NIST Cybersecurity Framework
2.0NIST
Organised around Govern, Identify, Protect, Detect, Respond and Recover. Widely used as the common language for describing a security programme to a board.
Framework library
Each one ships with its full requirement set already written and already mapped to the unified control library. Switch on the ones that apply to you and start the same day — there is no content-loading project and no consultant required.
NIST
Organised around Govern, Identify, Protect, Detect, Respond and Recover. Widely used as the common language for describing a security programme to a board.
ISO/IEC
The international standard for an information security management system, including the Annex A control set. The certification most customers and partners ask for by name.
Saudi National Cybersecurity Authority
The baseline cybersecurity controls mandated for organisations operating in Saudi Arabia, covering governance, defence, resilience and third-party risk.
Center for Internet Security
A prioritised set of safeguards grouped into implementation groups, aimed at the attacks that actually happen rather than the full universe of theoretical risk.
AICPA
Criteria covering security, availability, processing integrity, confidentiality and privacy, assessed by an external auditor and reported to your customers.
U.S. Department of Health and Human Services
Administrative, physical and technical safeguards for protected health information, together with the privacy and breach notification obligations that sit alongside them.
Saudi Central Bank
The Saudi Central Bank's mandatory cybersecurity framework for regulated financial institutions, structured around governance, risk, operations and third-party management.
Saudi Aramco
The cybersecurity certification Aramco requires from third parties in its supply chain, and a common contractual condition across the region's energy sector.
Cross-framework mapping
Take one control — establishing a cybersecurity governance committee with a board mandate, a charter and quarterly meetings. That single control answers a requirement in almost every framework on this page: ISO 27001, NIST CSF, SAMA CSF, NCA ECC, SOC 2, CIS Controls and HIPAA.
Implement it once, attach the charter and the minutes as evidence, and those requirements close together. Where a framework asks for more than the control provides, the mapping is recorded as partial and the requirement stays open until the remainder is done — so the score never flatters you.
That is the whole argument for the product. Everything else follows from it.
Frameworks are data, not code. A new rulebook — a fresh circular from your regulator, an internal standard, a customer's security schedule — is loaded along with its mappings to the existing control library.
The frameworks you already track keep working, your historical evidence stays attached, and the new framework arrives partly complete on day one, because the underlying work has already been done.
Tell us the frameworks you report against and we will show you what your coverage looks like on day one.