Where Adding Frameworks Doesn’t Mean More Work

Scale framework coverage using the same controls, evidence, and workflows, without increasing operational overhead.

Request A Demo

Instant Access to 200+ Security Frameworks

Reuse the same controls and evidence across frameworks without rebuilding or duplicating effort.

Book A Demo

All Frameworks

All Frameworks

Privacy

UK Data Protection Act

UK national legislation supplementing UK GDPR requirements.

Privacy

UK GDPR

United Kingdom data protection regime aligned with GDPR principles.

Security

UL 2900-1

Cybersecurity certification standard assessing network-connected products and software.

Security

UN ECE WP.29

Automotive cybersecurity regulation requiring cybersecurity management systems.

Security

UN R155

Automotive cybersecurity regulation mandating risk management and incident response for vehicle manufacturers.

Privacy

Uruguay Data Protection Law

National privacy law aligned with international data protection principles.

Privacy

Utah Consumer Privacy Act

State privacy framework governing transparency and data processing controls.

Privacy

Vermont Act 171

State data broker regulation governing data security and consumer rights.

Privacy

Virginia CDPA 2023

State privacy law establishing consumer data rights and controller obligations.

AI

EU AI Act

EU regulation establishing risk-based compliance requirements for artificial intelligence systems.

AI

ISO 42001 v2023

Artificial Intelligence Management System standard defining governance and risk controls.

AI

NIST AI 600-1

Guidelines for managing risks associated with artificial intelligence systems, including ethical, privacy, and security considerations.

AI

NIST AI RMF AI 100-1 v1.0

Structured methodology for managing risks associated with AI systems.

Financial

CPS 230

Australian operational risk and resilience standard.

Financial

CPS 234

Australian prudential standard requiring information security capability.

Financial

EU DORA

Digital Operational Resilience Act establishing ICT risk management requirements for financial institutions.

Financial

EU EBA GL/2019/04

European Banking Authority ICT and security risk management guidelines.

Financial

EU PSD2

Payment services directive requiring strong customer authentication.

Financial

FCA CRM

Financial Conduct Authority cyber risk management expectations.

Financial

FFIEC

Interagency cybersecurity and IT risk guidance for financial institutions.

Financial

FINRA

Supervisory cybersecurity requirements for broker-dealers.

Financial

GLBA CFR 314 (Dec 2023)

U.S. financial regulation mandating protection of consumer financial information.

Financial

Germany BAIT

Banking supervisory requirements for IT security and governance.

Financial

MAS TRM 2021

Monetary Authority of Singapore technology risk management guidelines.

Financial

NAIC Insurance Data Security Model Law

Model law requiring cybersecurity programs for insurance entities.

Financial

NY DFS 23 NYCRR500

Cybersecurity regulation for financial institutions operating in New York.

Financial

OSFI B-13 (Canada)

Guideline requiring technology and cyber risk management in federally regulated financial institutions.

Financial

PCI DSS SAQ A

Self-Assessment Questionnaire for merchants fully outsourcing cardholder data handling.

Financial

PCI DSS SAQ A-EP

SAQ for e-commerce merchants with partially outsourced payment processing.

Financial

PCI DSS SAQ B

SAQ for merchants using imprint or standalone dial-out terminals.

Financial

PCI DSS SAQ B-IP

SAQ for merchants using IP-connected standalone terminals.

Financial

PCI DSS SAQ C

SAQ for merchants with payment applications connected to internet.

Financial

PCI DSS SAQ C-VT

SAQ for merchants processing via web-based virtual terminals.

Financial

PCI DSS SAQ D Merchant

Comprehensive SAQ for merchants not eligible for other categories.

Financial

PCI DSS SAQ D Service Provider

SAQ for service providers storing or transmitting cardholder data.

Financial

PCI DSS SAQ P2PE

SAQ for merchants using validated point-to-point encryption solutions.

Financial

PCI DSS v3.2

Payment Card Industry standard defining requirements for protecting cardholder data.

Financial

PCI DSS v4.0.1

Updated PCI standard strengthening authentication and risk-based controls.

Financial

SEC Cybersecurity Rule

Regulation requiring public companies to disclose cybersecurity risks and governance oversight.

Financial

SOX

Corporate governance law requiring internal financial reporting controls.

