Supported Frameworks

SCF maps 506+ regulatory and industry frameworks to a unified control set

American Institute of Certified Public Accountants (AICPA) Privacy Management Framework (PMF) (2020)

109 controls

American Institute of Certified Public Accountants (AICPA) Trust Services Criteria (2017)

412 controls

Argentina - Protection of Personal Data (2018)

78 controls

Asia - Pacific Economic Cooperation (APEC) Privacy Framework (2015)

14 controls

Australia - Code of Practice - Securing the Internet of Things for Consumers (2020)

35 controls

Australia - Essential Eight maturity model and ISM mapping (2024)

37 controls

Australia - Information Security Manual (ISM) (March 2026)

389 controls

Australia - Privacy Principles (2026)

24 controls

Australia - Prudential Standard CPS 230 - Operational Risk Management (2023)

69 controls

Australia - Prudential Standard CPS 234 Information Security (2019)

23 controls

Austria - Data Protection Act (2018)

28 controls

Bahamas - Data Protection Act (DPA) (2003)

40 controls

Belgium - Act of 30 July 2018

27 controls

Bermuda - Bermuda Monetary Authority (BMA) Insurance Sector Operational Cyber Risk Management Code of Conduct (2020)

97 controls

Brazil - General Data Protection Law (LGPD) (2018)

29 controls

Bundesamt für Sicherheit in der Informationstechnik (BSI) - Standard 200 - 1 (v1.0)

35 controls

Canada - Office of the Superintendent of Financial Institutions Canada (OSFI) - Cyber Security Self - Assessment Guidance

125 controls

Canada - OSFI B - 13 (2022)

150 controls

Canada - Personal Information Protection and Electronic Documents Act (PIPEDA) (2000)

35 controls

Canada - Protecting controlled information in non - Government of Canada systems and organizations (ITSP.10.171) (2025)

415 controls

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1

234 controls

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG1

104 controls

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG2

208 controls

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG3

230 controls

Chile - Act 19628 - Protection of Personal Data (1999)

12 controls

China - Cybersecurity Law of the People's Republic of China (2017)

27 controls

China - Data Security Law of the People's Republic of China (2021)

10 controls

China - Decision on Strengthening Network Information Protection (2012)

7 controls

China - Personal Information Protection Law of the People's Republic of China (2021)

37 controls

Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) v4.1.0

291 controls

Cloud Security Alliance (CSA) Internet of Things Security Controls Framework v2

253 controls

Colombia - Law 1581 (2012)

21 controls

Committee of Sponsoring Organizations (COSO) (2013)

104 controls

Control Objectives for Information and Related Technologies (COBIT) (2019)

190 controls

Cyber Resilience Capability Maturity Model (CR - CMM) (2026)

46 controls

EU - Digital Operational Resilience Act (2023)

102 controls

EU - European Banking Authority Guidelines on ICT and Security Risk Management (2025)

153 controls

EU - European Union Agency for Cybersecurity NIS2 Annex (2024)

223 controls

EU - European Union Agency for Cybersecurity NIS2 Directive (EU) 2022/2555)

68 controls

EU - European Union Artificial Intelligence Act (Regulation (EU) 2024/1689)

119 controls

EU - European Union Cyber Resilience Act (2024)

35 controls

EU - European Union Cyber Resilience Act - Annex I (2024)

16 controls

EU - European Union General Data Protection Regulation (2016)

42 controls

EU - Second Payment Services Directive (PSD2) (2015)

11 controls

Germany - Banking Supervisory Requirements for IT (2017)

91 controls

Germany - Cloud Computing Compliance Controls Catalogue (C5) (2020)

207 controls

Germany - Federal Data Protection Act (2017)

46 controls

Government Risk and Authorization Management Program (GovRAMP)

441 controls

Government Risk and Authorization Management Program (GovRAMP) - Core Controls

86 controls

Government Risk and Authorization Management Program (GovRAMP) - High

441 controls

Government Risk and Authorization Management Program (GovRAMP) - Low

166 controls

Government Risk and Authorization Management Program (GovRAMP) - Low+

230 controls

Government Risk and Authorization Management Program (GovRAMP) - Moderate

347 controls

Greece - Protection of Individuals with Regard to the Processing of Personal Data (2472/1997)

