Frameworks

Every framework you need, growing every month

Mandates from India, the Middle East, Asia-Pacific, the UK, Europe and the Americas sit beside the global standards, each modelled control by control. Library frameworks adopt in a day and crosswalk to your existing programme instantly; anything we do not ship, you author with the same tooling.

India regulatory

India regulatory

SEBI CSCRF

SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) is the binding cybersecurity mandate for SEBI-regulated entities. It specifies a control set across governance, identification, protection, detection, response and recovery, an audit cadence, and a 6-hour window for reporting cyber incidents.

RBI Cyber Security Framework

RBI's Cyber Security Framework sets baseline cyber security controls, governance duties and incident reporting expectations for banks and regulated NBFCs, with board-level oversight and periodic review.

RBI IT Governance Master Direction

RBI's Master Direction on IT Governance, Risk, Controls and Assurance Practices consolidates the central bank's expectations for IT governance structures, strategy, risk management, outsourcing and audit in regulated entities.

DPDP Act

The Digital Personal Data Protection Act is India's comprehensive personal data law. It obliges data fiduciaries to lawful processing on consent or legitimate use, notice, data principal rights, security safeguards, breach notification and governance of data processors.

IRDAI Cyber Guidelines

IRDAI's Information and Cyber Security Guidelines bind insurers to a defined control set, policy governance duties, incident reporting timelines and periodic assurance, examined by the regulator.

CERT-In Directions

CERT-In's cyber security directions set binding obligations for reporting specified cyber incidents within six hours of noticing them, retaining ICT logs for a rolling 180 days within the country, synchronising system clocks to national time sources, and maintaining a designated point of contact.

RBI Digital Payment Security Controls

The RBI Master Direction on Digital Payment Security Controls sets requirements for the governance and security of internet banking, mobile banking and card payment channels.

UK & Europe

UK & Europe

UK GDPR & Data Protection Act

The UK General Data Protection Regulation, read with the Data Protection Act 2018, governs the processing of personal data in the UK: lawful basis, accountability, data-subject rights, international transfers and breach notification to the supervisory authority within 72 hours.

Cyber Essentials

Cyber Essentials is the UK government-backed baseline cyber scheme covering five technical control themes, with an annual assessment cycle. Cyber Essentials Plus adds independent technical verification of the same controls.

NCSC Cyber Assessment Framework

The UK's Cyber Assessment Framework sets out cyber security outcomes across four objectives, each assessed against indicators of good practice rather than a binary control checklist. It underpins oversight of essential services and is widely adopted for critical functions.

UK Operational Resilience

The UK operational resilience regime requires regulated financial firms to identify important business services, set impact tolerances for each, map the people, processes, technology and third parties supporting them, and test against severe but plausible scenarios.

EU Digital Operational Resilience

The Digital Operational Resilience Act sets uniform requirements for the security of network and information systems in the EU financial sector: ICT risk management, incident classification and reporting, digital operational resilience testing, ICT third-party risk management and a register of information.

EU GDPR

The General Data Protection Regulation governs the processing of personal data of people in the European Union, with duties for controllers and processors and supervisory authority enforcement.

EU NIS2

The NIS2 Directive raises cybersecurity requirements across essential and important entities in the European Union, with management accountability and staged incident reporting.

EU AI Act

The EU Artificial Intelligence Act regulates AI systems by risk class, imposing obligations on providers and deployers of high-risk systems along with transparency duties.

TISAX

TISAX is the automotive industry's information security assessment and exchange mechanism, based on the VDA ISA catalogue and assessed at defined levels.

Global standards

Global standards

ISO 27001:2022

ISO 27001:2022 is the international standard for information security management systems. It defines an Annex A control set across organisational, people, physical and technological themes, operated as a continuous management system with internal audit and certification.

SOC 2

SOC 2 is the AICPA's attestation framework for service organisations, reporting against the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy.

PCI DSS

The Payment Card Industry Data Security Standard is the card brands' security mandate for any entity that stores, processes or transmits cardholder data, organised into twelve requirement groups.

NIST SP 800-53

NIST Special Publication 800-53 is the US federal catalogue of security and privacy controls, organised into families with baselines selected by system impact level.

ISO 22301

ISO 22301 is the international standard for business continuity management systems, covering continuity strategy, plans, exercises and continual improvement.

HIPAA

The Health Insurance Portability and Accountability Act sets US requirements for protecting health information, through the Security Rule's administrative, physical and technical safeguards, the Privacy Rule and the Breach Notification Rule.

NIST CSF 2.0

The NIST Cybersecurity Framework 2.0 organises cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond and Recover, expressed through profiles and implementation tiers.

ISO 27701

ISO/IEC 27701 extends ISO 27001 and ISO 27002 into a privacy information management system, defining requirements for controllers and processors of personally identifiable information.

ISO 42001

ISO/IEC 42001 specifies requirements for an artificial intelligence management system, covering AI policy, risk and impact assessment, lifecycle controls and human oversight.

CIS Controls v8

The CIS Critical Security Controls v8 define a prioritised set of safeguards grouped into implementation groups, widely used as a practical technical baseline.

HITRUST CSF

The HITRUST CSF is a certifiable control framework that harmonises ISO, NIST, HIPAA and PCI requirements, assessed through a maturity scoring model.

You're done. We're not.

The audit ends. The readiness doesn't. See it on your own data.