Framework library
The security and privacy frameworks we work to.
We provide readiness, assessment, implementation support and audit support. We are not a certification body or an accredited auditor, and this page uses those words carefully.
Global
International standards recognized by customers and regulators
The standards enterprise customers and regulators recognize everywhere. Controls are implemented once and mapped across every framework that applies to you.
| Framework | How we support it |
|---|---|
| ISO/IEC 27001 | ISMS implementation to certification readiness |
| ISO/IEC 27701 | Privacy information management |
| ISO/IEC 27017 | Cloud security controls |
| ISO/IEC 27018 | Cloud PII protection |
| ISO/IEC 22301 | Business continuity |
| ISO/IEC 42001 | AI management systems |
| Framework | How we support it |
|---|---|
| SOC 2 | Type I & II readiness, audit support |
| SOC 1 | Financial-reporting control readiness |
| NIST CSF | Program structure & maturity |
| NIST SP 800-53 | Control implementation support |
| CIS Controls | Prioritized hardening baseline |
| PCI DSS | Cardholder data readiness |
| CSA CCM | Cloud controls matrix alignment |
| COBIT | IT governance advisory |
| Framework | How we support it |
|---|---|
| GDPR | EU data protection readiness |
| CCPA / CPRA | California privacy readiness |
| HIPAA | Security Rule safeguards review |
GCC
Readiness support for GCC national cybersecurity frameworks
National cybersecurity authorities across the GCC publish some of the most specific control frameworks in the world. We provide readiness, assessment and implementation support mapped to each.
| Framework | How we support it |
|---|---|
| UAE IA Regulation | Information assurance readiness |
| UAE PDPL | Federal data protection readiness |
| Dubai ISR | Information security regulation readiness |
| DESC requirements | Dubai government-sector advisory |
| ADHICS | Abu Dhabi healthcare security (where applicable) |
| Framework | How we support it |
|---|---|
| NCA ECC | Essential cybersecurity controls readiness |
| NCA CSCC | Critical systems controls readiness |
| NCA CCC | Cloud cybersecurity controls readiness |
| Saudi PDPL | Personal data protection readiness |
| SAMA CSF | Financial-sector cybersecurity readiness |
| Framework | How we support it |
|---|---|
| NIA Policy | National information assurance readiness |
| Qatar PDPPL | Data privacy readiness |
| QCB requirements | Financial-sector advisory (where applicable) |
| Framework | How we support it |
|---|---|
| Bahrain PDPL | Data protection readiness |
| CBB Rulebook | Financial-sector cyber advisory (where applicable) |
| Framework | How we support it |
|---|---|
| Oman PDPL | Personal data protection readiness |
| Sector requirements | Regulator-specific advisory (where applicable) |
| Framework | How we support it |
|---|---|
| Data protection & cyber requirements | Advisory / readiness (where applicable) |
APAC
Readiness and assessment across the major APAC regimes
APAC regulators move fast and differ sharply by market. We support readiness and assessment across the region’s major regimes, from MAS TRM to the Essential Eight.
| Framework | How we support it |
|---|---|
| MAS TRM | Technology risk management readiness |
| MAS Cyber Hygiene | Notice requirements readiness |
| PDPA | Data protection readiness |
| CSA requirements | Cybersecurity advisory (where applicable) |
| Framework | How we support it |
|---|---|
| Essential Eight | Maturity assessment & uplift |
| ISM | Control alignment advisory |
| APRA CPS 234 | Financial-sector readiness |
| Privacy Act | Privacy readiness |
| Framework | How we support it |
|---|---|
| ISMS / ISO 27001 | Implementation to certification readiness |
| APPI | Personal information protection readiness |
| Framework | How we support it |
|---|---|
| NZISM | Control alignment advisory |
| Privacy Act 2020 | Privacy readiness |
USA
Assurance and sector frameworks required in the United States
From SOC 2 reports required in enterprise procurement to sector and state regulation: readiness, gap assessment, control implementation support and audit preparation.
| Framework | How we support it |
|---|---|
| SOC 2 | Type I & II readiness, evidence programs |
| SOC 1 | ICFR-relevant control readiness |
| NIST CSF | Program structure & maturity |
| NIST SP 800-171 | CUI protection readiness |
| CMMC | Readiness & gap assessment |
| FedRAMP | Advisory / readiness (not a 3PAO) |
| Framework | How we support it |
|---|---|
| HIPAA Security Rule | Safeguards assessment & remediation |
| PCI DSS | Cardholder data readiness |
| GLBA Safeguards | Financial data protection readiness |
| NYDFS 500 | Cybersecurity regulation readiness |
| CCPA / CPRA | California privacy readiness |
| SEC cyber disclosure | Governance & disclosure readiness |
India
Readiness for data protection, CERT-In and financial-sector requirements in India
Readiness, assessment and implementation support for the DPDP Act, CERT-In directions and SEBI, RBI and IRDAI requirements, mapped to the global standards they overlap with.
| Framework | How we support it |
|---|---|
| DPDP Act | Data protection program readiness |
| CERT-In directions | Incident reporting & log retention readiness |
| ISO 27001 | ISMS to certification readiness |
| SOC 2 | Readiness for SaaS companies selling internationally |
| Framework | How we support it |
|---|---|
| SEBI CSCRF | Regulated-entity readiness & audit support |
| RBI cyber framework | Bank & NBFC readiness |
| IRDAI requirements | Insurer cybersecurity readiness |
| NPCI requirements | Payment ecosystem advisory (where applicable) |
Frameworks by industry
Types of engagement
Applicable requirements vary by country, sector, regulator and organizational profile. We scope every engagement against your actual obligations, and we will tell you plainly when a framework does not apply to you.
Questions we are asked
No, and by design. Independent certification requires an accredited body, and audits require an independent firm. We prepare you for those audits: gap assessment, control implementation, evidence programs, internal audit and audit-day support. When a request needs something only an auditor can provide, we say so.
We support readiness for NCA ECC, CSCC and CCC, the SAMA Cybersecurity Framework, UAE PDPL and the Information Assurance Regulation, Dubai ISR, ADHICS where healthcare scope applies, Qatar NIA and PDPPL, Bahrain PDPL and CBB requirements, Oman PDPL and applicable sectoral requirements. Applicability varies by regulator and organizational profile, so every engagement is scoped to the obligations that actually apply.
Yes. Where a single scope reasonably covers both, we design controls once and produce evidence that satisfies both audits. A common path for SaaS companies is ISO 27001 as the management-system anchor with SOC 2 Type II layered on top.
Timelines depend on current maturity and scope. A first-time ISO 27001 or SOC 2 program typically runs three to nine months from gap assessment through audit-ready. We give a realistic sequence at the end of the gap assessment, not before.
Yes, as readiness and remediation support. We are not a C3PAO and do not perform CMMC certification assessments. What we do is scope the CUI environment, close 800-171 gaps and prepare evidence and documentation before an accredited assessor arrives.
Yes. Overlapping requirements can run as a single coordinated engagement, for example GDPR with NIS2 and DORA, or the DPDP Act with SEBI CSCRF and RBI cybersecurity requirements. Shared controls are mapped once rather than treated separately for each requirement.
Turning a framework into a working program
The framework list is the easy part. The GRC practice page explains how we scope, implement and sustain a program.
