Frameworks

Everything in the catalogue is here, including standards we do not monitor yet — so you can see the gaps instead of guessing at them.

PCI DSS

PCI Security Standards Council

Contractual security requirements for any entity that stores, processes, or transmits payment card data. v4.0.1 (June 2024) is the current version; all require…

global standard

SOC 2

AICPA / CIMA

Audit framework for service organizations based on the Trust Services Criteria (TSC). Widely required by enterprise buyers; SOC 2 Type II reports attest to sec…

global framework

NIST CSF

NIST (National Institute of Standards and Technology)

Voluntary framework for improving critical infrastructure cybersecurity, organized around six functions: Govern, Identify, Protect, Detect, Respond, Recover. C…

global framework

NIST SP 800-53

NIST (National Institute of Standards and Technology)

Comprehensive catalog of security and privacy controls for US federal information systems, de-facto global reference for government and regulated industries. R…

global standard

NIST SP 800-171

NIST (National Institute of Standards and Technology)

Security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations, effectively mandatory for US DoD contr…

global standard

CIS Controls

Center for Internet Security (CIS)

Prioritized set of 18 safeguards for defending against the most common cyber attacks. v8.1 (June 2024) aligned the Govern security function with NIST CSF 2.0.

global framework

CIS Benchmarks

Center for Internet Security (CIS)

Monthly-updated technical configuration guidelines for operating systems, cloud platforms, and containers. Distinct from CIS Controls — these are system-harden…

global guidance

CSA CCM

Cloud Security Alliance (CSA)

Framework of 207 cloud-specific security controls across 17 domains, designed to align with ISO 27001, NIST, and PCI DSS. CCM v4.1 (January 2026) adds ISO 2700…

global framework

OWASP

OWASP (Open Worldwide Application Security Project)

Open standard for application-level security controls, covering authentication, session management, cryptography, and more. ASVS 5.0.0 (May 2025) is the curren…

global guidance

ISO 27001

ISO/IEC JTC 1/SC 27

Internationally recognized certifiable standard for information security management systems (ISMS). ISO/IEC 27001:2022 is the current edition; the 2013 transit…

global standard Not monitored yet

ISO 27002

ISO/IEC JTC 1/SC 27

Companion controls catalog to ISO 27001, providing implementation guidance for the 93 security controls in Annex A. ISO/IEC 27002:2022 aligns controls into fou…

global standard Not monitored yet

GDPR

European Parliament / European Data Protection Board (EDPB)

EU regulation on data protection and privacy for all individuals within the European Union and European Economic Area. Compliance shaped by EDPB guidelines and…

regional:eu regulation

NIS2

European Parliament / national competent authorities

EU directive on cybersecurity for essential and important entities across 18 sectors, replacing NIS1. Requires member states to transpose into national law; ph…

regional:eu regulation

DORA

European Parliament / EBA / ESMA / EIOPA (Joint Committee ESAs)

EU regulation on digital operational resilience for the financial sector, applicable since 17 January 2025. Requires ICT risk management, incident reporting, r…

regional:eu regulation

CRA

European Commission / European Parliament

EU regulation requiring cybersecurity-by-design for products with digital elements sold in the EU, entered into force December 2024. Vulnerability reporting ob…

regional:eu regulation

EU AI Act

European Commission / European Parliament

EU regulation classifying AI systems by risk level and imposing requirements on developers and deployers, entered into force August 2024. GPAI systemic-risk ru…

regional:eu regulation

eIDAS 2

European Commission / European Parliament

EU regulation requiring member states to make a European Digital Identity Wallet available to citizens by 24 December 2026. Regulated private-sector relying pa…

regional:eu regulation

EU Cybersecurity Act

European Commission / ENISA

EU regulation strengthening ENISA's mandate and establishing the EU cybersecurity certification framework for ICT products, services, and processes. The EUCC s…

regional:eu regulation

ENISA

ENISA (European Union Agency for Cybersecurity)

Publications, threat landscape reports, and technical guidelines issued by the EU Agency for Cybersecurity. ENISA is the issuing body for guidance under NIS2 a…

regional:eu guidance

HIPAA

HHS Office for Civil Rights (OCR)

