Included Laws, Regulations & Frameworks (LRF)

The SCF maps to 200+ unique laws, regulations, and frameworks across five geographic categories: General, USA, EMEA, APAC, and Americas. When you implement SCF controls, you satisfy requirements across all mapped LRF simultaneously through Set Theory Relationship Mapping (STRM).

200+

Unique LRF Mapped

5

Geographic Regions

2026.1

Current SCF Version

Download the SCF Learn More About the SCF

how lrf coverage works

One Control Set. Hundreds of Security, Compliance & Resilience Mappings.

The SCF Authoritative Sources tab in the downloadable spreadsheet contains every mapped LRF. Each SCF control includes columns showing which specific LRF requirements that control satisfies. These Authoritative Sources are categorized by:

  • General Frameworks (univeral and not country/geo-specific)
  • USA- United States of America
  • EMEA- Europe, Middle East & Africa
  • APAC- Asia Pacific
  • Americas- Non-USA North, Central & South America

To understand the coverage for these Laws, Regulations and Frameworks (LRF), please read through how the SCF leverages Set Theory Relationship Mapping (STRM) according to NIST IR 8477 to demonstrate how SCF controls address targeted LRF requirements. The 2026.1 version of the SCF contains coverage for 250 unique LRF:

The practical result: if your organization needs to comply with GDPR, HIPAA, and NIST CSF 2.0 simultaneously, you implement a single tailored set of SCF controls rather than three separate compliance programs. Each control tells you exactly which requirements from each framework it addresses.

Browse by Region

Included Laws, Regulations & Frameworks

The SCF maps to 200+ cybersecurity and data privacy laws, regulations, and frameworks worldwide. Filter by region or search to find what you need.

ALL GENERAL USA EMEA APAC AMERICAS

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

Americas

Colombia

Colombia - Law 1581 (2012)

View authoritative source (external link) →

Americas

Mexico

Mexico - Federal Law on Protection of Personal Data held by Private Parties (2010)

View authoritative source (external link) →

Americas

Canada

Canada - Personal Information Protection and Electronic Documents Act (PIPEDA) (2000)

View authoritative source (external link) →

Americas

Chile

Chile - Act 19628 - Protection of Personal Data (1999)

View authoritative source (external link) →

Americas

✓ STRM

Canada

Canada - Protecting controlled information in non-Government of Canada systems and organizations (ITSP.10.171)

View authoritative source (external link) →

Americas

✓ STRM

Canada

Canada - OSFI B-13 (2022)

View authoritative source (external link) →

Americas

Canada

Office of the Superintendent of Financial Institutions Canada (OSFI) - Cyber Security Self-Assessment Guidance

View authoritative source (external link) →

Americas

Brazil

Brazil - General Data Protection Law (LGPD) (2018)

View authoritative source (external link) →

Americas

Bermuda

Bermuda - Bermuda Monetary Authority (BMA) Insurance Sector Operational Cyber Risk Management Code of Conduct (2020)

View authoritative source (external link) →

Americas

Bahamas

Data Protection Act (2003)

View authoritative source (external link) →

Americas

Argentina

Protection of Personal Data - MEN-2018-147-APN-PTE (2018)

View authoritative source (external link) →

APAC

Taiwan

Taiwan - Personal Data Protection Act (PDPA) (2025)

View authoritative source (external link) →

APAC

Singapore

Singapore - Monitory Authority of Singapore (MAS) Technology Risk Management (TRM) Guidelines (2021)

View authoritative source (external link) →

APAC

South Korea

South Korea - Personal Information Protection Act (PIPA) (2011)

View authoritative source (external link) →

APAC

Singapore

Singapore - Cyber Hygiene Practice (2019)

View authoritative source (external link) →

APAC

Singapore

Singapore - Personal Data Protection Ac (PDPA) (2012)

View authoritative source (external link) →

APAC

Philippines

Philippines - Data Privacy Act (DPA) (2012)

View authoritative source (external link) →

APAC

New Zealand

New Zealand - Privacy Act (2020)

View authoritative source (external link) →

APAC

New Zealand

New Zealand - Information Security Manual (ISM) v3.9

View authoritative source (external link) →

APAC

✓ STRM

New Zealand

New Zealand - HISO 10029:2024 NZ Health Information Security Framework Guidance for Suppliers

View authoritative source (external link) →

APAC

✓ STRM

New Zealand

New Zealand - HISF MicroSmall (2023)

View authoritative source (external link) →

APAC

Malaysia

Malaysia - Personal Data Protection Act (PDPA) (2010)

View authoritative source (external link) →

APAC

✓ STRM

New Zealand

New Zealand - HISF MLHSP (2023)

View authoritative source (external link) →

APAC

Japan

Japan - Information System Security Management and Assessment Program (ISMAP)

View authoritative source (external link) →

APAC

Japan

Japan - Act on the Protection of Personal Information (2020)

View authoritative source (external link) →

APAC

✓ STRM

India

India - SEBI Cybersecurity and Cyber Resilience Framework (2024)

View authoritative source (external link) →

APAC

India

India - Information Technology Rules (Privacy Rules) (2011)

View authoritative source (external link) →

APAC

✓ STRM

India

India Digital Personal Data Protection Act (2023)

View authoritative source (external link) →

APAC

Hong Kong

Hong Kong - Personal Data Ordinance (2022)

View authoritative source (external link) →

APAC

China

China - Decision on Strengthening Network Information Protection (2012)

View authoritative source (external link) →

APAC

China

China - Personal Information Protection Law of the People's Republic of China (2021)

View authoritative source (external link) →

APAC

China

China - Data Security Law of the People's Republic of China (2021)

View authoritative source (external link) →

APAC

✓ STRM

China

China - Cybersecurity Law of the People's Republic of China (2017)

View authoritative source (external link) →

APAC

Australia

Australia - Prudential Standard CPS 234 Information Security (2019)

View authoritative source (external link) →

APAC

Australia

Australia - Prudential Standard CPS 230 - Operational Risk Management (2023)

View authoritative source (external link) →

APAC

✓ STRM

Australia

Australia - Information Security Manual (ISM) (June 2024)

View authoritative source (external link) →

APAC

Australia

Australia - Privacy Principles (2026)

View authoritative source (external link) →

APAC

Australia

Australia - Code of Practice - Securing the Internet of Things for Consumers (2020)

View authoritative source (external link) →

APAC

Australia

Australia - Privacy Act of 1998

View authoritative source (external link) →

APAC

✓ STRM

Australia

Australia -Essential Eight maturity model and ISM mapping (2024)

View authoritative source (external link) →

EMEA

United Kingdom

UK - Data Protection Act (DPA) (1998)

View authoritative source (external link) →

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L3

View authoritative source (external link) →

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L2

View authoritative source (external link) →

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L0

View authoritative source (external link) →

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L1

View authoritative source (external link) →

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024)

View authoritative source (external link) →

EMEA

✓ STRM

Spain

Royal Decree 311/2022, of May 3, which regulates the National Security Scheme (BOE-A-2022-7191)

View authoritative source (external link) →

EMEA

United Kingdom

UK - Cyber Essentials: Requirements for IT Infrastructure v3.3

View authoritative source (external link) →

EMEA

United Kingdom

UK - Cyber Assessment Framework for Aviation Guidance (CAP1850) (2020)

