14 frameworks cataloged
The compliance landscape, decoded.
Each framework explained in plain language — what it is, who needs it, and how it relates to the others. Hover a card to see the full picture.
01
ISO/IEC 27001
The world's best-known standard for a certifiable Information Security Management System (ISMS).
ISO/IEC 27001 defines requirements for establishing, operating, and continually improving an ISMS — a management system for how an organization identifies risks and applies controls to protect the confidentiality, integrity, and availability of information. The companion Annex A control set (aligned with ISO/IEC 27002) provides the reference controls. An accredited body audits you and, if you pass, issues a certificate valid for three years with annual surveillance audits.
ISO/IEC 27001 — details
- Certifiable?
- Yes — formal, third-party certification.
- Where used
- Global, and often the default expectation in European and international enterprise procurement.
- Typical trigger
- An enterprise customer or partner requires it as a condition of the deal; entering markets where it's the norm.
- Related frameworks
- The common anchor. Maps to SOC 2, NIST CSF, and CIS; BSI IT-Grundschutz can be used to certify against it.
02
SOC 2
An independent auditor's report on how well your controls meet the Trust Services Criteria.
SOC 2 (governed by the AICPA) is not a certification but an attestation: a licensed CPA firm examines your controls against up to five Trust Services Criteria — Security (always required), Availability, Confidentiality, Processing Integrity, and Privacy — and issues a report. Type I assesses design at a point in time; Type II assesses operating effectiveness over a period (typically 3–12 months). The report is shared under NDA with customers and prospects.
SOC 2 — details
- Certifiable?
- No — you receive an attestation report, not a certificate.
- Where used
- Very common for SaaS and cloud vendors, startups, and when selling to US customers.
- Typical trigger
- A prospect's security/vendor-risk team asks "Can you share your SOC 2?" before signing.
- Related frameworks
- Heavy overlap with ISO 27001 and CIS; one control program can feed both.
03
CIS Controls
A prioritized, practical answer to "what should we secure first?"
The CIS Critical Security Controls are a consensus-built, prioritized set of best practices maintained by the Center for Internet Security. The current release, v8.1 (June 2024), organizes 153 safeguards across 18 controls and adds a Govern function aligned to NIST CSF 2.0. Safeguards are grouped into three Implementation Groups: IG1 (56 safeguards — "essential cyber hygiene" for small orgs), IG2, and IG3 (full set, for high-risk/regulated orgs).
CIS Controls — details
- Certifiable?
- Not directly — organizations align with the Controls rather than certify to them.
- Where used
- Universal starting baseline, especially valuable for SMBs that find NIST 800-53 too heavy.
- Typical trigger
- A team wants concrete, ordered next steps rather than an abstract framework.
- Related frameworks
- Maps to SOC 2, ISO 27001, NIST CSF, PCI DSS, HIPAA — one assessment can produce evidence for several.
04
CIS Benchmarks
Step-by-step hardening recipes for specific platforms.
Distinct from the Controls, CIS Benchmarks are prescriptive configuration recommendations for concrete systems — Linux/Windows, AWS/Azure/GCP accounts, Kubernetes, databases, browsers, and more. Where Controls say what to do strategically, Benchmarks say how to configure a given system. The recurring challenge is configuration drift, which is why benchmark checking is a continuous activity.
CIS Benchmarks — details
- Certifiable?
- No — configuration baseline.
- Where used
- Anywhere systems need hardening; often the technical backbone of a broader program.
- Typical trigger
- "Prove our cloud accounts and servers are hardened to a recognized standard."
- Related frameworks
- Provides the technical evidence layer under CIS Controls, ISO 27001, and SOC 2.
05
NIST Cybersecurity Framework (NIST CSF 2.0)
A risk-management framework that structures security around six functions.
NIST CSF organizes cybersecurity into Govern, Identify, Protect, Detect, Respond, Recover. CSF 2.0 (2024) added Govern and is explicitly intended for organizations of any size or sector. It's outcome-oriented rather than prescriptive — it tells you what good looks like and lets you choose how to get there, which makes it a strong common language across teams and with leadership.
NIST Cybersecurity Framework (NIST CSF 2.0) — details
- Certifiable?
- No official certification — used for self-assessment and program structure.
- Where used
- US-centric in origin but widely adopted globally.
- Typical trigger
- Leadership wants a coherent way to talk about and prioritize risk.
- Related frameworks
- A structuring layer that maps down to CIS Controls and NIST 800-53.
06
NIST SP 800-53
A very large, granular catalog of security and privacy controls.
A comprehensive control catalog (organized into families such as Access Control, Audit, Incident Response) used where deep, rigorous control coverage is required. It underpins US federal compliance regimes (e.g., FedRAMP) and is common in heavily regulated environments.
NIST SP 800-53 — details
- Certifiable?
- It's a control catalog; compliance is assessed within programs built on it.
- Where used
- US government, federal contractors, high-assurance environments.
- Typical trigger
- Selling to US government or operating in a regime that mandates it.
- Related frameworks
- CSF and CIS map up to it; it's the "full detail" end of the spectrum.
07
TISAX
The automotive industry's shared information-security assessment.
TISAX (operated by the ENX Association) is an assessment and result-exchange mechanism built on an automotive-specific catalog (VDA ISA). You get assessed once, receive a label, and can share the result with multiple automotive partners instead of being audited repeatedly by each.
TISAX — details
- Certifiable?
- Yes — assessment with a shareable label (not a "certificate" in the ISO sense).
- Where used
- Automotive OEMs and their supply chain; strong in Germany and the wider DACH region.
