Cybersecurity & Compliance · Full article

Compliance Frameworks: SOC 2, ISO 27001, NIST, CIS, GDPR, HIPAA and PCI DSS

A plain-English map of major security, privacy, and industry frameworks and why organizations choose them.

Executive summary

These frameworks are not interchangeable. Some are attestations, some are certifiable standards, some are voluntary guidance, and some are laws or contractual requirements.

In plain English: Think of them as different building codes. A hospital, a payment processor, and a software company may share safety principles, but the inspections and requirements are not identical.

SOC 2

An independent attestation commonly requested from service providers. It focuses on controls related to the Trust Services Criteria.

ISO 27001

A certifiable international standard for building and continuously improving an information security management system.

NIST CSF

A risk-based framework organized around Govern, Identify, Protect, Detect, Respond, and Recover. It helps organizations structure cybersecurity programs.

CIS Controls

A prioritized set of safeguards designed to reduce common cyber risks through practical implementation groups.

GDPR and privacy laws

Privacy rules focus on lawful processing, transparency, individual rights, data minimization, retention, security, and accountability.

HIPAA and PCI DSS

HIPAA protects regulated health information in covered contexts. PCI DSS applies to environments that store, process, or transmit payment-card data.

Why this matters

The correct framework depends on customers, data, industry, geography, contracts, and risk. Compliance should support business strategy instead of becoming a collection of disconnected checklists.

Continue exploring

Technology makes more sense when it connects to a real outcome.

Knowledge Hub