American Institute of Certified Public Accountants (AICPA) Privacy Management Framework (PMF) (2020)
109 controlsAmerican Institute of Certified Public Accountants (AICPA) Trust Services Criteria (2017)
412 controlsArgentina - Protection of Personal Data (2018)
78 controlsAsia - Pacific Economic Cooperation (APEC) Privacy Framework (2015)
14 controlsAustralia - Code of Practice - Securing the Internet of Things for Consumers (2020)
35 controlsAustralia - Essential Eight maturity model and ISM mapping (2024)
37 controlsAustralia - Information Security Manual (ISM) (March 2026)
389 controlsAustralia - Privacy Principles (2026)
24 controlsAustralia - Prudential Standard CPS 230 - Operational Risk Management (2023)
69 controlsAustralia - Prudential Standard CPS 234 Information Security (2019)
23 controlsAustria - Data Protection Act (2018)
28 controlsBahamas - Data Protection Act (DPA) (2003)
40 controlsBelgium - Act of 30 July 2018
27 controlsBermuda - Bermuda Monetary Authority (BMA) Insurance Sector Operational Cyber Risk Management Code of Conduct (2020)
97 controlsBrazil - General Data Protection Law (LGPD) (2018)
29 controlsBundesamt für Sicherheit in der Informationstechnik (BSI) - Standard 200 - 1 (v1.0)
35 controlsCanada - Office of the Superintendent of Financial Institutions Canada (OSFI) - Cyber Security Self - Assessment Guidance
125 controlsCanada - OSFI B - 13 (2022)
150 controlsCanada - Personal Information Protection and Electronic Documents Act (PIPEDA) (2000)
35 controlsCanada - Protecting controlled information in non - Government of Canada systems and organizations (ITSP.10.171) (2025)
415 controlsCenter for Internet Security (CIS) Critical Security Controls (CSC) version 8.1
234 controlsCenter for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG1
104 controlsCenter for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG2
208 controlsCenter for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG3
230 controlsChile - Act 19628 - Protection of Personal Data (1999)
12 controlsChina - Cybersecurity Law of the People's Republic of China (2017)
27 controlsChina - Data Security Law of the People's Republic of China (2021)
10 controlsChina - Decision on Strengthening Network Information Protection (2012)
7 controlsChina - Personal Information Protection Law of the People's Republic of China (2021)
37 controlsCloud Security Alliance (CSA) Cloud Controls Matrix (CCM) v4.1.0
291 controlsCloud Security Alliance (CSA) Internet of Things Security Controls Framework v2
253 controlsColombia - Law 1581 (2012)
21 controlsCommittee of Sponsoring Organizations (COSO) (2013)
104 controlsControl Objectives for Information and Related Technologies (COBIT) (2019)
190 controlsCyber Resilience Capability Maturity Model (CR - CMM) (2026)
46 controlsEU - Digital Operational Resilience Act (2023)
102 controlsEU - European Banking Authority Guidelines on ICT and Security Risk Management (2025)
153 controlsEU - European Union Agency for Cybersecurity NIS2 Annex (2024)
223 controlsEU - European Union Agency for Cybersecurity NIS2 Directive (EU) 2022/2555)
68 controlsEU - European Union Artificial Intelligence Act (Regulation (EU) 2024/1689)
119 controlsEU - European Union Cyber Resilience Act (2024)
35 controlsEU - European Union Cyber Resilience Act - Annex I (2024)
16 controlsEU - European Union General Data Protection Regulation (2016)
42 controlsEU - Second Payment Services Directive (PSD2) (2015)
11 controlsGermany - Banking Supervisory Requirements for IT (2017)
91 controlsGermany - Cloud Computing Compliance Controls Catalogue (C5) (2020)
