Which framework do you actually need?
Eight frameworks, four very different kinds of audit. Some are certifications with a pass/fail outcome. Some are attestations. Some are regulatory work with no certificate at all. Start here before you post a bid.
Certifications
4 frameworksA pass/fail credential issued by an accredited certification body against a fixed standard. Directly comparable across companies.
ISO 27001
CertificationISO/IEC 27001 is the international standard for information security management. An accredited certification body audits your ISMS and issues a certificate.
Organizations that want an internationally recognized information-security certification, particularly those selling into European, UK, and APAC markets where ISO 27001 is commonly expected in procurement. It suits companies that want a certificate they can display, not just a report shared under NDA.
ISO 42001
CertificationISO/IEC 42001 is the first international standard for AI management systems. It certifies how an organization governs the AI it builds or uses.
Organizations that build, deploy, or significantly rely on AI systems and want independent assurance over their AI governance: AI-first product companies, enterprises adopting AI in regulated contexts, and vendors whose customers are beginning to ask how their AI is governed.
CMMC
CertificationCMMC is the US Department of Defense's cybersecurity certification requirement for contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), assessed by accredited C3PAOs (Level 2) or the government's DIBCAC (Level 3).
Any US Department of Defense prime contractor or subcontractor whose contract includes DFARS 252.204-7021 and handles Federal Contract Information or Controlled Unclassified Information.
HITRUST
CertificationHITRUST CSF is a certifiable framework widely required in US healthcare and health-tech, increasingly used alongside or instead of HIPAA, assessed by HITRUST Authorized External Assessor organizations.
Healthcare providers, payers, health-tech vendors, and any organization whose customers or business associates require HITRUST certification, most commonly as an alternative or complement to a HIPAA attestation.
Attestations
2 frameworksA licensed professional's written opinion on your controls. The scope is defined by the company being audited, so reports are not directly comparable.
SOC 2
AttestationSOC 2 is an AICPA attestation report that shows how a company protects customer data. A licensed CPA firm tests your controls and issues an independent opinion.
B2B software and cloud companies that store or process customer data, especially those selling to US enterprises. SOC 2 is the report mid-market and enterprise procurement teams request most often during vendor security reviews, so it is usually the first framework a growing SaaS company is asked to produce.
PCI DSS
AttestationPCI DSS is the mandatory security standard for any organization that stores, processes, or transmits payment card data, assessed by Qualified Security Assessor (QSA) firms via a Report on Compliance (RoC).
Any merchant, service provider, or processor that stores, processes, or transmits payment card data, including e-commerce platforms, payment gateways, SaaS providers handling card data, and fintechs whose acquirer or card brand requires a Report on Compliance.
Regulatory audits
4 frameworksAudit or assessment work driven by law rather than a certification scheme. What's delivered is a report or gap analysis, not a certificate.
HIPAA
Regulatory auditHIPAA is US law governing how protected health information is safeguarded. There is no official certificate. Compliance is shown through independent assessment.
Any organization that creates, receives, maintains, or transmits protected health information for the US healthcare system: providers and health plans, and the SaaS and cloud vendors that serve them as business associates.
GDPR
Regulatory auditGDPR is the EU's data protection law. Compliance is demonstrated through audits and documentation, not a single official certificate.
Any organization, anywhere, that processes the personal data of individuals in the EU, including non-EU companies offering goods or services to, or monitoring, people in the EU.
NIS2
Regulatory auditNIS2 is an EU cybersecurity law requiring essential and important entities to manage security risks, report incidents, and hold management accountable.
Medium and large organizations operating in the EU within covered sectors, including energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing of critical products, and digital providers. Smaller companies can also be pulled in through supply-chain requirements imposed by covered customers.
DORA
Regulatory auditDORA is an EU regulation requiring financial entities to withstand and recover from ICT disruptions. It applies from January 2025.
EU financial entities: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and more, plus the critical ICT third-party providers, including cloud and software vendors, that support them.
Product conformity
1 frameworkAssessment applies to a product placed on the market, not the company that made it. Most cases are self-assessment; some require a notified body.