- Typical trigger
- An OEM or Tier-1 supplier requires a TISAX label to keep working with them.
- Related frameworks
- Conceptually close to ISO 27001; the VDA ISA catalog derives from it.
08
BSI IT-Grundschutz
Germany's structured methodology for building an ISMS.
Published by the German Federal Office for Information Security (BSI), IT-Grundschutz is a detailed methodology plus a large catalog of standard modules and safeguards. It is designed to be compatible with ISO/IEC 27001 — you can achieve "ISO 27001 certification on the basis of IT-Grundschutz."
BSI IT-Grundschutz — details
- Certifiable?
- Yes — ISO 27001 certification via the IT-Grundschutz path.
- Where used
- Germany, especially public sector and regulated German organizations.
- Typical trigger
- German public-sector procurement or a regulator expects it.
- Related frameworks
- A German route to ISO 27001.
09
PCI DSS
The security standard for handling payment-card data.
Maintained by the PCI Security Standards Council, PCI DSS is a framework for safely storing, processing, and transmitting cardholder data. Validation ranges from a Self-Assessment Questionnaire (SAQ) for smaller merchants to a Report on Compliance (ROC) by a QSA for large volumes.
PCI DSS — details
- Certifiable?
- Validated compliance (SAQ or QSA-signed ROC), enforced by card brands/acquirers.
- Where used
- Any organization that touches cardholder data, worldwide.
- Typical trigger
- You start accepting or processing card payments.
- Related frameworks
- Overlaps with CIS/ISO on the technical controls, but is payment-specific.
10
CSA Cloud Controls Matrix (CCM)
A cloud-specific control matrix for assessing cloud security.
From the Cloud Security Alliance, the CCM is a cybersecurity control framework tailored to cloud computing, organized into domains and mapped to other standards. It underlies the CSA STAR program for cloud-provider assurance.
CSA Cloud Controls Matrix (CCM) — details
- Certifiable?
- Self-assessment (STAR Level 1) up to third-party (STAR Level 2).
- Where used
- Evaluating cloud providers and cloud implementations.
- Typical trigger
- You are a cloud provider proving assurance, or a customer assessing one.
- Related frameworks
- Maps to ISO 27001, SOC 2, NIST — a cloud-lens overlay.
11
OWASP ASVS / OWASP Top 10
The reference for building and testing secure applications.
The OWASP Top 10 is an awareness list of the most critical web-application risks. The Application Security Verification Standard (ASVS) is a detailed, leveled set of requirements for verifying the technical security controls of web apps and APIs. Together they guide secure coding, code review, and penetration testing.
OWASP ASVS / OWASP Top 10 — details
- Certifiable?
- No — a testing/requirements standard, not a certification.
- Where used
- Software development, web apps, APIs, secure coding, pentesting.
- Typical trigger
- You build software and need a concrete secure-development bar.
- Related frameworks
- Complements the org-level frameworks with app-level depth.
12
COBIT
A governance and management framework for enterprise IT.
From ISACA, COBIT frames how IT is governed and managed to deliver value and manage risk. It's used more by IT governance, audit, and risk functions than by hands-on security engineers.
COBIT — details
- Certifiable?
- Framework (individuals can be certified; organizations align).
- Where used
- Enterprise IT governance, internal audit, risk management.
- Typical trigger
- Board/audit wants a governance structure over IT.
- Related frameworks
- Sits above technical control sets as governance.
13
IEC 62443
The cybersecurity standard for industrial and OT environments.
A series of standards for the security of industrial automation and control systems (IACS/OT) — covering asset owners, integrators, and product suppliers across plants, ICS, and connected machinery.
IEC 62443 — details
- Certifiable?
- Yes — certification schemes exist for products and organizations.
- Where used
- Manufacturing, energy, utilities, industrial plants, connected machinery.
- Typical trigger
- You operate or build industrial/OT systems.
- Related frameworks
- OT counterpart to the IT-focused frameworks.
14
NIS2 / GDPR / HIPAA
These are laws and regulations — not optional guidance.
NIS2 is an EU directive raising cybersecurity requirements for "essential" and "important" entities across critical sectors, with governance and incident-reporting duties and national-law transposition. GDPR is the EU regulation governing protection of personal data, with strict obligations and significant fines. HIPAA is the US regime whose Security Rule protects electronic health information (ePHI).
NIS2 / GDPR / HIPAA — details
- Certifiable?
- No — these are legal obligations. Frameworks above help you demonstrate compliance, but you comply with the law itself.
- Where used
- NIS2 & GDPR — EU (and anyone handling EU personal data). HIPAA — US healthcare and its business associates.
- Typical trigger
- You fall within scope by sector, data type, or market — compliance is mandatory, not chosen.
- Related frameworks
- ISO 27001 / SOC 2 / CIS controls provide much of the evidence, but never replace legal counsel.
Category legend
- A formal certificate issued by an accredited third-party auditor, valid for a defined period.
- An independent auditor's report on your controls — shared privately, not a public certificate.
- A structured model for organizing and prioritizing security activities without prescribing exact controls.
- A set of recommended practices or testing requirements — not certifiable, but widely referenced.
- Prescriptive configuration recipes for hardening specific systems to a recognized baseline.
- A detailed, authoritative control catalog or specification used as compliance evidence.
- A legally binding obligation — non-compliance carries fines, liability, or operational restrictions.
Still not sure which applies to you?
Answer a few plain-language questions about your business and get a short, ordered plan — no compliance background required.
Take the 2-minute advisorNot legal advice. Standards evolve — verify current versions with the authoritative bodies. Last reviewed: 2026-07-01.