Financial

SWIFT CSF v2023

Security control framework for financial institutions connected to SWIFT network.

Financial

Saudi SACS-002

Saudi Arabian monetary authority cybersecurity standard for financial institutions.

Financial

Saudi SAMA CSF v1.0

Cybersecurity framework for financial institutions regulated by SAMA.

Government

C2M2 v2.1

Cybersecurity Capability Maturity Model for critical infrastructure sectors.

Government

CERT RMM v1.2

Resilience Management Model integrating cybersecurity and operational resilience.

Government

CISA CPG v2022

Cross-sector cybersecurity performance goals for critical infrastructure.

Government

CISA SSDAF

Secure software development attestation requirements for federal suppliers.

Government

CISA TIC 3.0

Trusted Internet Connections modernization framework for federal agencies.

Government

CJIS Security Policy 5.9.3

FBI policy governing protection of Criminal Justice Information systems.

Government

CMMC 2.0 Level 1

Basic cybersecurity certification level for defense contractors handling FCI.

Government

CMMC 2.0 Level 2

Intermediate cybersecurity maturity requirements aligned to NIST 800-171.

Government

CMMC 2.0 Level 3

Advanced cybersecurity requirements for critical defense information.

Government

China Cybersecurity Law

National cybersecurity legislation establishing infrastructure protection and controls.

Government

China DNSIP

National standards for data network security infrastructure protection.

Government

China Data Security Law (DSL)

Law governing classification and protection of data.

Government

Cyber Hygiene Practice (Singapore)

Mandatory baseline cybersecurity requirements for regulated entities.

Government

DFARS 252.204-70xx

Defense acquisition regulation mandating cybersecurity compliance for contractors.

Government

DHS Zero Trust Cross-Sector Framework

Government guidance supporting zero trust adoption across sectors.

Government

DoD Zero Trust Reference Architecture v2.0

Defense framework implementing zero trust principles for military systems.

Government

EU NIS2

Directive mandating cybersecurity risk management and incident reporting.

Government

EU NIS2 Annex

Technical and sector-specific requirements supporting NIS2 compliance.

Government

FAR 52.204-21

Federal contract clause requiring basic safeguarding of covered information systems.

Government

FAR 52.204-27

Federal clause restricting use of covered telecommunications equipment.

Government

FAR Section 889

Procurement restriction prohibiting certain foreign telecommunications equipment.

Government

FedRAMP R4

Federal cloud authorization program standardizing security assessment.

Government

FedRAMP R5

Updated federal cloud security authorization framework.

Government

IRS Publication 1075

Security requirements governing protection of Federal Tax Information.

Government

ISM June 2024

Australian government Information Security Manual defining mandatory controls.

Government

ISMAP (Japan)

Government cloud security assessment program for public sector adoption.

Government

ITAR Part 120

Export control regulation governing defense-related technical data.

Government

ITR (India)

Indian IT Rules governing cybersecurity and intermediary obligations.

Government

ITSP-10-171 (Canada)

Government IT security standard defining baseline controls for federal systems.

Government

Israel CDMO v1.0

Cyber defense and monitoring obligations for regulated Israeli entities.

Government

NERC CIP 2024

Cybersecurity standards protecting bulk electric system infrastructure.

Government

NISPOM

National Industrial Security Program manual governing classified information handling.

Government

NIST 800-161 rev1

Supply chain risk management framework for ICT systems and vendors.

Government

NIST 800-171 rev2

Security requirements for protecting Controlled Unclassified Information (CUI).

Government

NIST 800-171 rev3

Updated security requirements strengthening CUI protection controls.

Government

NIST 800-171A

Assessment procedures supporting NIST 800-171 control evaluation.

Government

NIST 800-171A rev3

Updated assessment guidance for validating NIST 800-171 implementation.

Government

NIST 800-172

Enhanced security requirements for critical defense programs.

Government

NIST 800-37 rev2

Risk Management Framework guiding system authorization and continuous monitoring.

Government

NIST 800-39

Enterprise-level risk management guidance for federal agencies.

Government

NSTC NSPM-33

National security memorandum establishing research security program requirements.

Government

NZISM 3.6

New Zealand Information Security Manual defining government controls.

Government

Nigeria DPR 2019

Data protection regulation governing lawful processing of personal data.

