Compliance Made Simple

57 frameworks, mapped to real controls

Every framework below carries the actual articles your auditor cites, with the policies, classifications, and reports that satisfy them. Browse the catalogue here, or start withthe compliance platform. Not sure which of these you answer to?Answer twelve questionsand see what is commonly in scope — and how each one is enforced.

57
Compliance frameworks
228
Cited requirements mapped
<1s
Detection to alert
9
Platform capabilities mapped
GDPREuropean UnionAll Industries

EU General Data Protection Regulation

Comprehensive data protection regulation governing how organizations collect, store, and process personal data of EU residents. Non-compliance can result in fines up to 4% of global annual revenue.

ComplianceSecurityIncident Management
CitedArticle 30 ·Article 32 ·Article 33 ·Article 35
View the full mapping
CCPA/CPRACalifornia, USAAll Industries

California Consumer Privacy Act / California Privacy Rights Act

California privacy law granting consumers rights over their personal information. Applies to businesses with >$25M revenue, data on 100k+ consumers, or 50%+ revenue from selling data.

ComplianceSecurity
CitedSection 1798.100 ·Section 1798.105 ·Section 1798.150 ·CPRA Addition
View the full mapping
LGPDBrazilAll Industries

Lei Geral de Proteção de Dados

Brazil comprehensive data protection law modeled after GDPR. Applies to any processing of personal data of individuals located in Brazil, regardless of where the processor is located.

ComplianceSecurityIncident Management
CitedArticle 37 ·Article 46 ·Article 48 ·Article 18
View the full mapping
PIPEDACanadaAll Industries

Personal Information Protection and Electronic Documents Act

Canadian federal privacy law governing how private sector organizations collect, use, and disclose personal information in commercial activities.

ComplianceSecurityIncident Management
CitedPrinciple 4.7 ·Principle 4.9 ·PIPEDA Breach ·Principle 4.1
View the full mapping
PDPASingaporeAll Industries

Singapore Personal Data Protection Act

Singapore data protection law governing collection, use, and disclosure of personal data by private organizations in Singapore.

ComplianceSecurityIncident Management
CitedSection 24 ·Section 21 ·Section 26B ·Section 25
View the full mapping
PIPLChinaAll Industries

Personal Information Protection Law of China

China comprehensive data protection law with strict requirements for processing personal information of individuals in China, including data localization requirements.

ComplianceSecurityIncident Management
CitedArticle 51 ·Article 55 ·Article 57 ·Article 40
View the full mapping
SOXUnited StatesPublic Companies

Sarbanes-Oxley Act

U.S. federal law mandating internal controls and audit trails for financial reporting systems in publicly traded companies. Criminal penalties for executives who certify false statements.

ComplianceSecurityIncident Management
CitedSection 302 ·Section 404 ·Section 802 ·Section 103
View the full mapping
PCI-DSSGlobalPayment Card Processing

Payment Card Industry Data Security Standard

Security standard for organizations handling credit card data. Required for all merchants and service providers that store, process, or transmit cardholder data.

ComplianceSecurityIncident Management
CitedRequirement 10.1 ·Requirement 10.2 ·Requirement 10.4 ·Requirement 10.7
View the full mapping
GLBAUnited StatesFinancial Services

Gramm-Leach-Bliley Act

U.S. law requiring financial institutions to protect customer financial information and explain data sharing practices. Enforced by FTC, SEC, and banking regulators.

ComplianceSecurityIncident Management
CitedSafeguards Rule ·314.4(c) ·314.4(d) ·Safeguards Rule
View the full mapping
DORAEuropean UnionFinancial Services

EU Digital Operational Resilience Act

EU regulation ensuring financial entities can withstand, respond to, and recover from ICT-related disruptions. Effective January 2025 for all EU financial institutions.

ComplianceSecurityIncident Management
CitedArticle 6 ·Article 17 ·Article 19 ·Article 28
View the full mapping
HIPAAUnited StatesHealthcare

Health Insurance Portability and Accountability Act

U.S. law protecting sensitive patient health information. Applies to healthcare providers, health plans, and healthcare clearinghouses. Civil penalties up to $1.5M per violation category per year.