View authoritative source (external link) →

EMEA

✓ STRM

United Kingdom

UK - Cyber Assessment Framework (CAF) v4.0

View authoritative source (external link) →

EMEA

✓ STRM

UAE

UAE - National Information Assurance Framework (NIAF) (2023)

View authoritative source (external link) →

EMEA

Turkey

Law on the Protection of Personal Data (LPPD) (2016)

View authoritative source (external link) →

EMEA

Spain

Spain - Royal Decree 311/2022

View authoritative source (external link) →

EMEA

Spain

Spain - ICT Security Guide CCN-STIC 825 (2023)

View authoritative source (external link) →

EMEA

Spain

Spain - Royal Decree 1720/2007

View authoritative source (external link) →

EMEA

Switzerland

Switzerland - Federal Act on Data Protection (FADP) (2025)

View authoritative source (external link) →

EMEA

✓ STRM

Saudi Arabia

Saudi Arabia - Personal Data Protection Law (PDPL) (2023)

View authoritative source (external link) →

USA

✓ STRM

State

Colorado Privacy Act (2021)

View authoritative source (external link) →

EMEA

South Africa

South Africa - Protection of Personal Information Act (POPIA) (2013)

View authoritative source (external link) →

EMEA

Serbia

Serbia - Act of 9 November 2018 on Personal Data Protection (Official Gazette No. 87/18)

View authoritative source (external link) →

EMEA

Saudi Arabia

Saudi Arabia - Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework Version 1.0 (2017)

View authoritative source (external link) →

EMEA

Saudi Arabia

Saudi Arabia - SACS-002 Third Party Cybersecurity Standard (2022)

View authoritative source (external link) →

EMEA

Saudi Arabia

Saudi Arabia - Operational Technology Cybersecurity Controls (OTCC -1: 2022)

View authoritative source (external link) →

EMEA

Saudi Arabia

Saudi Arabia - Essential Cybersecurity Controls (ECC – 1 : 2018)

View authoritative source (external link) →

EMEA

✓ STRM

Saudi Arabia

Saudi Arabia - Cybersecurity Guidelines for Internet of Things (CGIoT-1:2024)

View authoritative source (external link) →

EMEA

Saudi Arabia

Saudi Arabia - Critical Systems Cybersecurity Controls (CSCC – 1: 2019)

View authoritative source (external link) →

EMEA

Russia

Russia - Federal Law of 27 (2006)

View authoritative source (external link) →

EMEA

Qatar

Qatar - Personal Data Privacy Protection Law (PDPPL) (2020)

View authoritative source (external link) →

EMEA

Poland

Poland - Act of 29 August 1997 on the Protection of Personal Data

View authoritative source (external link) →

EMEA

Norway

Norway - Personal Data Act (PDA) (2018)

View authoritative source (external link) →

EMEA

Nigeria

Nigeria - Data Protection Regulation (DPR) (2019)

View authoritative source (external link) →

EMEA

Kenya

Kenya - Data Protection Act (DPA) (2019)

View authoritative source (external link) →

EMEA

Italy

Italy - Personal Data Protection Code (2003)

View authoritative source (external link) →

EMEA

Israel

Israel - Protection of Privacy Law, 5741 (1981)

View authoritative source (external link) →

EMEA

Ireland

Ireland - Data Protection Act (DPA) (2003)

View authoritative source (external link) →

EMEA

Israel

Cybersecurity Methodology for an Organization v1.0

View authoritative source (external link) →

EMEA

Hungary

Hungary - Informational Self-Determination and Freedom of Information (Act CXII of 2011)

View authoritative source (external link) →

EMEA

Germany

Germany - Banking Supervisory Requirements for IT (2017)

View authoritative source (external link) →

EMEA

Germany

Germany - Cloud Computing Compliance Controls Catalogue (C5) (2020)

View authoritative source (external link) →

EMEA

Greece

Greece - Protection of Individuals with Regard to the Processing of Personal Data (2472/1997)

View authoritative source (external link) →

EMEA

Germany

Germany - Federal Data Protection Act (2017)

View authoritative source (external link) →

EMEA

Belgium

Belgium - Act of 8 December 1992

View authoritative source (external link) →

EMEA

Austria

Austria - Federal Act concerning the Protection of Personal Data (2000)

View authoritative source (external link) →

EMEA

EU

Second Payment Services Directive (PSD2) (2015)

View authoritative source (external link) →

EMEA

✓ STRM

EU

European Union Agency for Cybersecurity NIS2 (Directive (EU) 2022/2555)

View authoritative source (external link) →

EMEA

✓ STRM

EU

European Union Agency for Cybersecurity NIS2 Annex (2024)

View authoritative source (external link) →

EMEA

✓ STRM

EU

European Union General Data Protection Regulation (2016)

View authoritative source (external link) →

EMEA

✓ STRM

EU

Digital Operational Resilience Act (2023)

View authoritative source (external link) →

EMEA

EU

European Banking Authority Guidelines on ICT and Security Risk Management (2025)

View authoritative source (external link) →

EMEA

✓ STRM

EU

European Union Cyber Resilience Act - Annexes (2022)

View authoritative source (external link) →

EMEA

✓ STRM

EU

European Union Cyber Resilience Act (2022)

View authoritative source (external link) →

EMEA

✓ STRM

EU

European Union Artificial Intelligence Act (Regulation (EU) 2024/1689)

View authoritative source (external link) →

USA

✓ STRM

State

Virginia Consumer Data Protection Act (2023)

View authoritative source (external link) →

USA

✓ STRM

State

Vermont Data Broker Registration Act (Act 171 of 2018)

View authoritative source (external link) →

USA

✓ STRM

State

Texas Risk & Authorization Management Program 2.0 - Level 2

View authoritative source (external link) →

USA

✓ STRM

State

Texas Safe Harbor Law (SB2610) (2025)

View authoritative source (external link) →

USA

✓ STRM

State

Texas Risk & Authorization Management Program 2.0 - Level 1

View authoritative source (external link) →

USA

✓ STRM

State

Texas SB820 (2019)

View authoritative source (external link) →

USA

✓ STRM

State

Tennessee Information Protection Act (TIPA) (2025)

View authoritative source (external link) →

USA

✓ STRM

State

Texas Identity Theft Enforcement and Protection Act (BC521) (2009)

View authoritative source (external link) →

USA

✓ STRM

State

Texas DIR Security Control Standards Catalog v2.2

View authoritative source (external link) →

USA

✓ STRM

State

Texas Consumer Data Protection Act (2025)

View authoritative source (external link) →

USA

✓ STRM

State

New York Department of Financial Services 23NYCRR Part 500 (2023 Amendment 2)

View authoritative source (external link) →

USA

✓ STRM

State

Oregon Consumer Privacy Act (SB 619) (2023)

View authoritative source (external link) →

USA

✓ STRM

State

Oregon Consumer Information Protection Act (ORS 646A) (2025)

View authoritative source (external link) →

USA

✓ STRM

State

New York SHIELD Act (SB S5575B) (2019)

