Here is an overview of the compliance frameworks for security, privacy, AI, government, finance and other areas.







Compliance Frameworks
Framework vs Standard vs Regulation
- Framework is a set of principles, domains and controls used for governance, structure and continuous control coverage.
- Standard is for formal certification or audit requirements (ISO 27001).
- Regulation is for referencing laws or mandatory obligations.
Learn here more about single vs cross-compliance frameworks.
Security Frameworks
SOC 2
A US auditing standard that evaluates how well a service organization protects customer data across security, availability, processing integrity, confidentiality, and privacy.
ISO 27001
A global standard for establishing, implementing, maintaining, and improving an information security management system (ISMS).
PCI DSS
A mandatory security standard for organizations that store, process, or transmit credit card data, focusing on protecting payment card information.
NIST CSF 2.0
A cybersecurity framework that provides best practices for managing and reducing cybersecurity risk across five core functions: Identify, Protect, Detect, Respond, and Recover.
CIS Controls
CIS Critical Security Controls (CIS Controls) is a prioritized set of 18 best-practice cybersecurity safeguards developed by the Center for Internet Security (CIS).
CIS AWS
Benchmarks AWS (Amazon Web Services) accounts and services against CIS best practices to reduce misconfigurations and strengthen cloud security posture.
CIS Azure
Assesses Azure subscriptions and resources against CIS benchmarks to identify and remediate security gaps.
CIS GCP
Evaluates GCP (Google Cloud Platform) environments against CIS controls to ensure secure configuration and continuous compliance.
CIS OCI
Benchmarks OCI (Oracle Cloud Infrastructure) environments against CIS best practices to detect misconfigurations and harden cloud security posture.
CIS Alibaba Cloud
Assesses Alibaba Cloud accounts and services against CIS benchmarks to identify security gaps and enforce secure configuration standards.
CIS Kubernetes
Validates Kubernetes clusters against CIS controls to secure cluster configuration, workloads, and control plane components.
CIS EKS
Enforces CIS Kubernetes and EKS (Elastic Kubernetes Service) best practices to continuously secure managed Kubernetes clusters on AWS.
CIS AKS
Applies CIS Kubernetes and AKS (Azure Kubernetes Service) benchmarks to ensure secure configuration of managed Kubernetes on Azure.
CIS GKS
Applies CIS Kubernetes and GKS (Google Kubernetes Service) benchmarks to ensure secure configuration of managed Kubernetes on GCP.
CIS Github
Applies CIS Github benchmarks to ensure secure configuration on Github.
HITRUST CSF
A certifiable framework that harmonizes healthcare, security, and privacy regulations (HIPAA, NIST, ISO) into a single control set.
NIS 2
An EU cybersecurity directive requiring essential and important entities to strengthen security, risk management, and incident reporting.
ISO 27017
An international standard providing guidance and controls specifically for cloud security.
AWS FTR
AWS Foundational Technical Review; a technical and security checklist vendors must meet to list solutions in AWS Marketplace or qualify for AWS programs.
MVSP
Minimum Viable Secure Product; a lightweight security standard defining essential baseline security requirements for enterprise-ready SaaS products.
TISAX
A security assessment and certification framework for the automotive industry focusing on information security and data protection.
Privacy Frameworks
GDPR
A comprehensive EU data protection regulation governing personal data rights, processing, security, and cross-border transfers.
HIPAA
A US healthcare regulation that protects the privacy and security of patient health information (PHI).
USDP
Unified Security & Data Protection framework (often referencing Meta’s or other internal models), used to align privacy and security practices across regions.
ISO 27701
A privacy extension to ISO 27001 that establishes a Privacy Information Management System (PIMS).
ISO 27018
A cloud privacy standard focusing on the protection of personally identifiable information (PII) in cloud environments.
Microsoft SSPA
Supplier Security & Privacy Assurance Program; requires Microsoft suppliers to meet strict data protection and security obligations.
AI Frameworks
ISO 42001
An international standard for managing AI systems responsibly through an AI Management System (AIMS).
EU AI Act
A landmark EU regulation classifying AI systems by risk and imposing mandatory requirements for high-risk AI, transparency, and governance.
NIST AI RMF
A US framework providing guidance for designing, developing, and deploying trustworthy, responsible AI systems.
Government Frameworks
FedRAMP
A US government program that standardizes security assessments for cloud service providers used by federal agencies.
Custom Frameworks
Tailored, organization-specific control frameworks built to meet internal risk, legal, regulatory, or customer requirements.
Financial Frameworks
DORA
The EU Digital Operational Resilience Act, requiring financial institutions and third-party providers to manage ICT risk and ensure operational resilience.
OFDSS
Open Finance Data Security Standard; a lightweight, open-source security framework for fintechs and open banking participants.
CRI Profile
Cyber Risk Institute’s profile that harmonizes regulatory expectations (NIST, FFIEC, ISO) for financial institutions into a unified control set.
Other
ISO 9001
A globally recognized standard for quality management systems focused on continuous improvement and customer satisfaction.
Custom Frameworks
Organization-developed standards for security, privacy, quality, AI, or compliance tailored to specific business or regulatory needs.
Need help with your cybersecurity? Feel free to contact us.
