Framework library

The security and privacy frameworks we work to.

We provide readiness, assessment, implementation support and audit support. We are not a certification body or an accredited auditor, and this page uses those words carefully.

Global

International standards recognized by customers and regulators

The standards enterprise customers and regulators recognize everywhere. Controls are implemented once and mapped across every framework that applies to you.

Information security & privacy
FrameworkHow we support it
ISO/IEC 27001ISMS implementation to certification readiness
ISO/IEC 27701Privacy information management
ISO/IEC 27017Cloud security controls
ISO/IEC 27018Cloud PII protection
ISO/IEC 22301Business continuity
ISO/IEC 42001AI management systems
Assurance & control frameworks
FrameworkHow we support it
SOC 2Type I & II readiness, audit support
SOC 1Financial-reporting control readiness
NIST CSFProgram structure & maturity
NIST SP 800-53Control implementation support
CIS ControlsPrioritized hardening baseline
PCI DSSCardholder data readiness
CSA CCMCloud controls matrix alignment
COBITIT governance advisory
Privacy regulation (advisory / readiness)
FrameworkHow we support it
GDPREU data protection readiness
CCPA / CPRACalifornia privacy readiness
HIPAASecurity Rule safeguards review

GCC

Readiness support for GCC national cybersecurity frameworks

National cybersecurity authorities across the GCC publish some of the most specific control frameworks in the world. We provide readiness, assessment and implementation support mapped to each.

United Arab Emirates
FrameworkHow we support it
UAE IA RegulationInformation assurance readiness
UAE PDPLFederal data protection readiness
Dubai ISRInformation security regulation readiness
DESC requirementsDubai government-sector advisory
ADHICSAbu Dhabi healthcare security (where applicable)
Saudi Arabia
FrameworkHow we support it
NCA ECCEssential cybersecurity controls readiness
NCA CSCCCritical systems controls readiness
NCA CCCCloud cybersecurity controls readiness
Saudi PDPLPersonal data protection readiness
SAMA CSFFinancial-sector cybersecurity readiness
Qatar
FrameworkHow we support it
NIA PolicyNational information assurance readiness
Qatar PDPPLData privacy readiness
QCB requirementsFinancial-sector advisory (where applicable)
Bahrain
FrameworkHow we support it
Bahrain PDPLData protection readiness
CBB RulebookFinancial-sector cyber advisory (where applicable)
Oman
FrameworkHow we support it
Oman PDPLPersonal data protection readiness
Sector requirementsRegulator-specific advisory (where applicable)
Kuwait
FrameworkHow we support it
Data protection & cyber requirementsAdvisory / readiness (where applicable)

APAC

Readiness and assessment across the major APAC regimes

APAC regulators move fast and differ sharply by market. We support readiness and assessment across the region’s major regimes, from MAS TRM to the Essential Eight.

Singapore
FrameworkHow we support it
MAS TRMTechnology risk management readiness
MAS Cyber HygieneNotice requirements readiness
PDPAData protection readiness
CSA requirementsCybersecurity advisory (where applicable)
Australia
FrameworkHow we support it
Essential EightMaturity assessment & uplift
ISMControl alignment advisory
APRA CPS 234Financial-sector readiness
Privacy ActPrivacy readiness
Japan
FrameworkHow we support it
ISMS / ISO 27001Implementation to certification readiness
APPIPersonal information protection readiness
New Zealand
FrameworkHow we support it
NZISMControl alignment advisory
Privacy Act 2020Privacy readiness

USA

Assurance and sector frameworks required in the United States

From SOC 2 reports required in enterprise procurement to sector and state regulation: readiness, gap assessment, control implementation support and audit preparation.