View authoritative source (external link) →

USA

✓ STRM

State

Nevada SB220 (2019)

View authoritative source (external link) →

USA

✓ STRM

State

Nevada Privacy Law (2023)- CHAPTER 603A - SECURITY AND PRIVACY OF PERSONAL INFORMATION

View authoritative source (external link) →

USA

✓ STRM

State

Nevada Operation of Gaming Establishments - Regulation 5.260 (Cybersecurity)

View authoritative source (external link) →

USA

✓ STRM

State

Massachusetts 201 CMR 17.00 (2008)

View authoritative source (external link) →

USA

✓ STRM

State

Illinois Personal Information Protection Act (PIPA) (2006)

View authoritative source (external link) →

USA

✓ STRM

State

Illinois Identity Protection Act (IPA) (2009)

View authoritative source (external link) →

USA

✓ STRM

State

Illinois Biometric Information Privacy Act (BIPA) (2008)

View authoritative source (external link) →

USA

✓ STRM

State

California SB1386 (2002)

View authoritative source (external link) →

USA

✓ STRM

State

California SB327 (2018)

View authoritative source (external link) →

USA

✓ STRM

State

Alaska Personal Information Protection Act (PIPA) (2009)

View authoritative source (external link) →

USA

✓ STRM

State

California Consumer Privacy Act (CCPA) (January 2026) - amended California Privacy Rights Act (CPRA)

View authoritative source (external link) →

USA

✓ STRM

Federal

Transportation Security Administration Security Directive 1580/82-2022-01 - Rail Cybersecurity Mitigation Actions and Testing

View authoritative source (external link) →

USA

✓ STRM

Federal

Sarbanes Oxley Act (2002)

View authoritative source (external link) →

USA

✓ STRM

Federal

SEC Cybersecurity Rule (2023)

View authoritative source (external link) →

USA

✓ STRM

Federal

North American Electric Reliability Corporation Critical Infrastructure Protection (2024)

View authoritative source (external link) →

USA

✓ STRM

Federal

National Industrial Security Program Operating Manual (2020)

View authoritative source (external link) →

USA

✓ STRM

Federal

Safeguarding of Naval Nuclear Propulsion Information (NNPI) (2010)

View authoritative source (external link) →

USA

✓ STRM

Federal

US Centers for Medicare & Medicaid Services MARS-E Document Suite, Version 2.0

View authoritative source (external link) →

USA

✓ STRM

Federal

Internal Revenue Service 1075 (2021)

View authoritative source (external link) →

USA

✓ STRM

Federal

HIPAA Security Rule (2013)

View authoritative source (external link) →

USA

✓ STRM

Federal

HIPAA Administrative Simplification (2013)

USA

✓ STRM

Federal

Gramm Leach Bliley Act - CFR 314 (Dec 2023)

View authoritative source (external link) →

USA

✓ STRM

Federal

HHS § 155.260 - Privacy and Security of Personally Identifiable Information (2016)

View authoritative source (external link) →

USA

✓ STRM

Federal

Federal Trade Commission (FTC) Act

View authoritative source (external link) →

USA

✓ STRM

Federal

US Fair Information Practice Principles (FIPPs) (1973)

View authoritative source (external link) →

USA

✓ STRM

Federal

Financial Industry Regulatory Authority (FINRA) Cybersecurity Rules

View authoritative source (external link) →

USA

✓ STRM

Federal

Family Educational Rights and Privacy Act (FERPA) (2010)

View authoritative source (external link) →

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - Li-SAAS Baseline

View authoritative source (external link) →

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - High Baseline

View authoritative source (external link) →

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - Moderate Baseline

View authoritative source (external link) →

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - Low Baseline

View authoritative source (external link) →

USA

✓ STRM

Federal

Food & Drug Administration 21 CFR Part 11 (2025)

View authoritative source (external link) →

USA

✓ STRM

Federal

Farm Credit Administration Cyber Risk Management (2023)

View authoritative source (external link) →

USA

✓ STRM

Federal

Federal Acquisition Regulation 52.204-27 - Prohibition on a ByteDance Covered Application

View authoritative source (external link) →

USA

✓ STRM

Federal

Federal Acquisition Regulation 52.204-25 (NDAA Section 889) - Prohibition on Contracting With Entities Using Certain Telecommunications and Video Surveillance Services or Equipment

View authoritative source (external link) →

USA

✓ STRM

Federal

Federal Acquisition Regulation 52.204-21 - Basic Safeguarding of Covered Contractor Information Systems

View authoritative source (external link) →

USA

✓ STRM

Federal

Fair & Accurate Credit Transactions Act (FACTA) & Fair Credit Reporting Act (FCRA) (2023)

View authoritative source (external link) →

USA

✓ STRM

Federal

Executive Order 14028 - Improving the Nation's Cybersecurity

View authoritative source (external link) →

USA

✓ STRM

Federal

Department of War (DoW) - Zero Trust Reference Architecture v2

View authoritative source (external link) →

USA

✓ STRM

Federal

Defense Federal Acquisition Regulation Supplement 252.204-7012

View authoritative source (external link) →

USA

✓ STRM

Federal

Data Privacy Framework (2023)

View authoritative source (external link) →

USA

✓ STRM

Federal

Department of War (DoW) - Zero Trust Execution Roadmap v1.1

View authoritative source (external link) →

USA

✓ STRM

Federal

US Department of Justice - Criminal Justice Information Services (CJIS) Security Policy v6.0

View authoritative source (external link) →

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 3

View authoritative source (external link) →

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 2

View authoritative source (external link) →

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 1 Assessment Objectives

View authoritative source (external link) →

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 1

View authoritative source (external link) →

USA

✓ STRM

Federal

Department of Energy (DOE) - Cybersecurity Capability Maturity Model version 2.1

View authoritative source (external link) →

USA

✓ STRM

Federal

Cybersecurity & Infrastructure Security Agency (CISA) Cross-Sector Cybersecurity Performance Goals 2.0

View authoritative source (external link) →

USA

✓ STRM

Federal

Cybersecurity & Infrastructure Security Agency (CISA) Trusted Internet Connections 3.0 Security Capabilities Catalog

View authoritative source (external link) →

USA

✓ STRM

Federal

Cybersecurity & Infrastructure Security Agency (CISA) Secure Software Development Attestation Form (SSDAF) (2024)

View authoritative source (external link) →

USA

✓ STRM

Federal

Children's Online Privacy Protection Act (COPPA) (2024)

View authoritative source (external link) →

USA

✓ STRM

Federal

US Computer Emergency Response Team Resilience Management Model Version 1.2

View authoritative source (external link) →

General

✓ STRM

United Nations

United Nations Regulation No. 155 - Cyber security and cyber security management system (2021)

View authoritative source (external link) →

General

✓ STRM

United Nations

United Nations Economic Commission for Europe - Working Party on Automated/autonomous and Connected Vehicles -Proposal for a new UN Regulation on uniform provisions concerning the approval of vehicles with regards to cyber security and cyber security manag

View authoritative source (external link) →

General

✓ STRM

UL

UL 2900-2-2 Ed. 1-2016 - Outline of Investigation for Software Cybersecurity for Network-Connectable Products, Part 2-2: Particular Requirements for Industrial Control Systems

