Skip to content
1,069 controls across 13 frameworks

13 frameworks,
ready to go

Pre-built controls with shared mappings across frameworks. Activate any framework with a single message.

SOC 2 Type II

Service organization security for SaaS and tech companies

43

controls

SaaS/Tech
$ activate soc2
US / Global | Technology | 2017

ISO 27001:2022

International information security standard

93

controls

Enterprise
$ activate iso27001
Global | All industries | 2022

HIPAA Security Rule

Healthcare data protection

29

controls

Healthcare
$ activate hipaa
US | Healthcare | 2013

GDPR

EU data protection regulation

25

controls

EU business
$ activate gdpr
EU / EEA | All industries | 2018

NIST CSF

US cybersecurity framework

31

controls

Critical infrastructure
$ activate nist-csf
US | Critical infra | 2.0

PCI DSS v4.0

Payment card data security

30

controls

Payments
$ activate pci-dss
Global | Payments | 4.0

CIS Controls v8

Prioritized security controls

153

controls

Any organization
$ activate cis-controls
Global | All industries | 8.0

CMMC 2.0

Defense supply chain cybersecurity

113

controls

DoD contractors
$ activate cmmc
US | Defense | 2.0

HITRUST CSF

Healthcare comprehensive security

152

controls

Healthcare orgs
$ activate hitrust
US / Global | Healthcare | 11.x

CCPA

California consumer privacy

28

controls

CA businesses
$ activate ccpa
California | All industries | 2020

FedRAMP Moderate

US government cloud authorization

282

controls

Gov cloud providers
$ activate fedramp
US | Cloud / Gov | Moderate

ISO 42001:2023

AI management system standard

40

controls

AI/ML companies
$ activate iso42001
Global | AI / Technology | 2023

SOX ITGC

IT controls for financial reporting

50

controls

Public companies
$ activate sox-itgc
US | Finance | 2002
Comparison

Framework matrix

Side-by-side comparison of all 13 frameworks.

Framework Controls Industry Region Mandatory? Version
SOC 2 Type II
43 Technology US / Global Voluntary 2017
ISO 27001:2022
93 All industries Global Voluntary 2022
HIPAA Security Rule
29 Healthcare US Mandatory 2013
GDPR
25 All industries EU / EEA Mandatory 2018
NIST CSF
31 Critical infra US Voluntary 2.0
PCI DSS v4.0
30 Payments Global Mandatory 4.0
CIS Controls v8
153 All industries Global Voluntary 8.0
CMMC 2.0
113 Defense US Mandatory 2.0
HITRUST CSF
152 Healthcare US / Global Voluntary 11.x
CCPA
28 All industries California Mandatory 2020
FedRAMP Moderate
282 Cloud / Gov US Mandatory Moderate
ISO 42001:2023
40 AI / Technology Global Voluntary 2023
SOX ITGC
50 Finance US Mandatory 2002
Total 1,069 across 13 frameworks
Decision Guide

Which framework do I need?

Answer one question and get your starting point.

SaaS company selling to enterprises?

SOC 2

Handle healthcare data?

HIPAA, HITRUST

Process payments?

PCI DSS

EU customers?

GDPR

Government contracts?

FedRAMP, CMMC

Public company?

SOX ITGC

Building AI products?

ISO 42001

Want a comprehensive baseline?

CIS Controls, ISO 27001

Activate your first framework
in under a minute

Just tell the bot which framework you need. Controls, scoring, and gap analysis are instant.

AuditClaw
activate soc2

SOC 2 Type II activated. 43 controls loaded, scoring ready.