207 controlsGermany - Federal Data Protection Act (2017)
46 controlsGovernment Risk and Authorization Management Program (GovRAMP)
441 controlsGovernment Risk and Authorization Management Program (GovRAMP) - Core Controls
86 controlsGovernment Risk and Authorization Management Program (GovRAMP) - High
441 controlsGovernment Risk and Authorization Management Program (GovRAMP) - Low
166 controlsGovernment Risk and Authorization Management Program (GovRAMP) - Low+
230 controlsGovernment Risk and Authorization Management Program (GovRAMP) - Moderate
347 controlsGreece - Protection of Individuals with Regard to the Processing of Personal Data (2472/1997)
26 controlsHong Kong - Personal Data Ordinance (2022)
18 controlsHungary - Act CXII of 2011
35 controlsIndia Digital Personal Data Protection Act (2023)
41 controlsIndia - Information Technology Rules (Privacy Rules) (2011)
13 controlsIndia - SEBI Cybersecurity and Cyber Resilience Framework (2024)
170 controlsInternational Electrotechnical Commission 62443 - 4 - 2 Ed. 1.0 b:2019 - Security for industrial automation and control systems - Part 4 - 2: Technical security requirements for IACS components
89 controlsInternational Electrotechnical Commission (IEC) 62443 - 2 - 1:2024 - Security for industrial automation and control systems - Part 2 - 1: Security program requirements for IACS asset owners
112 controlsInternational Electrotechnical Commission (IEC) 62443 - 3 - 3:2013 - Industrial communication networks - Network and system security - Part 3 - 3: System security requirements and security levels
80 controlsInternational Electrotechnical Commission (IEC) 62443 - 4 - 1:2018 - Security for industrial automation and control systems - Part 4 - 1: Secure product development lifecycle requirements
25 controlsInternational Electrotechnical Commission (IEC) Technical Report 60601 - 4 - 5:2021 - Medical electrical equipment - Part 4 - 5: Guidance and interpretation - Safety - related technical security specifications
26 controlsInternational Maritime Organization (IMO) Guidelines on Maritime Cyber Risk Management (2025)
75 controlsIreland - Cybersecurity Methodology for an Organization (CMO) v2.0
67 controlsIreland - Data Protection Act (DPA) (2018)
17 controlsISO/IEC 22301:2019 - Security and resilience - Business continuity management systems - Requirements
36 controlsISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection - Information security management systems - Requirements
51 controlsISO/IEC 27002:2022 - Information security, cybersecurity and privacy protection - Information security controls
316 controlsISO/IEC 27017:2015 - Information technology - Security techniques - Code of practice for information security controls based on ISO/IEC 27002 for cloud services
224 controlsISO/IEC 27018:2025 - Information security, cybersecurity and privacy protection - Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors
322 controlsISO/IEC 27701:2025 - Information security, cybersecurity and privacy protection - Privacy information management systems - Requirements and guidance
59 controlsISO/IEC 29100:2024 - Information technology - Security techniques - Privacy framework
43 controlsISO/IEC 31000:2018 - Risk management - Guidelines
53 controlsISO/IEC 31010:2019 - Risk management - Risk assessment techniques
31 controlsISO/IEC 42001:2023 - Information technology - Artificial intelligence - Management system
149 controlsISO/SAE 21434:2021 - Road vehicles — Cybersecurity engineering
51 controlsIsrael - Protection of Privacy Law, 5741 (2025)