View authoritative source (external link) →

General

✓ STRM

UL

UL 2900-1- Software Cybersecurity for Network-Connectable Products, Part 1: General Requirements (2017)

View authoritative source (external link) →

General

✓ STRM

TISAX

Trusted Information Security Assessment Exchange (TISAX) 6.0.3

View authoritative source (external link) →

General

✓ STRM

SWIFT

Society for Worldwide Interbank Financial Telecommunication Customer Security Controls Framework 2025

View authoritative source (external link) →

General

Shared Assessments

Shared Assessments Standard Information Gathering (SIG) Questionnaire 2025

View authoritative source (external link) →

General

✓ STRM

SPARTA

Space Attack Research & Tactic Analysis (SPARTA) Countermeasures

View authoritative source (external link) →

General

✓ STRM

SCF

Secure Controls Framework (SCF) Data Privacy Management Principles (2025)

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire P2PE

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire D Service Provider

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire D Merchant

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire C-VT

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire B-IP

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire C

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire B

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire A-EP

View authoritative source (external link) →

General

✓ STRM

OWASP

Open Worldwide Application Security Project (OWASP) Top 10 (2025)

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire A

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.01

View authoritative source (external link) →

General

✓ STRM

OECD

Organisation for Economic Co-operation and Development Privacy Principles

View authoritative source (external link) →

General

✓ STRM

NIST

NIST Cybersecurity Framework v2.0

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-218 - Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-207 - Zero Trust Architecture

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-172 - Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-171A R3 - Assessing Security Requirements for Controlled Unclassified Information

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-171 R2 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-171 R3 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 3 Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 2 Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 1 Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Flow Down Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - C-SCRM Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-160 Volume 2, Revision 1 - Developing Cyber-Resilient Systems: A Systems Security Engineering Approach

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - High OT Overlay

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Moderate OT Overlay

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Low OT Overlay

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Low OT Overlay

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-66 R2 - Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - High Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Moderate Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Low Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Privacy Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations

View authoritative source (external link) →

General

NIST

NIST SP 800-53 R4 - Security and Privacy Controls for Federal Information Systems and Organizations

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-39 - Managing Information Security Risk: Organization, Mission, and Information System View

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-37 R2 - Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy

View authoritative source (external link) →

General

✓ STRM

NIST

NIST Privacy Framework v1.0

View authoritative source (external link) →

General

✓ STRM

NIST

NIST AI 600-1 - Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile

View authoritative source (external link) →

General

✓ STRM

NIST

NIST AI 100-1 - Artificial Intelligence Risk Management Framework (AI RMF 1.0)

View authoritative source (external link) →

General

✓ STRM

NAIC

National Association of Insurance Commissioners Insurance Data Security Model Law (MDL-668) (2017)

View authoritative source (external link) →

General

✓ STRM

MPA

Motion Picture Association (MPA) Content Security Best Practices Common Guidelines v5.3.1

View authoritative source (external link) →

General

✓ STRM

MITRE

MITRE Adversarial Tactics, Techniques, and Common Knowledge - NIST 800-53 mappings

View authoritative source (external link) →

General

✓ STRM

ISO

ISO/IEC 42001:2023 - Information technology - Artificial intelligence - Management system

View authoritative source (external link) →

General

✓ STRM

ISO

IEC 31010:2019 - Risk management - Risk assessment techniques

View authoritative source (external link) →

General

✓ STRM

ISO

ISO/IEC 29100:2024 - Information technology - Security techniques - Privacy framework

View authoritative source (external link) →

General

✓ STRM

ISO

ISO 31000:2018 - Risk management - Guidelines

View authoritative source (external link) →

General

✓ STRM

ISO

ISO/IEC 27701:2025 - Information security, cybersecurity and privacy protection - Privacy information management systems - Requirements and guidance

View authoritative source (external link) →

General

✓ STRM

ISO

ISO/IEC 27018:2025 - Information security, cybersecurity and privacy protection - Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors

View authoritative source (external link) →

General

✓ STRM

ISO

ISO/IEC 27017:2015 - Information technology - Security techniques -Code of practice for information security controls based on ISO/IEC 27002 for cloud services

View authoritative source (external link) →

General

✓ STRM

ISO

ISO/IEC 27002:2022 - Information security, cybersecurity and privacy protection - Information security controls

View authoritative source (external link) →

General

✓ STRM

ISO

ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection - Information security management systems - Requirements

View authoritative source (external link) →

General

✓ STRM

ISO

ISO 22301:2019 - Security and resilience - Business continuity management systems - Requirements

View authoritative source (external link) →

General

✓ STRM

IEC

ISO/SAE 21434:2021 - Road vehicles - Cybersecurity engineering

View authoritative source (external link) →

General

✓ STRM

IMO

International Maritime Organization (IMO) Guidelines on Maritime Cyber Risk Management (2025)

View authoritative source (external link) →

General

✓ STRM

IEC

International Electrotechnical Commission 62443-4-1:2018 - Security for industrial automation and control systems - Part 4-1: Secure product development lifecycle requirements

View authoritative source (external link) →

General

✓ STRM

IEC

International Electrotechnical Commission 62443-4-2 Ed. 1.0 b:2019 - Security for industrial automation and control systems - Part 4-2: Technical security requirements for IACS components

View authoritative source (external link) →

General

✓ STRM

IEC

International Electrotechnical Commission 62443-3-3:2013 - Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels

View authoritative source (external link) →

General

✓ STRM

IEC

International Electrotechnical Commission 62443-2-1:2024 - Security for industrial automation and control systems - Part 2-1: Security program requirements for IACS asset owners

View authoritative source (external link) →

General

✓ STRM

IEC

International Electrotechnical Commission Technical Report 60601-4-5:2021 - Medical electrical equipment - Part 4-5: Guidance and interpretation - Safety-related technical security specifications

View authoritative source (external link) →

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - High

View authoritative source (external link) →

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Moderate

View authoritative source (external link) →

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Core Controls

View authoritative source (external link) →

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP)

View authoritative source (external link) →

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Low+

View authoritative source (external link) →

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Low

View authoritative source (external link) →

General

✓ STRM

CR

Cyber Resilience Capability Maturity Model (CR-CMM) (2026)

View authoritative source (external link) →

General

✓ STRM

COSO

Committee of Sponsoring Organizations (COSO) (2013)

View authoritative source (external link) →

General

✓ STRM

CSA

Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) v4.1.0

View authoritative source (external link) →

General

✓ STRM

ISACA

Control Objectives for Information and Related Technologies (COBIT) (2019)

View authoritative source (external link) →

General

✓ STRM

CSA

Cloud Security Alliance (CSA) Internet of Things Security Controls Framework v2

View authoritative source (external link) →

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG3

View authoritative source (external link) →

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG2

View authoritative source (external link) →

General

✓ STRM

APEC

Asia-Pacific Economic Cooperation (APEC) Privacy Framework (2015)

View authoritative source (external link) →

General

✓ STRM

BSI

Bundesamt für Sicherheit in der Informationstechnik (BSI) - Standard 200-1 (v1.0)

View authoritative source (external link) →

General

✓ STRM

AICPA

American Institute of Certified Public Accountants (AICPA) Trust Services Criteria (2017)

