Knowledge Base

Compliance Framework Encyclopedia

Comprehensive, free reference for every compliance framework. Understand requirements, controls, and implementation guidance.

Data Privacy
EU

GDPR

General Data Protection Regulation

EU regulation on data protection and privacy for individuals within the European Union and European Economic Area.

99 Articles
173 Recitals
Data Subject Rights Consent Data Transfers DPO
View Full Guide
Healthcare
US

HIPAA

Health Insurance Portability and Accountability Act

US law providing data privacy and security provisions for safeguarding medical information.

5 Rules
18 Identifiers
PHI Protection Security Rule Privacy Rule BAA
View Full Guide
Security
Global

SOC 2

Service Organization Control 2

Auditing procedure ensuring service providers securely manage data to protect interests and privacy of clients.

5 Trust Principles
64 Controls
Security Availability Processing Integrity Confidentiality
View Full Guide
Security
Global

ISO 27001

Information Security Management System

International standard for managing information security with a systematic approach to managing sensitive information.

14 Domains
114 Controls
Risk Assessment Asset Management Access Control ISMS
View Full Guide
Payment
Global

PCI DSS

Payment Card Industry Data Security Standard

Security standard for organizations handling branded credit cards from major card schemes.

12 Requirements
281 Sub-requirements
Cardholder Data Network Security Encryption Monitoring
View Full Guide
Government
US

NIST CSF

NIST Cybersecurity Framework

Framework for improving critical infrastructure cybersecurity with guidelines and best practices.

5 Functions
23 Categories
Identify Protect Detect Respond
View Full Guide
Data Privacy
US - California

CCPA/CPRA

California Consumer Privacy Act

State statute enhancing privacy rights and consumer protection for California residents.

7 Rights
$7.5K Max Fine/Violation
Consumer Rights Opt-Out Data Sale Privacy Notice
View Full Guide
Financial
US

SOX

Sarbanes-Oxley Act

Federal law setting standards for public company boards, management, and accounting firms.

11 Titles
302 Key Section
Internal Controls Financial Reporting Audit Section 404
View Full Guide
Government
US

FedRAMP

Federal Risk and Authorization Management Program

Government-wide program for security assessment and authorization of cloud products.

3 Impact Levels
325+ Controls
Cloud Security ATO Continuous Monitoring 3PAO
View Full Guide
Defense
US

CMMC

Cybersecurity Maturity Model Certification

DoD certification for defense contractors to protect controlled unclassified information.

3 Levels
171 Practices (L3)
CUI Protection Maturity Assessment DFARS
View Full Guide
Security
Global

CIS Controls

Center for Internet Security Controls

Prioritized set of actions to protect organizations from known cyber attack vectors.

18 Controls
153 Safeguards
Asset Inventory Secure Configuration Vulnerability Mgmt Access Control
View Full Guide
Financial
EU

DORA

Digital Operational Resilience Act

EU regulation on digital operational resilience for the financial sector.

5 Pillars
2025 Effective
ICT Risk Incident Reporting Third Party Testing
View Full Guide

Framework Comparison Tool

Compare requirements and controls across different frameworks.

VS