Auditen
Home / Frameworks

Framework hub

The frameworks organizations actually get assessed against — each broken down control by control: what it means, how to meet it, and the evidence an auditor asks for.

Tier 1

The essential frameworks — the standards and laws most organizations are actually assessed against.

AICPA Tier 1

SOC 2 (System and Organization Controls 2)

An attestation report on a service organization's controls over security, availability, processing integrity, confidentiality and privacy — the Trust Services Criteria.

11 guides →
ISO/IEC Tier 1

ISO/IEC 27001:2022

The international standard for an information security management system (ISMS): a risk-based framework for selecting, operating and improving security controls.

10 guides →
PCI Security Standards Council Tier 1

PCI DSS v4.0 (Payment Card Industry Data Security Standard)

The security standard every organization that stores, processes or transmits cardholder data must meet, built around twelve core requirements.

12 guides →
European Union Tier 1

General Data Protection Regulation (EU) 2016/679

The EU regulation governing how personal data of people in the EU and UK must be collected, processed, secured and accounted for.

10 guides →
European Union Tier 1

NIS2 Directive (EU) 2022/2555

The EU's network and information security directive: cybersecurity risk-management duties, management accountability and strict incident-reporting deadlines for essential and important entities.

10 guides →
European Union Tier 1

EU Artificial Intelligence Act (Regulation (EU) 2024/1689)

The first comprehensive AI law: a risk-based regime that bans some AI practices outright, puts heavy obligations on high-risk systems, and adds transparency duties for chatbots, deepfakes and general-purpose models.

14 guides →
European Union Tier 1

EU Cyber Resilience Act (Regulation (EU) 2024/2847)

Cybersecurity requirements for manufacturers of hardware and software sold in the EU: secure-by-design products, vulnerability handling through the product's life, CE marking and rapid reporting of exploited flaws.

10 guides →
US HHS Tier 1

HIPAA (Health Insurance Portability and Accountability Act)

The US law protecting health information, enforced through its Privacy, Security and Breach Notification Rules.

9 guides →
European Union Tier 1

Digital Operational Resilience Act (Regulation (EU) 2022/2554)

Operational resilience rules for the EU financial sector: ICT risk management, incident reporting, resilience testing and hard obligations around ICT third parties, applying since January 2025.

10 guides →
US Congress / SEC / PCAOB Tier 1

Sarbanes-Oxley Act of 2002

The US financial-reporting integrity law: officer certifications and audited internal control over financial reporting — with IT general controls at the heart of every modern SOX programme.

10 guides →
NIST Tier 1

NIST Cybersecurity Framework 2.0

The most widely used voluntary cybersecurity framework: six functions organizations use to describe, assess and improve their security posture — and the map other standards are measured against.

10 guides →
US SEC Tier 1

SEC Cybersecurity Disclosure Rules (2023)

The SEC's rules requiring public companies to disclose material cyber incidents within four business days and to describe their cyber risk management and governance annually.

8 guides →
UK Government / OPSS Tier 1

UK Product Security and Telecommunications Infrastructure Act 2022

The UK's consumer connectable-product security law, enforceable since April 2024: no default passwords, a vulnerability disclosure route, and honesty about how long products get security updates.

8 guides →
ISO/IEC Tier 1

ISO/IEC 42001:2023

The international standard for an AI management system (AIMS): the certifiable governance wrapper organizations use to run AI responsibly — and increasingly to evidence EU AI Act readiness.

9 guides →