40 cybersecurity frameworks, one reference
From NIST CSF and ISO 27001 to MITRE ATT&CK, CMMC, CIS Controls and BSI IT-Grundschutz — the complete catalogue with region, sector, and compliance type.
What is Cybersecurity compliance automation?
Cybersecurity frameworks are structured collections of controls, processes, and guidance that organisations use to manage and reduce cybersecurity risk. They cover risk management, security controls, threat intelligence, incident response, and compliance — and most mature security programmes adopt several at once. This reference catalogues the 40 most widely-used frameworks worldwide, classified by region, sector, and whether they are mandatory or voluntary.
Why a single-framework programme is no longer enough
- Most enterprises must satisfy three or more frameworks simultaneously (e.g. SOC 2 + ISO 27001 + PCI DSS)
- Sector-specific frameworks (HIPAA, NERC CIP, IEC 62443) overlap with general frameworks but use different control taxonomies
- National frameworks (BSI IT-Grundschutz, ENS, TISAX) add region-specific requirements on top of international standards
- Without a cross-mapped control library, the same evidence is collected three times for three different auditors
A four-step operational model
Pick your primary frameworks
Identify the frameworks that are mandatory for your industry and geography (e.g. PCI DSS for payments, HIPAA for US healthcare, NERC CIP for North American energy).
Layer voluntary frameworks
Add voluntary frameworks that demonstrate maturity to customers and partners — typically NIST CSF, ISO 27001, SOC 2, and CIS Controls.
Map controls once, attest everywhere
Use a unified control library so a single evidence artifact (e.g. an MFA enforcement check) satisfies the equivalent control in every framework you adopt.
Track adoption and certification
Some frameworks are certifiable (ISO 27001, SOC 2, ISO 27701); others are voluntary attestations. Threatstealth tracks both alongside continuous-control evidence.
Complete Cybersecurity Frameworks Reference (40)
Every major cybersecurity framework recognised globally — full name, region, sector focus, and whether adoption is voluntary or mandatory.
| Framework | Full Name | Region | Sector | Type |
|---|---|---|---|---|
| NIST CSF | National Institute of Standards and Technology Cybersecurity Framework | USA | General | Voluntary |
| NIST SP 800-53 | Security and Privacy Controls for Information Systems | USA | Federal/General | Mandatory (Federal) |
| NIST SP 800-171 | Protecting Controlled Unclassified Information | USA | Defense Contractors | Mandatory |
| ISO/IEC 27001 | Information Security Management Systems | International | General | Voluntary/Certifiable |
| ISO/IEC 27002 | Code of Practice for Information Security Controls | International | General | Voluntary |
| ISO/IEC 27005 | Information Security Risk Management | International | General | Voluntary |
| ISO/IEC 27017 | Cloud Security Controls | International | Cloud | Voluntary |
| ISO/IEC 27018 | PII Protection in Public Clouds | International | Cloud | Voluntary |
| ISO/IEC 27032 | Cybersecurity Guidelines | International | General | Voluntary |
| CIS Controls | Center for Internet Security Critical Security Controls | USA | General | Voluntary |
| MITRE ATT&CK | Adversarial Tactics, Techniques & Common Knowledge | USA | Threat Intelligence | Voluntary |
| MITRE D3FEND | Defensive Techniques Knowledge Graph | USA | Defense | Voluntary |
| SOC 2 | Service Organization Control 2 | USA | SaaS/Cloud | Voluntary/Certifiable |
| PCI DSS | Payment Card Industry Data Security Standard | International | Finance/Retail | Mandatory |
| HIPAA Security Rule | Health Insurance Portability and Accountability Act | USA | Healthcare | Mandatory |
| CMMC | Cybersecurity Maturity Model Certification | USA | Defense | Mandatory |
| FedRAMP | Federal Risk and Authorization Management Program | USA | Cloud/Federal | Mandatory |
