Here is an overview of the compliance frameworks for security, privacy, AI, government, finance and other areas.

Compliance Frameworks

Framework vs Standard vs Regulation

  • Framework is a set of principles, domains and controls used for governance, structure and continuous control coverage.
  • Standard is for formal certification or audit requirements (ISO 27001).
  • Regulation is for referencing laws or mandatory obligations.

Learn here more about single vs cross-compliance frameworks.

Security Frameworks

SOC 2

A US auditing standard that evaluates how well a service organization protects customer data across security, availability, processing integrity, confidentiality, and privacy.

ISO 27001

A global standard for establishing, implementing, maintaining, and improving an information security management system (ISMS).

PCI DSS

A mandatory security standard for organizations that store, process, or transmit credit card data, focusing on protecting payment card information.

NIST CSF 2.0

A cybersecurity framework that provides best practices for managing and reducing cybersecurity risk across five core functions: Identify, Protect, Detect, Respond, and Recover.

CIS Controls

CIS Critical Security Controls (CIS Controls) is a prioritized set of 18 best-practice cybersecurity safeguards developed by the Center for Internet Security (CIS).

CIS AWS

Benchmarks AWS (Amazon Web Services) accounts and services against CIS best practices to reduce misconfigurations and strengthen cloud security posture.

CIS Azure

Assesses Azure subscriptions and resources against CIS benchmarks to identify and remediate security gaps.

CIS GCP

Evaluates GCP (Google Cloud Platform) environments against CIS controls to ensure secure configuration and continuous compliance.

CIS OCI 

Benchmarks OCI (Oracle Cloud Infrastructure) environments against CIS best practices to detect misconfigurations and harden cloud security posture.

CIS Alibaba Cloud

Assesses Alibaba Cloud accounts and services against CIS benchmarks to identify security gaps and enforce secure configuration standards.

CIS Kubernetes

Validates Kubernetes clusters against CIS controls to secure cluster configuration, workloads, and control plane components.

CIS EKS

Enforces CIS Kubernetes and EKS (Elastic Kubernetes Service) best practices to continuously secure managed Kubernetes clusters on AWS.

CIS AKS

Applies CIS Kubernetes and AKS (Azure Kubernetes Service) benchmarks to ensure secure configuration of managed Kubernetes on Azure.

CIS GKS

Applies CIS Kubernetes and GKS (Google Kubernetes Service) benchmarks to ensure secure configuration of managed Kubernetes on GCP.

CIS Github

Applies CIS Github benchmarks to ensure secure configuration on Github.

HITRUST CSF

A certifiable framework that harmonizes healthcare, security, and privacy regulations (HIPAA, NIST, ISO) into a single control set.

NIS 2

An EU cybersecurity directive requiring essential and important entities to strengthen security, risk management, and incident reporting.

ISO 27017

An international standard providing guidance and controls specifically for cloud security.

AWS FTR

AWS Foundational Technical Review; a technical and security checklist vendors must meet to list solutions in AWS Marketplace or qualify for AWS programs.

MVSP

Minimum Viable Secure Product; a lightweight security standard defining essential baseline security requirements for enterprise-ready SaaS products.

TISAX

A security assessment and certification framework for the automotive industry focusing on information security and data protection.

Privacy Frameworks

GDPR

A comprehensive EU data protection regulation governing personal data rights, processing, security, and cross-border transfers.

HIPAA

A US healthcare regulation that protects the privacy and security of patient health information (PHI).

USDP

Unified Security & Data Protection framework (often referencing Meta’s or other internal models), used to align privacy and security practices across regions.

ISO 27701

A privacy extension to ISO 27001 that establishes a Privacy Information Management System (PIMS).

ISO 27018

A cloud privacy standard focusing on the protection of personally identifiable information (PII) in cloud environments.

Microsoft SSPA

Supplier Security & Privacy Assurance Program; requires Microsoft suppliers to meet strict data protection and security obligations.

AI Frameworks

ISO 42001

An international standard for managing AI systems responsibly through an AI Management System (AIMS).

EU AI Act

A landmark EU regulation classifying AI systems by risk and imposing mandatory requirements for high-risk AI, transparency, and governance.

NIST AI RMF

A US framework providing guidance for designing, developing, and deploying trustworthy, responsible AI systems.

Government Frameworks

FedRAMP

A US government program that standardizes security assessments for cloud service providers used by federal agencies.

Custom Frameworks

Tailored, organization-specific control frameworks built to meet internal risk, legal, regulatory, or customer requirements.

Financial Frameworks

DORA

The EU Digital Operational Resilience Act, requiring financial institutions and third-party providers to manage ICT risk and ensure operational resilience.

OFDSS

Open Finance Data Security Standard; a lightweight, open-source security framework for fintechs and open banking participants.

CRI Profile

Cyber Risk Institute’s profile that harmonizes regulatory expectations (NIST, FFIEC, ISO) for financial institutions into a unified control set.

Other

ISO 9001

A globally recognized standard for quality management systems focused on continuous improvement and customer satisfaction.

Custom Frameworks

Organization-developed standards for security, privacy, quality, AI, or compliance tailored to specific business or regulatory needs.

Need help with your cybersecurity? Feel free to contact us.