ComplianceSecurityIncident Management
Cited164.312(b) ·164.308(a)(1)(ii)(D) ·164.312(c)(1) ·164.308(a)(6)
View the full mapping
FedRAMPUnited StatesGovernment & Cloud Providers

Federal Risk and Authorization Management Program

U.S. government program providing standardized security assessment for cloud products serving federal agencies. Mandatory for cloud service providers working with federal government.

ComplianceSecurityIncident Management
CitedAU-2 ·AU-3 ·AU-6 ·AU-9
View the full mapping
FISMAUnited StatesFederal Government

Federal Information Security Management Act

U.S. law requiring federal agencies to develop, document, and implement information security programs. Mandates NIST standards for all federal information systems.

ComplianceSecurityIncident Management
CitedNIST 800-53 AU-2 ·Continuous Monitoring ·NIST 800-53 SI-4 ·Annual Assessment
View the full mapping
StateRAMPUnited States (State Level)State Government

State Risk and Authorization Management Program

Standardized security framework for state and local governments to assess cloud service providers. Based on FedRAMP with state-specific adaptations.

ComplianceSecurityIncident Management
CitedAU Controls ·Continuous Monitoring ·3PAO Assessment ·Annual Review
View the full mapping
CMMCUnited StatesDefense Industrial Base

Cybersecurity Maturity Model Certification

DoD framework verifying cybersecurity practices of contractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

ComplianceSecurityIncident Management
CitedAU.L2-3.3.1 ·AU.L2-3.3.2 ·AU.L2-3.3.4 ·SI.L2-3.14.6
View the full mapping
SOC 2GlobalService Providers

Service Organization Control 2

Trust service criteria framework for evaluating controls related to security, availability, processing integrity, confidentiality, and privacy. Required by enterprise customers for vendor assessment.

ComplianceSecurityIncident Management
CitedCC6.1 ·CC7.2 ·CC7.3 ·CC8.1
View the full mapping
ISO 27001GlobalAll Industries

ISO/IEC 27001 Information Security Management

International standard for information security management systems (ISMS). Certification demonstrates commitment to security and is often required for international business.

ComplianceSecurityIncident Management
CitedA.12.4.1 ·A.12.4.3 ·A.9.2.1 ·A.16.1.2
View the full mapping
NIST CSFUnited States / GlobalAll Industries

NIST Cybersecurity Framework

Voluntary framework providing guidance for organizations to manage and reduce cybersecurity risk. Widely adopted as a baseline for security programs worldwide.

ComplianceSecurityIncident Management
CitedDE.CM-1 ·DE.CM-3 ·DE.CM-7 ·PR.DS-1
View the full mapping
CIS ControlsGlobalAll Industries

Center for Internet Security Critical Security Controls

Prioritized set of actions to protect organizations from known cyber attack vectors. Adopted by numerous organizations as a practical security framework.

ComplianceSecurityIncident Management
CitedControl 3 ·Control 6 ·Control 8 ·Control 13
View the full mapping
NIS2European UnionEssential & Important Entities

EU Network and Information Security Directive 2

EU directive establishing cybersecurity obligations for entities operating essential and important services. Effective October 2024 with significant penalties for non-compliance.

ComplianceSecurityIncident Management
CitedArticle 21(1) ·Article 21(2)(g) ·Article 23 ·Article 21(2)(d)
View the full mapping
21 CFR Part 11United States / GlobalPharmaceuticals & Life Sciences

FDA Electronic Records and Electronic Signatures

FDA regulation establishing criteria for electronic records and signatures to be considered trustworthy and equivalent to paper records. Required for any company manufacturing or distributing FDA-regulated products.

ComplianceSecurityIncident Management
Cited§11.10(e) ·§11.10(k)(2) ·§11.10(g) ·§11.50
View the full mapping
CMSUnited StatesHealthcare / Medicare & Medicaid

Centers for Medicare & Medicaid Services Requirements

CMS security and privacy requirements for organizations handling Medicare and Medicaid data. Includes Minimum Acceptable Risk Standards (MARS-E) and Acceptable Risk Safeguards (ARS).

ComplianceSecurityIncident Management
CitedMARS-E 2.0 AU-2 ·MARS-E 2.0 AU-3 ·ARS 3.1 AC-2 ·MARS-E 2.0 AU-6
View the full mapping
ISO 13485GlobalMedical Devices

Medical Devices Quality Management Systems

International standard specifying requirements for quality management systems for medical device manufacturers. Required for CE marking and FDA approval processes.

