MASTER
COMPLIANCE
With 33+ global compliances and comprehensive Compliance support, we enable our customers to operate with greater confidence in a complex threat landscape.
System and Organization Controls 2 (SOC 2)
- SaaS
- Global
Trust and security framework for service organizations
SOC 2 provides a framework for evaluating how service organizations protect customer data and operate effective controls across security, availability, processing integrity, confidentiality, and privacy. It helps organizations demonstrate that their systems and processes are designed and operated with appropriate safeguards.
HIPAA Compliance Framework
- Healthcare
- North America
U.S. healthcare data protection framework
HIPAA establishes requirements for protecting protected health information (PHI) and maintaining the security and privacy of healthcare data. It focuses on safeguards for access control, data protection, audit controls, security management, and protection against unauthorized disclosure or access.
CSA Cloud Controls Matrix (CCM) v4.0.13
- General
- Global
Cloud security control framework
The CSA Cloud Controls Matrix (CCM) provides a structured set of cloud-specific security controls for assessing and managing security risks across cloud environments. Version 4.0.13 covers areas including governance, risk management, identity and access management, data security, application security, infrastructure security, and operational resilience.
ISO/IEC 27001 Information Security Management Standard 2022
- General
- Global
International standard for information security management
ISO/IEC 27001:2022 defines requirements for establishing, maintaining, and continually improving an Information Security Management System (ISMS). It uses a risk-based approach to protect information assets through organizational, people, physical, and technological security controls.
FedRAMP 20x Key Security Indicators (KSIs) – Low Impact Level v25.05C
- General
- North America
Modernized U.S. federal cloud security assessment
FedRAMP 20x introduces a more automated and evidence-driven approach to assessing cloud service security. The Low Impact Level KSIs provide measurable security indicators for evaluating areas such as access control, asset management, vulnerability management, logging, incident response, and continuous monitoring.
Cloud Computing Compliance Criteria Catalogue (C5) 2025
- General
- Germany
German cloud security and compliance framework
The C5 framework, developed by Germany’s Federal Office for Information Security (BSI), defines security requirements for cloud service providers and helps organizations assess the security of cloud services. It covers areas including information security, access control, operations, data protection, and organizational security.
NIS2 – Network and Information Security Directive
- General
- Europe
EU cybersecurity and resilience directive
NIS2 establishes cybersecurity risk-management and incident-reporting requirements for organizations operating in critical and important sectors across the European Union. It strengthens requirements around risk management, supply-chain security, access control, incident handling, business continuity, and security governance.
MITRE ATT&CK Compliance Framework
- General
- Global
Threat-informed cybersecurity knowledge base
MITRE ATT&CK is a globally used knowledge base that maps real-world adversary tactics and techniques observed across cyber attacks. It helps organizations evaluate security capabilities against threats such as credential access, privilege escalation, persistence, lateral movement, discovery, and data exfiltration.
Payment Card Industry Data Security Standard (PCI DSS) v4.0
- General
- Global
Global standard for payment card data security
PCI DSS v4.0 defines security requirements for organizations that store, process, or transmit payment card data. It strengthens protection through requirements covering access control, secure configurations, vulnerability management, encryption, logging, monitoring, authentication, and regular security testing.
Reserve Bank of India (RBI) Cyber Security Framework
- Financial Services
- India
Indian cybersecurity framework for financial institutions
The RBI Cyber Security Framework establishes security and governance requirements for banks and regulated financial entities in India. It emphasizes cyber-risk management, access controls, vulnerability management, security monitoring, incident response, data protection, and resilience against cyber threats.
Digital Operational Resilience Act (DORA)
- Financial Services
- Europe
EU framework for financial-sector digital resilience
DORA establishes requirements for managing information and communication technology (ICT) risks across the European financial sector. It focuses on ICT risk management, resilience testing, incident reporting, third-party risk, and continuous monitoring of critical technology services.
ASD Essential Eight Maturity Model – Maturity Level One (AWS)
- General
- Australia
Foundational Australian cybersecurity baseline
Developed by the Australian Signals Directorate (ASD), the Essential Eight provides foundational security practices to mitigate common cyber threats. Maturity Level One focuses on application control, patching, secure configuration, restricted administrative privileges, and multi-factor authentication.
