Frameworks
COBIT 2019
2019

ISACA COBIT 2019 framework for governance and management of enterprise information and technology. Provides 40 governance and management objectives or...

192 controls
ITIL 4
4

ITIL 4 framework for IT service management. Provides 34 management practices organized into General Management, Service Management, and Technical Mana...

192 controls
Sarbanes-Oxley Act (SOX)
2002

Sarbanes-Oxley Act of 2002 — US federal law requiring publicly traded companies to maintain internal controls over financial reporting (ICFR). Secti...

17 controls USA
C-SOX (Canadian Securities NI 52-109)
2023

Canadian equivalent of Sarbanes-Oxley, implemented through National Instrument 52-109 — Certification of Disclosure in Issuers Annual and Interim Fi...

9 controls Canada
Security Frameworks
General security frameworks and controls
CIS Controls v8
8.1

Center for Internet Security Critical Security Controls Version 8.1. Community-developed set of 18 prioritized safeguards to mitigate the most prevale...

105 controls
Canadian Program for Cyber Security Certification (CPCSC)
1.0

The CPCSC is Canada's official cyber security certification program for defence and government suppliers, managed by Public Services and Procurement C...

253 controls Canada
NIST Cybersecurity Framework
2.0

The NIST Cybersecurity Framework provides a policy framework of computer security guidance for how organizations can assess and improve their ability ...

82 controls
NIST SP 800-171
r3

Protecting Controlled Unclassified Information in Nonfederal Systems...

71 controls USA
HITRUST CSF
11

HITRUST Common Security Framework (CSF) v11 — a certifiable framework that provides organizations with a comprehensive, flexible, and efficient appr...

111 controls
Canadian Centre for Cyber Security Guidance
2024

Baseline Cyber Security Controls for Small and Medium Organizations from the Canadian Centre for Cyber Security....

13 controls Canada
Physical Security Assessment
1.0

Comprehensive physical security audit checklist covering facility access, server room controls, environmental protections, credit card handling, wirel...

178 controls
ISO/IEC 27001
2022

ISO/IEC 27001 is an international standard for information security management systems (ISMS)....

103 controls
EU NIS2 Directive
2024

Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. Effective October 2024, replaces NIS1. Applies to esse...

16 controls EU
CMMC
v2.0

Cybersecurity Maturity Model Certification - Required for DoD contractors handling CUI/FCI. Three levels from basic safeguarding (Level 1) to advanced...

53 controls USA
UK Cyber Essentials
2025

UK government-backed Cyber Essentials certification scheme (Willow update, effective April 2025). Covers five fundamental security controls required t...

10 controls UK
EU Cyber Resilience Act (CRA)
2024

Regulation (EU) 2024/2847 — Cyber Resilience Act, entered into force 10 December 2024. Establishes mandatory cybersecurity requirements for products...

8 controls EU
SOC 2
2024

SOC 2 Trust Services Criteria — Type I (point-in-time design assessment) and Type II (operating effectiveness over a period, typically 6-12 months)....

61 controls
Canadian Cyber Essentials
2024

Baseline cyber security for Canadian small and medium organizations...

20 controls Canada
Australian Essential Eight
2024

Australian Signals Directorate (ASD) Essential Eight Maturity Model — eight prioritized mitigation strategies to protect internet-connected IT netwo...

18 controls Australia
Privacy Frameworks
Privacy and data protection regulations
CCPA / CPRA
2023

California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). Applies to for-profit businesses that collect Californi...

10 controls USA - California
Alberta PIPA
2022

Alberta Personal Information Protection Act (PIPA). Governs the collection, use, and disclosure of personal information by private sector organization...

21 controls Canada - Alberta
HIPAA Security Rule
2024

The HIPAA Security Rule establishes national standards to protect individuals' electronic personal health information....

52 controls USA
BC E-Health Act
2024

British Columbia E-Health (Personal Health Information Access and Protection of Privacy) Act. Governs electronic personal health information held by h...

10 controls Canada - BC
BC PIPA
2023

British Columbia Personal Information Protection Act (PIPA). Governs the collection, use, and disclosure of personal information by private sector org...

10 controls Canada - BC
Alberta Health Information Act
2024

Alberta Health Information Act (HIA) requirements for custodians of health information....

10 controls Canada - Alberta
Quebec Law 25 (Private Sector Privacy)
2024

Quebec Act respecting the protection of personal information in the private sector, as amended by Bill 64 (Law 25). Phased implementation 2022-2024. A...

