Every cybersecurity compliance framework, explained.
Plain-English guides to every major framework — what it requires, who needs it, real penalty data, audit timelines, and how to actually get there. Not sure which apply to you? Use our 5-step framework finder →
Pick a framework to get started.
PDPA
🇸🇬 Singapore
Any business handling Singapore personal data
HIPAA Security Rule
🇺🇸 United States
Healthcare providers, plans, business associates
SOC 2 Type II
🌍 Global
SaaS & service organizations selling to enterprise
ISO 27001:2022
🌍 Global
Any organization seeking global ISMS certification
GDPR
🇪🇺 EU / UK
Any business processing EU/UK resident data
CSA Cyber Essentials
🇸🇬 Singapore
Singapore SMEs & government tender bidders
CSA Cyber Trust Mark
🇸🇬 Singapore
Singapore organizations with mature operations
CMMC 2.0
🇺🇸 United States
All DoD contractors handling FCI / CUI
NIST SP 800-171
🇺🇸 United States
Federal contractors handling CUI
NIST CSF 2.0
� Global
Any organisation seeking a single cybersecurity posture framework
PCI DSS 4.0
🌍 Global
Any business storing/processing card data
FTC Safeguards Rule
🇺🇸 United States
Financial institutions including auto/mortgage/tax
CCPA / CPRA
🇺🇸 California
Businesses with California consumers (above thresholds)
Multi-State Privacy Laws
🇺🇸 20 states
Businesses with consumers in multiple US states
NY DFS 23 NYCRR 500
🇺🇸 New York
NY-licensed financial services firms
FedRAMP
🇺🇸 United States
Cloud providers selling to federal agencies
SEC Cybersecurity Rules
🇺🇸 United States
All public companies (Form 8-K Item 1.05)
NIS2 Directive
🇪🇺 European Union
Essential & important entities in 18 EU sectors