Compliance Frameworks.
Explore our comprehensive library of 200+ global frameworks. Cyrama automates the evidence collection and monitoring for every control.
Showing 53 Standards
SOC 2 Type I
PopularService Organization Control 2 (Point-in-time)
Evaluates the design of security controls at a specific point in time.
SOC 2 Type II
PopularService Organization Control 2 (Period-of-time)
The industry standard for SaaS security, evaluating control effectiveness over 6-12 months.
ISO 27001
PopularInformation Security Management System
The primary international standard for establishing and maintaining an ISMS.
ISO 27017
Cloud Security Controls
Guidelines for information security controls applicable to the provision and use of cloud services.
ISO 27018
Cloud Privacy Protection
Focuses on protecting personal data in the cloud.
ISO 22301
Business Continuity Management
Specifies requirements to plan, establish, and operate a documented management system to protect against disruptions.
NIST CSF
PopularNIST Cybersecurity Framework
A voluntary framework to manage and reduce cybersecurity risk for critical infrastructure.
NIST 800-53
Security and Privacy Controls for Information Systems
A comprehensive catalog of controls for federal information systems.
NIST 800-171
Protecting CUI in Nonfederal Systems
Required for contractors handling Controlled Unclassified Information.
GDPR
PopularGeneral Data Protection Regulation
The primary regulation in EU law on data protection and privacy.
CCPA
PopularCalifornia Consumer Privacy Act
Empowers California consumers with rights over their personal data.
CPRA
California Privacy Rights Act
An amendment to CCPA that adds new consumer privacy rights.
VCDPA
Virginia Consumer Data Protection Act
Virginia's comprehensive data privacy law.
LGPD
Lei Geral de Proteção de Dados
Brazil's comprehensive data protection law.
PDPA SG
Personal Data Protection Act (Singapore)
Governs the collection, use, and disclosure of personal data by organizations in Singapore.
PIPEDA
Personal Information Protection and Electronic Documents Act
Canada's federal privacy law for private-sector organizations.
POPIA
Protection of Personal Information Act
South Africa's data protection law.
HIPAA
PopularHealth Insurance Portability and Accountability Act
US law providing data privacy and security provisions for safeguarding medical information.
HITRUST CSF
PopularHealth Information Trust Alliance
A certifiable framework that leverages various standards for healthcare security.
HITECH
Health Information Technology for Economic and Clinical Health
Promotes the adoption and meaningful use of health information technology.
PCI DSS v4.0
PopularPayment Card Industry Data Security Standard
The latest global standard for securing credit card data.
GLBA
Gramm-Leach-Bliley Act
Requires financial institutions to explain their information-sharing practices to customers.
FFIEC
Federal Financial Institutions Examination Council
Uniform principles and standards for the federal examination of financial institutions.
SOC 1
Service Organization Control 1
Focuses on controls at a service organization relevant to user entities' internal control over financial reporting.
FedRAMP High
Federal Risk and Authorization Management Program
Security standards for cloud services used by the US federal government (High Impact).
FedRAMP Med
PopularFederal Risk and Authorization Management Program
Security standards for cloud services used by the US federal government (Moderate Impact).
CMMC Level 1
Cybersecurity Maturity Model Certification
Foundational cybersecurity for DOD contractors.
CMMC Level 2
PopularCybersecurity Maturity Model Certification
Advanced cybersecurity protecting CUI.
FISMA
Federal Information Security Modernization Act
Requires federal agencies to develop, document, and implement an information security program.
ITRR
Information Technology Risk Rating
System for evaluating IT risk within government agencies.
CSA STAR L1
Cloud Security Alliance STAR Self-Assessment
A rigorous self-assessment for cloud provider transparency.
CSA STAR L2
PopularCloud Security Alliance STAR Attestation
Third-party independent assessment of cloud security.
TX-RAMP
Texas Risk and Authorization Management Program
Security requirements for cloud providers doing business with Texas state agencies.
StateRAMP
State Risk and Authorization Management Program
Cybersecurity standards for cloud service providers serving state and local governments.
Essential Eight
ACSC Essential Eight
Australia's baseline cybersecurity strategies.
Cyber Essentials
UK Cyber Essentials
A UK government-backed, industry-supported scheme to help organizations protect against cyber threats.
TISAX
Trusted Information Security Assessment Exchange
Information security standard for the European automotive industry.
FERPA
Family Educational Rights and Privacy Act
Protects the privacy of student education records.
COPPA
Children's Online Privacy Protection Act
Regulates the collection of personal information from children under 13.
Custom GRC
Custom Governance, Risk & Compliance
Build your own internal framework based on specific organizational needs.
ISO 9001
Quality Management Systems
The international standard for quality management.
ISO 14001
Environmental Management
Standard for environmental management systems.
ISO 20000
IT Service Management
International standard for IT service management.
ISO 45001
Occupational Health and Safety
International standard for health and safety at work.
IRAP
Information Security Registered Assessors Program
Australian government security assessment.
NESA
National Electronic Security Authority
UAE federal authority responsible for cybersecurity.
SACS
Saudi Arabian Cybersecurity Standard
Cybersecurity requirements for entities in Saudi Arabia.
Cyber Essentials Plus
UK Cyber Essentials Plus
Verified version of the Cyber Essentials scheme.
APRA CPS 234
Information Security Standard
Australian Prudential Regulation Authority standard for information security.
NY DFS 500
Cybersecurity Requirements for Financial Services Companies
New York state regulation for financial institutions.
MAS TRM
Monetary Authority of Singapore Technology Risk Management
Guidelines for managing technology risk in financial institutions in Singapore.
K-ISMS
Korea Information Security Management System
Information security certification system in South Korea.
T-RAMP
Thailand Risk and Authorization Management Program
Cloud security standards for the Thai government.
Don't see your framework?
We probably support it.
Our neural engine supports custom control mapping for virtually any regulatory requirement, industry standard, or internal security policy.