ComplianceSecurity
Cited§4.2.5 ·§4.2.4 ·§7.5.1 ·§8.2.4
View the full mapping
EU EHDSEuropean UnionHealthcare / Research

European Health Data Space

EU regulation establishing a common framework for health data sharing across member states. Effective 2026, enables secondary use of health data for research while maintaining patient privacy.

ComplianceSecurity
CitedArticle 33 ·Article 35 ·Article 37 ·Article 41
View the full mapping
NIST 800-53United StatesFederal Government / Contractors

NIST Special Publication 800-53 Revision 5

Comprehensive catalog of security and privacy controls for federal information systems. Required for all US federal agencies and their contractors. The gold standard for government security.

ComplianceSecurityIncident Management
CitedAU-2 ·AU-3 ·AU-6 ·AU-9
View the full mapping
IRS Pub 1075United StatesTaxation / Government

IRS Publication 1075 - Tax Information Security Guidelines

IRS requirements for safeguarding Federal Tax Information (FTI). Applies to all agencies, contractors, and agents receiving FTI from the IRS.

ComplianceSecurityIncident Management
Cited9.3.3.2 ·9.3.3.3 ·9.3.3.6 ·9.3.3.9
View the full mapping
CJISUnited StatesLaw Enforcement

FBI Criminal Justice Information Services Security Policy

Security policy for all entities accessing FBI Criminal Justice Information (CJI). Applies to law enforcement agencies, contractors, and any organization with CJI access.

ComplianceSecurityIncident Management
Cited5.4.1.1 ·5.4.1.2 ·5.4.3 ·5.4.6
View the full mapping
UK DPAUnited KingdomAll Industries

UK Data Protection Act 2018

UK implementation of data protection principles post-Brexit. Supplements UK GDPR and applies to all organizations processing personal data of UK residents.

ComplianceSecurityIncident Management
CitedSection 57 ·Section 59 ·Section 66 ·Section 107
View the full mapping
SEC 17a-4United StatesSecurities / Broker-Dealers

SEC Rule 17a-4 - Records to be Preserved

SEC regulation requiring broker-dealers to preserve records in non-rewritable, non-erasable format (WORM). Critical for trading firms, investment advisors, and financial institutions.

ComplianceSecurityIncident Management
Cited17a-4(b)(4) ·17a-4(f) ·17a-4(f)(2)(ii) ·17a-4(f)(3)
View the full mapping
NAIC MDL-668United States (State)Insurance

NAIC Insurance Data Security Model Law

Model law adopted by most US states requiring insurance companies to implement comprehensive information security programs with annual certification requirements.

ComplianceSecurityIncident Management
CitedSection 4D ·Section 4F ·Section 6 ·Section 8
View the full mapping
MiCAEuropean UnionCrypto / Web3 / Digital Assets

EU Markets in Crypto-Assets Regulation

EU regulation establishing uniform rules for crypto-asset service providers. Effective 2024, requires comprehensive audit trails for distributed ledger operations.

ComplianceSecurityIncident Management
CitedArticle 68 ·Article 76 ·Article 78 ·Article 83
View the full mapping
DPDP ActIndiaAll Industries

India Digital Personal Data Protection Act 2023

India comprehensive data protection law governing processing of digital personal data. Applies to organizations processing data of individuals in India with penalties up to ₹250 crore.

ComplianceSecurityIncident Management
CitedSection 8(7) ·Section 8(6) ·Section 11 ·Section 8(9)
View the full mapping
APPIJapanAll Industries

Japan Act on Protection of Personal Information

Japan primary data protection law governing handling of personal information. Updated 2022 with stricter requirements for cross-border transfers and breach notification.

ComplianceSecurityIncident Management
CitedArticle 23 ·Article 26 ·Article 33 ·Article 28
View the full mapping
Quebec Law 25Quebec, CanadaAll Industries

Quebec Law 25 - An Act to Modernize Legislative Provisions Respecting Personal Information

Quebec comprehensive privacy law with strict requirements for logging personal information access. Fully effective September 2024 with significant penalties.

ComplianceSecurityIncident Management
CitedSection 3.1 ·Section 3.3 ·Section 3.5 ·Section 8
View the full mapping
ISO 27701GlobalAll Industries

ISO/IEC 27701 Privacy Information Management System

International standard extending ISO 27001 to include privacy management. Provides framework for PII controllers and processors to demonstrate compliance with privacy regulations.

