What each framework actually requires, who it applies to, and why it exists — before you ever start mapping a single control.
The AICPA standard most SaaS companies are asked for in the US.
The international standard for an Information Security Management System.
A common-language risk framework, not a pass/fail certification.
The detailed control catalog behind FedRAMP and US federal systems.
A prioritized, practical 18-control list from the Center for Internet Security.
The EU's data protection regulation, with extraterritorial reach.
California's consumer privacy law, expanded by the CPRA.
The privacy extension to ISO 27001, mapped to GDPR.
The US law protecting health information, enforced by HHS.
A certifiable framework that harmonizes HIPAA, NIST, ISO, and more.
The mandatory standard for handling payment card data.
The standardized security authorization for cloud services sold to US agencies.
The shared assessment standard for the automotive supply chain.
The EU's digital resilience regulation for financial services.
A UK government-backed baseline for basic cyber hygiene.
The first international management-system standard for AI.
A voluntary framework for managing risk across the AI lifecycle.
The world's first comprehensive AI regulation, risk-tiered by use case.
Environmental, social, and governance disclosure, increasingly mandatory.