Frameworks
Every framework you need, growing every month
Mandates from India, the Middle East, Asia-Pacific, the UK, Europe and the Americas sit beside the global standards, each modelled control by control. Library frameworks adopt in a day and crosswalk to your existing programme instantly; anything we do not ship, you author with the same tooling.
India regulatory
India regulatory
SEBI CSCRF
SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) is the binding cybersecurity mandate for SEBI-regulated entities. It specifies a control set across governance, identification, protection, detection, response and recovery, an audit cadence, and a 6-hour window for reporting cyber incidents.
RBI Cyber Security Framework
RBI's Cyber Security Framework sets baseline cyber security controls, governance duties and incident reporting expectations for banks and regulated NBFCs, with board-level oversight and periodic review.
RBI IT Governance Master Direction
RBI's Master Direction on IT Governance, Risk, Controls and Assurance Practices consolidates the central bank's expectations for IT governance structures, strategy, risk management, outsourcing and audit in regulated entities.
DPDP Act
The Digital Personal Data Protection Act is India's comprehensive personal data law. It obliges data fiduciaries to lawful processing on consent or legitimate use, notice, data principal rights, security safeguards, breach notification and governance of data processors.
IRDAI Cyber Guidelines
IRDAI's Information and Cyber Security Guidelines bind insurers to a defined control set, policy governance duties, incident reporting timelines and periodic assurance, examined by the regulator.
CERT-In Directions
CERT-In's cyber security directions set binding obligations for reporting specified cyber incidents within six hours of noticing them, retaining ICT logs for a rolling 180 days within the country, synchronising system clocks to national time sources, and maintaining a designated point of contact.
RBI Digital Payment Security Controls
The RBI Master Direction on Digital Payment Security Controls sets requirements for the governance and security of internet banking, mobile banking and card payment channels.
Middle East
Middle East
SAMA Cyber Security Framework
The Saudi Central Bank's Cyber Security Framework sets mandatory cyber security requirements for financial institutions it supervises, organised by domain and assessed against defined maturity levels rather than a simple pass or fail.
NCA Essential Cybersecurity Controls
The National Cybersecurity Authority's Essential Cybersecurity Controls define the minimum cybersecurity requirements for national organisations in Saudi Arabia, structured into domains, subdomains and controls, with periodic compliance assessment.
Qatar National Information Assurance
Qatar's National Information Assurance framework sets the information security requirements for national organisations, driven by data classification and risk, with a defined control set and assurance reporting.
UAE Personal Data Protection Law
The UAE's federal personal data protection law governs the processing of personal data, setting obligations for lawful basis, transparency, data-subject rights, security, cross-border transfer and breach notification, alongside free-zone regimes with their own regulations.
UAE IA / NESA
The UAE Information Assurance Regulation, formerly the NESA standards, defines the control set for protecting critical information infrastructure in the UAE, tiered by criticality.
Asia-Pacific
Asia-Pacific
MAS TRM
The Monetary Authority of Singapore's Technology Risk Management Guidelines set expectations for technology risk governance, system resilience and cyber security in financial institutions.
APRA CPS 234
APRA Prudential Standard CPS 234 requires regulated entities in Australia to maintain information security capability commensurate with threats and to notify APRA of material incidents.
Singapore PDPA
Singapore's Personal Data Protection Act governs the collection, use and disclosure of personal data, including a mandatory data breach notification regime and accountability obligations.
UK & Europe
UK & Europe
UK GDPR & Data Protection Act
The UK General Data Protection Regulation, read with the Data Protection Act 2018, governs the processing of personal data in the UK: lawful basis, accountability, data-subject rights, international transfers and breach notification to the supervisory authority within 72 hours.
Cyber Essentials
Cyber Essentials is the UK government-backed baseline cyber scheme covering five technical control themes, with an annual assessment cycle. Cyber Essentials Plus adds independent technical verification of the same controls.
NCSC Cyber Assessment Framework
The UK's Cyber Assessment Framework sets out cyber security outcomes across four objectives, each assessed against indicators of good practice rather than a binary control checklist. It underpins oversight of essential services and is widely adopted for critical functions.
UK Operational Resilience
The UK operational resilience regime requires regulated financial firms to identify important business services, set impact tolerances for each, map the people, processes, technology and third parties supporting them, and test against severe but plausible scenarios.
EU Digital Operational Resilience
The Digital Operational Resilience Act sets uniform requirements for the security of network and information systems in the EU financial sector: ICT risk management, incident classification and reporting, digital operational resilience testing, ICT third-party risk management and a register of information.
EU GDPR
The General Data Protection Regulation governs the processing of personal data of people in the European Union, with duties for controllers and processors and supervisory authority enforcement.
EU NIS2
The NIS2 Directive raises cybersecurity requirements across essential and important entities in the European Union, with management accountability and staged incident reporting.
EU AI Act
The EU Artificial Intelligence Act regulates AI systems by risk class, imposing obligations on providers and deployers of high-risk systems along with transparency duties.
TISAX
TISAX is the automotive industry's information security assessment and exchange mechanism, based on the VDA ISA catalogue and assessed at defined levels.
Americas
Americas
SOX ITGC
Sarbanes-Oxley IT general controls support financial reporting assurance, covering access to programs and data, change management, and computer operations.
CCPA / CPRA
The California Consumer Privacy Act as amended by the CPRA gives California residents rights over their personal information and imposes duties on qualifying businesses.
Global standards
Global standards
ISO 27001:2022
ISO 27001:2022 is the international standard for information security management systems. It defines an Annex A control set across organisational, people, physical and technological themes, operated as a continuous management system with internal audit and certification.
SOC 2
SOC 2 is the AICPA's attestation framework for service organisations, reporting against the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy.
PCI DSS
The Payment Card Industry Data Security Standard is the card brands' security mandate for any entity that stores, processes or transmits cardholder data, organised into twelve requirement groups.
NIST SP 800-53
NIST Special Publication 800-53 is the US federal catalogue of security and privacy controls, organised into families with baselines selected by system impact level.
ISO 22301
ISO 22301 is the international standard for business continuity management systems, covering continuity strategy, plans, exercises and continual improvement.
HIPAA
The Health Insurance Portability and Accountability Act sets US requirements for protecting health information, through the Security Rule's administrative, physical and technical safeguards, the Privacy Rule and the Breach Notification Rule.
NIST CSF 2.0
The NIST Cybersecurity Framework 2.0 organises cybersecurity outcomes across six functions: Govern, Identify, Protect, Detect, Respond and Recover, expressed through profiles and implementation tiers.
ISO 27701
ISO/IEC 27701 extends ISO 27001 and ISO 27002 into a privacy information management system, defining requirements for controllers and processors of personally identifiable information.
ISO 42001
ISO/IEC 42001 specifies requirements for an artificial intelligence management system, covering AI policy, risk and impact assessment, lifecycle controls and human oversight.
CIS Controls v8
The CIS Critical Security Controls v8 define a prioritised set of safeguards grouped into implementation groups, widely used as a practical technical baseline.
HITRUST CSF
The HITRUST CSF is a certifiable control framework that harmonises ISO, NIST, HIPAA and PCI requirements, assessed through a maturity scoring model.
Sector & GxP
Sector & GxP
21 CFR Part 11
21 CFR Part 11 is the US FDA's rule for electronic records and electronic signatures, defining the controls under which electronic records are considered trustworthy and equivalent to paper.
EU GMP Annex 11
Annex 11 of the EU Good Manufacturing Practice guidelines sets expectations for computerised systems used in regulated manufacturing, covering validation, data integrity and supplier management.