Assurance & federal alignment
FrameworkHow we support it
SOC 2Type I & II readiness, evidence programs
SOC 1ICFR-relevant control readiness
NIST CSFProgram structure & maturity
NIST SP 800-171CUI protection readiness
CMMCReadiness & gap assessment
FedRAMPAdvisory / readiness (not a 3PAO)
Sector & state regulation
FrameworkHow we support it
HIPAA Security RuleSafeguards assessment & remediation
PCI DSSCardholder data readiness
GLBA SafeguardsFinancial data protection readiness
NYDFS 500Cybersecurity regulation readiness
CCPA / CPRACalifornia privacy readiness
SEC cyber disclosureGovernance & disclosure readiness

India

Readiness for data protection, CERT-In and financial-sector requirements in India

Readiness, assessment and implementation support for the DPDP Act, CERT-In directions and SEBI, RBI and IRDAI requirements, mapped to the global standards they overlap with.

National & data protection
FrameworkHow we support it
DPDP ActData protection program readiness
CERT-In directionsIncident reporting & log retention readiness
ISO 27001ISMS to certification readiness
SOC 2Readiness for SaaS companies selling internationally
Financial sector
FrameworkHow we support it
SEBI CSCRFRegulated-entity readiness & audit support
RBI cyber frameworkBank & NBFC readiness
IRDAI requirementsInsurer cybersecurity readiness
NPCI requirementsPayment ecosystem advisory (where applicable)

Frameworks by industry

Financial Services
  • SOC 2
  • PCI DSS
  • NIST CSF
  • DORA
  • NYDFS 500
  • SAMA CSF
  • APRA CPS 234
  • SEBI CSCRF
  • RBI framework
Healthcare
  • HIPAA
  • ISO 27001
  • SOC 2
  • GDPR
  • ADHICS
  • DPDP Act
Technology & SaaS
  • SOC 2
  • ISO 27001
  • ISO 27701
  • GDPR
  • CCPA / CPRA
  • CSA CCM

Types of engagement

  • Gap Assessment
  • Readiness Assessment
  • Risk Assessment
  • Control Assessment
  • Policy Development
  • Control Implementation
  • Evidence Readiness
  • Audit Preparation
  • Remediation Support
  • Internal Security Assessment
  • Third-Party Risk
  • Vendor Risk
  • ISMS Implementation
  • Continuous Compliance
  • Compliance Automation
  • Security Governance

Applicable requirements vary by country, sector, regulator and organizational profile. We scope every engagement against your actual obligations, and we will tell you plainly when a framework does not apply to you.

Questions we are asked

No, and by design. Independent certification requires an accredited body, and audits require an independent firm. We prepare you for those audits: gap assessment, control implementation, evidence programs, internal audit and audit-day support. When a request needs something only an auditor can provide, we say so.

We support readiness for NCA ECC, CSCC and CCC, the SAMA Cybersecurity Framework, UAE PDPL and the Information Assurance Regulation, Dubai ISR, ADHICS where healthcare scope applies, Qatar NIA and PDPPL, Bahrain PDPL and CBB requirements, Oman PDPL and applicable sectoral requirements. Applicability varies by regulator and organizational profile, so every engagement is scoped to the obligations that actually apply.

Yes. Where a single scope reasonably covers both, we design controls once and produce evidence that satisfies both audits. A common path for SaaS companies is ISO 27001 as the management-system anchor with SOC 2 Type II layered on top.

Timelines depend on current maturity and scope. A first-time ISO 27001 or SOC 2 program typically runs three to nine months from gap assessment through audit-ready. We give a realistic sequence at the end of the gap assessment, not before.

Yes, as readiness and remediation support. We are not a C3PAO and do not perform CMMC certification assessments. What we do is scope the CUI environment, close 800-171 gaps and prepare evidence and documentation before an accredited assessor arrives.

Yes. Overlapping requirements can run as a single coordinated engagement, for example GDPR with NIS2 and DORA, or the DPDP Act with SEBI CSCRF and RBI cybersecurity requirements. Shared controls are mapped once rather than treated separately for each requirement.

Turning a framework into a working program

The framework list is the easy part. The GRC practice page explains how we scope, implement and sustain a program.