13 controls Canada - Quebec
BC FIPPA
2023

British Columbia Freedom of Information and Protection of Privacy Act (FIPPA/FOIPPA). Applies to BC public bodies including provincial government mini...

22 controls Canada - BC
EU GDPR
2018

General Data Protection Regulation (EU) 2016/679 — the world's strongest data privacy law. Applies to any organization processing personal data of E...

17 controls EU
UK GDPR / Data Protection Act 2018
2021

UK General Data Protection Regulation (retained EU law post-Brexit) together with the Data Protection Act 2018. Substantively mirrors EU GDPR with UK-...

12 controls UK
Australian Privacy Act 1988
2024

Australian Privacy Act 1988 including the Australian Privacy Principles (APPs). Applies to Australian Government agencies and private sector organizat...

10 controls Australia
PIPEDA
2024

Personal Information Protection and Electronic Documents Act — Canada's federal private-sector privacy law. Applies to organizations that collect, u...

36 controls Canada
Industry Frameworks
Industry-specific compliance requirements
PCI DSS SAQ A
v4.0.1

For card-not-present merchants (e-commerce, mail/telephone order) that have fully outsourced all cardholder data functions to PCI DSS compliant third-...

15 controls
PCI DSS SAQ B
v4.0.1

For merchants using only imprint machines or standalone dial-out terminals (no electronic cardholder data storage). Connected via analogue phone line ...

10 controls
PCI DSS SAQ A-EP
v4.0.1

For e-commerce merchants with a website that redirects to a third-party payment processor. The merchant website does not receive cardholder data but d...

33 controls
PCI DSS SAQ B-IP
v4.0.1

For merchants using only standalone, PCI PTS-approved point-of-interaction (POI) terminals with an IP connection to the payment processor. No electron...

20 controls
PCI DSS SAQ C
v4.0.1

For merchants with payment application systems (e.g., POS systems) connected to the Internet. No electronic cardholder data storage. Covers all 12 PCI...

39 controls
PCI DSS SAQ C-VT
v4.0.1

For merchants manually entering a single transaction at a time via a web-based virtual terminal provided by a PCI DSS compliant third-party service pr...

16 controls
PCI DSS SAQ D
v4.0.1

Full PCI DSS assessment for merchants and service providers that do not meet the criteria for any other SAQ type. Covers all 12 requirement areas with...

95 controls
FTC Safeguards Rule
2023

FTC Standards for Safeguarding Customer Information (16 CFR 314), revised 2023. Applies to non-bank financial institutions including auto dealerships,...

21 controls USA
GLBA — Gramm-Leach-Bliley Act
2023

Gramm-Leach-Bliley Act (GLBA) financial privacy and safeguards requirements for US financial institutions. Includes the Financial Privacy Rule (custom...

13 controls USA
FINTRAC / PCMLTFA
2024

Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) requirements under the Proceeds of Crime (Money Laundering) and Terrorist Finan...

12 controls Canada
EU DORA
2025

Digital Operational Resilience Act — Regulation (EU) 2022/2554, effective 17 January 2025. Applies to 20 types of EU financial entities (banks, insu...

19 controls EU
NERC CIP
7

North American Electric Reliability Corporation Critical Infrastructure Protection standards for the bulk electric system....

11 controls North America
IIROC Cybersecurity Best Practices
2024

Investment Industry Regulatory Organization of Canada Cybersecurity Best Practices for member firms....

25 controls Canada
CPA Canada Cybersecurity Framework
2024

CPA Canada guidance on cybersecurity risk management and reporting....

34 controls Canada
Regional Frameworks
Regional and jurisdictional requirements
Ontario Cyber Security Framework
2024

Ontario government cybersecurity framework for public sector organizations....

39 controls Canada - Ontario
NYDFS Cybersecurity Regulation
2023

New York Department of Financial Services Cybersecurity Regulation (23 NYCRR 500), amended 2023. Applies to all DFS-regulated entities including banks...

19 controls USA - New York
BC Financial Services Authority Security Guidance
2024

British Columbia Financial Services Authority cybersecurity and technology risk management guidance....

33 controls Canada - BC
Onboarding Frameworks
Client onboarding checklists
MSP Onboarding Checklist
1.0

Custom onboarding checklist for MSP clients including security tools, Microsoft 365, and billing setup....

0 controls