Government

Saudi CSCC – 1:2019

Cloud cybersecurity controls for Saudi cloud service providers.

Government

Saudi ECC-1:2018

Essential Cybersecurity Controls baseline for Saudi government entities.

Government

Spain 311/2022

National cybersecurity regulation updating security requirements.

Government

Spain BOE-A-2022-7191

Official publication establishing updated cybersecurity compliance obligations.

Government

Spain CCN-STIC 825

Technical cybersecurity guideline for Spanish public administration systems.

Government

TSA / DHS 1580/82-2022-01

Transportation security directive mandating cybersecurity controls for critical infrastructure.

Government

Texas Cybersecurity Act

State law establishing cybersecurity risk management requirements for government entities.

Government

UAE NIAF

UAE National Information Assurance Framework defining baseline security controls.

Government

UK CAF v3.1

Cyber Assessment Framework for assessing cybersecurity maturity of essential services.

Government

UK CAP 1850

UK aviation cybersecurity framework outlining risk management obligations.

Government

UK DEFSTAN 05-138

UK defense cybersecurity standard applied to contractors.

Health

CMS MARS-E v2.0

Security and privacy control framework for U.S. healthcare exchange systems.

Health

FDA 21 CFR Part 11

Regulation governing electronic records and electronic signatures in regulated industries.

Health

HIPAA

U.S. healthcare regulation establishing privacy and security requirements for protected health information.

Health

HIPAA Large Practice

HIPAA compliance structure designed for large healthcare enterprises.

Health

HIPAA Medium Practice

HIPAA compliance guidance tailored for mid-sized healthcare organizations.

Health

HIPAA Security Rule / NIST 800-66 R2

Implementation guidance aligning HIPAA Security Rule controls with NIST standards.

Health

HIPAA Small Practice

Scaled HIPAA compliance framework tailored for small healthcare providers.

Health

HISF 2022 (NZ)

New Zealand Health Information Security Framework.

Health

HISF Suppliers 2023

Supplier-specific health information security requirements.

Health

HITRUST e1

A streamlined, entry-level assessment for startups needing rapid market entry and essential cybersecurity validation.

Health

HITRUST i1

A mid-tier, threat-informed certification for organizations requiring a "security-first" posture without full audit complexity.

Health

HITRUST r2

The gold standard "Assess Once, Report Many" framework. A tailored, multi-year certification for leaders handling sensitive data.

Health

IEC TR 60601-4-5 v2021

Cybersecurity risk management guidance for medical electrical equipment.

Privacy

APPI (Japan)

Act on the Protection of Personal Information regulating privacy compliance.

Privacy

Alaska PIPA

State breach notification law requiring disclosure of security incidents.

Privacy

Argentina Reg 132-2018

Regulation supporting Argentina’s personal data protection law enforcement.

Privacy

Australia Privacy Act

National law governing collection and disclosure of personal information.

Privacy

Austria Data Protection Act

National implementation of EU data protection requirements.

Privacy

Belgium Data Protection Law

National privacy legislation aligned with GDPR obligations.

Privacy

Brazil LGPD

Brazil’s General Data Protection Law regulating lawful processing of personal data.

Privacy

CA SB1386

California breach notification statute.

Privacy

CCPA / CPRA

California privacy law granting consumer data rights and imposing business obligations.

Privacy

Chile Data Protection Law

Privacy framework regulating lawful personal data processing.

Privacy

China Privacy Law (PIPL)

Comprehensive privacy law regulating personal data processing.

Privacy

Colombia Data Protection Law

National law establishing rights and obligations for personal data processing.

Privacy

Colorado Privacy Act

State-level privacy law regulating personal data processing.

Privacy

Connecticut Data Privacy Act

State law regulating consumer data protection and processor responsibilities.

Privacy

Costa Rica Data Protection Law

National privacy legislation governing personal data handling.

Privacy

DPDPA 2023 (India)

National privacy law governing processing of digital personal data.

Privacy

EU–US Data Privacy Framework

Cross-border mechanism enabling lawful EU–US personal data transfers.

Privacy

GAPP

Privacy governance framework establishing accountability and data protection principles.

Privacy

GDPR

EU regulation governing lawful processing of personal data.

