Skip to main content
Threatstealth
Login
// CYBERSECURITY.FRAMEWORKS

40 cybersecurity frameworks, one reference

From NIST CSF and ISO 27001 to MITRE ATT&CK, CMMC, CIS Controls and BSI IT-Grundschutz — the complete catalogue with region, sector, and compliance type.

Reviewed by Threatstealth Security Architects·Aligned to SOC 2 · ISO 27001 · NIST CSF · PCI DSS V 4.0.1
// DEFINITION

What is Cybersecurity compliance automation?

Cybersecurity frameworks are structured collections of controls, processes, and guidance that organisations use to manage and reduce cybersecurity risk. They cover risk management, security controls, threat intelligence, incident response, and compliance — and most mature security programmes adopt several at once. This reference catalogues the 40 most widely-used frameworks worldwide, classified by region, sector, and whether they are mandatory or voluntary.

// THE.PROBLEM

Why a single-framework programme is no longer enough

  • Most enterprises must satisfy three or more frameworks simultaneously (e.g. SOC 2 + ISO 27001 + PCI DSS)
  • Sector-specific frameworks (HIPAA, NERC CIP, IEC 62443) overlap with general frameworks but use different control taxonomies
  • National frameworks (BSI IT-Grundschutz, ENS, TISAX) add region-specific requirements on top of international standards
  • Without a cross-mapped control library, the same evidence is collected three times for three different auditors
// HOW.IT.WORKS

A four-step operational model

1

Pick your primary frameworks

Identify the frameworks that are mandatory for your industry and geography (e.g. PCI DSS for payments, HIPAA for US healthcare, NERC CIP for North American energy).

2

Layer voluntary frameworks

Add voluntary frameworks that demonstrate maturity to customers and partners — typically NIST CSF, ISO 27001, SOC 2, and CIS Controls.

3

Map controls once, attest everywhere

Use a unified control library so a single evidence artifact (e.g. an MFA enforcement check) satisfies the equivalent control in every framework you adopt.

4

Track adoption and certification

Some frameworks are certifiable (ISO 27001, SOC 2, ISO 27701); others are voluntary attestations. Threatstealth tracks both alongside continuous-control evidence.

40
Cybersecurity frameworks tracked
5
Regulatory regions covered
12+
Sector-specific standards
100
Total global frameworks (cyber+privacy+AI)
// REFERENCE.01

Complete Cybersecurity Frameworks Reference (40)

Every major cybersecurity framework recognised globally — full name, region, sector focus, and whether adoption is voluntary or mandatory.