ComplianceSecurityIncident Management
Cited7.2.2 ·7.2.6 ·8.2.2 ·7.3.6
View the full mapping
SOCI ActAustraliaCritical Infrastructure

Australia Security of Critical Infrastructure Act 2018

Australian law protecting critical infrastructure assets. Requires mandatory incident reporting within 72 hours and comprehensive risk management programs.

ComplianceSecurityIncident Management
CitedPart 2A ·Section 30BC ·Part 3 ·Section 30BF
View the full mapping
BSIMM12GlobalSoftware Development

Building Security In Maturity Model

Framework for measuring and improving software security practices. Measures activities across governance, intelligence, SSDL touchpoints, and deployment.

ComplianceSecurityIncident Management
CitedSE2.4 ·SE3.2 ·CMVM2.1 ·SM2.2
View the full mapping
NERC CIP-007-6North AmericaPower / Utilities

NERC Critical Infrastructure Protection - Systems Security Management

NERC reliability standard requiring security management for Bulk Electric System (BES) Cyber Systems. Mandatory for all electric utilities in North America.

ComplianceSecurityIncident Management
CitedR4.1 ·R4.2 ·R4.3 ·R5.6
View the full mapping
TSA SD 1580/82United StatesRail / Transit

TSA Security Directives for Surface Transportation

TSA security directives requiring rail and transit operators to implement cybersecurity measures including 24/7 monitoring of critical systems.

ComplianceSecurityIncident Management
CitedSD 1580-21-01 ·SD 1580-21-01 §4 ·SD 1582-21-01 ·SD 1580-21-01 §3
View the full mapping
IATA IOSAGlobalAviation

IATA Operational Safety Audit (ISM v16)

International standard for airline operational safety management. Required for IATA membership and accepted by aviation authorities worldwide.

ComplianceSecurityIncident Management
CitedORG 3.1.1 ·FLT 3.11.1 ·MNT 1.10.3 ·SEC 3.1.1
View the full mapping
IMO MSC.428(98)GlobalMaritime

IMO Maritime Cyber Risk Management

International Maritime Organization resolution requiring cyber risk management in safety management systems. Applies to all ships subject to ISM Code.

ComplianceSecurityIncident Management
CitedResolution §2 ·ISM Code 12.1 ·Resolution §4 ·Resolution §5
View the full mapping
CER DirectiveEuropean UnionWater / Waste / Energy

EU Critical Entities Resilience Directive

EU directive requiring critical infrastructure operators to implement resilience measures. Covers water, waste management, energy, and digital infrastructure sectors.

ComplianceSecurityIncident Management
CitedArticle 12 ·Article 13 ·Article 15 ·Article 14
View the full mapping
SPD-5United StatesSpace / Satellite

US Space Policy Directive 5 - Cybersecurity Principles for Space Systems

US policy establishing cybersecurity principles for space systems. Requires Zero-Trust architecture and comprehensive logging for ground and space operations.

ComplianceSecurityIncident Management
CitedPrinciple 1 ·Principle 3 ·Principle 4 ·Principle 5
View the full mapping
ECC-1:2018Saudi ArabiaGovernment / Critical Infrastructure

Saudi Arabia Essential Cybersecurity Controls (NCA)

Saudi National Cybersecurity Authority mandatory controls for government entities and critical infrastructure. Requires protected logs for all national infrastructure.

ComplianceSecurityIncident Management
Cited3-1-1 ·3-1-2 ·3-1-3 ·3-1-4
View the full mapping
EU AI ActEuropean Union / GlobalAI Systems / All Industries

EU Artificial Intelligence Act

EU regulation establishing harmonized rules for AI systems. Requires immutable "Black Box" logging for high-risk AI with complete traceability of inputs, outputs, and agentic actions.

ComplianceSecurityIncident Management
CitedArticle 12 ·Article 13 ·Article 14 ·Article 17
View the full mapping
ISO/IEC 42001GlobalAI Systems

ISO/IEC 42001 Artificial Intelligence Management System

International standard for AI management systems. Provides framework for responsible AI development with continuous monitoring of model-data interactions.