View authoritative source (external link) →

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1

View authoritative source (external link) →

General

✓ STRM

AICPA

American Institute of Certified Public Accountants (AICPA) Privacy Management Framework (PMF) (2020)

View authoritative source (external link) →

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG1

View authoritative source (external link) →

Back Next

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

General

✓ STRM

United Nations

United Nations Regulation No. 155 - Cyber security and cyber security management system (2021)

View authoritative source (external link) →

General

✓ STRM

United Nations

View authoritative source (external link) →

General

✓ STRM

UL

View authoritative source (external link) →

General

✓ STRM

UL

UL 2900-1- Software Cybersecurity for Network-Connectable Products, Part 1: General Requirements (2017)

View authoritative source (external link) →

General

✓ STRM

TISAX

Trusted Information Security Assessment Exchange (TISAX) 6.0.3

View authoritative source (external link) →

General

✓ STRM

SWIFT

Society for Worldwide Interbank Financial Telecommunication Customer Security Controls Framework 2025

View authoritative source (external link) →

General

Shared Assessments

Shared Assessments Standard Information Gathering (SIG) Questionnaire 2025

View authoritative source (external link) →

General

✓ STRM

SPARTA

Space Attack Research & Tactic Analysis (SPARTA) Countermeasures

View authoritative source (external link) →

General

✓ STRM

SCF

Secure Controls Framework (SCF) Data Privacy Management Principles (2025)

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire P2PE

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire D Service Provider

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire D Merchant

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire C-VT

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire B-IP

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire C

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire B

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire A-EP

View authoritative source (external link) →

General

✓ STRM

OWASP

Open Worldwide Application Security Project (OWASP) Top 10 (2025)

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire A

View authoritative source (external link) →

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.01

View authoritative source (external link) →

General

✓ STRM

OECD

Organisation for Economic Co-operation and Development Privacy Principles

View authoritative source (external link) →

General

✓ STRM

NIST

NIST Cybersecurity Framework v2.0

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-218 - Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-207 - Zero Trust Architecture

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-172 - Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-171A R3 - Assessing Security Requirements for Controlled Unclassified Information

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-171 R2 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-171 R3 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 3 Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 2 Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 1 Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Flow Down Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - C-SCRM Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-160 Volume 2, Revision 1 - Developing Cyber-Resilient Systems: A Systems Security Engineering Approach

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - High OT Overlay

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Moderate OT Overlay

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Low OT Overlay

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Low OT Overlay

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-66 R2 - Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - High Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Moderate Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Low Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Privacy Baseline

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations

View authoritative source (external link) →

General

NIST

NIST SP 800-53 R4 - Security and Privacy Controls for Federal Information Systems and Organizations

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-39 - Managing Information Security Risk: Organization, Mission, and Information System View

View authoritative source (external link) →

General

✓ STRM

NIST

NIST SP 800-37 R2 - Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy

View authoritative source (external link) →

General

✓ STRM

NIST

NIST Privacy Framework v1.0

View authoritative source (external link) →

General

✓ STRM

NIST

NIST AI 600-1 - Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile

View authoritative source (external link) →

General

✓ STRM

NIST

NIST AI 100-1 - Artificial Intelligence Risk Management Framework (AI RMF 1.0)

View authoritative source (external link) →

General

✓ STRM

NAIC

National Association of Insurance Commissioners Insurance Data Security Model Law (MDL-668) (2017)

View authoritative source (external link) →

General

✓ STRM

MPA

Motion Picture Association (MPA) Content Security Best Practices Common Guidelines v5.3.1

General

✓ STRM

MITRE

MITRE Adversarial Tactics, Techniques, and Common Knowledge - NIST 800-53 mappings

View authoritative source (external link) →

General

✓ STRM

ISO

ISO/IEC 42001:2023 - Information technology - Artificial intelligence - Management system

View authoritative source (external link) →

General

✓ STRM

ISO

IEC 31010:2019 - Risk management - Risk assessment techniques

View authoritative source (external link) →

General

✓ STRM

ISO

ISO/IEC 29100:2024 - Information technology - Security techniques - Privacy framework

View authoritative source (external link) →

General

✓ STRM

ISO

ISO 31000:2018 - Risk management - Guidelines

View authoritative source (external link) →

General

✓ STRM

ISO

ISO/IEC 27701:2025 - Information security, cybersecurity and privacy protection - Privacy information management systems - Requirements and guidance

View authoritative source (external link) →

General

✓ STRM

ISO

View authoritative source (external link) →

General

✓ STRM

ISO

ISO/IEC 27017:2015 - Information technology - Security techniques -Code of practice for information security controls based on ISO/IEC 27002 for cloud services

View authoritative source (external link) →

General

✓ STRM

ISO

ISO/IEC 27002:2022 - Information security, cybersecurity and privacy protection - Information security controls

View authoritative source (external link) →

General

✓ STRM

ISO

ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection - Information security management systems - Requirements

View authoritative source (external link) →

General

✓ STRM

ISO

ISO 22301:2019 - Security and resilience - Business continuity management systems - Requirements

View authoritative source (external link) →

General

✓ STRM

IEC

ISO/SAE 21434:2021 - Road vehicles - Cybersecurity engineering

View authoritative source (external link) →

General

✓ STRM

IMO

International Maritime Organization (IMO) Guidelines on Maritime Cyber Risk Management (2025)

General

✓ STRM

IEC

View authoritative source (external link) →

General

✓ STRM

IEC

View authoritative source (external link) →

General

✓ STRM

IEC

View authoritative source (external link) →

General

✓ STRM

IEC

View authoritative source (external link) →

General

✓ STRM

IEC

View authoritative source (external link) →

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - High

View authoritative source (external link) →

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Moderate

View authoritative source (external link) →

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Core Controls

View authoritative source (external link) →

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP)

View authoritative source (external link) →

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Low+

View authoritative source (external link) →

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Low

View authoritative source (external link) →

General

✓ STRM

CR

Cyber Resilience Capability Maturity Model (CR-CMM) (2026)

View authoritative source (external link) →

General

✓ STRM

COSO

Committee of Sponsoring Organizations (COSO) (2013)

View authoritative source (external link) →

General

✓ STRM

CSA

Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) v4.1.0

View authoritative source (external link) →

General

✓ STRM

ISACA

Control Objectives for Information and Related Technologies (COBIT) (2019)

View authoritative source (external link) →

General

✓ STRM

CSA

Cloud Security Alliance (CSA) Internet of Things Security Controls Framework v2

View authoritative source (external link) →

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG3

View authoritative source (external link) →

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG2

View authoritative source (external link) →

General

✓ STRM

APEC

Asia-Pacific Economic Cooperation (APEC) Privacy Framework (2015)

General

✓ STRM

BSI

Bundesamt für Sicherheit in der Informationstechnik (BSI) - Standard 200-1 (v1.0)

General

✓ STRM

AICPA

American Institute of Certified Public Accountants (AICPA) Trust Services Criteria (2017)

View authoritative source (external link) →

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1

View authoritative source (external link) →

General

✓ STRM

AICPA

American Institute of Certified Public Accountants (AICPA) Privacy Management Framework (PMF) (2020)