13 controlsItaly - Personal Data Protection Code (2018)
13 controlsJapan - Act on the Protection of Personal Information (2020)
34 controlsJapan - Information System Security Management and Assessment Program (ISMAP)
249 controlsKenya - Data Protection Act (DPA) (2019)
42 controlsMalaysia - Personal Data Protection Act (PDPA) (2010)
19 controlsMalaysia - Risk Management in Technology (RMiT) (2025)
197 controlsMexico - Federal Law on Protection of Personal Data held by Private Parties (2010)
23 controlsMITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) - NIST 800 - 53 mappings
108 controlsMotion Picture Association (MPA) Content Security Best Practices Common Guidelines v5.3.1
232 controlsNational Association of Insurance Commissioners (NAIC) Insurance Data Security Model Law (MDL - 668) (2017)
58 controlsNew Zealand - HISF MicroSmall (2023)
102 controlsNew Zealand - HISF MLHSP (2023)
0 controlsNew Zealand - HISO 10029:2024 NZ Health Information Security Framework Guidance for Suppliers
101 controlsNew Zealand - Information Security Manual (ISM) v3.9
289 controlsNew Zealand - Privacy Act (2020)
20 controlsNigeria - Data Protection Regulation (DPR) (2019)
32 controlsNIST AI 100 - 1 - Artificial Intelligence Risk Management Framework (AI RMF 1.0)
158 controlsNIST AI 600 - 1 - Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile
139 controlsNIST CSWP 39 - Considerations for Achieving Crypto Agility
15 controlsNIST Cybersecurity Framework v2.0
250 controlsNIST Privacy Framework v1.0
153 controlsNIST SP 800 - 160 Volume 2, Revision 1 - Developing Cyber - Resilient Systems: A Systems Security Engineering Approach
204 controlsNIST SP 800 - 161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
341 controlsNIST SP 800 - 161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - C - SCRM Baseline
132 controlsNIST SP 800 - 161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Flow Down Baseline
107 controlsNIST SP 800 - 161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 1 Baseline
95 controlsNIST SP 800 - 161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 2 Baseline
273 controlsNIST SP 800 - 161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 3 Baseline
284 controlsNIST SP 800 - 171A - Assessing Security Requirements for Controlled Unclassified Information
134 controlsNIST SP 800 - 171A R3 - Assessing Security Requirements for Controlled Unclassified Information
414 controlsNIST SP 800 - 171 R2 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
251 controlsNIST SP 800 - 171 R3 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
414 controlsNIST SP 800 - 172A R3 - Assessing Enhanced Security Requirements for Controlled Unclassified Information
163 controlsNIST SP 800 - 172 R3 - Enhanced Security Requirements for Protecting Controlled Unclassified Information
162 controlsNIST SP 800 - 207 - Zero Trust Architecture
93 controlsNIST SP 800 - 218 - Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities
59 controlsNIST SP 800 - 37 R2 - Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
45 controlsNIST SP 800 - 39 - Managing Information Security Risk: Organization, Mission, and Information System View
17 controlsNIST SP 800 - 53 R4 - Security and Privacy Controls for Federal Information Systems and Organizations
653 controlsNIST SP 800 - 53 R5 - Security and Privacy Controls for Information Systems and Organizations
777 controlsNIST SP 800 - 53 R5 - Security and Privacy Controls for Information Systems and Organizations - High Baseline
