57 frameworks, mapped to real controls
Every framework below carries the actual articles your auditor cites, with the policies, classifications, and reports that satisfy them. Browse the catalogue here, or start withthe compliance platform. Not sure which of these you answer to?Answer twelve questionsand see what is commonly in scope — and how each one is enforced.
EU General Data Protection Regulation
Comprehensive data protection regulation governing how organizations collect, store, and process personal data of EU residents. Non-compliance can result in fines up to 4% of global annual revenue.
California Consumer Privacy Act / California Privacy Rights Act
California privacy law granting consumers rights over their personal information. Applies to businesses with >$25M revenue, data on 100k+ consumers, or 50%+ revenue from selling data.
Lei Geral de Proteção de Dados
Brazil comprehensive data protection law modeled after GDPR. Applies to any processing of personal data of individuals located in Brazil, regardless of where the processor is located.
Personal Information Protection and Electronic Documents Act
Canadian federal privacy law governing how private sector organizations collect, use, and disclose personal information in commercial activities.
Singapore Personal Data Protection Act
Singapore data protection law governing collection, use, and disclosure of personal data by private organizations in Singapore.
Personal Information Protection Law of China
China comprehensive data protection law with strict requirements for processing personal information of individuals in China, including data localization requirements.
Sarbanes-Oxley Act
U.S. federal law mandating internal controls and audit trails for financial reporting systems in publicly traded companies. Criminal penalties for executives who certify false statements.
Payment Card Industry Data Security Standard
Security standard for organizations handling credit card data. Required for all merchants and service providers that store, process, or transmit cardholder data.
Gramm-Leach-Bliley Act
U.S. law requiring financial institutions to protect customer financial information and explain data sharing practices. Enforced by FTC, SEC, and banking regulators.
EU Digital Operational Resilience Act
EU regulation ensuring financial entities can withstand, respond to, and recover from ICT-related disruptions. Effective January 2025 for all EU financial institutions.
Health Insurance Portability and Accountability Act
U.S. law protecting sensitive patient health information. Applies to healthcare providers, health plans, and healthcare clearinghouses. Civil penalties up to $1.5M per violation category per year.
Federal Risk and Authorization Management Program
U.S. government program providing standardized security assessment for cloud products serving federal agencies. Mandatory for cloud service providers working with federal government.
Federal Information Security Management Act
U.S. law requiring federal agencies to develop, document, and implement information security programs. Mandates NIST standards for all federal information systems.
State Risk and Authorization Management Program
Standardized security framework for state and local governments to assess cloud service providers. Based on FedRAMP with state-specific adaptations.
Cybersecurity Maturity Model Certification
DoD framework verifying cybersecurity practices of contractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
Service Organization Control 2
Trust service criteria framework for evaluating controls related to security, availability, processing integrity, confidentiality, and privacy. Required by enterprise customers for vendor assessment.
ISO/IEC 27001 Information Security Management
International standard for information security management systems (ISMS). Certification demonstrates commitment to security and is often required for international business.
NIST Cybersecurity Framework
Voluntary framework providing guidance for organizations to manage and reduce cybersecurity risk. Widely adopted as a baseline for security programs worldwide.
Center for Internet Security Critical Security Controls
Prioritized set of actions to protect organizations from known cyber attack vectors. Adopted by numerous organizations as a practical security framework.
EU Network and Information Security Directive 2
EU directive establishing cybersecurity obligations for entities operating essential and important services. Effective October 2024 with significant penalties for non-compliance.
FDA Electronic Records and Electronic Signatures
FDA regulation establishing criteria for electronic records and signatures to be considered trustworthy and equivalent to paper records. Required for any company manufacturing or distributing FDA-regulated products.
Centers for Medicare & Medicaid Services Requirements
CMS security and privacy requirements for organizations handling Medicare and Medicaid data. Includes Minimum Acceptable Risk Standards (MARS-E) and Acceptable Risk Safeguards (ARS).
Medical Devices Quality Management Systems
International standard specifying requirements for quality management systems for medical device manufacturers. Required for CE marking and FDA approval processes.
European Health Data Space
EU regulation establishing a common framework for health data sharing across member states. Effective 2026, enables secondary use of health data for research while maintaining patient privacy.
NIST Special Publication 800-53 Revision 5
Comprehensive catalog of security and privacy controls for federal information systems. Required for all US federal agencies and their contractors. The gold standard for government security.
IRS Publication 1075 - Tax Information Security Guidelines
IRS requirements for safeguarding Federal Tax Information (FTI). Applies to all agencies, contractors, and agents receiving FTI from the IRS.
FBI Criminal Justice Information Services Security Policy
Security policy for all entities accessing FBI Criminal Justice Information (CJI). Applies to law enforcement agencies, contractors, and any organization with CJI access.
UK Data Protection Act 2018
UK implementation of data protection principles post-Brexit. Supplements UK GDPR and applies to all organizations processing personal data of UK residents.
SEC Rule 17a-4 - Records to be Preserved
SEC regulation requiring broker-dealers to preserve records in non-rewritable, non-erasable format (WORM). Critical for trading firms, investment advisors, and financial institutions.
NAIC Insurance Data Security Model Law
Model law adopted by most US states requiring insurance companies to implement comprehensive information security programs with annual certification requirements.
