Skip to content

Frameworks

Path: /frameworks

Frameworks

Browse the compliance frameworks loaded in the system. Each framework contains a set of controls your organization must implement.

Supported Frameworks

Control counts below are pulled from the live /api/v1/frameworks response — they reflect exactly what the backend ships: 20 frameworks, 2,082 controls.

Framework Controls Description
NIST SP 800-53 Rev. 5 1014 Full federal security and privacy control catalogue
CMMC Level 2 110 Cybersecurity Maturity Model Certification for defense contractors
NIST SP 800-171 Rev. 2 110 Protecting CUI in non-federal systems and organizations
CCPA / CPRA 107 California consumer privacy statute plus the CCPA Regulations
NIST Cybersecurity Framework 2.0 106 CSF 2.0 subcategories across GOVERN / IDENTIFY / PROTECT / DETECT / RESPOND / RECOVER
ISO/IEC 27001:2022 93 Information Security Management System (ISMS) requirements and Annex A controls
TISAX (VDA ISA 6.0.3) 80 Automotive information-security assessment catalogue
DORA (Regulation (EU) 2022/2554) 64 EU digital operational resilience obligations for financial entities
PCI DSS v4.0.1 63 Payment-card industry data security requirements
NIS2 (Directive (EU) 2022/2555) 63 EU network and information security obligations, incl. IR 2024/2690
SOC 2 Type II 61 Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy
ISO/IEC 42001:2023 38 AI Management System — all Annex A reference controls (ids prefixed 42001-)
GDPR 30 EU data-protection obligations (Articles 25–34)
HIPAA Security Rule 25 Administrative, physical, and technical safeguards for ePHI (§ 164.308–316)
NYDFS Part 500 25 23 NYCRR Part 500 cybersecurity requirements (Second Amendment)
CMMC Level 3 24 Expert-level CUI protection for the highest-priority DoD programs
NIST AI RMF 1.0 19 AI Risk Management Framework Core at category level (GOVERN / MAP / MEASURE / MANAGE)
EU AI Act (2024/1689) 19 Article-cited obligation checklist: prohibited practices, high-risk requirements, transparency, GPAI, post-market monitoring
GLBA Safeguards Rule (FTC) 16 FTC Standards for Safeguarding Customer Information — required program elements under 16 CFR § 314.4(a)–(i)
CMMC Level 1 15 FAR 52.204-21 basic safeguarding of federal contract information

ISO/IEC 42001, NIST AI RMF, and the EU AI Act form the AI-governance pack, which also ships an AI-system registry and crosswalks into ISO 27001.

NIST 800-53 Rev 5 — the full catalogue, served live

All 1,014 NIST SP 800-53 Rev. 5 controls are served by /api/v1/frameworks and browsable in this UI, so they are available for assessment and cross-framework mapping like any other framework.

How to Explore a Framework

  1. Click View Controls on any framework card.
  2. Browse controls by category/family.
  3. Use the search bar to find specific controls (e.g., "encryption", "access control").
  4. Each control shows its ID, title, description, and category.