Compliance Comparison
Compare frameworks side by side
Region, nature, obligation, and how each framework is assured — at a glance.
| Framework | Region | Nature | Obligation | Assurance |
|---|---|---|---|---|
| ISO/IEC 27001 | International | Standard (ISMS) | Voluntary | Accredited certification |
| NIST CSF 2.0 | US / International | Framework (outcomes) | Voluntary | Self-assessment / profiles |
| SOC 2 | US (widely used) | Attestation (TSC) | Contractual | CPA-firm report (Type I/II) |
| GDPR | EU / EEA | Regulation (privacy) | Legal | Supervisory-authority enforcement |
| CIS Controls v8 | International | Control catalog | Voluntary | Self-assessment (IG1–IG3) |
| DORA | EU (financial sector) | Regulation (resilience) | Legal | Regulatory supervision |
| NIS2 | EU (essential/important) | Directive (security) | Legal | Competent-authority supervision |
| ISO/IEC 42001 | International | Standard (AIMS) | Voluntary | Accredited certification |
High-level comparison for orientation. Obligation depends on your sector and jurisdiction; always confirm applicability against the authoritative text. A richer, filterable comparator is planned as this section matures.