AWS Account Security Onboarding
- General
- Global
AWS AI Security Framework 1
- AI/ML Companies
- Global
AWS Audit Manager Control Tower Guardrails
- General
- Global
AWS governance and compliance controls
AWS Control Tower guardrails establish preventive and detective controls for governing AWS environments, while AWS Audit Manager helps collect evidence against defined requirements. Together, they provide a structured approach to enforcing account-level governance, security configurations, and ongoing compliance across AWS workloads.
AWS Foundational Security Best Practices
- General
- Global
AWS security baseline for foundational protection
A set of AWS-recommended security controls designed to identify and reduce common security risks across AWS accounts and workloads. It focuses on establishing secure configurations across identity, permissions, logging, monitoring, network controls, and data protection.
AWS Foundational Technical Review
- General
- Global
AWS architecture and operational readiness assessment
The AWS Foundational Technical Review (FTR) evaluates solutions against key AWS best practices to identify security, reliability, operational, and architectural risks. It helps organizations establish a stronger technical foundation for running and scaling workloads on AWS.
AWS Well-Architected Framework – Reliability Pillar
- Industry
- Global
Building resilient and recoverable AWS workloads
The Reliability Pillar focuses on designing AWS workloads that can withstand failures, recover quickly, and continue operating as demand changes. It covers resilient architecture, automated recovery, change management, monitoring, backup and disaster recovery, and capacity management.
AWS Well-Architected Framework – Security Pillar
- General
- Global
Protecting AWS workloads through security-focused architecture
The Security Pillar provides guidance for protecting AWS workloads, systems, and data throughout their lifecycle. It focuses on identity and access management, detection, infrastructure protection, data security, incident response, and maintaining secure operations.
CIS Amazon Web Services Foundations Benchmark
- General
- Global
- v 1.4.0
- v 1.4.0
- v 1.4.0
- v 1.4.0
- v 1.4.0
- v 1.4.0
- v 1.4.0
AWS security configuration benchmark
The CIS AWS Foundations Benchmark provides prescriptive recommendations for securely configuring AWS accounts and core services. It helps organizations identify configuration weaknesses across areas such as IAM, logging, monitoring, networking, and security settings.
CISA Cyber Essentials Framework
- General
- North America
Foundational cybersecurity practices for organizations
CISA Cyber Essentials provides a practical starting point for organizations to strengthen their cybersecurity and protect critical systems, data, and services. It emphasizes foundational practices such as asset management, identity and access control, secure configuration, vulnerability management, and incident preparedness.
FedRAMP Low Revision 4
- General
- North America
U.S. federal cloud security baseline
FedRAMP Low Revision 4 defines security controls and assessment requirements for cloud services handling federal information at the Low impact level. It establishes a baseline for protecting the confidentiality, integrity, and availability of federal data in cloud environments.
FedRAMP Moderate Revision 4
- General
- North America
U.S. federal cloud security baseline
FedRAMP Moderate Revision 4 defines a comprehensive set of security controls for cloud services handling federal information with moderate impact. It provides stronger security and assessment requirements for protecting sensitive federal data and supporting secure cloud operations.
FFIEC Cybersecurity Assessment Tool Framework
- Financial Services
- North America
Cybersecurity assessment framework for financial institutions
The FFIEC Cybersecurity Assessment Tool helps financial institutions evaluate their cybersecurity preparedness against inherent risks and identify areas requiring stronger controls. It supports structured assessment of cybersecurity maturity across governance, threat intelligence, resilience, risk management, and security practices.
GDPR Compliance Framework
- General
- Europe
European data protection and privacy framework
The General Data Protection Regulation (GDPR) establishes requirements for protecting personal data and privacy of individuals in the European Union. It emphasizes data protection, privacy by design, access controls, breach management, data retention, and accountability throughout the handling of personal information.
GxP (Good Practices) 21 CFR Part 11
- Healthcare
- North America
U.S. requirements for electronic records and signatures
21 CFR Part 11 establishes requirements for electronic records and electronic signatures used in FDA-regulated industries. It focuses on ensuring records are trustworthy, reliable, traceable, and protected through controls such as access management, audit trails, validation, and data integrity.
