50+ standards & best practices, one control set
Satisfy a control once — comply everywhere it applies. Cross-framework mapping handles the overlap automatically.
The catalogue, searchable
One control set underneath all of them. Satisfying a requirement once satisfies it everywhere the same requirement appears.
52 frameworks matching
- AI FrameworksEU AI ActEUAISentinel · 74 clauses
Risk tiering, transparency and post-market monitoring for AI systems placed on the EU market.
- AI FrameworksISO/IEC 42001GlobalAISentinel · 65 clauses
The AI management system standard — governance, impact assessment and lifecycle control.
- AI FrameworksNIST AI RMFUSAISentinel · 72 clauses
Govern, map, measure and manage AI risk across the model lifecycle.
- AI FrameworksOWASP LLM Top 10GlobalAISentinel · 13 clauses
The canonical list of LLM-native failure modes, from prompt injection to excessive agency.
- AI FrameworksMITRE ATLASGlobalAISentinel · 109 clauses
Adversarial tactics and techniques observed against machine learning systems.
- AI FrameworksOWASP Agentic Top 10GlobalAISentinel · 10 clauses
The 2026 Agentic Security Initiative list — goal hijack, tool misuse, rogue agents and the rest of what breaks once a model can act.
- AI FrameworksAI VerifySingapore
Singapore's testing framework for trustworthy AI.
- Security & PrivacyISO/IEC 27001:2022Global
Information security management system certification.
- Security & PrivacySOC 2US
Trust services criteria for security, availability and confidentiality.
- Security & PrivacyPCI DSSGlobal
Cardholder data protection across storage, processing and transmission.
- Security & PrivacyHIPAAUS
Safeguards for protected health information.
- Security & PrivacyHITRUSTUS
The HITRUST CSF — a certifiable control framework that harmonises HIPAA, ISO, NIST and PCI for healthcare and its vendors.
- Security & PrivacyEU GDPREU
Lawful basis, data subject rights and processor obligations.
- Security & PrivacyDPDP ActIndia
India's Digital Personal Data Protection Act — consent, notice and breach reporting.
- Security & PrivacyCIS BenchmarksGlobal
Hardening baselines for cloud services, Kubernetes and operating systems.
- Security & PrivacyNIST CSFUS
Identify, protect, detect, respond, recover — plus the new govern function.
- Security & PrivacyNIST 800-53US
The federal control catalogue — the control families FedRAMP and most US public-sector baselines are built from.
- Security & PrivacyFedRAMPUS
Authorisation baseline for cloud services sold to US federal agencies.
- Security & PrivacyCCPAUS
California consumer privacy rights and opt-out obligations.
- Security & PrivacyGxP / 21 CFR Part 11US
Electronic records and signatures in regulated life sciences.
- Security & PrivacyCISA Cyber EssentialsUS
Baseline practices for critical infrastructure operators.
- Security & PrivacyISO/IEC 27001:2013Global
The superseded revision, still the certified baseline for organisations mid-transition.
- Security & PrivacyCSA CCM v4Global
The Cloud Security Alliance control set, mapped across the shared-responsibility line.
- Security & PrivacyCloud Computing Compliance Criteria Catalogue C5Germany
Germany's cloud computing compliance criteria catalogue.
- Security & PrivacyC2M2US
US Department of Energy cybersecurity capability maturity model.
- Security & PrivacyLGPDBrazil
Brazil's general data protection law — consent, rights and controller duties.
- Security & PrivacyKorea ISMS-P 2023South Korea
Korea's information security and personal information management certification.
- Security & PrivacyGxP EU Annex 11EU
EudraLex Volume 4 Annex 11 — computerised systems in EU-regulated pharmaceutical manufacturing.
- Security & PrivacyMITRE ATT&CKGlobal
Adversarial tactics and techniques observed against enterprise IT — distinct from ATLAS, which covers ML systems.
- Security & PrivacyNIST SP 800-171US
Protecting controlled unclassified information in non-federal systems — the baseline behind CMMC.
- Security & PrivacyNIST SP 800-66r2US
The HIPAA Security Rule read as a NIST control mapping.
- Security & PrivacyFoundational Security Best PracticesGlobal
AWS's own security control set — the baseline the Foundational Technical Review is scored against.
- Security & PrivacyWell Architected Framework - Security PillarGlobal
AWS Well-Architected's security pillar — identity, detection, infrastructure and data protection.
- Security & PrivacyWell Architected Framework - Reliability PillarGlobal
AWS Well-Architected's reliability pillar — recovery, change management and workload architecture.
- Security & PrivacyControl Tower GuardrailsGlobal
AWS Control Tower's preventive and detective guardrails across a multi-account landing zone.
- Security & PrivacyAccount Onboarding Best PracticesGlobal
AWS's baseline for bringing a new account into a governed multi-account estate.
- Security & PrivacyFoundational Technical ReviewGlobal
The AWS Partner Network's technical bar for a solution listed in the AWS Marketplace.
- Regional & SectorRBI Cyber Security FrameworkIndia
Reserve Bank of India directions for banks and regulated entities.
- Regional & SectorSEBI CSCRFIndia
Cybersecurity and cyber resilience framework for India's market infrastructure.
- Regional & SectorIRDAI ICSGIndia
Information and cyber security guidelines for Indian insurers.
- Regional & SectorDORAEU
Digital operational resilience for EU financial entities and their ICT providers.
- Regional & SectorNIS2EU
Security and reporting duties for essential and important entities across the EU.
- Regional & SectorMAS TRMSingapore
Technology risk management guidelines for Singapore financial institutions.
- Regional & SectorAPRA CPS 234Australia
Information security prudential standard for Australian regulated entities.
- Regional & SectorEssential Eight maturity model (2023)Australia
ACSC mitigation strategies and maturity levels.
- Regional & SectorFFIEC IT Examination HandbookUS
Cybersecurity assessment for US financial institutions.
- Regional & SectorBAIT (2021)Germany
BaFin supervisory requirements for IT in German banks and insurers.
- Regional & SectorISMAustralia
The Australian Signals Directorate's Information Security Manual.
- Regional & SectorCyber Essentials (UK)UK
The UK government's baseline cyber hygiene certification, assessed by IASME on behalf of the NCSC.
- Regional & SectorRBI UCB Cyber Security Framework (2026)India
The Reserve Bank of India's cyber security framework for urban co-operative banks.
- Regional & SectorCITRA Data Privacy Protection Regulation (Kuwait)Kuwait
Kuwait's telecoms and IT regulator's data privacy protection regulation.
- Regional & SectorNCSC Cyber Assessment Framework (CAF) v4.0UK
The UK NCSC's outcome-based framework for assessing cyber resilience in essential services.




