EU Markets in Crypto-Assets Regulation
EU regulation establishing uniform rules for crypto-asset service providers. Effective 2024, requires comprehensive audit trails for distributed ledger operations.
India Digital Personal Data Protection Act 2023
India comprehensive data protection law governing processing of digital personal data. Applies to organizations processing data of individuals in India with penalties up to ₹250 crore.
Japan Act on Protection of Personal Information
Japan primary data protection law governing handling of personal information. Updated 2022 with stricter requirements for cross-border transfers and breach notification.
Quebec Law 25 - An Act to Modernize Legislative Provisions Respecting Personal Information
Quebec comprehensive privacy law with strict requirements for logging personal information access. Fully effective September 2024 with significant penalties.
ISO/IEC 27701 Privacy Information Management System
International standard extending ISO 27001 to include privacy management. Provides framework for PII controllers and processors to demonstrate compliance with privacy regulations.
Australia Security of Critical Infrastructure Act 2018
Australian law protecting critical infrastructure assets. Requires mandatory incident reporting within 72 hours and comprehensive risk management programs.
Building Security In Maturity Model
Framework for measuring and improving software security practices. Measures activities across governance, intelligence, SSDL touchpoints, and deployment.
NERC Critical Infrastructure Protection - Systems Security Management
NERC reliability standard requiring security management for Bulk Electric System (BES) Cyber Systems. Mandatory for all electric utilities in North America.
TSA Security Directives for Surface Transportation
TSA security directives requiring rail and transit operators to implement cybersecurity measures including 24/7 monitoring of critical systems.
IATA Operational Safety Audit (ISM v16)
International standard for airline operational safety management. Required for IATA membership and accepted by aviation authorities worldwide.
IMO Maritime Cyber Risk Management
International Maritime Organization resolution requiring cyber risk management in safety management systems. Applies to all ships subject to ISM Code.
EU Critical Entities Resilience Directive
EU directive requiring critical infrastructure operators to implement resilience measures. Covers water, waste management, energy, and digital infrastructure sectors.
US Space Policy Directive 5 - Cybersecurity Principles for Space Systems
US policy establishing cybersecurity principles for space systems. Requires Zero-Trust architecture and comprehensive logging for ground and space operations.
Saudi Arabia Essential Cybersecurity Controls (NCA)
Saudi National Cybersecurity Authority mandatory controls for government entities and critical infrastructure. Requires protected logs for all national infrastructure.
EU Artificial Intelligence Act
EU regulation establishing harmonized rules for AI systems. Requires immutable "Black Box" logging for high-risk AI with complete traceability of inputs, outputs, and agentic actions.
ISO/IEC 42001 Artificial Intelligence Management System
International standard for AI management systems. Provides framework for responsible AI development with continuous monitoring of model-data interactions.
EU Digital Services Act
EU regulation establishing obligations for digital platforms including audit trails for content moderation and algorithmic transparency.
SOC 2 Trust Services Criteria for AI Systems
Extended SOC 2 framework addressing AI-specific risks. Covers model governance, data provenance, and algorithmic accountability for AI service providers.
ISA/IEC 62443 Industrial Automation and Control Systems Security
International standard series for industrial automation security. Covers security lifecycle for industrial control systems and Industry 4.0 environments.
IACS Unified Requirements for Cyber Resilience
International Association of Classification Societies requirements for cyber security of ships and offshore units. Applies to computer-based systems in heavy equipment and maritime operations.
UN Regulation 155 - Cyber Security and Cyber Security Management System
UN regulation requiring cybersecurity management systems for vehicle manufacturers. Mandatory for type approval in UNECE countries including EU, UK, Japan, and Korea.
Canada Consumer Privacy Protection Act (Digital Charter)
Proposed Canadian federal privacy law replacing PIPEDA. Includes specific requirements for traceability of farm-to-table data and supply chain personal information.
Health Management System Billing (OHIP/Alberta)
Canadian provincial requirements for health management system billing auditing. Requires correlation of billing codes with clinical access records to prevent fraud.
Family Educational Rights and Privacy Act
US federal law protecting the privacy of student education records. Applies to all schools receiving federal funding and requires comprehensive access logging.
Dubai Information Security Regulation Version 2
Dubai mandatory information security requirements for government and service entities. Requires detailed CRUD logging for property registry and citizen service databases.
NIS2 Directive Article 21 - Supply Chain Security
NIS2 requirements specifically for logistics and supply chain operators. Requires data integrity auditing and proof of business continuity.
GDPR Article 32 - Gaming Industry Application
GDPR requirements as applied to gaming industry including user account data protection and micro-transaction integrity. 5-year retention for financial data.
No frameworks match that search. Try a framework name, a region, or a capability like “vulnerability” or “file integrity”.
One platform, all 57 frameworks
Nine capabilities across three pillars produce the evidence. Every framework above maps its cited requirements onto them — follow any framework through to see which, and why.
Compliance
- Sensitive Data DiscoveryFinds and classifies the regulated data, so everything downstream knows what is in scope.
- Policy & ComplianceTurns the captured activity into the report shape the framework asks for.
- Change Request TrackingTies every database change to the request that authorised it.
- Compliance Advisory ServicesOrganises the gap register, the remediation roadmap, and the auditor-ready pack.
Security
Ready to simplify compliance?
Start your free trial and see how DB Audit accelerates your path to compliance.