Privacy

Germany Federal Data Protection Act

National data protection legislation complementing GDPR.

Privacy

Greece Data Protection Law

National privacy framework implementing EU requirements.

Privacy

Hungary Data Protection Act

National data protection legislation aligned with GDPR.

Privacy

ISO 27018 v2014

Standard protecting personally identifiable information in public cloud services.

Privacy

ISO 27701:2019

Privacy Information Management System extension to ISO 27001.

Privacy

ISO 29100 v2011

International privacy framework defining global data protection principles.

Privacy

Illinois BIPA

Biometric Information Privacy Act regulating collection of biometric identifiers.

Privacy

Illinois IPA

Identity Protection Act governing protection of Social Security numbers.

Privacy

Illinois PIPA

Personal Information Protection Act governing breach notification requirements.

Privacy

Ireland Data Protection Act

National legislation implementing EU data protection obligations.

Privacy

Israel Privacy Protection Law

National data protection law establishing personal data safeguards.

Privacy

Italy Data Protection Code

National framework governing personal data protection.

Privacy

Kenya Data Protection Act 2019

National privacy law regulating personal data processing.

Privacy

Massachusetts 201 CMR 17.00

State regulation requiring comprehensive information security programs.

Privacy

Mexico Data Protection Law

Federal law regulating processing of personal data by private parties.

Privacy

NIST Privacy Framework v1.0

Framework for identifying and managing privacy risks aligned to enterprise risk management.

Privacy

NY SHIELD Act

State law requiring reasonable data security safeguards and breach notification.

Privacy

Netherlands GDPR Implementation Act

National implementation of GDPR within Dutch jurisdiction.

Privacy

Nevada SB220

State privacy law regulating sale of consumer personal data.

Privacy

Nigeria DPR 2019

Data protection regulation governing lawful processing of personal data.

Privacy

Norway Personal Data Act

National privacy legislation aligned with EU standards.

Privacy

Oregon 646A

Oregon breach notification and data protection statute.

Privacy

Oregon CPA

Oregon Consumer Privacy Act regulating personal data processing.

Privacy

PDPA (Singapore)

National privacy legislation regulating collection and use of personal data.

Privacy

PIPEDA (Canada)

Federal privacy law governing personal information in commercial activities.

Privacy

Peru Data Protection Law

National legislation governing processing and safeguarding of personal data.

Privacy

Poland Data Protection Act

National law implementing GDPR obligations.

Privacy

Privacy Act 2020 (New Zealand)

National data protection law establishing privacy principles.

Privacy

Qatar PDPPL

National personal data protection law regulating lawful data processing.

Privacy

Russia Personal Data Law

National legislation governing data localization and personal data processing.

Privacy

Saudi PDPL

Personal Data Protection Law regulating data processing obligations.

Privacy

Serbia 87/2018

National data protection law aligned with European standards.

Privacy

South Africa POPIA

Protection of Personal Information Act governing privacy compliance.

Privacy

Spain 1720/2007

Spanish regulation implementing data protection obligations.

Privacy

Sweden Data Protection Act

National privacy law aligned with GDPR framework.

Privacy

Switzerland Federal Act on Data Protection

Swiss data protection law governing processing of personal data.

Privacy

Tennessee Information Protection Act

State privacy law regulating personal data processing and safeguards.

Privacy

Texas Data Privacy and Security Act

State law regulating consumer data protection and transparency obligations.

Privacy

Turkey Data Protection Law

National privacy legislation regulating personal data processing.

Privacy

UK Data Protection Act

UK national legislation supplementing UK GDPR requirements.

Privacy

UK GDPR

United Kingdom data protection regime aligned with GDPR principles.

Privacy

Uruguay Data Protection Law

National privacy law aligned with international data protection principles.

Privacy

Utah Consumer Privacy Act

State privacy framework governing transparency and data processing controls.

Privacy

Vermont Act 171

State data broker regulation governing data security and consumer rights.

Privacy

Virginia CDPA 2023

State privacy law establishing consumer data rights and controller obligations.

Security

CA SB327

California IoT security law requiring reasonable security features.

Security

CIS Controls v8.1

Prioritized cybersecurity safeguards mitigating common attack techniques.

Security

COBIT 2019

Enterprise IT governance and management framework aligning technology strategy with business objectives and risk.

