Skip to content
SCA

Compliance Comparison

Compare frameworks side by side

Region, nature, obligation, and how each framework is assured — at a glance.

FrameworkRegionNatureObligationAssurance
ISO/IEC 27001InternationalStandard (ISMS)VoluntaryAccredited certification
NIST CSF 2.0US / InternationalFramework (outcomes)VoluntarySelf-assessment / profiles
SOC 2US (widely used)Attestation (TSC)ContractualCPA-firm report (Type I/II)
GDPREU / EEARegulation (privacy)LegalSupervisory-authority enforcement
CIS Controls v8InternationalControl catalogVoluntarySelf-assessment (IG1–IG3)
DORAEU (financial sector)Regulation (resilience)LegalRegulatory supervision
NIS2EU (essential/important)Directive (security)LegalCompetent-authority supervision
ISO/IEC 42001InternationalStandard (AIMS)VoluntaryAccredited certification

High-level comparison for orientation. Obligation depends on your sector and jurisdiction; always confirm applicability against the authoritative text. A richer, filterable comparator is planned as this section matures.