Frameworks¶
Path: /frameworks

Browse the compliance frameworks loaded in the system. Each framework contains a set of controls your organization must implement.
Supported Frameworks¶
Control counts below are pulled from the live /api/v1/frameworks response —
they reflect exactly what the backend ships: 20 frameworks, 2,082 controls.
| Framework | Controls | Description |
|---|---|---|
| NIST SP 800-53 Rev. 5 | 1014 | Full federal security and privacy control catalogue |
| CMMC Level 2 | 110 | Cybersecurity Maturity Model Certification for defense contractors |
| NIST SP 800-171 Rev. 2 | 110 | Protecting CUI in non-federal systems and organizations |
| CCPA / CPRA | 107 | California consumer privacy statute plus the CCPA Regulations |
| NIST Cybersecurity Framework 2.0 | 106 | CSF 2.0 subcategories across GOVERN / IDENTIFY / PROTECT / DETECT / RESPOND / RECOVER |
| ISO/IEC 27001:2022 | 93 | Information Security Management System (ISMS) requirements and Annex A controls |
| TISAX (VDA ISA 6.0.3) | 80 | Automotive information-security assessment catalogue |
| DORA (Regulation (EU) 2022/2554) | 64 | EU digital operational resilience obligations for financial entities |
| PCI DSS v4.0.1 | 63 | Payment-card industry data security requirements |
| NIS2 (Directive (EU) 2022/2555) | 63 | EU network and information security obligations, incl. IR 2024/2690 |
| SOC 2 Type II | 61 | Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy |
| ISO/IEC 42001:2023 | 38 | AI Management System — all Annex A reference controls (ids prefixed 42001-) |
| GDPR | 30 | EU data-protection obligations (Articles 25–34) |
| HIPAA Security Rule | 25 | Administrative, physical, and technical safeguards for ePHI (§ 164.308–316) |
| NYDFS Part 500 | 25 | 23 NYCRR Part 500 cybersecurity requirements (Second Amendment) |
| CMMC Level 3 | 24 | Expert-level CUI protection for the highest-priority DoD programs |
| NIST AI RMF 1.0 | 19 | AI Risk Management Framework Core at category level (GOVERN / MAP / MEASURE / MANAGE) |
| EU AI Act (2024/1689) | 19 | Article-cited obligation checklist: prohibited practices, high-risk requirements, transparency, GPAI, post-market monitoring |
| GLBA Safeguards Rule (FTC) | 16 | FTC Standards for Safeguarding Customer Information — required program elements under 16 CFR § 314.4(a)–(i) |
| CMMC Level 1 | 15 | FAR 52.204-21 basic safeguarding of federal contract information |
ISO/IEC 42001, NIST AI RMF, and the EU AI Act form the AI-governance pack, which also ships an AI-system registry and crosswalks into ISO 27001.
NIST 800-53 Rev 5 — the full catalogue, served live
All 1,014 NIST SP 800-53 Rev. 5 controls are served by
/api/v1/frameworks and browsable in this UI, so they are available for
assessment and cross-framework mapping like any other framework.
How to Explore a Framework¶
- Click View Controls on any framework card.
- Browse controls by category/family.
- Use the search bar to find specific controls (e.g., "encryption", "access control").
- Each control shows its ID, title, description, and category.