Framework hub
The frameworks organizations actually get assessed against — each broken down control by control: what it means, how to meet it, and the evidence an auditor asks for.
Tier 1
The essential frameworks — the standards and laws most organizations are actually assessed against.
SOC 2 (System and Organization Controls 2)
An attestation report on a service organization's controls over security, availability, processing integrity, confidentiality and privacy — the Trust Services Criteria.
ISO/IEC 27001:2022
The international standard for an information security management system (ISMS): a risk-based framework for selecting, operating and improving security controls.
PCI DSS v4.0 (Payment Card Industry Data Security Standard)
The security standard every organization that stores, processes or transmits cardholder data must meet, built around twelve core requirements.
General Data Protection Regulation (EU) 2016/679
The EU regulation governing how personal data of people in the EU and UK must be collected, processed, secured and accounted for.
NIS2 Directive (EU) 2022/2555
The EU's network and information security directive: cybersecurity risk-management duties, management accountability and strict incident-reporting deadlines for essential and important entities.
EU Artificial Intelligence Act (Regulation (EU) 2024/1689)
The first comprehensive AI law: a risk-based regime that bans some AI practices outright, puts heavy obligations on high-risk systems, and adds transparency duties for chatbots, deepfakes and general-purpose models.
EU Cyber Resilience Act (Regulation (EU) 2024/2847)
Cybersecurity requirements for manufacturers of hardware and software sold in the EU: secure-by-design products, vulnerability handling through the product's life, CE marking and rapid reporting of exploited flaws.
HIPAA (Health Insurance Portability and Accountability Act)
The US law protecting health information, enforced through its Privacy, Security and Breach Notification Rules.
Digital Operational Resilience Act (Regulation (EU) 2022/2554)
Operational resilience rules for the EU financial sector: ICT risk management, incident reporting, resilience testing and hard obligations around ICT third parties, applying since January 2025.
Sarbanes-Oxley Act of 2002
The US financial-reporting integrity law: officer certifications and audited internal control over financial reporting — with IT general controls at the heart of every modern SOX programme.
NIST Cybersecurity Framework 2.0
The most widely used voluntary cybersecurity framework: six functions organizations use to describe, assess and improve their security posture — and the map other standards are measured against.
SEC Cybersecurity Disclosure Rules (2023)
The SEC's rules requiring public companies to disclose material cyber incidents within four business days and to describe their cyber risk management and governance annually.
UK Product Security and Telecommunications Infrastructure Act 2022
The UK's consumer connectable-product security law, enforceable since April 2024: no default passwords, a vulnerability disclosure route, and honesty about how long products get security updates.
ISO/IEC 42001:2023
The international standard for an AI management system (AIMS): the certifiable governance wrapper organizations use to run AI responsibly — and increasingly to evidence EU AI Act readiness.