Framework library

Twelve frameworks, built in

Each one ships with its full requirement set already written and already mapped to the unified control library. Switch on the ones that apply to you and start the same day — there is no content-loading project and no consultant required.

Information Security

NIST Cybersecurity Framework

2.0

NIST

Organised around Govern, Identify, Protect, Detect, Respond and Recover. Widely used as the common language for describing a security programme to a board.

Applies to: Organisations of any size building or benchmarking a security programme.

ISO/IEC 27001

2022

ISO/IEC

The international standard for an information security management system, including the Annex A control set. The certification most customers and partners ask for by name.

Applies to: Any organisation seeking certifiable information security assurance.

NCA Essential Cybersecurity Controls

ECC

Saudi National Cybersecurity Authority

The baseline cybersecurity controls mandated for organisations operating in Saudi Arabia, covering governance, defence, resilience and third-party risk.

Applies to: Government and critical-sector entities in Saudi Arabia.

CIS Controls

v8

Center for Internet Security

A prioritised set of safeguards grouped into implementation groups, aimed at the attacks that actually happen rather than the full universe of theoretical risk.

Applies to: Teams that need a defensible order of work, not just a list.

Assurance

SOC 2

Trust Services Criteria

AICPA

Criteria covering security, availability, processing integrity, confidentiality and privacy, assessed by an external auditor and reported to your customers.

Applies to: Service providers whose clients demand independent assurance.

Healthcare

HIPAA

Security & Privacy Rules

U.S. Department of Health and Human Services

Administrative, physical and technical safeguards for protected health information, together with the privacy and breach notification obligations that sit alongside them.

Applies to: Covered entities and the business associates that handle PHI on their behalf.

Banking & Finance

SAMA Cyber Security Framework

1.0

Saudi Central Bank

The Saudi Central Bank's mandatory cybersecurity framework for regulated financial institutions, structured around governance, risk, operations and third-party management.

Applies to: Banks, insurers and financing companies operating in Saudi Arabia.

Supply Chain

Aramco CCC

Cybersecurity Compliance Certificate

Saudi Aramco

The cybersecurity certification Aramco requires from third parties in its supply chain, and a common contractual condition across the region's energy sector.

Applies to: Suppliers and contractors bidding for Aramco work.

Cross-framework mapping

What "mapped" actually means

Take one control — establishing a cybersecurity governance committee with a board mandate, a charter and quarterly meetings. That single control answers a requirement in almost every framework on this page: ISO 27001, NIST CSF, SAMA CSF, NCA ECC, SOC 2, CIS Controls and HIPAA.

Implement it once, attach the charter and the minutes as evidence, and those requirements close together. Where a framework asks for more than the control provides, the mapping is recorded as partial and the requirement stays open until the remainder is done — so the score never flatters you.

That is the whole argument for the product. Everything else follows from it.

Adding a framework

Frameworks are data, not code. A new rulebook — a fresh circular from your regulator, an internal standard, a customer's security schedule — is loaded along with its mappings to the existing control library.

The frameworks you already track keep working, your historical evidence stays attached, and the new framework arrives partly complete on day one, because the underlying work has already been done.

Ask about a framework we do not list

Which of these apply to you?

Tell us the frameworks you report against and we will show you what your coverage looks like on day one.