Knowledge centre
Standards and framework document library.
Every standard our assessors work against, 122 of them, each with the practitioner view rather than a restatement of the text. What it is, who it binds, what an assessor actually looks for, and how to get ready.
Security frameworks33
The control catalogues and models an assessment is run against. Pick the one your customers or your regulator names, not the one with the most controls.
- NIST Cybersecurity Framework (CSF 2.0)NIST · GLOBALA voluntary, outcome-based framework for managing and reducing cybersecurity risk.Read the guide
- NIST SP 800-53NIST · GLOBALA comprehensive catalog of security and privacy controls for information systems.Read the guide
- COBITISACA · GLOBALA governance and management framework for enterprise information and technology.Read the guide
- CIS ControlsCENTER FOR INTERNET SECURITY · GLOBALA prioritised set of 18 safeguards that stop the most common attacks.Read the guide
- MITRE ATT&CKMITRE · GLOBALA knowledge base of real-world adversary tactics and techniques.Read the guide
- SANS / CWE Top 25MITRE / SANS · GLOBALThe most dangerous and common software weaknesses developers must avoid.Read the guide
- OWASP Top 10OWASP · GLOBALThe standard awareness document for the most critical web application risks.Read the guide
- SABSA (Security Architecture)THE SABSA INSTITUTE · GLOBALA business-driven framework and methodology for enterprise security architecture.Read the guide
- CSA CCM & STARCLOUD SECURITY ALLIANCE · GLOBALThe Cloud Controls Matrix and STAR programme for cloud security assurance.Read the guide
- TOGAFTHE OPEN GROUP · GLOBALThe leading enterprise architecture framework and method (ADM).Read the guide
- NIST SP 800-171NIST · GLOBAL / USProtecting Controlled Unclassified Information (CUI) in non-federal systems.Read the guide
- IEC 62443 (OT/ICS Security)IEC / ISA · GLOBALThe standard for cybersecurity of industrial automation and control systems.Read the guide
- Zero Trust (NIST SP 800-207)NIST · GLOBALA security model of "never trust, always verify" for modern architectures.Read the guide
- MITRE D3FENDMITRE · GLOBALA knowledge base of defensive countermeasures mapped to ATT&CK.Read the guide
- OWASP ASVSOWASP · GLOBALA detailed, testable standard for verifying application security.Read the guide
- COSO Internal Control FrameworkCOSO · GLOBALThe leading framework for internal control and enterprise risk management.Read the guide
- MITRE ATLAS (AI/ML Threats)MITRE · GLOBALA knowledge base of adversarial threats to AI and machine-learning systems.Read the guide
- OWASP API Security Top 10OWASP · GLOBALThe most critical security risks to APIs.Read the guide
- ISO/IEC 27005 (Information Security Risk Management)ISO / IEC · GLOBALGuidance for managing information security risk.Read the guide
- ISO/IEC 27035 (Incident Management)ISO / IEC · GLOBALThe standard for information security incident management.Read the guide
- ISO/IEC 27031 (ICT Continuity)ISO / IEC · GLOBALICT readiness for business continuity.Read the guide
- ISO/IEC 29147 & 30111 (Vulnerability Disclosure)ISO / IEC · GLOBALStandards for vulnerability disclosure and handling.Read the guide
- NIST Secure Software Development Framework (SSDF)NIST · GLOBALSecure software development practices (SP 800-218).Read the guide
- NIST SP 800-63 (Digital Identity)NIST · GLOBALDigital identity guidelines, identity proofing, authentication and federation.Read the guide
- NIST AI Risk Management FrameworkNIST · GLOBALVoluntary framework to manage risks of AI systems.Read the guide
- CSA AI Controls Matrix (AICM)CLOUD SECURITY ALLIANCE · GLOBALCSA control matrix for securing and governing AI systems.Read the guide
- Cyber Risk Institute (CRI) ProfileCYBER RISK INSTITUTE · GLOBAL (FINANCE)Harmonised cybersecurity profile for the financial sector.Read the guide
- Secure Controls Framework (SCF)SECURE CONTROLS FRAMEWORK COUNCIL · GLOBALMetaframework mapping controls across 100+ authorities.Read the guide
- NIST SP 800-161 (C-SCRM)NIST · GLOBALCyber supply-chain risk management practices for systems.Read the guide
- NIST SP 800-82 (OT Security)NIST · GLOBALGuide to securing operational technology and control systems.Read the guide
- NIST Ransomware Risk Management ProfileNIST · GLOBALCSF profile to prevent, detect and recover from ransomware.Read the guide
- Cybersecurity Capability Maturity Model (C2M2)US DOE · GLOBALMaturity model to evaluate and improve cyber capabilities.Read the guide
- CryptoCurrency Security Standard (CCSS)C4 (CRYPTOCURRENCY CERTIFICATION CONSORTIUM) · GLOBALSecurity standard for systems that use cryptocurrencies.Read the guide
Certifications and attestations24
Standards you can be certified or attested against, where the deliverable is a certificate or a report somebody else will read.