26 controls

Hong Kong - Personal Data Ordinance (2022)

18 controls

Hungary - Act CXII of 2011

35 controls

India Digital Personal Data Protection Act (2023)

41 controls

India - Information Technology Rules (Privacy Rules) (2011)

13 controls

India - SEBI Cybersecurity and Cyber Resilience Framework (2024)

170 controls

International Electrotechnical Commission 62443 - 4 - 2 Ed. 1.0 b:2019 - Security for industrial automation and control systems - Part 4 - 2: Technical security requirements for IACS components

89 controls

International Electrotechnical Commission (IEC) 62443 - 2 - 1:2024 - Security for industrial automation and control systems - Part 2 - 1: Security program requirements for IACS asset owners

112 controls

International Electrotechnical Commission (IEC) 62443 - 3 - 3:2013 - Industrial communication networks - Network and system security - Part 3 - 3: System security requirements and security levels

80 controls

International Electrotechnical Commission (IEC) 62443 - 4 - 1:2018 - Security for industrial automation and control systems - Part 4 - 1: Secure product development lifecycle requirements

25 controls

International Electrotechnical Commission (IEC) Technical Report 60601 - 4 - 5:2021 - Medical electrical equipment - Part 4 - 5: Guidance and interpretation - Safety - related technical security specifications

26 controls

International Maritime Organization (IMO) Guidelines on Maritime Cyber Risk Management (2025)

75 controls

Ireland - Cybersecurity Methodology for an Organization (CMO) v2.0

67 controls

Ireland - Data Protection Act (DPA) (2018)

17 controls

ISO/IEC 22301:2019 - Security and resilience - Business continuity management systems - Requirements

36 controls

ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection - Information security management systems - Requirements

51 controls

ISO/IEC 27002:2022 - Information security, cybersecurity and privacy protection - Information security controls

316 controls

ISO/IEC 27017:2015 - Information technology - Security techniques - Code of practice for information security controls based on ISO/IEC 27002 for cloud services

224 controls

ISO/IEC 27018:2025 - Information security, cybersecurity and privacy protection - Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors

322 controls

ISO/IEC 27701:2025 - Information security, cybersecurity and privacy protection - Privacy information management systems - Requirements and guidance

59 controls

ISO/IEC 29100:2024 - Information technology - Security techniques - Privacy framework

43 controls

ISO/IEC 31000:2018 - Risk management - Guidelines

53 controls

ISO/IEC 31010:2019 - Risk management - Risk assessment techniques

31 controls

ISO/IEC 42001:2023 - Information technology - Artificial intelligence - Management system

149 controls

ISO/SAE 21434:2021 - Road vehicles — Cybersecurity engineering

51 controls

Israel - Protection of Privacy Law, 5741 (2025)

13 controls

Italy - Personal Data Protection Code (2018)

13 controls

Japan - Act on the Protection of Personal Information (2020)

34 controls

Japan - Information System Security Management and Assessment Program (ISMAP)

249 controls

Kenya - Data Protection Act (DPA) (2019)

42 controls

Malaysia - Personal Data Protection Act (PDPA) (2010)

19 controls

Malaysia - Risk Management in Technology (RMiT) (2025)

197 controls

Mexico - Federal Law on Protection of Personal Data held by Private Parties (2010)

23 controls

MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) - NIST 800 - 53 mappings

108 controls

Motion Picture Association (MPA) Content Security Best Practices Common Guidelines v5.3.1

232 controls

National Association of Insurance Commissioners (NAIC) Insurance Data Security Model Law (MDL - 668) (2017)

58 controls

New Zealand - HISF MicroSmall (2023)

102 controls

New Zealand - HISF MLHSP (2023)

0 controls

New Zealand - HISO 10029:2024 NZ Health Information Security Framework Guidance for Suppliers

101 controls

New Zealand - Information Security Manual (ISM) v3.9

289 controls

New Zealand - Privacy Act (2020)

20 controls

Nigeria - Data Protection Regulation (DPR) (2019)

32 controls

NIST AI 100 - 1 - Artificial Intelligence Risk Management Framework (AI RMF 1.0)

