Skip to main content
// Compliance & Frameworks

The Standards That Define Trust

Security frameworks are a shared language for doing the right things and proving it. Here is a plain-language map of the global standards that matter — what each one is, who it is for, and why it exists.

// Start Here

NIST CSF 2.0 — The Six Functions

The most widely adopted framework for organizing a security program. Every other standard maps back to these outcomes.

1

Govern

Establish and monitor the cybersecurity risk-management strategy, expectations, and policy. (New in CSF 2.0.)

2

Identify

Understand assets, suppliers, and the risks to them — you cannot protect what you have not inventoried.

3

Protect

Put safeguards in place: access control, data security, awareness training, and maintenance.

4

Detect

Find anomalies and adverse events quickly through continuous monitoring.

5

Respond

Take action on a detected incident — contain, analyze, communicate, and mitigate.

6

Recover

Restore assets and operations, and capture lessons learned to improve resilience.

// The Landscape

Frameworks, Standards & Regulations

The difference matters: frameworks guide, standards certify, and regulations are the law.

NIST CSF 2.0

NIST Cybersecurity Framework

FrameworkGlobal / US
What it is

A voluntary, outcome-based framework organizing security into six functions: Govern, Identify, Protect, Detect, Respond, Recover.

Who it's for

Any organization wanting a common language to describe and improve its security posture.

Why it matters

The de facto starting point for building a risk-based program that maps cleanly onto other standards.

ISO 27001

ISO/IEC 27001:2022

StandardGlobal
What it is

An internationally certifiable standard for an Information Security Management System (ISMS) — the processes for managing security risk.

Who it's for

Organizations needing a globally recognized certification, often for enterprise or international customers.

Why it matters

Certification is independent, audited proof that security is systematically managed, not ad hoc.

SOC 2

SOC 2 (Trust Services Criteria)

FrameworkUS / Global
What it is

An attestation report on controls relevant to security, availability, processing integrity, confidentiality, and privacy.

Who it's for

SaaS and service providers that handle customer data and need to prove it to buyers.

Why it matters

A SOC 2 report is frequently a hard requirement to close B2B and enterprise deals.

PCI DSS 4.0

Payment Card Industry Data Security Standard

StandardGlobal
What it is

A mandatory standard of technical and operational requirements for anyone that stores, processes, or transmits cardholder data.

Who it's for

Merchants, processors, and any business touching payment card data.

Why it matters

Non-compliance can mean fines and loss of the ability to process card payments.

GDPR

General Data Protection Regulation

RegulationEU / EEA
What it is

A law governing how personal data of individuals in the EU/EEA is collected, processed, and protected.

Who it's for

Any organization worldwide that handles the personal data of EU/EEA residents.

Why it matters

Penalties can reach the greater of €20M or 4% of global annual revenue.

HIPAA

Health Insurance Portability and Accountability Act

RegulationUS
What it is

US law setting national standards to protect sensitive patient health information (PHI), including a Security Rule for electronic PHI.

Who it's for

Healthcare providers, plans, clearinghouses, and their business associates.

Why it matters

Protects patient privacy and carries significant civil and criminal penalties for breaches.

CIS Controls v8

CIS Critical Security Controls

FrameworkGlobal
What it is

A prioritized set of 18 safeguards that defend against the most common and impactful attacks.

Who it's for

Teams wanting a concrete, action-first checklist to improve defenses fast.

Why it matters

Highly practical and prioritized — an excellent bridge from strategy to hands-on hardening.

OWASP

Open Worldwide Application Security Project

Knowledge BaseGlobal
What it is

Community standards for application security, including the OWASP Top 10, ASVS, and the Top 10 for LLM Applications.

Who it's for

Developers and security teams building and testing web, API, and AI applications.

Why it matters

The industry reference for what application weaknesses to prevent, test for, and verify.

MITRE ATT&CK

MITRE ATT&CK & D3FEND

Knowledge BaseGlobal
What it is

A curated knowledge base of real-world adversary tactics and techniques (ATT&CK) and the defensive countermeasures that address them (D3FEND).

Who it's for

Detection engineers, threat hunters, and red/blue teams.

Why it matters

A shared vocabulary for describing attacks and measuring detection coverage.

NIST AI RMF

NIST AI Risk Management Framework

FrameworkGlobal / US
What it is

Guidance for managing risks unique to AI systems across the Govern, Map, Measure, and Manage functions.

Who it's for

Organizations building, deploying, or relying on AI and LLM-powered systems.

Why it matters

The emerging reference for trustworthy, secure, and accountable AI.

// Orientation

Which One Do I Need?

A starting point, not legal advice — most mature programs adopt several in layers.

“We sell software to enterprises”
SOC 2, then ISO 27001
“We handle EU customers’ personal data”
GDPR
“We process credit-card payments”
PCI DSS 4.0
“We handle US patient health data”
HIPAA
“We want a fast, practical hardening checklist”
CIS Controls v8
“We are building AI / LLM products”
NIST AI RMF + OWASP Top 10 for LLMs
“We are starting a program from scratch”
NIST CSF 2.0

Not sure where you stand?

Our Compliance Readiness & Gap Assessment maps your current controls to the framework that matters to your business — and hands you a prioritized roadmap to close the gaps.