89 controlsNIST SP 800 - 53 R5 - Security and Privacy Controls for Information Systems and Organizations - Low Baseline
202 controlsNIST SP 800 - 53 R5 - Security and Privacy Controls for Information Systems and Organizations - Moderate Baseline
157 controlsNIST SP 800 - 53 R5 - Security and Privacy Controls for Information Systems and Organizations - Privacy Baseline
346 controlsNIST SP 800 - 66 R2 - Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide
112 controlsNIST SP 800 - 82 R3 - Guide to Operational Technology (OT) Security - High OT Overlay
467 controlsNIST SP 800 - 82 R3 - Guide to Operational Technology (OT) Security - Low OT Overlay
777 controlsNIST SP 800 - 82 R3 - Guide to Operational Technology (OT) Security - Low OT Overlay
251 controlsNIST SP 800 - 82 R3 - Guide to Operational Technology (OT) Security - Moderate OT Overlay
390 controlsNorway - Personal Data Act (PDA) (2018)
4 controlsOpen Worldwide Application Security Project (OWASP) Top 10 (2025)
139 controlsOrganisation for Economic Co - operation and Development (EOCD) Privacy Principles
14 controlsPayment Card Industry Data Security Standard (PCI DSS) v4.01
371 controlsPayment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) A
71 controlsPayment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) A - EP
239 controlsPayment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) B
58 controlsPayment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) B - IP
121 controlsPayment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) C
227 controlsPayment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) C - VT
115 controlsPayment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) D Merchant
322 controlsPayment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) D Service Provider
339 controlsPayment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self - Assessment Questionnaire (SAQ) P2PE
47 controlsPhilippines - Data Privacy Act (DPA) (2012)
16 controlsPoland - Act of 10 May 2018 on the Protection of Personal Data
2 controlsQatar - Personal Data Privacy Protection Law (PDPPL) (2020)
33 controlsRussia - Federal Law No. 152 - FZ (2025)
17 controlsSaudi Arabia - Critical Systems Cybersecurity Controls (CSCC – 1: 2019)
172 controlsSaudi Arabia - Cybersecurity Guidelines for Internet of Things (CGIoT - 1:2024)
118 controlsSaudi Arabia - Essential Cybersecurity Controls (ECC – 1 : 2018)
169 controlsSaudi Arabia - Operational Technology Cybersecurity Controls (OTCC - 1: 2022)
160 controlsSaudi Arabia - Personal Data Protection Law (PDPL) (2023)
36 controlsSaudi Arabia - SACS - 002 Third Party Cybersecurity Standard (2022)
101 controlsSaudi Arabia - Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework Version 1.0 (2017)
91 controlsSecure Controls Framework (SCF) Data Privacy Management Principles (2025)
0 controlsSerbia - Act of 9 November 2018 on Personal Data Protection (Official Gazette No. 87/18)
31 controlsShared Assessments Standard Information Gathering (SIG) Questionnaire 2025
128 controlsSingapore - Cyber Hygiene Practice (2019)
17 controlsSingapore - Monitory Authority of Singapore (MAS) Technology Risk Management (TRM) Guidelines (2021)
219 controlsSingapore - Personal Data Protection Ac (PDPA) (2012)
33 controlsSociety for Worldwide Interbank Financial Telecommunication Customer Security Controls Framework 2025
164 controlsSouth Africa - Protection of Personal Information Act (POPIA) (2013)
23 controlsSouth Korea - Personal Information Protection Act (PIPA) (2011)
24 controlsSpace Attack Research & Tactic Analysis (SPARTA) Countermeasures