Security

CSA Cloud Controls Matrix v4

Cloud security control framework mapping domains to global regulations and standards.

Security

CSA IoT SCF v2

IoT-focused security control framework addressing device lifecycle and ecosystem risks.

Security

CSAG (Canada)

Canadian Centre for Cyber Security guidance outlining baseline cyber controls.

Security

ENISA

EU cybersecurity agency guidance supporting resilience and regulatory alignment.

Security

EU Cyber Resilience Act

EU regulation imposing cybersecurity requirements for digital products.

Security

EU Cyber Resilience Act Annexes

Technical security measures supporting compliance with the Cyber Resilience Act.

Security

Essential 8

Australian baseline cybersecurity mitigation strategies.

Security

Germany C5-2020

Cloud computing compliance criteria issued by German authorities.

Security

IEC 62443-4-2

Industrial control system cybersecurity standard for operational technology environments.

Security

ISO 27001 v2013

International standard defining requirements for an Information Security Management System (ISMS).

Security

ISO 27001:2022

Updated ISMS standard incorporating modern risk and control restructuring.

Security

ISO 27002 v2013

Guidance standard providing best practices for implementing security controls.

Security

ISO 27002:2022

Revised guidance aligning control structure with modern threat landscape.

Security

ISO 27017 v2015

Cloud-specific extension providing guidance for shared responsibility risks.

Security

ISO/SAE 21434 v2021

Automotive cybersecurity lifecycle standard addressing vehicle supply chain risks.

Security

IoT Code of Practice

Australian guidance outlining baseline IoT security principles.

Security

MITRE ATT&CK v10

Knowledge base of adversary tactics and techniques for threat modeling and detection.

Security

NIST 800-160

Systems security engineering guidance integrating security into lifecycle design.

Security

NIST 800-207

Zero Trust Architecture guidance defining identity-centric security models.

Security

NIST 800-218 v1.1 (SSDF)

Secure Software Development Framework outlining secure coding and lifecycle practices.

Security

NIST 800-53 rev4

Comprehensive catalog of federal security and privacy controls.

Security

NIST 800-53 rev5

Updated control catalog incorporating privacy and supply chain risk controls.

Security

NIST 800-53B rev5

Baseline control selection guidance supporting NIST 800-53 implementation.

Security

NIST 800-63B

Digital identity and authentication assurance guidelines.

Security

NIST 800-82 rev3

Guidance for securing industrial control systems and operational technology.

Security

NIST CSF v1.1

Risk-based cybersecurity framework organized into Identify, Protect, Detect, Respond, and Recover functions.

Security

NIST CSF v2.0

Updated cybersecurity framework expanding governance and supply chain risk coverage.

Security

OWASP Top 10 v2021

Industry benchmark identifying critical web application security risks.

Security

SOC 2

AICPA attestation framework assessing service organizations against Trust Services Criteria. It evaluates control design and operating effectiveness.

Security

Saudi IoT CGIoT-1:2024

IoT cybersecurity guidance establishing baseline security requirements.

Security

Saudi OTCC-1:2022

Operational Technology Cybersecurity Controls framework.

Security

Secure Controls Framework (SCF)

Unified control framework harmonizing global cybersecurity and privacy standards.

Security

Shared Assessments SIG 2024

Standardized third-party risk assessment questionnaire for vendor security reviews.

Security

UK Cyber Essentials

Government-backed baseline cybersecurity certification scheme.

Security

UL 2900-1

Cybersecurity certification standard assessing network-connected products and software.

Security

UN ECE WP.29

Automotive cybersecurity regulation requiring cybersecurity management systems.

Security

UN R155

Automotive cybersecurity regulation mandating risk management and incident response for vehicle manufacturers.

Other

COSO ERM 2017

Enterprise Risk Management framework integrating governance, strategy, and performance oversight.

Other

ISO 22301:2019

Business Continuity Management standard supporting resilience and recovery.

Other

ISO 31000 v2009

Enterprise risk management guidance establishing structured risk governance.

Other

ISO 31010 v2009

Risk assessment techniques supporting structured enterprise risk programs.

What If Your Expertise Could Scale Itself?

Move beyond spreadsheets to a purpose-built platform that helps you compete effectively—without overspending or expanding your team.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.