- CMMI V3.0ISACA / CMMI INSTITUTE · GLOBALCapability Maturity Model Integration, a model for building repeatable, measurable, continually improving organisational capability.Read the guide
- ISO/IEC 27001ISO / IEC · GLOBALThe international standard for an Information Security Management System (ISMS).Read the guide
- SOC 2 (AICPA)AICPA · GLOBALAn attestation report on controls relevant to security, availability and privacy.Read the guide
- PCI DSSPCI SSC · GLOBALThe security standard for organisations that handle payment card data.Read the guide
- SWIFT CSP / CSCFSWIFT · GLOBALSWIFT's Customer Security Controls Framework for institutions on the SWIFT network.Read the guide
- PCI PIN & P2PEPCI SSC · GLOBALStandards for secure PIN management and point-to-point encryption of card data.Read the guide
- HITRUST CSFHITRUST ALLIANCE · GLOBAL / USA certifiable security framework that harmonises HIPAA, ISO, NIST, PCI and more.Read the guide
- CMMCUS DEPARTMENT OF DEFENSE · UNITED STATESCybersecurity Maturity Model Certification for the US defense supply chain.Read the guide
- FedRAMPUS FEDRAMP PMO / GSA · UNITED STATESThe US government authorisation programme for cloud services.Read the guide
- ISO 22301ISO · GLOBALThe international standard for business continuity management systems (BCMS).Read the guide
- ISO/IEC 27017ISO / IEC · GLOBALCloud-specific information security controls extending ISO 27002.Read the guide
- ISO/IEC 42001 (AI Management)ISO / IEC · GLOBALThe management-system standard for artificial intelligence (AIMS).Read the guide
- ISO/IEC 20000-1ISO / IEC · GLOBALThe international standard for an IT service management system (SMS).Read the guide
- ISO 9001 (Quality)ISO · GLOBALThe international standard for a quality management system (QMS).Read the guide
- SOX IT General Controls (ITGC)US SEC / PCAOB · UNITED STATESIT general controls supporting Sarbanes-Oxley financial-reporting compliance.Read the guide
- TISAX (Automotive)ENX ASSOCIATION · GLOBAL / EUROPEThe information-security assessment standard for the automotive industry.Read the guide
- Common Criteria (ISO/IEC 15408) / IC3SCOMMON CRITERIA / STQC · GLOBAL / INDIAInternational product security evaluation and certification.Read the guide
- FIPS 140-3 Cryptographic Module ValidationNIST / CMVP · GLOBALValidation of cryptographic modules to US federal standards.Read the guide
- PCI Software Security Framework & 3DSPCI SSC · GLOBALPCI standards for payment software security and 3-D Secure.Read the guide
- ISO/SAE 21434 & UNECE R155 (Automotive Cybersecurity)ISO / SAE / UNECE · GLOBALCybersecurity engineering for road vehicles.Read the guide
- Medical Device CybersecurityFDA / IEC · GLOBALCybersecurity for medical devices across the product lifecycle.Read the guide
- BSI C5 (Cloud Computing Compliance Criteria Catalogue)BSI (GERMANY) · GERMANY / EUGerman catalogue of cloud security controls attested by auditors.Read the guide
- ISO 28000 (Supply Chain Security)ISO · GLOBALManagement system for security of the supply chain.Read the guide
- ISO 27799 (Health Informatics Security)ISO · GLOBALHealth-sector application of ISO 27002 controls.Read the guide
Data privacy laws10
Statutory obligations that attach to personal data. These bind you whether or not anyone asks for a certificate.