79 controlsSpain - ICT Security Guide CCN - STIC 825 (2026)
234 controlsSpain - Royal Decree 311/2022
72 controlsSwitzerland - Federal Act on Data Protection (FADP) (2025)
25 controlsTaiwan - Personal Data Protection Act (PDPA) (2025)
9 controlsTrusted Information Security Assessment Exchange (TISAX) 6.0.3
154 controlsTurkey - Law on the Protection of Personal Data (LPPD) (2016)
7 controlsUAE - National Information Assurance Framework (NIAF) (2023)
20 controlsUK - Cyber Assessment Framework (CAF) v4.0
66 controlsUK - Cyber Assessment Framework for Aviation Guidance (CAP1850) (2020)
36 controlsUK - Cyber Essentials: Requirements for IT Infrastructure v3.3
27 controlsUK - Data Protection Act (DPA) (2018)
25 controlsUK - Ministry of Defence Standard (DEFSTAN) 05 - 138 (2024)
213 controlsUK - Ministry of Defence Standard (DEFSTAN) 05 - 138 (2024) - L0
2 controlsUK - Ministry of Defence Standard (DEFSTAN) 05 - 138 (2024) - L1
159 controlsUK - Ministry of Defence Standard (DEFSTAN) 05 - 138 (2024) - L2
206 controlsUK - Ministry of Defence Standard (DEFSTAN) 05 - 138 (2024) - L3
212 controlsUL 2900 - 1 - Software Cybersecurity for Network - Connectable Products, Part 1: General Requirements (2017)
23 controlsUL 2900 - 2 - 2 Ed. 1 - 2016 - Outline of Investigation for Software Cybersecurity for Network - Connectable Products, Part 2 - 2: Particular Requirements for Industrial Control Systems
20 controlsUnited Nations - Regulation No. 155 - Cyber security and cyber security management system (2021)
57 controlsUnited Nations - United Nations Economic Commission for Europe (UNECE) Working Party 29 (2020)
57 controlsUS - 33 CFR Part 101 Subpart F (up to date as of 4 - 17 - 2026)
104 controlsUS - Alaska Personal Information Protection Act (PIPA) (2009)
5 controlsUS - California Consumer Privacy Act (CCPA) (January 2026) - amended California Privacy Rights Act (CPRA)
258 controlsUS - California SB1386 (2002)
4 controlsUS - California SB327 (2018)
3 controlsUS - Centers for Medicare & Medicaid Services MARS - E Document Suite, Version 2.0
392 controlsUS - Children's Online Privacy Protection Act (COPPA) (2024)
10 controlsUS - Colorado Privacy Act (2021)
23 controlsUS - Cybersecurity & Infrastructure Security Agency (CISA) Cross - Sector Cybersecurity Performance Goals 2.0
126 controlsUS - Cybersecurity & Infrastructure Security Agency (CISA) Secure Software Development Attestation Form (SSDAF) (2024)
41 controlsUS - Cybersecurity & Infrastructure Security Agency (CISA) Trusted Internet Connections 3.0 Security Capabilities Catalog
148 controlsUS - Data Privacy Framework (2023)
31 controlsUS - Defense Federal Acquisition Regulation Supplement (DFARS) 252.204 - 7012
19 controlsUS - Department of Energy (DOE) - Cybersecurity Capability Maturity Model version 2.1
224 controlsUS - Department of Justice - Criminal Justice Information Services (CJIS) Security Policy v6.0
365 controlsUS - Department of War (DoW) - Computer Emergency Response Team (CERT) Resilience Management Model (RMM) Version 1.2
85 controlsUS - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 1
52 controlsUS - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 1 Assessment Objectives
16 controlsUS Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 2
198 controlsUS Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 3
55 controlsUS - Department of War (DoW) - Zero Trust Execution Roadmap v1.1
117 controlsUS - Department of War (DoW) - Zero Trust Reference Architecture v2
39 controlsUS - Executive Order (EO) 14028 - Improving the Nation's Cybersecurity
