The Global Directory

Compliance Frameworks.

Explore our comprehensive library of 200+ global frameworks. Cyrama automates the evidence collection and monitoring for every control.

Showing 53 Standards

SOC 2 Type I

Popular

Service Organization Control 2 (Point-in-time)

Evaluates the design of security controls at a specific point in time.

SecurityExplore

SOC 2 Type II

Popular

Service Organization Control 2 (Period-of-time)

The industry standard for SaaS security, evaluating control effectiveness over 6-12 months.

SecurityExplore

ISO 27001

Popular

Information Security Management System

The primary international standard for establishing and maintaining an ISMS.

SecurityExplore

ISO 27017

Cloud Security Controls

Guidelines for information security controls applicable to the provision and use of cloud services.

ISO 27018

Cloud Privacy Protection

Focuses on protecting personal data in the cloud.

PrivacyExplore

ISO 22301

Business Continuity Management

Specifies requirements to plan, establish, and operate a documented management system to protect against disruptions.

SecurityExplore

NIST CSF

Popular

NIST Cybersecurity Framework

A voluntary framework to manage and reduce cybersecurity risk for critical infrastructure.

SecurityExplore

NIST 800-53

Security and Privacy Controls for Information Systems

A comprehensive catalog of controls for federal information systems.

SecurityExplore

NIST 800-171

Protecting CUI in Nonfederal Systems

Required for contractors handling Controlled Unclassified Information.

GovernmentExplore

GDPR

Popular

General Data Protection Regulation

The primary regulation in EU law on data protection and privacy.

PrivacyExplore

CCPA

Popular

California Consumer Privacy Act

Empowers California consumers with rights over their personal data.

PrivacyExplore

CPRA

California Privacy Rights Act

An amendment to CCPA that adds new consumer privacy rights.

PrivacyExplore

VCDPA

Virginia Consumer Data Protection Act

Virginia's comprehensive data privacy law.

PrivacyExplore

LGPD

Lei Geral de Proteção de Dados

Brazil's comprehensive data protection law.

PrivacyExplore

PDPA SG

Personal Data Protection Act (Singapore)

Governs the collection, use, and disclosure of personal data by organizations in Singapore.

RegionalExplore

PIPEDA

Personal Information Protection and Electronic Documents Act

Canada's federal privacy law for private-sector organizations.

RegionalExplore

POPIA

Protection of Personal Information Act

South Africa's data protection law.

RegionalExplore

HIPAA

Popular

Health Insurance Portability and Accountability Act

US law providing data privacy and security provisions for safeguarding medical information.

HealthcareExplore

HITRUST CSF

Popular

Health Information Trust Alliance

A certifiable framework that leverages various standards for healthcare security.

HealthcareExplore

HITECH

Health Information Technology for Economic and Clinical Health

Promotes the adoption and meaningful use of health information technology.

HealthcareExplore

PCI DSS v4.0

Popular

Payment Card Industry Data Security Standard

The latest global standard for securing credit card data.

FinanceExplore

GLBA

Gramm-Leach-Bliley Act

Requires financial institutions to explain their information-sharing practices to customers.

FinanceExplore

FFIEC

Federal Financial Institutions Examination Council

Uniform principles and standards for the federal examination of financial institutions.

FinanceExplore

SOC 1

Service Organization Control 1

Focuses on controls at a service organization relevant to user entities' internal control over financial reporting.

FinanceExplore

FedRAMP High

Federal Risk and Authorization Management Program

Security standards for cloud services used by the US federal government (High Impact).

GovernmentExplore

FedRAMP Med

Popular

Federal Risk and Authorization Management Program

Security standards for cloud services used by the US federal government (Moderate Impact).

GovernmentExplore

CMMC Level 1

Cybersecurity Maturity Model Certification

Foundational cybersecurity for DOD contractors.

GovernmentExplore

CMMC Level 2

Popular

Cybersecurity Maturity Model Certification

Advanced cybersecurity protecting CUI.

GovernmentExplore

FISMA

Federal Information Security Modernization Act

Requires federal agencies to develop, document, and implement an information security program.

GovernmentExplore

ITRR

Information Technology Risk Rating

System for evaluating IT risk within government agencies.

GovernmentExplore

CSA STAR L1

Cloud Security Alliance STAR Self-Assessment

A rigorous self-assessment for cloud provider transparency.

CSA STAR L2

Popular

Cloud Security Alliance STAR Attestation

Third-party independent assessment of cloud security.

TX-RAMP

Texas Risk and Authorization Management Program

Security requirements for cloud providers doing business with Texas state agencies.

StateRAMP

State Risk and Authorization Management Program

Cybersecurity standards for cloud service providers serving state and local governments.

Essential Eight

ACSC Essential Eight

Australia's baseline cybersecurity strategies.

RegionalExplore

Cyber Essentials

UK Cyber Essentials

A UK government-backed, industry-supported scheme to help organizations protect against cyber threats.

RegionalExplore

TISAX

Trusted Information Security Assessment Exchange

Information security standard for the European automotive industry.

IndustryExplore

FERPA

Family Educational Rights and Privacy Act

Protects the privacy of student education records.

IndustryExplore

COPPA

Children's Online Privacy Protection Act

Regulates the collection of personal information from children under 13.

PrivacyExplore

Custom GRC

Custom Governance, Risk & Compliance

Build your own internal framework based on specific organizational needs.

SecurityExplore

ISO 9001

Quality Management Systems

The international standard for quality management.

IndustryExplore

ISO 14001

Environmental Management

Standard for environmental management systems.

IndustryExplore

ISO 20000

IT Service Management

International standard for IT service management.

SecurityExplore

ISO 45001

Occupational Health and Safety

International standard for health and safety at work.

IndustryExplore

IRAP

Information Security Registered Assessors Program

Australian government security assessment.

RegionalExplore

NESA

National Electronic Security Authority

UAE federal authority responsible for cybersecurity.

RegionalExplore

SACS

Saudi Arabian Cybersecurity Standard

Cybersecurity requirements for entities in Saudi Arabia.

RegionalExplore

Cyber Essentials Plus

UK Cyber Essentials Plus

Verified version of the Cyber Essentials scheme.

RegionalExplore

APRA CPS 234

Information Security Standard

Australian Prudential Regulation Authority standard for information security.

FinanceExplore

NY DFS 500

Cybersecurity Requirements for Financial Services Companies

New York state regulation for financial institutions.

FinanceExplore

MAS TRM

Monetary Authority of Singapore Technology Risk Management

Guidelines for managing technology risk in financial institutions in Singapore.

FinanceExplore

K-ISMS

Korea Information Security Management System

Information security certification system in South Korea.

RegionalExplore

T-RAMP

Thailand Risk and Authorization Management Program

Cloud security standards for the Thai government.

RegionalExplore

Don't see your framework?
We probably support it.

Our neural engine supports custom control mapping for virtually any regulatory requirement, industry standard, or internal security policy.

100% Custom Control Support