ComplianceSecurity
Cited6.1.4 ·8.4 ·9.1 ·10.1
View the full mapping
DSAEuropean UnionDigital Platforms / Social Media

EU Digital Services Act

EU regulation establishing obligations for digital platforms including audit trails for content moderation and algorithmic transparency.

ComplianceSecurityIncident Management
CitedArticle 15 ·Article 27 ·Article 37 ·Article 40
View the full mapping
SOC 2 + AIGlobalAI Service Providers

SOC 2 Trust Services Criteria for AI Systems

Extended SOC 2 framework addressing AI-specific risks. Covers model governance, data provenance, and algorithmic accountability for AI service providers.

ComplianceSecurityIncident Management
CitedCC7.2 AI ·CC6.7 AI ·CC8.1 AI ·PI1.4 AI
View the full mapping
ISA/IEC 62443GlobalManufacturing / Industrial

ISA/IEC 62443 Industrial Automation and Control Systems Security

International standard series for industrial automation security. Covers security lifecycle for industrial control systems and Industry 4.0 environments.

ComplianceSecurityIncident Management
CitedSR 2.8 ·SR 2.9 ·SR 2.10 ·SR 6.1
View the full mapping
IACS UR E26/E27GlobalMaritime Industrial / Mining

IACS Unified Requirements for Cyber Resilience

International Association of Classification Societies requirements for cyber security of ships and offshore units. Applies to computer-based systems in heavy equipment and maritime operations.

ComplianceSecurityIncident Management
CitedE26 §5.1 ·E27 §4.3 ·E26 §5.3 ·E27 §5.1
View the full mapping
UN R155GlobalAutomotive

UN Regulation 155 - Cyber Security and Cyber Security Management System

UN regulation requiring cybersecurity management systems for vehicle manufacturers. Mandatory for type approval in UNECE countries including EU, UK, Japan, and Korea.

ComplianceSecurityIncident Management
Cited7.2.2.2(g) ·7.2.2.2(h) ·7.2.2.5 ·Annex 5 Part C
View the full mapping
Bill C-27 CPPACanadaAll Industries / Agriculture

Canada Consumer Privacy Protection Act (Digital Charter)

Proposed Canadian federal privacy law replacing PIPEDA. Includes specific requirements for traceability of farm-to-table data and supply chain personal information.

ComplianceSecurityIncident Management
CitedSection 57 ·Section 72 ·Section 63 ·Section 59
View the full mapping
HMS OHIPCanadaHealthcare Billing

Health Management System Billing (OHIP/Alberta)

Canadian provincial requirements for health management system billing auditing. Requires correlation of billing codes with clinical access records to prevent fraud.

ComplianceSecurity
CitedPHIPA Section 12 ·HIA Section 60 ·PHIPA Section 10 ·Billing Audit Requirements
View the full mapping
FERPAUnited StatesEducation

Family Educational Rights and Privacy Act

US federal law protecting the privacy of student education records. Applies to all schools receiving federal funding and requires comprehensive access logging.

ComplianceSecurity
Cited34 CFR 99.32 ·34 CFR 99.31 ·34 CFR 99.10 ·34 CFR 99.35
View the full mapping
Dubai ISR v2United Arab EmiratesGovernment / Real Estate / Services

Dubai Information Security Regulation Version 2

Dubai mandatory information security requirements for government and service entities. Requires detailed CRUD logging for property registry and citizen service databases.

ComplianceSecurityIncident Management
CitedISR-AO-02 ·ISR-SM-04 ·ISR-IM-01 ·ISR-AO-04
View the full mapping
NIS2 (Logistics)European UnionLogistics / Supply Chain

NIS2 Directive Article 21 - Supply Chain Security

NIS2 requirements specifically for logistics and supply chain operators. Requires data integrity auditing and proof of business continuity.

ComplianceSecurityIncident Management
CitedArticle 21(2)(d) ·Article 21(2)(c) ·Article 21(2)(e) ·Article 23
View the full mapping
GDPR (Gaming)European Union / GlobalGaming / Entertainment

GDPR Article 32 - Gaming Industry Application

GDPR requirements as applied to gaming industry including user account data protection and micro-transaction integrity. 5-year retention for financial data.

ComplianceSecurityIncident Management
CitedArticle 32 ·Article 17 ·Article 25 ·Article 33
View the full mapping

Ready to simplify compliance?

Start your free trial and see how DB Audit accelerates your path to compliance.