Security Frameworks & Compliance Standards

Browse 20+ security frameworks and compliance standards — filter by industry, purpose, geography or audience.

Understanding the landscape

Why Frameworks & Standards Matter

In today’s complex threat landscape, organizations cannot rely on intuition alone to manage risk. Frameworks and standards provide structured, proven approaches to identifying vulnerabilities, implementing controls, and demonstrating accountability — to regulators, customers, and stakeholders alike. Whether you’re securing patient data, protecting financial systems, or building cloud infrastructure, there is a framework designed to guide you.

Not all frameworks carry the same weight. Some are legal obligations — non-compliance means fines, penalties, or loss of operating licenses. Others are voluntary best practices that signal maturity and build trust.

⚖️ Mandatory

Required by law or regulation

  • GDPR — EU data protection law
  • HIPAA — US healthcare data compliance
  • PCI DSS — Payment card industry requirement
  • NYDFS — NY financial services regulation
  • SAMA CSF — Saudi financial sector mandate
  • SOX — US public company financial reporting law
Voluntary

Adopted by choice to demonstrate maturity

  • ISO 27001 — Global security best practice
  • NIST CSF — Flexible risk management guide
  • CIS Controls — Prioritized security actions
  • SOC 2 — Trust-based assurance standard
  • NIST SP 800-53 — Federal security controls catalog
  • COBIT 2019 — IT governance & management

Use the library below to explore, compare, and understand the frameworks most relevant to your industry, role, and regulatory environment.

Filter by Industry

Filter by Industry

Filter by Purpose

Risk Management

NIST Cybersecurity Framework 2.0

The go-to framework for managing cybersecurity risk across all organisation types — updated in 2024 with a new Govern function.

NIST · USA · Voluntary

Compliance

ISO 27001:2022

International standard for information security management systems. Certifiable, globally recognised and widely adopted.

ISO · Global · Voluntary

Privacy

GDPR

The EU’s comprehensive data protection regulation — mandatory for any organisation handling EU resident data.

EU · European Union · Mandatory

Compliance

PCI DSS v4.0

Payment Card Industry Data Security Standard — required for all organisations that handle cardholder data.

PCI SSC · Global · Mandatory

Healthcare

HIPAA

US federal law protecting sensitive patient health information. Applies to covered entities and business associates.

HHS · USA · Mandatory

Cloud Security

SOC 2 Type II

Trust Services Criteria audit for service organisations — the standard for demonstrating security to enterprise customers.

AICPA · USA · Voluntary

Government

NIST SP 800-53 Rev 5

Comprehensive security and privacy controls catalogue for US federal systems — the most detailed controls framework available.

NIST · USA · Mandatory

IT Governance

COBIT 2019

Leading framework for IT governance and management — bridges business requirements, technical issues and control risks.

ISACA · Global · Voluntary

Privacy

CCPA / CPRA

California’s comprehensive consumer privacy law giving residents rights over their personal data — strengthened by CPRA in 2023.

California · USA · Mandatory

Cloud Security

CSA Cloud Controls Matrix v4

197 cloud-specific security controls across 17 domains — the definitive framework for cloud security assurance.

CSA · Global · Voluntary

Compliance

SOX — Sarbanes-Oxley Act

US federal law requiring strict financial reporting and internal controls for publicly traded companies.

SEC · USA · Mandatory

Risk Management

COSO Internal Control Framework

The primary framework for designing and evaluating internal controls — foundation of SOX Section 404 compliance.

COSO · Global · Voluntary

Risk Management

CIS Controls v8

18 prioritised cybersecurity actions organised into implementation groups — the most practical starting point for any organisation.

CIS · Global · Voluntary

Healthcare

HITRUST CSF

Certifiable framework integrating HIPAA, NIST, ISO 27001 and PCI DSS — the de facto standard for US healthcare vendors.

HITRUST · USA · Voluntary

Compliance

ISO 27002:2022

Implementation guidance for ISO 27001 Annex A controls — the how to ISO 27001’s what.

ISO · Global · Voluntary

Healthcare

ISO 27799

Healthcare-specific guidance for implementing ISO 27002 controls — covers personal health information and clinical systems security.

ISO · Global · Voluntary

AI Governance

ISO 42001:2023

The world’s first certifiable AI management system standard — aligned with the EU AI Act.

ISO · Global · Voluntary

Finance

NYDFS 23 NYCRR 500

Mandatory cybersecurity regulation for DFS-licensed financial entities — amended and strengthened in 2023.

NYDFS · USA · Mandatory

Government

Qatar NIA Policy

National information assurance framework for Qatar government entities and critical infrastructure operators.

MOTC · Qatar · Mandatory

Finance

SAMA Cyber Security Framework

Mandatory cybersecurity framework for all SAMA-regulated financial institutions in Saudi Arabia.

SAMA · Saudi Arabia · Mandatory

Finance

SEBI CSCRF

Mandatory cybersecurity framework for India’s capital markets — brokers, AMCs, exchanges and depositories.

SEBI · India · Mandatory

IT Governance

SOC 1

AICPA audit standard for internal controls over financial reporting — required by payroll processors and financial data centres.

AICPA · USA · Voluntary

Government

UAE Information Assurance

National information security framework for UAE federal government entities — aligned with ISO 27001 and NIST.

TDRA · UAE · Mandatory

IT Governance

ITIL 4

World’s most widely adopted IT service management framework — 34 practices across the Service Value System.

AXELOS · Global · Voluntary

Finance

DORA

EU regulation for digital operational resilience in the financial sector — in force January 2025.

EU · European Union · Mandatory

Government

NIS2 Directive

EU cybersecurity directive covering 18 critical sectors — personal management liability, effective October 2024.

EU · European Union · Mandatory

Showing 26 of 40+ frameworks — more to be added soon.

Securitora curates this library based on global relevance, regulatory reach, and practitioner demand. We prioritise frameworks that are actively enforced or widely adopted across major economies — with particular depth in financial services, healthcare, and technology sectors, where compliance requirements are most rigorous. Broadly applicable standards such as ISO, NIST, and CIS are included because they cross borders and serve organizations of every size.

Securitora reviews this library on a regular basis — adding new frameworks, reflecting version updates, and retiring content that is no longer current.