View authoritative source (external link) →

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG1

View authoritative source (external link) →

Back Next

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

USA

✓ STRM

State

Colorado Privacy Act (2021)

View authoritative source (external link) →

USA

✓ STRM

State

Virginia Consumer Data Protection Act (2023)

View authoritative source (external link) →

USA

✓ STRM

State

Vermont Data Broker Registration Act (Act 171 of 2018)

View authoritative source (external link) →

USA

✓ STRM

State

Texas Risk & Authorization Management Program 2.0 - Level 2

View authoritative source (external link) →

USA

✓ STRM

State

Texas Safe Harbor Law (SB2610) (2025)

View authoritative source (external link) →

USA

✓ STRM

State

Texas Risk & Authorization Management Program 2.0 - Level 1

View authoritative source (external link) →

USA

✓ STRM

State

Texas SB820 (2019)

View authoritative source (external link) →

USA

✓ STRM

State

Tennessee Information Protection Act (TIPA) (2025)

View authoritative source (external link) →

USA

✓ STRM

State

Texas Identity Theft Enforcement and Protection Act (BC521) (2009)

View authoritative source (external link) →

USA

✓ STRM

State

Texas DIR Security Control Standards Catalog v2.2

View authoritative source (external link) →

USA

✓ STRM

State

Texas Consumer Data Protection Act (2025)

View authoritative source (external link) →

USA

✓ STRM

State

New York Department of Financial Services 23NYCRR Part 500 (2023 Amendment 2)

View authoritative source (external link) →

USA

✓ STRM

State

Oregon Consumer Privacy Act (SB 619) (2023)

View authoritative source (external link) →

USA

✓ STRM

State

Oregon Consumer Information Protection Act (ORS 646A) (2025)

View authoritative source (external link) →

USA

✓ STRM

State

New York SHIELD Act (SB S5575B) (2019)

View authoritative source (external link) →

USA

✓ STRM

State

Nevada SB220 (2019)

View authoritative source (external link) →

USA

✓ STRM

State

Nevada Privacy Law (2023)- CHAPTER 603A - SECURITY AND PRIVACY OF PERSONAL INFORMATION

View authoritative source (external link) →

USA

✓ STRM

State

Nevada Operation of Gaming Establishments - Regulation 5.260 (Cybersecurity)

View authoritative source (external link) →

USA

✓ STRM

State

Massachusetts 201 CMR 17.00 (2008)

USA

✓ STRM

State

Illinois Personal Information Protection Act (PIPA) (2006)

View authoritative source (external link) →

USA

✓ STRM

State

Illinois Identity Protection Act (IPA) (2009)

View authoritative source (external link) →

USA

✓ STRM

State

Illinois Biometric Information Privacy Act (BIPA) (2008)

View authoritative source (external link) →

USA

✓ STRM

State

California SB1386 (2002)

View authoritative source (external link) →

USA

✓ STRM

State

California SB327 (2018)

View authoritative source (external link) →

USA

✓ STRM

State

Alaska Personal Information Protection Act (PIPA) (2009)

View authoritative source (external link) →

USA

✓ STRM

State

California Consumer Privacy Act (CCPA) (January 2026) - amended California Privacy Rights Act (CPRA)

View authoritative source (external link) →

USA

✓ STRM

Federal

Transportation Security Administration Security Directive 1580/82-2022-01 - Rail Cybersecurity Mitigation Actions and Testing

View authoritative source (external link) →

USA

✓ STRM

Federal

Sarbanes Oxley Act (2002)

View authoritative source (external link) →

USA

✓ STRM

Federal

SEC Cybersecurity Rule (2023)

View authoritative source (external link) →

USA

✓ STRM

Federal

North American Electric Reliability Corporation Critical Infrastructure Protection (2024)

View authoritative source (external link) →

USA

✓ STRM

Federal

National Industrial Security Program Operating Manual (2020)

USA

✓ STRM

Federal

Safeguarding of Naval Nuclear Propulsion Information (NNPI) (2010)

USA

✓ STRM

Federal

US Centers for Medicare & Medicaid Services MARS-E Document Suite, Version 2.0

USA

✓ STRM

Federal

Internal Revenue Service 1075 (2021)

View authoritative source (external link) →

USA

✓ STRM

Federal

HIPAA Security Rule (2013)

USA

✓ STRM

Federal

HIPAA Administrative Simplification (2013)

USA

✓ STRM

Federal

Gramm Leach Bliley Act - CFR 314 (Dec 2023)

View authoritative source (external link) →

USA

✓ STRM

Federal

HHS § 155.260 - Privacy and Security of Personally Identifiable Information (2016)

View authoritative source (external link) →

USA

✓ STRM

Federal

Federal Trade Commission (FTC) Act

View authoritative source (external link) →

USA

✓ STRM

Federal

US Fair Information Practice Principles (FIPPs) (1973)

View authoritative source (external link) →

USA

✓ STRM

Federal

Financial Industry Regulatory Authority (FINRA) Cybersecurity Rules

View authoritative source (external link) →

USA

✓ STRM

Federal

Family Educational Rights and Privacy Act (FERPA) (2010)

View authoritative source (external link) →

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - Li-SAAS Baseline

View authoritative source (external link) →

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - High Baseline

View authoritative source (external link) →

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - Moderate Baseline

View authoritative source (external link) →

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - Low Baseline

View authoritative source (external link) →

USA

✓ STRM

Federal

Food & Drug Administration 21 CFR Part 11 (2025)

View authoritative source (external link) →

USA

✓ STRM

Federal

Farm Credit Administration Cyber Risk Management (2023)

View authoritative source (external link) →

USA

✓ STRM

Federal

Federal Acquisition Regulation 52.204-27 - Prohibition on a ByteDance Covered Application

View authoritative source (external link) →

USA

✓ STRM

Federal

USA

✓ STRM

Federal

Federal Acquisition Regulation 52.204-21 - Basic Safeguarding of Covered Contractor Information Systems

View authoritative source (external link) →

USA

✓ STRM

Federal

Fair & Accurate Credit Transactions Act (FACTA) & Fair Credit Reporting Act (FCRA) (2023)

View authoritative source (external link) →

USA

✓ STRM

Federal

Executive Order 14028 - Improving the Nation's Cybersecurity

View authoritative source (external link) →

USA

✓ STRM

Federal

Department of War (DoW) - Zero Trust Reference Architecture v2

View authoritative source (external link) →

USA

✓ STRM

Federal

Defense Federal Acquisition Regulation Supplement 252.204-7012

View authoritative source (external link) →

USA

✓ STRM

Federal

Data Privacy Framework (2023)

View authoritative source (external link) →

USA

✓ STRM

Federal

Department of War (DoW) - Zero Trust Execution Roadmap v1.1

View authoritative source (external link) →

USA

✓ STRM

Federal

US Department of Justice - Criminal Justice Information Services (CJIS) Security Policy v6.0

View authoritative source (external link) →

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 3

View authoritative source (external link) →

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 2

View authoritative source (external link) →

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 1 Assessment Objectives

View authoritative source (external link) →

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 1

View authoritative source (external link) →

USA

✓ STRM

Federal

Department of Energy (DOE) - Cybersecurity Capability Maturity Model version 2.1

View authoritative source (external link) →

USA

✓ STRM

Federal

Cybersecurity & Infrastructure Security Agency (CISA) Cross-Sector Cybersecurity Performance Goals 2.0

