Security Frameworks & Compliance Standards
Browse 20+ security frameworks and compliance standards — filter by industry, purpose, geography or audience.
Understanding the landscape
Why Frameworks & Standards Matter
In today’s complex threat landscape, organizations cannot rely on intuition alone to manage risk. Frameworks and standards provide structured, proven approaches to identifying vulnerabilities, implementing controls, and demonstrating accountability — to regulators, customers, and stakeholders alike. Whether you’re securing patient data, protecting financial systems, or building cloud infrastructure, there is a framework designed to guide you.
Not all frameworks carry the same weight. Some are legal obligations — non-compliance means fines, penalties, or loss of operating licenses. Others are voluntary best practices that signal maturity and build trust.
Required by law or regulation
- → GDPR — EU data protection law
- → HIPAA — US healthcare data compliance
- → PCI DSS — Payment card industry requirement
- → NYDFS — NY financial services regulation
- → SAMA CSF — Saudi financial sector mandate
- → SOX — US public company financial reporting law
Adopted by choice to demonstrate maturity
- → ISO 27001 — Global security best practice
- → NIST CSF — Flexible risk management guide
- → CIS Controls — Prioritized security actions
- → SOC 2 — Trust-based assurance standard
- → NIST SP 800-53 — Federal security controls catalog
- → COBIT 2019 — IT governance & management
Use the library below to explore, compare, and understand the frameworks most relevant to your industry, role, and regulatory environment.
Filter by Industry
Filter by Industry
Filter by Purpose
Risk Management
NIST Cybersecurity Framework 2.0
The go-to framework for managing cybersecurity risk across all organisation types — updated in 2024 with a new Govern function.
NIST · USA · Voluntary
Compliance
ISO 27001:2022
International standard for information security management systems. Certifiable, globally recognised and widely adopted.
ISO · Global · Voluntary
Privacy
GDPR
The EU’s comprehensive data protection regulation — mandatory for any organisation handling EU resident data.
EU · European Union · Mandatory
Compliance
PCI DSS v4.0
Payment Card Industry Data Security Standard — required for all organisations that handle cardholder data.
PCI SSC · Global · Mandatory
Healthcare
HIPAA
US federal law protecting sensitive patient health information. Applies to covered entities and business associates.
HHS · USA · Mandatory
Cloud Security
SOC 2 Type II
Trust Services Criteria audit for service organisations — the standard for demonstrating security to enterprise customers.
AICPA · USA · Voluntary
Government
NIST SP 800-53 Rev 5
Comprehensive security and privacy controls catalogue for US federal systems — the most detailed controls framework available.
NIST · USA · Mandatory
IT Governance
COBIT 2019
Leading framework for IT governance and management — bridges business requirements, technical issues and control risks.
ISACA · Global · Voluntary
Privacy
CCPA / CPRA
California’s comprehensive consumer privacy law giving residents rights over their personal data — strengthened by CPRA in 2023.
California · USA · Mandatory
Cloud Security
CSA Cloud Controls Matrix v4
197 cloud-specific security controls across 17 domains — the definitive framework for cloud security assurance.
CSA · Global · Voluntary
Compliance
SOX — Sarbanes-Oxley Act
US federal law requiring strict financial reporting and internal controls for publicly traded companies.
SEC · USA · Mandatory
Risk Management
COSO Internal Control Framework
The primary framework for designing and evaluating internal controls — foundation of SOX Section 404 compliance.
COSO · Global · Voluntary
Risk Management
CIS Controls v8
18 prioritised cybersecurity actions organised into implementation groups — the most practical starting point for any organisation.
CIS · Global · Voluntary
Healthcare
HITRUST CSF
Certifiable framework integrating HIPAA, NIST, ISO 27001 and PCI DSS — the de facto standard for US healthcare vendors.
HITRUST · USA · Voluntary
Compliance
ISO 27002:2022
Implementation guidance for ISO 27001 Annex A controls — the how to ISO 27001’s what.
ISO · Global · Voluntary
Healthcare
ISO 27799
Healthcare-specific guidance for implementing ISO 27002 controls — covers personal health information and clinical systems security.
ISO · Global · Voluntary
AI Governance
ISO 42001:2023
The world’s first certifiable AI management system standard — aligned with the EU AI Act.
ISO · Global · Voluntary
Finance
NYDFS 23 NYCRR 500
Mandatory cybersecurity regulation for DFS-licensed financial entities — amended and strengthened in 2023.
NYDFS · USA · Mandatory
Government
Qatar NIA Policy
National information assurance framework for Qatar government entities and critical infrastructure operators.
MOTC · Qatar · Mandatory
Finance
SAMA Cyber Security Framework
Mandatory cybersecurity framework for all SAMA-regulated financial institutions in Saudi Arabia.
SAMA · Saudi Arabia · Mandatory
Finance
SEBI CSCRF
Mandatory cybersecurity framework for India’s capital markets — brokers, AMCs, exchanges and depositories.
SEBI · India · Mandatory
IT Governance
SOC 1
AICPA audit standard for internal controls over financial reporting — required by payroll processors and financial data centres.
AICPA · USA · Voluntary
Government
UAE Information Assurance
National information security framework for UAE federal government entities — aligned with ISO 27001 and NIST.
TDRA · UAE · Mandatory
IT Governance
ITIL 4
World’s most widely adopted IT service management framework — 34 practices across the Service Value System.
AXELOS · Global · Voluntary
Finance
DORA
EU regulation for digital operational resilience in the financial sector — in force January 2025.
EU · European Union · Mandatory
Government
NIS2 Directive
EU cybersecurity directive covering 18 critical sectors — personal management liability, effective October 2024.
EU · European Union · Mandatory
Showing 26 of 40+ frameworks — more to be added soon.
Securitora curates this library based on global relevance, regulatory reach, and practitioner demand. We prioritise frameworks that are actively enforced or widely adopted across major economies — with particular depth in financial services, healthcare, and technology sectors, where compliance requirements are most rigorous. Broadly applicable standards such as ISO, NIST, and CIS are included because they cross borders and serve organizations of every size.
Securitora reviews this library on a regular basis — adding new frameworks, reflecting version updates, and retiring content that is no longer current.