US federal law protecting the privacy and security of individually identifiable health information. The Security Rule (45 CFR 164) governs electronic PHI; a ma…

regional:us law

CMMC

US Department of Defense (DoD)

US DoD framework requiring defense contractors to achieve cybersecurity maturity certification as a prerequisite for federal contracts. The program rule (32 CF…

regional:us regulation

FedRAMP

General Services Administration (GSA) / FedRAMP PMO

US federal program standardizing security authorization for cloud services used by federal agencies. CR26 Consolidated Rules (June 2026) mandate machine-readab…

regional:us regulation

SEC Cybersecurity

US Securities and Exchange Commission (SEC)

US disclosure regime for public companies: material cybersecurity incidents are reported on Form 8-K, and risk management, strategy, and board governance are d…

regional:us regulation

NYDFS Part 500

New York State Department of Financial Services (DFS)

New York State regulation binding DFS-licensed banks, insurers, and other financial services companies to a documented cybersecurity program — risk assessment,…

regional:us regulation

CISA

CISA (US Department of Homeland Security)

Binding Operational Directives, Emergency Directives, and cross-sector guidance from the US federal cyber defence agency. The directives bind federal civilian …

regional:us guidance

NCSC

National Cyber Security Centre (United Kingdom)

Guidance and assurance schemes from the UK's national cyber authority: Cyber Essentials, the Cyber Assessment Framework used by regulators of essential service…

national:uk guidance

UA Cybersecurity Law

Verkhovna Rada of Ukraine

Ukrainian law establishing the legal framework for national cybersecurity, mandatory CISO roles, and obligations for critical infrastructure operators. Law 433…

national:ua law

UA Personal Data Law

Verkhovna Rada of Ukraine

Ukrainian law on the protection of personal data; draft law 8153 (passed first reading November 2024) proposes GDPR-aligned reforms including sanctions of up t…

national:ua law Not monitored yet

UA Cloud Services Law

Verkhovna Rada of Ukraine / Cabinet of Ministers / Ministry of Digital Transformation / National Bank of Ukraine

Ukrainian law on cloud services (2022) and related regulations for critical infrastructure operators. Secondary regulation setting security requirements for cl…

national:ua law

CMU Resolution 518

Cabinet of Ministers of Ukraine

Ukrainian government resolution establishing general cybersecurity requirements for critical infrastructure operators, transitioning from the legacy KSZI certi…

national:ua regulation

NBU Regulation 95

National Bank of Ukraine

NBU regulations on cybersecurity for banks and payment institutions, anchored in Resolution No. 178 (August 2022). Open banking requirements (August 2025) adde…

national:ua regulation

DSSZZI KSZI Requirements

State Service of Special Communications and Information Protection of Ukraine (SSSCIP)

DSSZI (State Service of Special Communications) technical standards for comprehensive information protection systems (KSZI) and security profiles. The transiti…

national:ua regulation

Mintsyfra Security Profiles

Ministry of Digital Transformation of Ukraine

Sector-specific cybersecurity baseline profiles for Ukrainian public-sector and critical infrastructure systems, replacing legacy KSZI requirements. New profil…

national:ua regulation

DSTU ISO/IEC 27001

SE "UkrNDNC" (Ministry of Economy of Ukraine)

Ukrainian national adoption of ISO/IEC 27001:2022, designated DSTU ISO/IEC 27001:2023 (Order No. 210, August 2023). Paywalled; published changes appear only in…

national:ua standard Not monitored yet

NIST AI RMF

NIST (National Institute of Standards and Technology) / AI Resource Center

Voluntary framework for managing risks throughout the AI lifecycle, organized around four functions: Govern, Map, Measure, Manage. AI RMF 1.0 (January 2023) is…

global framework Not monitored yet

TISAX

ENX Association / VDA (Verband der Automobilindustrie)

Automotive industry standard for information security assessments, exchanged via the ENX portal. ISA2027 (published July 2026, effective 1 January 2027) introd…

global standard Not monitored yet

SWIFT CSCF

SWIFT (Society for Worldwide Interbank Financial Telecommunication)

Annual mandatory security controls framework for all SWIFT network participants, requiring attestation by 31 December each year. CSCF v2026 (32 controls: 26 ma…

global framework Not monitored yet