Building with AI? Ask us about LLM red teaming and ISO 42001.Explore AI security

Standards and regulations

The 50 security and privacy standards we work with.

Selling into a new market usually means meeting a new rulebook. Search the list below to see what each standard asks of you and which Coditing practice helps you meet it.

50
standards and laws
6
regions
16
international frameworks

International standards and frameworks (16)

ISO/IEC 27001The international standard for an information security management system (ISMS), and the most widely requested security certification.Information Security · IS Audit
ISO/IEC 27701An extension to ISO 27001 for managing personal data through a privacy information management system.Data Privacy
ISO/IEC 42001The international standard for AI management systems, covering responsible development and use of AI.AI Security
ISO 22301Requirements for a business continuity management system, so critical services keep running through disruption.Information Security
ISO/IEC 27017 and 27018Guidance on security controls for cloud services, and on protecting personal data in public clouds.Information Security · Data Privacy
ISO/IEC 20000-1Requirements for an IT service management system, often paired with ISO 27001 by service providers.IS Audit
SOC 1 and SOC 2Independent attestation reports on controls over financial reporting (SOC 1) and over security, availability, confidentiality, processing integrity and privacy (SOC 2).IS Audit
PCI DSS v4.0Security requirements for any organisation that stores, processes or transmits payment card data.IS Audit · Cyber Security
CSA STARThe Cloud Security Alliance assurance programme for cloud providers, built on the Cloud Controls Matrix.IS Audit
SWIFT CSPMandatory and advisory security controls for financial institutions connected to the SWIFT network.IS Audit
NIST CSF 2.0A risk-based framework organised around six functions: Govern, Identify, Protect, Detect, Respond and Recover.Information Security
NIST SP 800-53A detailed catalogue of security and privacy controls for information systems and organisations.Information Security
NIST AI RMFA voluntary framework for identifying, measuring and managing the risks of AI systems.AI Security
CIS Controls v8A prioritised set of practical safeguards that defend against the most common cyber attacks.Cyber Security
COBIT 2019A framework for the governance and management of enterprise IT, widely used by auditors.IS Audit
OWASP Top 10 for LLM applicationsThe most critical security risks for applications built on large language models, such as prompt injection.AI Security · Cyber Security

India (5)

DPDP Act 2023India’s Digital Personal Data Protection Act, governing how organisations collect and process digital personal data.Data Privacy
RBI cybersecurity requirementsReserve Bank of India frameworks and directions on cybersecurity and IT governance for banks and regulated entities.IS Audit · Information Security
SEBI CSCRFSEBI’s Cybersecurity and Cyber Resilience Framework for regulated entities in India’s securities markets.IS Audit
IRDAI guidelinesInformation and cybersecurity guidelines issued by the insurance regulator for insurers and intermediaries.IS Audit
CERT-In directionsNational directions covering cyber incident reporting timelines, log retention and related obligations.Cyber Security · Information Security

Middle East (6)

SAMA CSFThe Saudi Central Bank cybersecurity framework for banks, insurers and other financial institutions.IS Audit
NCA ECCEssential Cybersecurity Controls from Saudi Arabia’s National Cybersecurity Authority.Information Security · IS Audit
Saudi PDPLSaudi Arabia’s Personal Data Protection Law and its implementing regulations.Data Privacy
UAE IA RegulationThe UAE Information Assurance Regulation, setting security controls for critical sector entities.Information Security
UAE PDPLThe UAE federal law on the protection of personal data.Data Privacy
Qatar NIAQatar’s National Information Assurance policy and standard for securing information.Information Security

Europe and the United Kingdom (7)

GDPRThe EU General Data Protection Regulation, the benchmark for privacy law worldwide.Data Privacy
UK GDPRThe UK’s version of the GDPR, applied alongside the Data Protection Act 2018.Data Privacy
NIS2The EU directive that raises cybersecurity and incident-reporting duties for essential and important entities.Information Security
DORAThe EU Digital Operational Resilience Act for financial entities and their critical technology providers.IS Audit · Information Security
EU AI ActThe EU’s risk-based regulation of artificial intelligence, with duties that scale with the risk of the use case.AI Security
Cyber Resilience ActEU security requirements for hardware and software products with digital elements.Cyber Security
Cyber EssentialsA UK government-backed certification for basic technical security controls.Cyber Security

Americas (7)

HIPAAUS law protecting health information, including the Privacy and Security Rules.Data Privacy · Information Security
HITRUSTA certifiable security and privacy framework widely used across US healthcare.IS Audit
CCPA / CPRACalifornia’s consumer privacy law, as expanded by the California Privacy Rights Act.Data Privacy
CMMC 2.0The US Department of Defense cybersecurity maturity model for defence contractors.IS Audit
SOX ITGCIT general controls that support reliable financial reporting under Sarbanes-Oxley.IS Audit
PIPEDACanada’s federal privacy law for private-sector organisations.Data Privacy
LGPDBrazil’s General Data Protection Law.Data Privacy

Asia-Pacific (5)

MAS TRMThe Monetary Authority of Singapore’s Technology Risk Management Guidelines for financial institutions.IS Audit
Singapore PDPASingapore’s Personal Data Protection Act.Data Privacy
APRA CPS 234Australia’s prudential standard on information security for regulated financial entities.IS Audit
Essential EightThe Australian Signals Directorate’s eight mitigation strategies, assessed against maturity levels.Cyber Security
Australian Privacy ActAustralia’s Privacy Act 1988 and the Australian Privacy Principles.Data Privacy

Africa (4)

POPIASouth Africa’s Protection of Personal Information Act.Data Privacy
Zambia DPA 2021Zambia’s Data Protection Act of 2021.Data Privacy
Kenya DPA 2019Kenya’s Data Protection Act of 2019.Data Privacy
Nigeria NDPA 2023Nigeria’s Data Protection Act of 2023.Data Privacy

No match. Ask us about it: we map new standards to the controls you already have.

Our approach

One set of controls, many standards.

Most frameworks ask for the same things in different words. We build one control set and map it to every standard you need, so each new certification or market takes a fraction of the work.

Map

We list the standards and laws that apply to your markets, customers and data.

Unify

We design one control set with shared policies and evidence, mapped to every requirement.

Prove

We collect evidence once and reuse it for audits, certifications and customer reviews.

Not sure which standards apply to you?.

Tell us where you sell and what data you handle. We will list the standards that matter and the order to tackle them in.