Skip to content

Every framework your auditor will ask about.

SOC 2 to NIS2, HIPAA to DORA — 53 frameworks across 7 regions, 3 clouds. Assess any of them free.

Global

9

Internationally recognized frameworks applicable worldwide

SOC 2

Service Organization Control 2 — trust services criteria for security, availability, processing integrity, confidentiality, and privacy

community Audit

Center for Internet Security Benchmark for Google Cloud Platform

community Benchmark

Center for Internet Security Benchmark for Microsoft Azure

community Benchmark

Center for Internet Security Benchmark for Amazon Web Services

community Benchmark

International standard for information security management systems

pro Audit

Payment Card Industry Data Security Standard

pro Financial

NIST Cybersecurity Framework version 2.0

pro Government

Cloud Security Alliance Cloud Controls Matrix

team Benchmark

HITRUST Common Security Framework

agency Audit

North America

15

United States and Canada

HIPAA

Health Insurance Portability and Accountability Act

pro Data Protection
NIST 800-53

Security and Privacy Controls for Information Systems and Organizations

pro Government
CCPA

California Consumer Privacy Act / California Privacy Rights Act

pro Data Protection
PHIPA

Personal Health Information Protection Act (Ontario)

team Data Protection
SOX IT

Sarbanes-Oxley Act IT general controls

agency Audit
FedRAMP

Federal Risk and Authorization Management Program

agency Government
CMMC

Cybersecurity Maturity Model Certification

agency Government
CJIS

Criminal Justice Information Services Security Policy

agency Government
FISMA

Federal Information Security Modernization Act

agency Government
NERC CIP

North American Electric Reliability Corporation Critical Infrastructure Protection

agency Government
TX-RAMP

Texas Risk and Authorization Management Program

agency Government
StateRAMP

State Risk and Authorization Management Program

agency Government
GLBA

Gramm-Leach-Bliley Act safeguards rule

agency Financial
FERPA

Family Educational Rights and Privacy Act

agency Data Protection
ITAR

International Traffic in Arms Regulations

agency Government

Europe

5

European Union and European national frameworks

GDPR

General Data Protection Regulation

pro Data Protection
NIS2

Network and Information Security Directive 2

team Government
DORA

Digital Operational Resilience Act

team Financial
BSI C5

Cloud Computing Compliance Criteria Catalogue

team Government
ENS

Esquema Nacional de Seguridad — Spanish national security framework

team Government

Asia-Pacific

5

Asia-Pacific region including Australia, Japan, Korea, Singapore

IRAP

Information Security Registered Assessors Program

team Government
K-ISMS-P

Korea Information Security Management System — Personal Information

team Government
MTCS

Multi-Tier Cloud Security Standard Singapore

team Government
OSPAR

Outsourced Service Provider's Audit Report — Singapore financial sector

team Financial
ISMAP

Information System Security Management and Assessment Program — Japan

team Government

Middle East

17

Gulf Cooperation Council and wider Middle East

NCA ECC

National Cybersecurity Authority Essential Cybersecurity Controls

enterprise Government
NCA DCC

National Cybersecurity Authority Data Cybersecurity Controls

enterprise Government
NCA TCC

National Cybersecurity Authority Telecommunications and IT Controls

enterprise Government
NCA CSCC

National Cybersecurity Authority Cloud Security Controls

enterprise Government
NCA OSMACC

National Cybersecurity Authority Operational and Social Media Access Controls

enterprise Government
NCA CGIoT

National Cybersecurity Authority Cybersecurity Guidelines for IoT

enterprise Government
NCA OTCC

National Cybersecurity Authority Operational Technology Cybersecurity Controls

enterprise Government

National Cybersecurity Authority Telework Cybersecurity Controls

enterprise Government
SAMA CSF

Saudi Arabian Monetary Authority Cyber Security Framework

enterprise Financial
UAE IA

UAE Information Assurance Standards

enterprise Government
NCA CCC

National Cybersecurity Authority Critical Systems Cybersecurity Controls

enterprise Government
DESC CSP

Dubai Electronic Security Center Cloud Service Provider Security Standard

enterprise Government
CBB Cloud

Central Bank of Bahrain Cloud Computing Directive

enterprise Financial
CBK CORF

Central Bank of Kuwait Cybersecurity and Operational Resilience Framework

enterprise Financial
NIA Qatar

Qatar National Information Assurance Policy

enterprise Government

Kuwait Communications and Information Technology Regulatory Authority

enterprise Government
MTCIT Oman

Ministry of Transport, Communications and IT Oman — cybersecurity framework

enterprise Government

South America

1

South American countries

LGPD

Lei Geral de Proteção de Dados — Brazilian general data protection law

team Data Protection

Africa

1

African countries

POPIA

Protection of Personal Information Act — South Africa

team Data Protection
Assess all 53 frameworks free —
uv tool install complyform
View Pricing