43 controlsUS - Fair & Accurate Credit Transactions Act (FACTA) & Fair Credit Reporting Act (FCRA) (2023)
3 controlsUS - Fair Information Practice Principles (FIPPs) (1973)
30 controlsUS - Family Educational Rights and Privacy Act (FERPA) (2010)
5 controlsUS - Farm Credit Administration (FCA) Cyber Risk Management (2023)
81 controlsUS - Federal Acquisition Regulation (FAR) 52.204 - 21 - Basic Safeguarding of Covered Contractor Information Systems
59 controlsUS - Federal Acquisition Regulation (FAR) 52.204 - 25 (NDAA Section 889) - Prohibition on Contracting With Entities Using Certain Telecommunications and Video Surveillance Services or Equipment
2 controlsUS - Federal Acquisition Regulation (FAR) 52.204 - 27 - Prohibition on a ByteDance Covered Application
3 controlsUS - Federal Risk and Authorization Management Program (FedRAMP) R5 - High Baseline
561 controlsUS - Federal Risk and Authorization Management Program (FedRAMP) R5 - Li - SAAS Baseline
383 controlsUS - Federal Risk and Authorization Management Program (FedRAMP) R5 - Low Baseline
383 controlsUS - Federal Risk and Authorization Management Program (FedRAMP) R5 - Moderate Baseline
491 controlsUS - Federal Trade Commission (FTC) Act
16 controlsUS - Financial Industry Regulatory Authority (FINRA) Cybersecurity Rules
17 controlsUS - Food & Drug Administration (FDA) 21 CFR Part 11 (2025)
62 controlsUS - Gramm Leach Bliley Act (GLBA) - CFR 314 (Dec 2023)
70 controlsUS - Health and Human Services (HHS) § 155.260 - Privacy and Security of Personally Identifiable Information (2016)
36 controlsUS - Health Insurance Portability and Accountability Act (HIPAA) Administrative Simplification (2013)
170 controlsUS - Health Insurance Portability and Accountability Act (HIPAA) Security Rule (2013)
136 controlsUS - Illinois Biometric Information Privacy Act (BIPA) (2008)
6 controlsUS - Illinois Identity Protection Act (IPA) (2009)
12 controlsUS - Illinois Personal Information Protection Act (PIPA) (2006)
10 controlsUS - Internal Revenue Service (IRS) 1075 (2021)
443 controlsUS - Massachusetts 201 CMR 17.00 (2008)
53 controlsUS - National Industrial Security Program Operating Manual (NISPOM) (2020)
35 controlsUS - Nevada Operation of Gaming Establishments - Regulation 5.260 (Cybersecurity)
20 controlsUS - Nevada Privacy Law (2023) - CHAPTER 603A - SECURITY AND PRIVACY OF PERSONAL INFORMATION
29 controlsUS - Nevada SB220 (2019)
3 controlsUS - New York Department of Financial Services (NY DFS) 23NYCRR Part 500 (2023 Amendment 2)
156 controlsUS - New York SHIELD Act (SB S5575B) (2019)
28 controlsUS - North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) (2024)
122 controlsUS - Oregon Consumer Information Protection Act (ORS 646A) (2025)
24 controlsUS - Oregon Consumer Privacy Act (SB 619) (2023)
34 controlsUS - Safeguarding of Naval Nuclear Propulsion Information (NNPI) (2010)
32 controlsUS - Sarbanes Oxley Act (SOX) (2002)
4 controlsUS - Securities and Exchange Commission (SEC) Cybersecurity Rule (2023)
40 controlsUS - Tennessee Information Protection Act (TIPA) (2025)
29 controlsUS - Texas Consumer Data Protection Act (2025)
28 controlsUS - Texas DIR Security Control Standards Catalog v2.2
238 controlsUS - Texas Identity Theft Enforcement and Protection Act (BC521) (2009)
5 controlsUS - Texas Risk & Authorization Management Program 2.0 - Level 1
173 controlsUS - Texas Risk & Authorization Management Program 2.0 - Level 2
285 controlsUS - Texas Safe Harbor Law (SB2610) (2025)
6 controlsUS - Texas SB820 (2019)
4 controlsUS - Transportation Security Administration (TSA) Security Directive 1580/82 - 2022 - 01 - Rail Cybersecurity Mitigation Actions and Testing