View authoritative source (external link) →

USA

✓ STRM

Federal

Cybersecurity & Infrastructure Security Agency (CISA) Trusted Internet Connections 3.0 Security Capabilities Catalog

View authoritative source (external link) →

USA

✓ STRM

Federal

Cybersecurity & Infrastructure Security Agency (CISA) Secure Software Development Attestation Form (SSDAF) (2024)

View authoritative source (external link) →

USA

✓ STRM

Federal

Children's Online Privacy Protection Act (COPPA) (2024)

View authoritative source (external link) →

USA

✓ STRM

Federal

US Computer Emergency Response Team Resilience Management Model Version 1.2

View authoritative source (external link) →

Back Next

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

EMEA

United Kingdom

UK - Data Protection Act (DPA) (1998)

View authoritative source (external link) →

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L3

View authoritative source (external link) →

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L2

View authoritative source (external link) →

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L0

View authoritative source (external link) →

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L1

View authoritative source (external link) →

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024)

View authoritative source (external link) →

EMEA

✓ STRM

Spain

Royal Decree 311/2022, of May 3, which regulates the National Security Scheme (BOE-A-2022-7191)

View authoritative source (external link) →

EMEA

United Kingdom

UK - Cyber Essentials: Requirements for IT Infrastructure v3.3

View authoritative source (external link) →

EMEA

United Kingdom

UK - Cyber Assessment Framework for Aviation Guidance (CAP1850) (2020)

View authoritative source (external link) →

EMEA

✓ STRM

United Kingdom

UK - Cyber Assessment Framework (CAF) v4.0

View authoritative source (external link) →

EMEA

✓ STRM

UAE

UAE - National Information Assurance Framework (NIAF) (2023)

View authoritative source (external link) →

EMEA

Turkey

Law on the Protection of Personal Data (LPPD) (2016)

View authoritative source (external link) →

EMEA

Spain

Spain - Royal Decree 311/2022

View authoritative source (external link) →

EMEA

Spain

Spain - ICT Security Guide CCN-STIC 825 (2023)

EMEA

Spain

Spain - Royal Decree 1720/2007

EMEA

Switzerland

Switzerland - Federal Act on Data Protection (FADP) (2025)

View authoritative source (external link) →

EMEA

✓ STRM

Saudi Arabia

Saudi Arabia - Personal Data Protection Law (PDPL) (2023)

View authoritative source (external link) →

EMEA

South Africa

South Africa - Protection of Personal Information Act (POPIA) (2013)

View authoritative source (external link) →

EMEA

Serbia

Serbia - Act of 9 November 2018 on Personal Data Protection (Official Gazette No. 87/18)

View authoritative source (external link) →

EMEA

Saudi Arabia

Saudi Arabia - Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework Version 1.0 (2017)

View authoritative source (external link) →

EMEA

Saudi Arabia

Saudi Arabia - SACS-002 Third Party Cybersecurity Standard (2022)

View authoritative source (external link) →

EMEA

Saudi Arabia

Saudi Arabia - Operational Technology Cybersecurity Controls (OTCC -1: 2022)

View authoritative source (external link) →

EMEA

Saudi Arabia

Saudi Arabia - Essential Cybersecurity Controls (ECC – 1 : 2018)

View authoritative source (external link) →

EMEA

✓ STRM

Saudi Arabia

Saudi Arabia - Cybersecurity Guidelines for Internet of Things (CGIoT-1:2024)

View authoritative source (external link) →

EMEA

Saudi Arabia

Saudi Arabia - Critical Systems Cybersecurity Controls (CSCC – 1: 2019)

View authoritative source (external link) →

EMEA

Russia

Russia - Federal Law of 27 (2006)

View authoritative source (external link) →

EMEA

Qatar

Qatar - Personal Data Privacy Protection Law (PDPPL) (2020)

EMEA

Poland

Poland - Act of 29 August 1997 on the Protection of Personal Data

View authoritative source (external link) →

EMEA

Norway

Norway - Personal Data Act (PDA) (2018)

View authoritative source (external link) →

EMEA

Nigeria

Nigeria - Data Protection Regulation (DPR) (2019)

View authoritative source (external link) →

EMEA

Kenya

Kenya - Data Protection Act (DPA) (2019)

View authoritative source (external link) →

EMEA

Italy

Italy - Personal Data Protection Code (2003)

View authoritative source (external link) →

EMEA

Israel

Israel - Protection of Privacy Law, 5741 (1981)

View authoritative source (external link) →

EMEA

Ireland

Ireland - Data Protection Act (DPA) (2003)

View authoritative source (external link) →

EMEA

Israel

Cybersecurity Methodology for an Organization v1.0

EMEA

Hungary

Hungary - Informational Self-Determination and Freedom of Information (Act CXII of 2011)

View authoritative source (external link) →

EMEA

Germany

Germany - Banking Supervisory Requirements for IT (2017)

EMEA

Germany

Germany - Cloud Computing Compliance Controls Catalogue (C5) (2020)

EMEA

Greece

Greece - Protection of Individuals with Regard to the Processing of Personal Data (2472/1997)

View authoritative source (external link) →

EMEA

Germany

Germany - Federal Data Protection Act (2017)

View authoritative source (external link) →

EMEA

Belgium

Belgium - Act of 8 December 1992

View authoritative source (external link) →

EMEA

Austria

Austria - Federal Act concerning the Protection of Personal Data (2000)

View authoritative source (external link) →

EMEA

EU

Second Payment Services Directive (PSD2) (2015)

View authoritative source (external link) →

EMEA

✓ STRM

EU

European Union Agency for Cybersecurity NIS2 (Directive (EU) 2022/2555)

View authoritative source (external link) →

EMEA

✓ STRM

EU

European Union Agency for Cybersecurity NIS2 Annex (2024)

View authoritative source (external link) →

EMEA

✓ STRM

EU

European Union General Data Protection Regulation (2016)

View authoritative source (external link) →

EMEA

✓ STRM

EU

Digital Operational Resilience Act (2023)

View authoritative source (external link) →

EMEA

EU

European Banking Authority Guidelines on ICT and Security Risk Management (2025)

EMEA

✓ STRM

EU

European Union Cyber Resilience Act - Annexes (2022)

View authoritative source (external link) →

EMEA

✓ STRM

EU

European Union Cyber Resilience Act (2022)

View authoritative source (external link) →

EMEA

✓ STRM

EU

European Union Artificial Intelligence Act (Regulation (EU) 2024/1689)

View authoritative source (external link) →

Back Next

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

APAC

Taiwan

Taiwan - Personal Data Protection Act (PDPA) (2025)

View authoritative source (external link) →

APAC

Singapore

Singapore - Monitory Authority of Singapore (MAS) Technology Risk Management (TRM) Guidelines (2021)

APAC

South Korea

South Korea - Personal Information Protection Act (PIPA) (2011)

View authoritative source (external link) →

APAC

Singapore

Singapore - Cyber Hygiene Practice (2019)

