Frameworks

    Which framework do you actually need?

    Eight frameworks, four very different kinds of audit. Some are certifications with a pass/fail outcome. Some are attestations. Some are regulatory work with no certificate at all. Start here before you post a bid.

    11 of 11 frameworks
    Type
    Jurisdiction
    Pathway availability

    Certifications

    4 frameworks

    A pass/fail credential issued by an accredited certification body against a fixed standard. Directly comparable across companies.

    ISO 27001

    Certification
    ISO/IEC; certified by accredited certification bodies

    ISO/IEC 27001 is the international standard for information security management. An accredited certification body audits your ISMS and issues a certificate.

    Who needs it

    Organizations that want an internationally recognized information-security certification, particularly those selling into European, UK, and APAC markets where ISO 27001 is commonly expected in procurement. It suits companies that want a certificate they can display, not just a report shared under NDA.

    ISO 42001

    Certification
    ISO/IEC; certified by accredited certification bodies

    ISO/IEC 42001 is the first international standard for AI management systems. It certifies how an organization governs the AI it builds or uses.

    Who needs it

    Organizations that build, deploy, or significantly rely on AI systems and want independent assurance over their AI governance: AI-first product companies, enterprises adopting AI in regulated contexts, and vendors whose customers are beginning to ask how their AI is governed.

    CMMC

    Certification

    CMMC is the US Department of Defense's cybersecurity certification requirement for contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), assessed by accredited C3PAOs (Level 2) or the government's DIBCAC (Level 3).

    Who needs it

    Any US Department of Defense prime contractor or subcontractor whose contract includes DFARS 252.204-7021 and handles Federal Contract Information or Controlled Unclassified Information.

    HITRUST

    Certification

    HITRUST CSF is a certifiable framework widely required in US healthcare and health-tech, increasingly used alongside or instead of HIPAA, assessed by HITRUST Authorized External Assessor organizations.

    Who needs it

    Healthcare providers, payers, health-tech vendors, and any organization whose customers or business associates require HITRUST certification, most commonly as an alternative or complement to a HIPAA attestation.

    Attestations

    2 frameworks

    A licensed professional's written opinion on your controls. The scope is defined by the company being audited, so reports are not directly comparable.

    Regulatory audits

    4 frameworks

    Audit or assessment work driven by law rather than a certification scheme. What's delivered is a report or gap analysis, not a certificate.

    HIPAA

    Regulatory audit
    US Department of Health and Human Services, Office for Civil Rights (OCR)

    HIPAA is US law governing how protected health information is safeguarded. There is no official certificate. Compliance is shown through independent assessment.

    Who needs it

    Any organization that creates, receives, maintains, or transmits protected health information for the US healthcare system: providers and health plans, and the SaaS and cloud vendors that serve them as business associates.

    GDPR

    Regulatory audit
    European Union; enforced by national Data Protection Authorities

    GDPR is the EU's data protection law. Compliance is demonstrated through audits and documentation, not a single official certificate.

    Who needs it

    Any organization, anywhere, that processes the personal data of individuals in the EU, including non-EU companies offering goods or services to, or monitoring, people in the EU.

    NIS2

    Regulatory audit
    European Union, enforced by each member state's national competent authority

    NIS2 is an EU cybersecurity law requiring essential and important entities to manage security risks, report incidents, and hold management accountable.

    Who needs it

    Medium and large organizations operating in the EU within covered sectors, including energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing of critical products, and digital providers. Smaller companies can also be pulled in through supply-chain requirements imposed by covered customers.

    DORA

    Regulatory audit
    European Union; European Supervisory Authorities (EBA, ESMA, EIOPA) and national competent authorities

    DORA is an EU regulation requiring financial entities to withstand and recover from ICT disruptions. It applies from January 2025.

    Who needs it

    EU financial entities: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and more, plus the critical ICT third-party providers, including cloud and software vendors, that support them.