GxP (Good Practices) EU Annex 11
- Healthcare
- Europe
European requirements for computerized systems
EU GMP Annex 11 defines requirements for computerized systems used in regulated pharmaceutical and life-sciences environments. It emphasizes data integrity, system validation, access control, audit trails, security, and controlled management of electronic records.
ISO/IEC 27001 Information Security Management Standard 2013
- General
- Global
International information security management standard
ISO/IEC 27001:2013 provides requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It takes a risk-based approach to protecting information assets through security controls covering access, operations, asset management, communications, and business continuity.
KISA ISMS Compliance Framework 2023
- General
- South Korea
South Korean information security management framework
The KISA Information Security Management System (ISMS) framework provides requirements for organizations to establish and operate systematic information security management practices in South Korea. It covers areas such as security governance, access control, asset management, risk management, incident response, and continuous security management.
NIST Security and Privacy Controls
- General
- North America
- 800-171 Rev. 2
- 800-53 Rev. 4
- 800-53 Rev. 5
NIST security control framework for protecting information systems
NIST security control publications provide structured requirements for protecting sensitive information and information systems through risk-based security and privacy practices. They address areas including access control, system security, incident response, configuration management, system integrity, and continuous monitoring.
NIST Cybersecurity Framework (CSF)
- General
- North America
Risk-based cybersecurity framework
The NIST Cybersecurity Framework provides a flexible, risk-based approach for organizations to manage and strengthen cybersecurity. It helps organizations identify and prioritize cybersecurity risks across governance, protection, detection, response, and recovery activities.
Payment Card Industry Data Security Standard (PCI DSS) v3.2.1
- Financial Services
- Global
Global standard for payment card data security
PCI DSS v3.2.1 establishes security requirements for organizations that store, process, or transmit payment card data. It focuses on protecting cardholder data through secure configurations, access controls, vulnerability management, monitoring, encryption, and regular security testing.
SecNumCloud Référentiel d'Exigences v3.2
- General
- France
French cloud security qualification framework
Developed by France’s National Cybersecurity Agency (ANSSI), SecNumCloud defines stringent security requirements for trusted cloud service providers handling sensitive information. Version 3.2 covers technical, operational, organizational, and legal security requirements for cloud services.
CIS Microsoft Azure Foundations Benchmark
- General
- Global
- v2.0.0
- v2.1.0
- v3.0.0
- v4.0.0
- v5.0.0
- v6.0.0
Azure security configuration benchmark
The CIS Microsoft Azure Foundations Benchmark provides prescriptive recommendations for securely configuring Azure environments and reducing common security risks. It focuses on foundational controls across identity and access management, logging, monitoring, networking, and secure Azure service configuration.
CIS Google Cloud Platform Foundation Benchmark
- General
- Global
- v3.0.0
- v4.0.0
- v5.0.0
Google Cloud security configuration benchmark
The CIS Google Cloud Platform Foundation Benchmark provides prescriptive recommendations for securely configuring GCP environments and reducing common security risks. It focuses on foundational controls across identity and access management, logging, monitoring, networking, and secure configuration of Google Cloud services.
ENS RD 311/2022 – Categoría Alta
- General
- Spain
Spanish national security framework for information systems
The Spanish National Security Framework (ENS), established under Royal Decree 311/2022, defines security principles and requirements for protecting information systems used by public-sector organizations and service providers. The High category applies to systems where a security incident could have significant consequences for the organization or the services it provides.
Common Cloud Controls Catalog (CCC) v2025.10
- General
- Global
Standardized cloud security control framework
The Common Cloud Controls Catalog (CCC) provides a common set of cloud security controls designed to create consistency across cloud security assessments. It helps organizations evaluate cloud environments against controls covering areas such as identity, data security, infrastructure protection, monitoring, and governance.
CIS Controls v8.1
- General
- Global
Prioritized cybersecurity safeguards
The CIS Controls provide a prioritized set of cybersecurity safeguards designed to help organizations defend against common and evolving cyber threats. Version 8.1 organizes these safeguards around areas such as asset management, secure configuration, account management, vulnerability management, audit logging, and incident response.