60 controlsUS - Vermont Data Broker Registration Act (Act 171 of 2018)
35 controlsUS - Virginia Consumer Data Protection Act (2023)
44 controlsAICPA Privacy Management Framework (PMF)
109 controlsAICPA TSC 2017:2022 (used for SOC 2)
412 controlsAmericas Argentina Reg 132-2018
25 controlsAmericas Bahamas
18 controlsAmericas Bermuda BMACCC
61 controlsAmericas Brazil LGPD
33 controlsAmericas Canada CSAG
141 controlsAmericas Canada ITSP-10-171
407 controlsAmericas Canada OSFI B-13
150 controlsAmericas Canada PIPEDA
28 controlsAmericas Chile
22 controlsAmericas Colombia
29 controlsAmericas Mexico
23 controlsAPAC Australia Essential 8
37 controlsAPAC Australia IoT Code of Practice
15 controlsAPAC Australia ISM June 2024
336 controlsAPAC Australian Privacy Principles
26 controlsAPAC Australia Privacy Act
23 controlsAPAC Australia Prudential Standard CPS230
41 controlsAPAC Australia Prudential Standard CPS234
52 controlsAPAC China Cybersecurity Law
27 controlsAPAC China Data Security Law
15 controlsAPAC China DNSIP
10 controlsAPAC China Privacy Law
79 controlsAPAC Hong Kong
14 controlsAPAC India DPDPA 2023
41 controlsAPAC India ITR
12 controlsAPAC India SEBI CSCRF
170 controlsAPAC Japan APPI
58 controlsAPAC Japan ISMAP
249 controlsAPAC New Zealand HISF Microsmall 2023
32 controlsAPAC New Zealand HISF MLHSP 2023
102 controlsAPAC New Zealand HISF Suppliers 2023
101 controlsAPAC New Zealand NZISM 3.6
291 controlsAPAC New Zealand Privacy Act of 2020
20 controlsAPAC Philippines
30 controlsAPAC Singapore
30 controlsAPAC Singapore Cyber Hygiene Practice
21 controlsAPAC Singapore MAS TRM 2021
214 controlsAPAC South Korea
37 controlsAPEC Privacy Framework 2015
14 controlsBSI Standard 200-1
35 controlsCIS CSC 8.1 IG1
104 controlsCIS CSC 8.1 IG2
208 controlsCIS CSC 8.1 IG3
230 controlsCSA CCM 4.1.0
291 controlsCSA IoT SCF 2
253 controlsEMEA EU AI Act
119 controlsEMEA EU Cyber Resiliency Act
18 controlsEMEA EU Cyber Resiliency Act Annexes
23 controlsEMEA EU EBA GL/2019/04
148 controlsEMEA EU NIS2 Annex
223 controlsEMEA Germany Banking Supervisory Requirements for IT (BAIT)
91 controlsEMEA Germany C5 2020
239 controlsEMEA Israel CDMO 1.0
393 controlsEMEA Kenya DPA 2019
41 controlsEMEA Nigeria DPR 2019
25 controlsEMEA Qatar PDPPL
56 controlsEMEA Saudi Arabia CSCC-1 2019
152 controlsEMEA Saudi Arabia ECC-1 2018
190 controlsEMEA Saudi Arabia IoT CGIoT-1 2024
118 controlsEMEA Saudi Arabia OTCC-1 2022
198 controlsEMEA Saudi Arabia PDPL
36 controlsEMEA Saudi Arabia SACS-002
185 controlsEMEA Saudi Arabia SAMA CSF 1.0
50 controlsEMEA Serbia 87/2018
56 controlsEMEA South Africa
101 controlsEMEA Spain 1720/2007
17 controlsEMEA Spain 311/2022
73 controlsEMEA Spain BOE-A-2022-7191
72 controlsEMEA Spain CCN-STIC 825
99 controlsEMEA Switzerland
16 controlsEMEA UK CAF 4.0
66 controlsEMEA UK CAP 1850
43 controlsEMEA UK Cyber Essentials
26 controlsEMEA UK DEFSTAN 05-138
213 controlsEMEA UK DEFSTAN 05-138 - L0
2 controlsEMEA UK DEFSTAN 05-138 - L1
159 controlsEMEA UK DEFSTAN 05-138 - L2
206 controlsEMEA UK DEFSTAN 05-138 - L3
212 controlsGovRAMP Moderate
347 controlsIEC 62443-2-1 2024
112 controlsIEC 62443-3-3 2013
80 controlsIEC 62443-4-1 2018
25 controlsIEC 62443-4-2 2019
89 controlsIEC TR 60601-4-5 2021
26 controlsIMO Maritime Cyber Risk Management
75 controlsISO 22301 2019
36 controlsISO 27001 2022
51 controlsISO 27002 2022
316 controlsISO 27017 2015
224 controlsISO 27018 2025
322 controlsISO 27701 2025
59 controlsISO 29100 2024
43 controlsISO 31000 2018
53 controlsISO 31010 2009