158 controls

NIST AI 600 - 1 - Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile

139 controls

NIST CSWP 39 - Considerations for Achieving Crypto Agility

15 controls

NIST Cybersecurity Framework v2.0

250 controls

NIST Privacy Framework v1.0

153 controls

NIST SP 800 - 160 Volume 2, Revision 1 - Developing Cyber - Resilient Systems: A Systems Security Engineering Approach

204 controls

NIST SP 800 - 161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

341 controls

NIST SP 800 - 161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - C - SCRM Baseline

132 controls

NIST SP 800 - 161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Flow Down Baseline

107 controls

NIST SP 800 - 161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 1 Baseline

95 controls

NIST SP 800 - 161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 2 Baseline

273 controls

NIST SP 800 - 161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 3 Baseline

284 controls

NIST SP 800 - 171A - Assessing Security Requirements for Controlled Unclassified Information

134 controls

NIST SP 800 - 171A R3 - Assessing Security Requirements for Controlled Unclassified Information

414 controls

NIST SP 800 - 171 R2 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

251 controls

NIST SP 800 - 171 R3 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

414 controls

NIST SP 800 - 172A R3 - Assessing Enhanced Security Requirements for Controlled Unclassified Information

163 controls

NIST SP 800 - 172 R3 - Enhanced Security Requirements for Protecting Controlled Unclassified Information

162 controls

NIST SP 800 - 207 - Zero Trust Architecture

93 controls

NIST SP 800 - 218 - Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities

59 controls

NIST SP 800 - 37 R2 - Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy

45 controls

NIST SP 800 - 39 - Managing Information Security Risk: Organization, Mission, and Information System View

17 controls

NIST SP 800 - 53 R4 - Security and Privacy Controls for Federal Information Systems and Organizations

653 controls

NIST SP 800 - 53 R5 - Security and Privacy Controls for Information Systems and Organizations

777 controls

NIST SP 800 - 53 R5 - Security and Privacy Controls for Information Systems and Organizations - High Baseline

89 controls

NIST SP 800 - 53 R5 - Security and Privacy Controls for Information Systems and Organizations - Low Baseline

202 controls

NIST SP 800 - 53 R5 - Security and Privacy Controls for Information Systems and Organizations - Moderate Baseline

157 controls

NIST SP 800 - 53 R5 - Security and Privacy Controls for Information Systems and Organizations - Privacy Baseline

346 controls

NIST SP 800 - 66 R2 - Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide

112 controls

NIST SP 800 - 82 R3 - Guide to Operational Technology (OT) Security - High OT Overlay

467 controls

NIST SP 800 - 82 R3 - Guide to Operational Technology (OT) Security - Low OT Overlay

777 controls

NIST SP 800 - 82 R3 - Guide to Operational Technology (OT) Security - Low OT Overlay

251 controls

NIST SP 800 - 82 R3 - Guide to Operational Technology (OT) Security - Moderate OT Overlay

390 controls

Norway - Personal Data Act (PDA) (2018)

4 controls

Open Worldwide Application Security Project (OWASP) Top 10 (2025)

139 controls

Organisation for Economic Co - operation and Development (EOCD) Privacy Principles

14 controls

Payment Card Industry Data Security Standard (PCI DSS) v4.01

371 controls

Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) A

71 controls

Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) A - EP

239 controls

Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) B

58 controls

Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) B - IP

121 controls

Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) C

227 controls

Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) C - VT

115 controls

Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) D Merchant

322 controls

Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) D Service Provider

339 controls

Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) P2PE

47 controls

Philippines - Data Privacy Act (DPA) (2012)

16 controls

Poland - Act of 10 May 2018 on the Protection of Personal Data

2 controls

Qatar - Personal Data Privacy Protection Law (PDPPL) (2020)

33 controls

Russia - Federal Law No. 152 - FZ (2025)

17 controls

Saudi Arabia - Critical Systems Cybersecurity Controls (CSCC – 1: 2019)

172 controls

Saudi Arabia - Cybersecurity Guidelines for Internet of Things (CGIoT - 1:2024)

118 controls

Saudi Arabia - Essential Cybersecurity Controls (ECC – 1 : 2018)

169 controls

Saudi Arabia - Operational Technology Cybersecurity Controls (OTCC - 1: 2022)

160 controls

Saudi Arabia - Personal Data Protection Law (PDPL) (2023)

36 controls

Saudi Arabia - SACS - 002 Third Party Cybersecurity Standard (2022)