| COBIT | Control Objectives for Information Technologies | International | IT Governance | Voluntary |
| ITIL | Information Technology Infrastructure Library | International | IT Service Mgmt | Voluntary |
| OWASP Top 10 | Open Web Application Security Project Top 10 | International | Web Security | Voluntary |
| OWASP ASVS | Application Security Verification Standard | International | App Security | Voluntary |
| OWASP SAMM | Software Assurance Maturity Model | International | Dev Security | Voluntary |
| NERC CIP | Critical Infrastructure Protection Standards | USA/Canada | Energy | Mandatory |
| IEC 62443 | Industrial Automation & Control Systems Security | International | OT/ICS | Voluntary |
| NIST SP 800-82 | Guide to ICS Security | USA | ICS/SCADA | Voluntary |
| Cloud Controls Matrix | CSA Cloud Controls Matrix | International | Cloud | Voluntary |
| Zero Trust (NIST SP 800-207) | Zero Trust Architecture | USA | Network/Architecture | Voluntary |
| STIG | Security Technical Implementation Guides | USA | Government | Mandatory |
| CVE | Common Vulnerabilities and Exposures | USA | Vulnerability Mgmt | Voluntary |
| CVSS | Common Vulnerability Scoring System | International | Vulnerability Mgmt | Voluntary |
| STRIDE | Spoofing, Tampering, Repudiation, Info Disclosure, DoS, Elevation | International | Threat Modeling | Voluntary |
| PASTA | Process for Attack Simulation and Threat Analysis | International | Threat Modeling | Voluntary |
| TOGAF | The Open Group Architecture Framework | International | Enterprise Architecture | Voluntary |
| SABSA | Sherwood Applied Business Security Architecture | International | Enterprise Security | Voluntary |
| TISAX | Trusted Information Security Assessment Exchange | Germany/EU | Automotive | Mandatory |
| ENS | Esquema Nacional de Seguridad | Spain | Government | Mandatory |
| ISA/IEC 62443 | Industrial Cybersecurity Standards | International | Industrial | Voluntary |
| NIST SP 800-61 | Computer Security Incident Handling Guide | USA | Incident Response | Voluntary |
| NIST SP 800-137 | Information Security Continuous Monitoring | USA | Monitoring | Voluntary |
| BSI IT-Grundschutz | Federal Office for Information Security Baseline | Germany | General | Mandatory (Germany) |
Outcomes for security teams
Cuts duplicate evidence work by 60–80%
A unified control library means the same MFA, encryption, or logging evidence answers SOC 2, ISO 27001, and PCI DSS auditors at the same time.
Surfaces sector-specific gaps early
Industrial, healthcare, and government workloads carry sector frameworks that general programmes miss — IEC 62443, HIPAA Security Rule, FedRAMP, NERC CIP.
Future-proofs against regulatory shifts
Frameworks evolve continuously (PCI DSS V 4.0.1, NIST CSF 2.0, ISO 27001:2022). A live cross-mapped library updates with the standards.
Direct answers
Which cybersecurity framework should I start with?+
For most organisations, NIST CSF or CIS Controls is the right starting point — both are voluntary, prescriptive, and serve as a foundation that maps cleanly into ISO 27001, SOC 2, and PCI DSS later on.
Are these frameworks legally binding?+
Mandatory frameworks (PCI DSS, HIPAA, CMMC, NERC CIP, FedRAMP, BSI IT-Grundschutz) carry legal or contractual force in their respective jurisdictions. Voluntary frameworks (NIST CSF, ISO 27001, CIS Controls) are widely treated as a baseline of due care even when not legally required.
How do these relate to MITRE ATT&CK?+
MITRE ATT&CK is a knowledge base of adversary techniques rather than a control framework — it complements NIST CSF, ISO 27001, and SOC 2 by providing the threat-side reference that detection rules and red-team plans align to.
Can one platform satisfy several frameworks at once?+
Yes. Threatstealth's control library cross-maps each evidence artifact (MFA enforcement, encryption posture, logging coverage) to the equivalent control in every adopted framework, so the same check satisfies SOC 2 CC6.1, ISO 27001 A.5.15, PCI DSS Req. 7, and NIST CSF PR.AC at the same time.