- GDPREUROPEAN UNION · EU / EEAThe EU regulation governing the processing of personal data.Read the guide
- HIPAAUS DEPT. OF HEALTH & HUMAN SERVICES · UNITED STATESUS law protecting the privacy and security of protected health information (PHI).Read the guide
- ISO/IEC 27701ISO / IEC · GLOBALA privacy extension (PIMS) to ISO 27001 for managing personal data.Read the guide
- CCPA / CPRASTATE OF CALIFORNIA · UNITED STATESCalifornia's consumer privacy law and its CPRA amendments.Read the guide
- ISO/IEC 27018ISO / IEC · GLOBALProtection of personal data (PII) in public cloud services.Read the guide
- LGPD (Brazil)BRAZIL (ANPD) · BRAZILBrazil's General Data Protection Law for personal data.Read the guide
- POPIA (South Africa)SOUTH AFRICA (INFORMATION REGULATOR) · SOUTH AFRICASouth Africa's Protection of Personal Information Act.Read the guide
- PDPA (Singapore)PDPC (SINGAPORE) · SINGAPORESingapore's Personal Data Protection Act.Read the guide
- PIPEDA (Canada)CANADA (OPC) · CANADACanada's federal private-sector privacy law.Read the guide
- EU-US Data Privacy FrameworkUS DEPT OF COMMERCE / EC · EU / USTransatlantic mechanism for lawful personal-data transfers.Read the guide
India regulatory33
Directions and frameworks issued by Indian regulators. Most organisations we assess are inside more than one of these at once.
- DPDP Act, 2023 (India)MEITY, GOVERNMENT OF INDIA · INDIAIndia's data-protection law governing the personal data of data principals.Read the guide
- RBI Cyber Security Framework for BanksRESERVE BANK OF INDIA · INDIABaseline cybersecurity and resilience controls mandated by RBI for banks.Read the guide
- RBI Digital Payment Security ControlsRESERVE BANK OF INDIA · INDIARBI's master direction on securing internet, mobile and card digital payment channels.Read the guide
- RBI IT Governance, Risk, Controls & AssuranceRESERVE BANK OF INDIA · INDIARBI's master direction on IT governance, risk, controls and IS assurance practices.Read the guide
- RBI Payment Aggregators & Payment Gateways (PA-PG)RESERVE BANK OF INDIA · INDIAAuthorisation and security requirements for payment aggregators and payment gateways.Read the guide
- RBI Prepaid Payment Instruments (PPI)RESERVE BANK OF INDIA · INDIARules for issuing and operating prepaid payment instruments (wallets, cards).Read the guide
- RBI System Audit Report (SAR) & Data LocalisationRESERVE BANK OF INDIA · INDIAAnnual system audit and payment-data localisation assurance for payment system operators.Read the guide
- NPCI UPI / TPAP Security AuditNPCI · INDIASecurity audit requirements for UPI Third-Party Application Providers and PSP banks.Read the guide
- Bharat Bill Payment System (BBPS) AuditNPCI BHARAT BILLPAY (NBBL) · INDIASystem audit requirements for BBPS operating units in the bill-payment ecosystem.Read the guide
- SEBI CSCRFSEBI · INDIASEBI's Cyber Security and Cyber Resilience Framework for regulated entities.Read the guide
- IRDAI Information & Cyber SecurityIRDAI · INDIAInformation and cybersecurity guidelines for insurers and intermediaries.Read the guide
- UIDAI / Aadhaar (AUA-KUA)UIDAI · INDIASecurity and audit requirements for entities in the Aadhaar authentication ecosystem.Read the guide