101 controls

Saudi Arabia - Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework Version 1.0 (2017)

91 controls

Secure Controls Framework (SCF) Data Privacy Management Principles (2025)

0 controls

Serbia - Act of 9 November 2018 on Personal Data Protection (Official Gazette No. 87/18)

31 controls

Shared Assessments Standard Information Gathering (SIG) Questionnaire 2025

128 controls

Singapore - Cyber Hygiene Practice (2019)

17 controls

Singapore - Monitory Authority of Singapore (MAS) Technology Risk Management (TRM) Guidelines (2021)

219 controls

Singapore - Personal Data Protection Ac (PDPA) (2012)

33 controls

Society for Worldwide Interbank Financial Telecommunication Customer Security Controls Framework 2025

164 controls

South Africa - Protection of Personal Information Act (POPIA) (2013)

23 controls

South Korea - Personal Information Protection Act (PIPA) (2011)

24 controls

Space Attack Research & Tactic Analysis (SPARTA) Countermeasures

79 controls

Spain - ICT Security Guide CCN - STIC 825 (2026)

234 controls

Spain - Royal Decree 311/2022

72 controls

Switzerland - Federal Act on Data Protection (FADP) (2025)

25 controls

Taiwan - Personal Data Protection Act (PDPA) (2025)

9 controls

Trusted Information Security Assessment Exchange (TISAX) 6.0.3

154 controls

Turkey - Law on the Protection of Personal Data (LPPD) (2016)

7 controls

UAE - National Information Assurance Framework (NIAF) (2023)

20 controls

UK - Cyber Assessment Framework (CAF) v4.0

66 controls

UK - Cyber Assessment Framework for Aviation Guidance (CAP1850) (2020)

36 controls

UK - Cyber Essentials: Requirements for IT Infrastructure v3.3

27 controls

UK - Data Protection Act (DPA) (2018)

25 controls

UK - Ministry of Defence Standard (DEFSTAN) 05 - 138 (2024)

213 controls

UK - Ministry of Defence Standard (DEFSTAN) 05 - 138 (2024) - L0

2 controls

UK - Ministry of Defence Standard (DEFSTAN) 05 - 138 (2024) - L1

159 controls

UK - Ministry of Defence Standard (DEFSTAN) 05 - 138 (2024) - L2

206 controls

UK - Ministry of Defence Standard (DEFSTAN) 05 - 138 (2024) - L3

212 controls

UL 2900 - 1 - Software Cybersecurity for Network - Connectable Products, Part 1: General Requirements (2017)

23 controls

UL 2900 - 2 - 2 Ed. 1 - 2016 - Outline of Investigation for Software Cybersecurity for Network - Connectable Products, Part 2 - 2: Particular Requirements for Industrial Control Systems

20 controls

United Nations - Regulation No. 155 - Cyber security and cyber security management system (2021)

57 controls

United Nations - United Nations Economic Commission for Europe (UNECE) Working Party 29 (2020)

57 controls

US - 33 CFR Part 101 Subpart F (up to date as of 4 - 17 - 2026)

104 controls

US - Alaska Personal Information Protection Act (PIPA) (2009)

5 controls

US - California Consumer Privacy Act (CCPA) (January 2026) - amended California Privacy Rights Act (CPRA)

258 controls

US - California SB1386 (2002)

4 controls

US - California SB327 (2018)

3 controls

US - Centers for Medicare & Medicaid Services MARS - E Document Suite, Version 2.0

392 controls

US - Children's Online Privacy Protection Act (COPPA) (2024)

10 controls

US - Colorado Privacy Act (2021)

23 controls

US - Cybersecurity & Infrastructure Security Agency (CISA) Cross - Sector Cybersecurity Performance Goals 2.0

126 controls

US - Cybersecurity & Infrastructure Security Agency (CISA) Secure Software Development Attestation Form (SSDAF) (2024)

41 controls

US - Cybersecurity & Infrastructure Security Agency (CISA) Trusted Internet Connections 3.0 Security Capabilities Catalog

148 controls

US - Data Privacy Framework (2023)

31 controls

US - Defense Federal Acquisition Regulation Supplement (DFARS) 252.204 - 7012

19 controls

US - Department of Energy (DOE) - Cybersecurity Capability Maturity Model version 2.1

