Skip to content

14 frameworks cataloged

The compliance landscape, decoded.

Each framework explained in plain language — what it is, who needs it, and how it relates to the others. Hover a card to see the full picture.

01

ISO/IEC 27001

Certification

The world's best-known standard for a certifiable Information Security Management System (ISMS).

ISO/IEC 27001 defines requirements for establishing, operating, and continually improving an ISMS — a management system for how an organization identifies risks and applies controls to protect the confidentiality, integrity, and availability of information. The companion Annex A control set (aligned with ISO/IEC 27002) provides the reference controls. An accredited body audits you and, if you pass, issues a certificate valid for three years with annual surveillance audits.

hover to flip

ISO/IEC 27001 — details

Certifiable?
Yes — formal, third-party certification.
Where used
Global, and often the default expectation in European and international enterprise procurement.
Typical trigger
An enterprise customer or partner requires it as a condition of the deal; entering markets where it's the norm.
Related frameworks
The common anchor. Maps to SOC 2, NIST CSF, and CIS; BSI IT-Grundschutz can be used to certify against it.

02

SOC 2

Attestation

An independent auditor's report on how well your controls meet the Trust Services Criteria.

SOC 2 (governed by the AICPA) is not a certification but an attestation: a licensed CPA firm examines your controls against up to five Trust Services Criteria — Security (always required), Availability, Confidentiality, Processing Integrity, and Privacy — and issues a report. Type I assesses design at a point in time; Type II assesses operating effectiveness over a period (typically 3–12 months). The report is shared under NDA with customers and prospects.

hover to flip

SOC 2 — details

Certifiable?
No — you receive an attestation report, not a certificate.
Where used
Very common for SaaS and cloud vendors, startups, and when selling to US customers.
Typical trigger
A prospect's security/vendor-risk team asks "Can you share your SOC 2?" before signing.
Related frameworks
Heavy overlap with ISO 27001 and CIS; one control program can feed both.

03

CIS Controls

Framework

A prioritized, practical answer to "what should we secure first?"

The CIS Critical Security Controls are a consensus-built, prioritized set of best practices maintained by the Center for Internet Security. The current release, v8.1 (June 2024), organizes 153 safeguards across 18 controls and adds a Govern function aligned to NIST CSF 2.0. Safeguards are grouped into three Implementation Groups: IG1 (56 safeguards — "essential cyber hygiene" for small orgs), IG2, and IG3 (full set, for high-risk/regulated orgs).

hover to flip

CIS Controls — details

Certifiable?
Not directly — organizations align with the Controls rather than certify to them.
Where used
Universal starting baseline, especially valuable for SMBs that find NIST 800-53 too heavy.
Typical trigger
A team wants concrete, ordered next steps rather than an abstract framework.
Related frameworks
Maps to SOC 2, ISO 27001, NIST CSF, PCI DSS, HIPAA — one assessment can produce evidence for several.

04

CIS Benchmarks

Benchmark

Step-by-step hardening recipes for specific platforms.

Distinct from the Controls, CIS Benchmarks are prescriptive configuration recommendations for concrete systems — Linux/Windows, AWS/Azure/GCP accounts, Kubernetes, databases, browsers, and more. Where Controls say what to do strategically, Benchmarks say how to configure a given system. The recurring challenge is configuration drift, which is why benchmark checking is a continuous activity.

hover to flip

CIS Benchmarks — details

Certifiable?
No — configuration baseline.
Where used
Anywhere systems need hardening; often the technical backbone of a broader program.
Typical trigger
"Prove our cloud accounts and servers are hardened to a recognized standard."
Related frameworks
Provides the technical evidence layer under CIS Controls, ISO 27001, and SOC 2.

05

NIST Cybersecurity Framework (NIST CSF 2.0)

Framework

A risk-management framework that structures security around six functions.

NIST CSF organizes cybersecurity into Govern, Identify, Protect, Detect, Respond, Recover. CSF 2.0 (2024) added Govern and is explicitly intended for organizations of any size or sector. It's outcome-oriented rather than prescriptive — it tells you what good looks like and lets you choose how to get there, which makes it a strong common language across teams and with leadership.

hover to flip

NIST Cybersecurity Framework (NIST CSF 2.0) — details

Certifiable?
No official certification — used for self-assessment and program structure.
Where used
US-centric in origin but widely adopted globally.
Typical trigger
Leadership wants a coherent way to talk about and prioritize risk.
Related frameworks
A structuring layer that maps down to CIS Controls and NIST 800-53.

06

NIST SP 800-53

Standard

A very large, granular catalog of security and privacy controls.

A comprehensive control catalog (organized into families such as Access Control, Audit, Incident Response) used where deep, rigorous control coverage is required. It underpins US federal compliance regimes (e.g., FedRAMP) and is common in heavily regulated environments.

hover to flip

NIST SP 800-53 — details

Certifiable?
It's a control catalog; compliance is assessed within programs built on it.
Where used
US government, federal contractors, high-assurance environments.
Typical trigger
Selling to US government or operating in a regime that mandates it.
Related frameworks
CSF and CIS map up to it; it's the "full detail" end of the spectrum.

07

TISAX

Certification

The automotive industry's shared information-security assessment.

