Framework Deepdive

ISO/IEC 27001:2022
The international information security management system standard.
ISO/IEC 27701
Privacy Information Management System extension to ISO 27001.
ISO/IEC 42001:2023
First international AI management system standard.
SOC 2
Trust Services Criteria attestation for service organizations.
SOC 1
Financial reporting controls report for service organizations.
PCI DSS
Payment Card Industry Data Security Standard.
GDPR
EU general data protection regulation and accountability framework.
HIPAA
US health information privacy and security rules.
EU AI Act
First horizontal AI regulation under EU Regulation 2024/1689.
FedRAMP
Authorization for cloud services to US federal agencies.
CMMC / NIST SP 800-171
DoD cybersecurity certification for the Defense Industrial Base.
BSI C5
German federal cloud assurance criteria catalogue.
DORA
EU Digital Operational Resilience Act for ICT third-party providers to financial entities.
NIS 2
EU cybersecurity directive with explicit supply-chain security obligations.