224 controls

US - Department of Justice - Criminal Justice Information Services (CJIS) Security Policy v6.0

365 controls

US - Department of War (DoW) - Computer Emergency Response Team (CERT) Resilience Management Model (RMM) Version 1.2

85 controls

US - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 1

52 controls

US - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 1 Assessment Objectives

16 controls

US Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 2

198 controls

US Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 3

55 controls

US - Department of War (DoW) - Zero Trust Execution Roadmap v1.1

117 controls

US - Department of War (DoW) - Zero Trust Reference Architecture v2

39 controls

US - Executive Order (EO) 14028 - Improving the Nation's Cybersecurity

43 controls

US - Fair & Accurate Credit Transactions Act (FACTA) & Fair Credit Reporting Act (FCRA) (2023)

3 controls

US - Fair Information Practice Principles (FIPPs) (1973)

30 controls

US - Family Educational Rights and Privacy Act (FERPA) (2010)

5 controls

US - Farm Credit Administration (FCA) Cyber Risk Management (2023)

81 controls

US - Federal Acquisition Regulation (FAR) 52.204 - 21 - Basic Safeguarding of Covered Contractor Information Systems

59 controls

US - Federal Acquisition Regulation (FAR) 52.204 - 25 (NDAA Section 889) - Prohibition on Contracting With Entities Using Certain Telecommunications and Video Surveillance Services or Equipment

2 controls

US - Federal Acquisition Regulation (FAR) 52.204 - 27 - Prohibition on a ByteDance Covered Application

3 controls

US - Federal Risk and Authorization Management Program (FedRAMP) R5 - High Baseline

561 controls

US - Federal Risk and Authorization Management Program (FedRAMP) R5 - Li - SAAS Baseline

383 controls

US - Federal Risk and Authorization Management Program (FedRAMP) R5 - Low Baseline

383 controls

US - Federal Risk and Authorization Management Program (FedRAMP) R5 - Moderate Baseline

491 controls

US - Federal Trade Commission (FTC) Act

16 controls

US - Financial Industry Regulatory Authority (FINRA) Cybersecurity Rules

17 controls

US - Food & Drug Administration (FDA) 21 CFR Part 11 (2025)

62 controls

US - Gramm Leach Bliley Act (GLBA) - CFR 314 (Dec 2023)

70 controls

US - Health and Human Services (HHS) § 155.260 - Privacy and Security of Personally Identifiable Information (2016)

36 controls

US - Health Insurance Portability and Accountability Act (HIPAA) Administrative Simplification (2013)

170 controls

US - Health Insurance Portability and Accountability Act (HIPAA) Security Rule (2013)

136 controls

US - Illinois Biometric Information Privacy Act (BIPA) (2008)

6 controls

US - Illinois Identity Protection Act (IPA) (2009)

12 controls

US - Illinois Personal Information Protection Act (PIPA) (2006)

10 controls

US - Internal Revenue Service (IRS) 1075 (2021)

443 controls

US - Massachusetts 201 CMR 17.00 (2008)

53 controls

US - National Industrial Security Program Operating Manual (NISPOM) (2020)

35 controls

US - Nevada Operation of Gaming Establishments - Regulation 5.260 (Cybersecurity)

20 controls

US - Nevada Privacy Law (2023) - CHAPTER 603A - SECURITY AND PRIVACY OF PERSONAL INFORMATION

29 controls

US - Nevada SB220 (2019)

3 controls

US - New York Department of Financial Services (NY DFS) 23NYCRR Part 500 (2023 Amendment 2)

156 controls

US - New York SHIELD Act (SB S5575B) (2019)

28 controls

US - North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) (2024)

122 controls

US - Oregon Consumer Information Protection Act (ORS 646A) (2025)

24 controls

US - Oregon Consumer Privacy Act (SB 619) (2023)

34 controls

US - Safeguarding of Naval Nuclear Propulsion Information (NNPI) (2010)

32 controls

US - Sarbanes Oxley Act (SOX) (2002)

4 controls

US - Securities and Exchange Commission (SEC) Cybersecurity Rule (2023)

40 controls

US - Tennessee Information Protection Act (TIPA) (2025)

29 controls

US - Texas Consumer Data Protection Act (2025)