- CERT-In Directions (Cyber Incident Reporting)CERT-IN, MEITY · INDIACERT-In's directions on incident reporting, log retention and security practices.Read the guide
- RBI Account Aggregator FrameworkRESERVE BANK OF INDIA · INDIAThe consent-based financial-data-sharing framework in India.Read the guide
- RBI IT Framework for NBFCsRESERVE BANK OF INDIA · INDIARBI's IT governance, security and audit expectations for NBFCs.Read the guide
- PFRDA Cyber Security & IS AuditPFRDA · INDIAInformation and cybersecurity audit for the pension (NPS) ecosystem.Read the guide
- IFSCA Cyber Resilience AuditIFSCA · INDIA (GIFT IFSC)Cybersecurity and resilience audit for regulated entities in GIFT IFSC.Read the guide
- RBI Housing Finance Company (HFC) IS & Cyber AuditRESERVE BANK OF INDIA · INDIAInformation systems and cybersecurity audit for housing finance companies.Read the guide
- RBI Digital Lending (DLA/LSP) AuditRESERVE BANK OF INDIA · INDIATechnical and privacy due-diligence audit of digital lending apps and service providers.Read the guide
- RBI Co-operative Bank Cyber Security FrameworkRESERVE BANK OF INDIA · INDIABasic and Comprehensive (graded) cybersecurity framework audit for UCBs.Read the guide
- RBI IT Outsourcing Directions AuditRESERVE BANK OF INDIA · INDIAAudit of IT outsourcing, cloud and supply-chain risk for RBI-regulated entities.Read the guide
- RBI Fraud Risk Management AuditRESERVE BANK OF INDIA · INDIAAudit of fraud governance, monitoring and reporting technology for REs.Read the guide
- RBI KYC / V-CIP Technology AuditRESERVE BANK OF INDIA · INDIAAudit of KYC and Video-based Customer Identification Process technology controls.Read the guide
- NPCI Product Security Audits (IMPS, RuPay, AePS, NACH, NFS, FASTag, CTS)NPCI · INDIASecurity audits across NPCI's payment products beyond UPI.Read the guide
- SEBI Stock Broker & MII System AuditSEBI · INDIASystem audits for stock brokers, clearing members and market infrastructure institutions.Read the guide
- CERT-In Comprehensive Cyber Security AuditCERT-IN, MEITY · INDIACybersecurity audit under CERT-In's 2025 audit policy guidelines.Read the guide
- STQC IT Testing & CertificationSTQC, MEITY · INDIAGovernment testing and certification for IT products, e-governance and security.Read the guide
- TEC MTCTE (Telecom Equipment)TEC / DOT · INDIAMandatory Testing and Certification of Telecom Equipment, including security.Read the guide
- NCIIPC Critical Information Infrastructure AuditNCIIPC · INDIAProtection and audit of Critical Information Infrastructure in India.Read the guide
- CCA / eSign / Digital Signature AuditCCA (MEITY) · INDIAAudit of Certifying Authorities, eSign and digital-signature ecosystems.Read the guide
- GIGW & Web Accessibility (WCAG) AuditMEITY / W3C · INDIA / GLOBALGovernment website guidelines and web accessibility compliance audit.Read the guide
- ABDM / Health Data Security AuditNATIONAL HEALTH AUTHORITY · INDIASecurity and privacy audit for the Ayushman Bharat Digital Mission ecosystem.Read the guide
- CEA Power-Sector Cyber SecurityCENTRAL ELECTRICITY AUTHORITY · INDIACybersecurity in the power/electricity sector under CEA regulations.Read the guide
Regional and national frameworks22
Country and region specific requirements, relevant where you operate, hold data or serve customers there.