31 controlsISO 42001 2023
149 controlsISO/SAE 21434 2021
51 controlsMITRE ATT&CK 16
108 controlsMPA Content Security Program 5.3.1
232 controlsNAIC Insurance Data Security Model Law (MDL-668)
58 controlsNIST 800-160 Vol2 R1
204 controlsNIST 800-161 R1
341 controlsNIST 800-161 R1 C-SCRM Baseline
132 controlsNIST 800-161 R1 Flow Down
107 controlsNIST 800-161 R1 Level 1
95 controlsNIST 800-161 R1 Level 2
273 controlsNIST 800-161 R1 Level 3
284 controlsNIST 800-171A
134 controlsNIST 800-171A R3
215 controlsNIST 800-171 R2
251 controlsNIST 800-171 R3
407 controlsNIST 800-37 R2
45 controlsNIST 800-53B R5 (high)
89 controlsNIST 800-53B R5 (low)
202 controlsNIST 800-53B R5 (moderate)
157 controlsNIST 800-53B R5 (privacy)
346 controlsNIST 800-53 R4
653 controlsNIST 800-53 R5
777 controlsNIST 800-82 R3
777 controlsNIST 800-82 R3 HIGH OT Overlay
467 controlsNIST 800-82 R3 LOW OT Overlay
251 controlsNIST 800-82 R3 MODERATE OT Overlay
390 controlsNIST AI 100-1 (AI RMF) 1.0
158 controlsNIST AI 600-1
139 controlsNIST Privacy Framework 1.0
152 controlsNIST SP 800-66 R2
112 controlsOECD Privacy Principles
14 controlsOWASP Top 10 2025
139 controlsPCI DSS 4.0.1
371 controlsPCI DSS 4.0.1 SAQ A
71 controlsPCI DSS 4.0.1 SAQ A-EP
239 controlsPCI DSS 4.0.1 SAQ B
58 controlsPCI DSS 4.0.1 SAQ B-IP
121 controlsPCI DSS 4.0.1 SAQ C
227 controlsPCI DSS 4.0.1 SAQ C-VT
115 controlsPCI DSS 4.0.1 SAQ D Merchant
322 controlsPCI DSS 4.0.1 SAQ D Service Provider
339 controlsPCI DSS 4.0.1 SAQ P2PE
47 controlsSCF CORE AI-Enabled Operations
57 controlsSCF CORE AI Model Deployment
213 controlsSCF CORE ESP Level 1 Foundational
327 controlsSCF CORE ESP Level 2 Critical Infrastructure
573 controlsSCF CORE ESP Level 3 Advanced Threats
590 controlsSCF CORE Fundamentals
68 controlsSCF CORE Mergers, Acquisitions & Divestitures (MA&D)
732 controlsSCF DPMP 2025
218 controlsShared Assessments SIG 2025
128 controlsSWIFT CSF 2025
164 controlsTISAX ISA 6.0.3
154 controlsUL 2900-1 2017
23 controlsUL 2900-2-2 2016
20 controlsUS - CA CCPA 2025
258 controlsUS CERT RMM 1.2
85 controlsUS CISA CPG 2022
126 controlsUS CJIS Security Policy 6.0
365 controlsUS CMMC 2.0 Level 1
52 controlsUS CMMC 2.0 Level 1 AOs
16 controlsUS CMMC 2.0 Level 2
198 controlsUS CMMC 2.0 Level 3
55 controlsUS CMS MARS-E 2.0
391 controlsUS - CO Colorado Privacy Act
23 controlsUS Data Privacy Framework (DPF)
31 controlsUS DFARS Cybersecurity 252.204-7012
19 controlsUS DHS CISA SSDAF
41 controlsUS DHS CISA TIC 3.0
148 controlsUS DoD Zero Trust Execution Roadmap
117 controlsUS DoD Zero Trust Reference Architecture 2.0
39 controlsUS FACTA & FCRA
3 controlsUS FAR 52.204-21
59 controlsUS FAR 52.204-25 (NDAA Section 889)
2 controlsUS FAR 52.204-27
3 controlsUS FDA 21 CFR Part 11
62 controlsUS FedRAMP R5 (high)
561 controlsUS FedRAMP R5 (LI-SaaS)
383 controlsUS FedRAMP R5 (low)
383 controlsUS FedRAMP R5 (moderate)
491 controlsUS GLBA CFR 314 2023
70 controlsUS HHS 45 CFR 155.260
36 controlsUS HIPAA Administrative Simplification 2013
170 controlsUS HIPAA Security Rule / NIST SP 800-66 R2
136 controlsUS - MA 201 CMR 17.00
53 controlsUS NERC CIP 2024
122 controlsUS NISPOM 2020
35 controlsUS NNPI (unclass)
32 controlsUS - NV NOGE Reg 5
20 controlsUS - NY DFS 23 NYCRR500 2023 Amd 2
156 controlsUS - NY SHIELD Act S5575B
28 controlsUS SEC Cybersecurity Rule
40 controlsUS TSA / DHS 1580/82-2022-01
60 controlsUS - TX DIR Control Standards 2.2
238 controlsUS - TX SB 2610
6 controlsUS - TX TX-RAMP Level 1
173 controlsUS - TX TX-RAMP Level 2
285 controlsUS - VA CDPA 2023
44 controlsUS - VT Act 171 of 2018
35 controls