
- HIPAA shares canonical controls
- GDPR shares canonical controls
- COPPA shares canonical controls
- Google Play Families no shared canonical controls
- Amazon Appstore Child-Directed Apps no shared canonical controls
- Apple App Store Kids Category no shared canonical controls
- PIPEDA shares canonical controls
- ISO 9001 shares canonical controls
- AI Governance Essentials shares canonical controls
- ISO/IEC 42001 shares canonical controls
- NIST AI Risk Management Framework shares canonical controls
- EU AI Act no shared canonical controls
- US Employment Law - Federal Baseline shares canonical controls
A framework is lit when at least one canonical control satisfies both ESG Essentials and that framework. Unlit means none of them do, which is an absence rather than a judgment about that standard. 21 of 26 are lit here.
Other frameworks: ISO/IEC 27001 · CIS Critical Security Controls · PCI DSS · SOC 2 · SOX (Sarbanes-Oxley) Section 404 · NIST Cybersecurity Framework · All frameworks