50+ standards & best practices, one control set

Satisfy a control once — comply everywhere it applies. Cross-framework mapping handles the overlap automatically.

The catalogue, searchable

One control set underneath all of them. Satisfying a requirement once satisfies it everywhere the same requirement appears.

52 frameworks matching

  • EU AI ActEU
    AISentinel · 74 clauses

    Risk tiering, transparency and post-market monitoring for AI systems placed on the EU market.

    AI Frameworks
  • ISO/IEC 42001Global
    AISentinel · 65 clauses

    The AI management system standard — governance, impact assessment and lifecycle control.

    AI Frameworks
  • NIST AI RMFUS
    AISentinel · 72 clauses

    Govern, map, measure and manage AI risk across the model lifecycle.

    AI Frameworks
  • OWASP LLM Top 10Global
    AISentinel · 13 clauses

    The canonical list of LLM-native failure modes, from prompt injection to excessive agency.

    AI Frameworks
  • MITRE ATLASGlobal
    AISentinel · 109 clauses

    Adversarial tactics and techniques observed against machine learning systems.

    AI Frameworks
  • OWASP Agentic Top 10Global
    AISentinel · 10 clauses

    The 2026 Agentic Security Initiative list — goal hijack, tool misuse, rogue agents and the rest of what breaks once a model can act.

    AI Frameworks
  • AI VerifySingapore

    Singapore's testing framework for trustworthy AI.

    AI Frameworks
  • ISO/IEC 27001:2022Global

    Information security management system certification.

    Security & Privacy
  • SOC 2US

    Trust services criteria for security, availability and confidentiality.

    Security & Privacy
  • PCI DSSGlobal

    Cardholder data protection across storage, processing and transmission.

    Security & Privacy
  • HIPAAUS

    Safeguards for protected health information.

    Security & Privacy
  • HITRUSTUS

    The HITRUST CSF — a certifiable control framework that harmonises HIPAA, ISO, NIST and PCI for healthcare and its vendors.

    Security & Privacy
  • EU GDPREU

    Lawful basis, data subject rights and processor obligations.

    Security & Privacy
  • DPDP ActIndia

    India's Digital Personal Data Protection Act — consent, notice and breach reporting.

    Security & Privacy
  • CIS BenchmarksGlobal

    Hardening baselines for cloud services, Kubernetes and operating systems.

    Security & Privacy
  • NIST CSFUS

    Identify, protect, detect, respond, recover — plus the new govern function.

    Security & Privacy
  • NIST 800-53US

    The federal control catalogue — the control families FedRAMP and most US public-sector baselines are built from.

    Security & Privacy
  • FedRAMPUS

    Authorisation baseline for cloud services sold to US federal agencies.

    Security & Privacy
  • CCPAUS

    California consumer privacy rights and opt-out obligations.

    Security & Privacy
  • GxP / 21 CFR Part 11US

    Electronic records and signatures in regulated life sciences.

    Security & Privacy
  • CISA Cyber EssentialsUS

    Baseline practices for critical infrastructure operators.

    Security & Privacy
  • ISO/IEC 27001:2013Global

    The superseded revision, still the certified baseline for organisations mid-transition.

    Security & Privacy
  • CSA CCM v4Global

    The Cloud Security Alliance control set, mapped across the shared-responsibility line.

    Security & Privacy
  • Cloud Computing Compliance Criteria Catalogue C5Germany

    Germany's cloud computing compliance criteria catalogue.

    Security & Privacy
  • C2M2US

    US Department of Energy cybersecurity capability maturity model.

    Security & Privacy
  • LGPDBrazil

    Brazil's general data protection law — consent, rights and controller duties.

    Security & Privacy
  • Korea ISMS-P 2023South Korea

    Korea's information security and personal information management certification.

    Security & Privacy
  • GxP EU Annex 11EU

    EudraLex Volume 4 Annex 11 — computerised systems in EU-regulated pharmaceutical manufacturing.

    Security & Privacy
  • MITRE ATT&CKGlobal

    Adversarial tactics and techniques observed against enterprise IT — distinct from ATLAS, which covers ML systems.

    Security & Privacy
  • NIST SP 800-171US

    Protecting controlled unclassified information in non-federal systems — the baseline behind CMMC.

    Security & Privacy
  • NIST SP 800-66r2US

    The HIPAA Security Rule read as a NIST control mapping.

    Security & Privacy
  • Foundational Security Best PracticesGlobal

    AWS's own security control set — the baseline the Foundational Technical Review is scored against.

    Security & Privacy
  • Well Architected Framework - Security PillarGlobal

    AWS Well-Architected's security pillar — identity, detection, infrastructure and data protection.

    Security & Privacy
  • Well Architected Framework - Reliability PillarGlobal

    AWS Well-Architected's reliability pillar — recovery, change management and workload architecture.

    Security & Privacy
  • Control Tower GuardrailsGlobal

    AWS Control Tower's preventive and detective guardrails across a multi-account landing zone.

    Security & Privacy
  • Account Onboarding Best PracticesGlobal

    AWS's baseline for bringing a new account into a governed multi-account estate.

    Security & Privacy
  • Foundational Technical ReviewGlobal

    The AWS Partner Network's technical bar for a solution listed in the AWS Marketplace.

    Security & Privacy
  • RBI Cyber Security FrameworkIndia

    Reserve Bank of India directions for banks and regulated entities.

    Regional & Sector
  • SEBI CSCRFIndia

    Cybersecurity and cyber resilience framework for India's market infrastructure.

    Regional & Sector
  • IRDAI ICSGIndia

    Information and cyber security guidelines for Indian insurers.

    Regional & Sector
  • DORAEU

    Digital operational resilience for EU financial entities and their ICT providers.

    Regional & Sector
  • NIS2EU

    Security and reporting duties for essential and important entities across the EU.

    Regional & Sector
  • MAS TRMSingapore

    Technology risk management guidelines for Singapore financial institutions.

    Regional & Sector
  • APRA CPS 234Australia

    Information security prudential standard for Australian regulated entities.

    Regional & Sector
  • Essential Eight maturity model (2023)Australia

    ACSC mitigation strategies and maturity levels.

    Regional & Sector
  • FFIEC IT Examination HandbookUS

    Cybersecurity assessment for US financial institutions.

    Regional & Sector
  • BAIT (2021)Germany

    BaFin supervisory requirements for IT in German banks and insurers.

    Regional & Sector
  • ISMAustralia

    The Australian Signals Directorate's Information Security Manual.

    Regional & Sector
  • Cyber Essentials (UK)UK

    The UK government's baseline cyber hygiene certification, assessed by IASME on behalf of the NCSC.

    Regional & Sector
  • RBI UCB Cyber Security Framework (2026)India

    The Reserve Bank of India's cyber security framework for urban co-operative banks.

    Regional & Sector
  • CITRA Data Privacy Protection Regulation (Kuwait)Kuwait

    Kuwait's telecoms and IT regulator's data privacy protection regulation.

    Regional & Sector
  • NCSC Cyber Assessment Framework (CAF) v4.0UK

    The UK NCSC's outcome-based framework for assessing cyber resilience in essential services.

    Regional & Sector

Make your next audit a formality

See your live compliance score across every framework you care about — evidence included.