28 controls

US - Texas DIR Security Control Standards Catalog v2.2

238 controls

US - Texas Identity Theft Enforcement and Protection Act (BC521) (2009)

5 controls

US - Texas Risk & Authorization Management Program 2.0 - Level 1

173 controls

US - Texas Risk & Authorization Management Program 2.0 - Level 2

285 controls

US - Texas Safe Harbor Law (SB2610) (2025)

6 controls

US - Texas SB820 (2019)

4 controls

US - Transportation Security Administration (TSA) Security Directive 1580/82 - 2022 - 01 - Rail Cybersecurity Mitigation Actions and Testing

60 controls

US - Vermont Data Broker Registration Act (Act 171 of 2018)

35 controls

US - Virginia Consumer Data Protection Act (2023)

44 controls

AICPA Privacy Management Framework (PMF)

109 controls

AICPA TSC 2017:2022 (used for SOC 2)

412 controls

Americas Argentina Reg 132-2018

25 controls

Americas Bahamas

18 controls

Americas Bermuda BMACCC

61 controls

Americas Brazil LGPD

33 controls

Americas Canada CSAG

141 controls

Americas Canada ITSP-10-171

407 controls

Americas Canada OSFI B-13

150 controls

Americas Canada PIPEDA

28 controls

Americas Chile

22 controls

Americas Colombia

29 controls

Americas Mexico

23 controls

APAC Australia Essential 8

37 controls

APAC Australia IoT Code of Practice

15 controls

APAC Australia ISM June 2024

336 controls

APAC Australian Privacy Principles

26 controls

APAC Australia Privacy Act

23 controls

APAC Australia Prudential Standard CPS230

41 controls

APAC Australia Prudential Standard CPS234

52 controls

APAC China Cybersecurity Law

27 controls

APAC China Data Security Law

15 controls

APAC China DNSIP

10 controls

APAC China Privacy Law

79 controls

APAC Hong Kong

14 controls

APAC India DPDPA 2023

41 controls

APAC India ITR

12 controls

APAC India SEBI CSCRF

170 controls

APAC Japan APPI

58 controls

APAC Japan ISMAP

249 controls

APAC Malaysia

25 controls

APAC New Zealand HISF Microsmall 2023

32 controls

APAC New Zealand HISF MLHSP 2023

102 controls

APAC New Zealand HISF Suppliers 2023

101 controls

APAC New Zealand NZISM 3.6

291 controls

APAC New Zealand Privacy Act of 2020

20 controls

APAC Philippines

30 controls

APAC Singapore

30 controls

APAC Singapore Cyber Hygiene Practice

21 controls

APAC Singapore MAS TRM 2021

214 controls

APAC South Korea

37 controls

APAC Taiwan

23 controls

APEC Privacy Framework 2015

14 controls

BSI Standard 200-1

35 controls

CIS CSC 8.1

234 controls

CIS CSC 8.1 IG1

104 controls

CIS CSC 8.1 IG2

208 controls

CIS CSC 8.1 IG3

230 controls

COBIT 2019

190 controls

COSO 2013

104 controls

CR CMM 2026

46 controls

CSA CCM 4.1.0

291 controls

CSA IoT SCF 2

253 controls

EMEA Austria

63 controls

EMEA Belgium

59 controls

EMEA EU AI Act

119 controls

EMEA EU Cyber Resiliency Act

18 controls

EMEA EU Cyber Resiliency Act Annexes

23 controls

EMEA EU DORA

102 controls

EMEA EU EBA GL/2019/04

148 controls

EMEA EU GDPR

42 controls

EMEA EU NIS2

68 controls

EMEA EU NIS2 Annex

223 controls

EMEA EU PSD2

30 controls

EMEA Germany

18 controls

EMEA Germany Banking Supervisory Requirements for IT (BAIT)