TISAX (operated by the ENX Association) is an assessment and result-exchange mechanism built on an automotive-specific catalog (VDA ISA). You get assessed once, receive a label, and can share the result with multiple automotive partners instead of being audited repeatedly by each.

hover to flip

TISAX — details

Certifiable?
Yes — assessment with a shareable label (not a "certificate" in the ISO sense).
Where used
Automotive OEMs and their supply chain; strong in Germany and the wider DACH region.
Typical trigger
An OEM or Tier-1 supplier requires a TISAX label to keep working with them.
Related frameworks
Conceptually close to ISO 27001; the VDA ISA catalog derives from it.

08

BSI IT-Grundschutz

Standard

Germany's structured methodology for building an ISMS.

Published by the German Federal Office for Information Security (BSI), IT-Grundschutz is a detailed methodology plus a large catalog of standard modules and safeguards. It is designed to be compatible with ISO/IEC 27001 — you can achieve "ISO 27001 certification on the basis of IT-Grundschutz."

hover to flip

BSI IT-Grundschutz — details

Certifiable?
Yes — ISO 27001 certification via the IT-Grundschutz path.
Where used
Germany, especially public sector and regulated German organizations.
Typical trigger
German public-sector procurement or a regulator expects it.
Related frameworks
A German route to ISO 27001.

09

PCI DSS

Standard

The security standard for handling payment-card data.

Maintained by the PCI Security Standards Council, PCI DSS is a framework for safely storing, processing, and transmitting cardholder data. Validation ranges from a Self-Assessment Questionnaire (SAQ) for smaller merchants to a Report on Compliance (ROC) by a QSA for large volumes.

hover to flip

PCI DSS — details

Certifiable?
Validated compliance (SAQ or QSA-signed ROC), enforced by card brands/acquirers.
Where used
Any organization that touches cardholder data, worldwide.
Typical trigger
You start accepting or processing card payments.
Related frameworks
Overlaps with CIS/ISO on the technical controls, but is payment-specific.

10

CSA Cloud Controls Matrix (CCM)

Framework

A cloud-specific control matrix for assessing cloud security.

From the Cloud Security Alliance, the CCM is a cybersecurity control framework tailored to cloud computing, organized into domains and mapped to other standards. It underlies the CSA STAR program for cloud-provider assurance.

hover to flip

CSA Cloud Controls Matrix (CCM) — details

Certifiable?
Self-assessment (STAR Level 1) up to third-party (STAR Level 2).
Where used
Evaluating cloud providers and cloud implementations.
Typical trigger
You are a cloud provider proving assurance, or a customer assessing one.
Related frameworks
Maps to ISO 27001, SOC 2, NIST — a cloud-lens overlay.

11

OWASP ASVS / OWASP Top 10

Guideline

The reference for building and testing secure applications.

The OWASP Top 10 is an awareness list of the most critical web-application risks. The Application Security Verification Standard (ASVS) is a detailed, leveled set of requirements for verifying the technical security controls of web apps and APIs. Together they guide secure coding, code review, and penetration testing.

hover to flip

OWASP ASVS / OWASP Top 10 — details

Certifiable?
No — a testing/requirements standard, not a certification.
Where used
Software development, web apps, APIs, secure coding, pentesting.
Typical trigger
You build software and need a concrete secure-development bar.
Related frameworks
Complements the org-level frameworks with app-level depth.

12

COBIT

Framework

A governance and management framework for enterprise IT.

From ISACA, COBIT frames how IT is governed and managed to deliver value and manage risk. It's used more by IT governance, audit, and risk functions than by hands-on security engineers.

hover to flip

COBIT — details

Certifiable?
Framework (individuals can be certified; organizations align).
Where used
Enterprise IT governance, internal audit, risk management.
Typical trigger
Board/audit wants a governance structure over IT.
Related frameworks
Sits above technical control sets as governance.

13

IEC 62443

Standard

The cybersecurity standard for industrial and OT environments.

A series of standards for the security of industrial automation and control systems (IACS/OT) — covering asset owners, integrators, and product suppliers across plants, ICS, and connected machinery.

hover to flip

IEC 62443 — details

Certifiable?
Yes — certification schemes exist for products and organizations.
Where used
Manufacturing, energy, utilities, industrial plants, connected machinery.
Typical trigger
You operate or build industrial/OT systems.
Related frameworks
OT counterpart to the IT-focused frameworks.

Category legend

Certification
A formal certificate issued by an accredited third-party auditor, valid for a defined period.
Attestation
An independent auditor's report on your controls — shared privately, not a public certificate.
Framework
A structured model for organizing and prioritizing security activities without prescribing exact controls.
Guideline
A set of recommended practices or testing requirements — not certifiable, but widely referenced.
Benchmark
Prescriptive configuration recipes for hardening specific systems to a recognized baseline.
Standard
A detailed, authoritative control catalog or specification used as compliance evidence.
Regulation
A legally binding obligation — non-compliance carries fines, liability, or operational restrictions.

Still not sure which applies to you?

Answer a few plain-language questions about your business and get a short, ordered plan — no compliance background required.

Take the 2-minute advisor

Not legal advice. Standards evolve — verify current versions with the authoritative bodies. Last reviewed: 2026-07-01.