- SAMA Cyber Security FrameworkSAUDI CENTRAL BANK (SAMA) · SAUDI ARABIAMandatory cybersecurity framework for financial institutions in Saudi Arabia.Read the guide
- Saudi NCA Essential Cybersecurity Controls (ECC)NATIONAL CYBERSECURITY AUTHORITY (SAUDI ARABIA) · SAUDI ARABIASaudi Arabia's mandatory Essential Cybersecurity Controls for national entities.Read the guide
- UAE Information Assurance (NESA / SIA)UAE CYBERSECURITY COUNCIL / SIA · UNITED ARAB EMIRATESThe UAE's Information Assurance standards for government and critical entities.Read the guide
- Qatar National Information Assurance (NIA)QATAR (NCSA) · QATARQatar's National Information Assurance standard for information security.Read the guide
- MAS TRM (Singapore)MONETARY AUTHORITY OF SINGAPORE · SINGAPORETechnology Risk Management guidelines for Singapore financial institutions.Read the guide
- APRA CPS 234 (Australia)APRA (AUSTRALIA) · AUSTRALIAInformation security prudential standard for APRA-regulated entities.Read the guide
- ASD Essential Eight (Australia)AUSTRALIAN SIGNALS DIRECTORATE (ACSC) · AUSTRALIAEight prioritised mitigation strategies against cyber threats.Read the guide
- Cyber Essentials (UK)UK NCSC / IASME · UNITED KINGDOMA UK government-backed certification for baseline cyber hygiene.Read the guide
- DORA (Digital Operational Resilience Act)EUROPEAN UNION · EUEU regulation on ICT and operational resilience for financial entities.Read the guide
- NIS2 DirectiveEUROPEAN UNION · EUEU directive raising cybersecurity for essential and important entities.Read the guide
- EU AI ActEUROPEAN UNION · EURisk-tiered EU regulation governing AI systems and models.Read the guide
- UK FCA Operational ResilienceFCA / PRA / BANK OF ENGLAND · UKUK regulatory rules on operational resilience for financial firms.Read the guide
- GLBA & FTC Safeguards RuleUS FTC · UNITED STATESUS financial-privacy and information-safeguards requirements.Read the guide
- NYDFS Part 500 Cybersecurity RegulationNY DEPT OF FINANCIAL SERVICES · UNITED STATESNew York cybersecurity rules for financial-services companies.Read the guide
- FFIEC Cybersecurity AssessmentFFIEC · UNITED STATESUS banking regulators' cyber maturity and IT examination framework.Read the guide
- NERC CIP (Critical Infrastructure Protection)NERC · NORTH AMERICAMandatory cyber standards for the North American bulk power system.Read the guide
- FBI CJIS Security PolicyUS FBI · UNITED STATESSecurity policy protecting US criminal-justice information.Read the guide
- Canada OSFI B-13 (Technology & Cyber Risk)OSFI (CANADA) · CANADACanadian guideline on technology and cyber risk for FRFIs.Read the guide
- Korea ISMS-PKISA (KOREA) · SOUTH KOREAKorean certification for information security and privacy management.Read the guide
- Japan ISMAPGOVERNMENT OF JAPAN · JAPANJapanese assessment program for government cloud services.Read the guide
- China PIPL / Cybersecurity Law / MLPSPRC GOVERNMENT · CHINAChina's data-protection, cybersecurity and grading regime.Read the guide
- Australia ISM & IRAPASD / ACSC (AUSTRALIA) · AUSTRALIAAustralian government security manual and assessor program.Read the guide
Not sure which one applies?
Most organisations are inside more than one of these at once, and the overlap is larger than it looks: the same access review, the same log retention and the same incident record can satisfy three frameworks if you build the control once. A thirty minute call with an assessor will usually shorten your list rather than lengthen it.
- Free tools and calculatorsCost, scope, penalty exposure and readiness, worked out before you call anyone.Open
- Guides and downloadsChecklists, evidence registers and research, written from real engagements.Open
- Verify a certificateCheck a certificate we issued against the register of what we have issued.Open
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