91 controls

EMEA Germany C5 2020

239 controls

EMEA Greece

17 controls

EMEA Hungary

27 controls

EMEA Ireland

25 controls

EMEA Israel

22 controls

EMEA Israel CDMO 1.0

393 controls

EMEA Italy

28 controls

EMEA Kenya DPA 2019

41 controls

EMEA Nigeria DPR 2019

25 controls

EMEA Norway

23 controls

EMEA Poland

29 controls

EMEA Qatar PDPPL

56 controls

EMEA Russia

28 controls

EMEA Saudi Arabia CSCC-1 2019

152 controls

EMEA Saudi Arabia ECC-1 2018

190 controls

EMEA Saudi Arabia IoT CGIoT-1 2024

118 controls

EMEA Saudi Arabia OTCC-1 2022

198 controls

EMEA Saudi Arabia PDPL

36 controls

EMEA Saudi Arabia SACS-002

185 controls

EMEA Saudi Arabia SAMA CSF 1.0

50 controls

EMEA Serbia 87/2018

56 controls

EMEA South Africa

101 controls

EMEA Spain 1720/2007

17 controls

EMEA Spain 311/2022

73 controls

EMEA Spain BOE-A-2022-7191

72 controls

EMEA Spain CCN-STIC 825

99 controls

EMEA Switzerland

16 controls

EMEA Turkey

17 controls

EMEA UAE NIAF

20 controls

EMEA UK CAF 4.0

66 controls

EMEA UK CAP 1850

43 controls

EMEA UK Cyber Essentials

26 controls

EMEA UK DEFSTAN 05-138

213 controls

EMEA UK DEFSTAN 05-138 - L0

2 controls

EMEA UK DEFSTAN 05-138 - L1

159 controls

EMEA UK DEFSTAN 05-138 - L2

206 controls

EMEA UK DEFSTAN 05-138 - L3

212 controls

EMEA UK DPA

10 controls

GovRAMP

441 controls

GovRAMP Core

86 controls

GovRAMP High

441 controls

GovRAMP Low

230 controls

GovRAMP Moderate

347 controls

IEC 62443-2-1 2024

112 controls

IEC 62443-3-3 2013

80 controls

IEC 62443-4-1 2018

25 controls

IEC 62443-4-2 2019

89 controls

IEC TR 60601-4-5 2021

26 controls

IMO Maritime Cyber Risk Management

75 controls

ISO 22301 2019

36 controls

ISO 27001 2022

51 controls

ISO 27002 2022

316 controls

ISO 27017 2015

224 controls

ISO 27018 2025

322 controls

ISO 27701 2025

59 controls

ISO 29100 2024

43 controls

ISO 31000 2018

53 controls

ISO 31010 2009

31 controls

ISO 42001 2023

149 controls

ISO/SAE 21434 2021

51 controls

MITRE ATT&CK 16

108 controls

MPA Content Security Program 5.3.1

232 controls

NAIC Insurance Data Security Model Law (MDL-668)

58 controls

NIST 800-160 Vol2 R1

204 controls

NIST 800-161 R1

341 controls

NIST 800-161 R1 C-SCRM Baseline

132 controls

NIST 800-161 R1 Flow Down

107 controls

NIST 800-161 R1 Level 1

95 controls

NIST 800-161 R1 Level 2

273 controls

NIST 800-161 R1 Level 3

284 controls

NIST 800-171A

134 controls

NIST 800-171A R3

215 controls

NIST 800-171 R2

251 controls

NIST 800-171 R3

407 controls

NIST 800-172

74 controls

NIST 800-207

93 controls

NIST 800-218

59 controls

NIST 800-37 R2

45 controls

NIST 800-39

17 controls

NIST 800-53B R5 (high)

89 controls

NIST 800-53B R5 (low)

202 controls

NIST 800-53B R5 (moderate)

157 controls

NIST 800-53B R5 (privacy)