View authoritative source (external link) →

APAC

Singapore

Singapore - Personal Data Protection Ac (PDPA) (2012)

View authoritative source (external link) →

APAC

Philippines

Philippines - Data Privacy Act (DPA) (2012)

APAC

New Zealand

New Zealand - Privacy Act (2020)

View authoritative source (external link) →

APAC

New Zealand

New Zealand - Information Security Manual (ISM) v3.9

View authoritative source (external link) →

APAC

✓ STRM

New Zealand

New Zealand - HISO 10029:2024 NZ Health Information Security Framework Guidance for Suppliers

APAC

✓ STRM

New Zealand

New Zealand - HISF MicroSmall (2023)

View authoritative source (external link) →

APAC

Malaysia

Malaysia - Personal Data Protection Act (PDPA) (2010)

View authoritative source (external link) →

APAC

✓ STRM

New Zealand

New Zealand - HISF MLHSP (2023)

View authoritative source (external link) →

APAC

Japan

Japan - Information System Security Management and Assessment Program (ISMAP)

APAC

Japan

Japan - Act on the Protection of Personal Information (2020)

View authoritative source (external link) →

APAC

✓ STRM

India

India - SEBI Cybersecurity and Cyber Resilience Framework (2024)

APAC

India

India - Information Technology Rules (Privacy Rules) (2011)

View authoritative source (external link) →

APAC

✓ STRM

India

India Digital Personal Data Protection Act (2023)

View authoritative source (external link) →

APAC

Hong Kong

Hong Kong - Personal Data Ordinance (2022)

View authoritative source (external link) →

APAC

China

China - Decision on Strengthening Network Information Protection (2012)

APAC

China

China - Personal Information Protection Law of the People's Republic of China (2021)

View authoritative source (external link) →

APAC

China

China - Data Security Law of the People's Republic of China (2021)

View authoritative source (external link) →

APAC

✓ STRM

China

China - Cybersecurity Law of the People's Republic of China (2017)

APAC

Australia

Australia - Prudential Standard CPS 234 Information Security (2019)

View authoritative source (external link) →

APAC

Australia

Australia - Prudential Standard CPS 230 - Operational Risk Management (2023)

APAC

✓ STRM

Australia

Australia - Information Security Manual (ISM) (June 2024)

View authoritative source (external link) →

APAC

Australia

Australia - Privacy Principles (2026)

View authoritative source (external link) →

APAC

Australia

Australia - Code of Practice - Securing the Internet of Things for Consumers (2020)

View authoritative source (external link) →

APAC

Australia

Australia - Privacy Act of 1998

View authoritative source (external link) →

APAC

✓ STRM

Australia

Australia -Essential Eight maturity model and ISM mapping (2024)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

Americas

Colombia

Colombia - Law 1581 (2012)

View authoritative source (external link) →

Americas

Mexico

Mexico - Federal Law on Protection of Personal Data held by Private Parties (2010)

View authoritative source (external link) →

Americas

Canada

Canada - Personal Information Protection and Electronic Documents Act (PIPEDA) (2000)

View authoritative source (external link) →

Americas

Chile

Chile - Act 19628 - Protection of Personal Data (1999)

View authoritative source (external link) →

Americas

✓ STRM

Canada

Canada - Protecting controlled information in non-Government of Canada systems and organizations (ITSP.10.171)

Americas

✓ STRM

Canada

Canada - OSFI B-13 (2022)

View authoritative source (external link) →

Americas

Canada

Office of the Superintendent of Financial Institutions Canada (OSFI) - Cyber Security Self-Assessment Guidance

View authoritative source (external link) →

Americas

Brazil

Brazil - General Data Protection Law (LGPD) (2018)

View authoritative source (external link) →

Americas

Bermuda

Bermuda - Bermuda Monetary Authority (BMA) Insurance Sector Operational Cyber Risk Management Code of Conduct (2020)

Americas

Bahamas

Data Protection Act (2003)

View authoritative source (external link) →

Americas

Argentina

Protection of Personal Data - MEN-2018-147-APN-PTE (2018)

View authoritative source (external link) →

No matching frameworks found. Try a different search term or filter.

Practical Application

How To Use the LRF Coverage in Your Program

Understanding which LRF are mapped to the SCF allows you to use the framework as a single source of truth for your compliance program. Here’s how practitioners apply LRF coverage in real-world programs.

01

Identify Your MCR. Determine which laws, regulations and frameworks apply to your organization. Each applicable LRF represents a Minimum Compliance Requirement (MCR) that must be satisfied.

02

Filter Controls by LRF. Use the SCF spreadsheet to filter controls by your applicable LRF. Every control mapped to that framework represents a requirement you need to address in your program.

03

Satisfy Multiple LRF Simultaneously. Because multiple LRF map to the same SCF controls, implementing a single control can satisfy requirements across several frameworks at once, dramatically reducing compliance effort.

Don’t See a Framework?

The SCF is a volunteer-maintained, open-source project. If a framework you need isn’t currently mapped, you can contribute to the project or contact the SCF team to request coverage. New LRF mappings are added with each quarterly release.

Download the SCF Contact the SCF Team

What To Explore Next

Understand the Full SCF Picture

The LRF coverage is just one part of what makes the SCF the most comprehensive free cybersecurity metaframework. Explore these related areas to get the full picture.

Set Theory Relationship Mapping (STRM)

Understand how the SCF uses NIST IR 8477 to create authoritative, mathematically-sound crosswalk mappings between frameworks.

Learn More →

SCF Domains & Principles

Explore the 33 control domains that organize the 1,400+ SCF controls and see how they align with the frameworks you care about.

Learn More →

SCRMS Implementation

Learn how to implement a Security, Compliance & Resilience Management System using the SCF as your foundational control framework.

Learn More →

Download the SCF

Get the complete SCF spreadsheet with all 1,400+ controls and every LRF mapping. Free. No registration required.

Download The SCF

Join 25,000+ GRC Professionals

Get the latest SCF updates, cybersecurity insights, and community news delivered to your inbox. You know you want to do it!

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

%20(white).png)

Controls are your security, compliance & resilience program - A control is the power to influence or direct behaviors and the course of events.

‍

DOWNLOAD THE SCF

Start Here

What Is The SCF? How To Implement (SCRMS) Domains & Principles Laws & Frameworks (LRF) Relationship Mapping (STRM) NIST OLIR Participation ESG Considerations

Free Content

SCF Download Risk Management (SCR-RMM) Maturity Model (SCR-CMM) Assessment Standards (CDPAS) Mergers & Acquisitions (MA&D) Privacy Principles (DPMP) Evidence Request List (ERL) Scoping Guide (USG)

Resources

GRC Fundamentals SCF Certified Marketplace FAQ About Blog

Support

Donate Volunteer

© 2026 Secure Controls Framework Council, LLC. All rights reserved.

Terms & Conditions Privacy Cookies Sitemap

flowUI WEBFLOW SYSTEM

Save hours and build better websites.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt

Subheading One

Lorem ipsum dolor sit amet, consectetur adipiscing elit.

Subheading Two

Lorem ipsum dolor sit amet, consectetur adipiscing elit.

Get Started