346 controls

NIST 800-53 R4

653 controls

NIST 800-53 R5

777 controls

NIST 800-82 R3

777 controls

NIST 800-82 R3 HIGH OT Overlay

467 controls

NIST 800-82 R3 LOW OT Overlay

251 controls

NIST 800-82 R3 MODERATE OT Overlay

390 controls

NIST AI 100-1 (AI RMF) 1.0

158 controls

NIST AI 600-1

139 controls

NIST CSF 2.0

250 controls

NIST Privacy Framework 1.0

152 controls

NIST SP 800-66 R2

112 controls

OECD Privacy Principles

14 controls

OWASP Top 10 2025

139 controls

PCI DSS 4.0.1

371 controls

PCI DSS 4.0.1 SAQ A

71 controls

PCI DSS 4.0.1 SAQ A-EP

239 controls

PCI DSS 4.0.1 SAQ B

58 controls

PCI DSS 4.0.1 SAQ B-IP

121 controls

PCI DSS 4.0.1 SAQ C

227 controls

PCI DSS 4.0.1 SAQ C-VT

115 controls

PCI DSS 4.0.1 SAQ D Merchant

322 controls

PCI DSS 4.0.1 SAQ D Service Provider

339 controls

PCI DSS 4.0.1 SAQ P2PE

47 controls

SCF CORE AI-Enabled Operations

57 controls

SCF CORE AI Model Deployment

213 controls

SCF CORE ESP Level 1 Foundational

327 controls

SCF CORE ESP Level 2 Critical Infrastructure

573 controls

SCF CORE ESP Level 3 Advanced Threats

590 controls

SCF CORE Fundamentals

68 controls

SCF CORE Mergers, Acquisitions & Divestitures (MA&D)

732 controls

SCF DPMP 2025

218 controls

Shared Assessments SIG 2025

128 controls

SPARTA

79 controls

SWIFT CSF 2025

164 controls

TISAX ISA 6.0.3

154 controls

UL 2900-1 2017

23 controls

UL 2900-2-2 2016

20 controls

UN ECE WP.29

57 controls

UN R155

57 controls

US - AK PIPA

5 controls

US C2M2 2.1

224 controls

US - CA CCPA 2025

258 controls

US - CA SB1386

4 controls

US - CA SB327

3 controls

US CERT RMM 1.2

85 controls

US CISA CPG 2022

126 controls

US CJIS Security Policy 6.0

365 controls

US CMMC 2.0 Level 1

52 controls

US CMMC 2.0 Level 1 AOs

16 controls

US CMMC 2.0 Level 2

198 controls

US CMMC 2.0 Level 3

55 controls

US CMS MARS-E 2.0

391 controls

US - CO Colorado Privacy Act

23 controls

US COPPA

10 controls

US Data Privacy Framework (DPF)

31 controls

US DFARS Cybersecurity 252.204-7012

19 controls

US DHS CISA SSDAF

41 controls

US DHS CISA TIC 3.0

148 controls

US DoD Zero Trust Execution Roadmap

117 controls

US DoD Zero Trust Reference Architecture 2.0

39 controls

US EO 14028

43 controls

US FACTA & FCRA

3 controls

US FAR 52.204-21

59 controls

US FAR 52.204-25 (NDAA Section 889)

2 controls

US FAR 52.204-27

3 controls

US FCA CRM

81 controls

US FDA 21 CFR Part 11

62 controls

US FedRAMP R5 (high)

561 controls

US FedRAMP R5 (LI-SaaS)

383 controls

US FedRAMP R5 (low)

383 controls

US FedRAMP R5 (moderate)

491 controls

US FERPA

5 controls

US FINRA

17 controls

US FIPPS

30 controls

US FTC Act

16 controls

US GLBA CFR 314 2023

70 controls

US HHS 45 CFR 155.260

36 controls

US HIPAA Administrative Simplification 2013

170 controls

US HIPAA Security Rule / NIST SP 800-66 R2

136 controls

US - IL BIPA

6 controls

US - IL IPA

12 controls

US - IL PIPA

10 controls

US IRS 1075

442 controls

US - MA 201 CMR 17.00

53 controls

US NERC CIP 2024

122 controls

US NISPOM 2020

35 controls

US NNPI (unclass)

32 controls

US - NV NOGE Reg 5

20 controls

US - NV SB220

3 controls

US - NY DFS 23 NYCRR500 2023 Amd 2

156 controls

US - NY SHIELD Act S5575B

28 controls

US - OR 646A

24 controls

US - OR CPA

34 controls

US SEC Cybersecurity Rule

40 controls

US SOX

4 controls

US - TN TIPA

29 controls

US TSA / DHS 1580/82-2022-01

60 controls

US - TX BC521

5 controls

US - TX CDPA

28 controls

US - TX DIR Control Standards 2.2

238 controls

US - TX SB 2610

6 controls

US - TX SB 820

4 controls

US - TX TX-RAMP Level 1

173 controls

US - TX TX-RAMP Level 2

285 controls

US - VA CDPA 2023

44 controls

US - VT Act 171 of 2018

35 controls
Sign In to Explore