FrameworkFull NameRegionSectorType
NIST CSFNational Institute of Standards and Technology Cybersecurity FrameworkUSAGeneralVoluntary
NIST SP 800-53Security and Privacy Controls for Information SystemsUSAFederal/GeneralMandatory (Federal)
NIST SP 800-171Protecting Controlled Unclassified InformationUSADefense ContractorsMandatory
ISO/IEC 27001Information Security Management SystemsInternationalGeneralVoluntary/Certifiable
ISO/IEC 27002Code of Practice for Information Security ControlsInternationalGeneralVoluntary
ISO/IEC 27005Information Security Risk ManagementInternationalGeneralVoluntary
ISO/IEC 27017Cloud Security ControlsInternationalCloudVoluntary
ISO/IEC 27018PII Protection in Public CloudsInternationalCloudVoluntary
ISO/IEC 27032Cybersecurity GuidelinesInternationalGeneralVoluntary
CIS ControlsCenter for Internet Security Critical Security ControlsUSAGeneralVoluntary
MITRE ATT&CKAdversarial Tactics, Techniques & Common KnowledgeUSAThreat IntelligenceVoluntary
MITRE D3FENDDefensive Techniques Knowledge GraphUSADefenseVoluntary
SOC 2Service Organization Control 2USASaaS/CloudVoluntary/Certifiable
PCI DSSPayment Card Industry Data Security StandardInternationalFinance/RetailMandatory
HIPAA Security RuleHealth Insurance Portability and Accountability ActUSAHealthcareMandatory
CMMCCybersecurity Maturity Model CertificationUSADefenseMandatory
FedRAMPFederal Risk and Authorization Management ProgramUSACloud/FederalMandatory
COBITControl Objectives for Information TechnologiesInternationalIT GovernanceVoluntary
ITILInformation Technology Infrastructure LibraryInternationalIT Service MgmtVoluntary
OWASP Top 10Open Web Application Security Project Top 10InternationalWeb SecurityVoluntary
OWASP ASVSApplication Security Verification StandardInternationalApp SecurityVoluntary
OWASP SAMMSoftware Assurance Maturity ModelInternationalDev SecurityVoluntary
NERC CIPCritical Infrastructure Protection StandardsUSA/CanadaEnergyMandatory
IEC 62443Industrial Automation & Control Systems SecurityInternationalOT/ICSVoluntary
NIST SP 800-82Guide to ICS SecurityUSAICS/SCADAVoluntary
Cloud Controls MatrixCSA Cloud Controls MatrixInternationalCloudVoluntary
Zero Trust (NIST SP 800-207)Zero Trust ArchitectureUSANetwork/ArchitectureVoluntary
STIGSecurity Technical Implementation GuidesUSAGovernmentMandatory
CVECommon Vulnerabilities and ExposuresUSAVulnerability MgmtVoluntary
CVSSCommon Vulnerability Scoring SystemInternationalVulnerability MgmtVoluntary
STRIDESpoofing, Tampering, Repudiation, Info Disclosure, DoS, ElevationInternationalThreat ModelingVoluntary
PASTAProcess for Attack Simulation and Threat AnalysisInternationalThreat ModelingVoluntary
TOGAFThe Open Group Architecture FrameworkInternationalEnterprise ArchitectureVoluntary
SABSASherwood Applied Business Security ArchitectureInternationalEnterprise SecurityVoluntary
TISAXTrusted Information Security Assessment ExchangeGermany/EUAutomotiveMandatory
ENSEsquema Nacional de SeguridadSpainGovernmentMandatory
ISA/IEC 62443Industrial Cybersecurity StandardsInternationalIndustrialVoluntary
NIST SP 800-61Computer Security Incident Handling GuideUSAIncident ResponseVoluntary
NIST SP 800-137Information Security Continuous MonitoringUSAMonitoringVoluntary
BSI IT-GrundschutzFederal Office for Information Security BaselineGermanyGeneralMandatory (Germany)
40 entries
// WHY.IT.MATTERS

Outcomes for security teams

Cuts duplicate evidence work by 60–80%

A unified control library means the same MFA, encryption, or logging evidence answers SOC 2, ISO 27001, and PCI DSS auditors at the same time.

Surfaces sector-specific gaps early

Industrial, healthcare, and government workloads carry sector frameworks that general programmes miss — IEC 62443, HIPAA Security Rule, FedRAMP, NERC CIP.

Future-proofs against regulatory shifts

Frameworks evolve continuously (PCI DSS V 4.0.1, NIST CSF 2.0, ISO 27001:2022). A live cross-mapped library updates with the standards.

// FAQ

Direct answers

Which cybersecurity framework should I start with?+

For most organisations, NIST CSF or CIS Controls is the right starting point — both are voluntary, prescriptive, and serve as a foundation that maps cleanly into ISO 27001, SOC 2, and PCI DSS later on.

Are these frameworks legally binding?+

Mandatory frameworks (PCI DSS, HIPAA, CMMC, NERC CIP, FedRAMP, BSI IT-Grundschutz) carry legal or contractual force in their respective jurisdictions. Voluntary frameworks (NIST CSF, ISO 27001, CIS Controls) are widely treated as a baseline of due care even when not legally required.

How do these relate to MITRE ATT&CK?+

MITRE ATT&CK is a knowledge base of adversary techniques rather than a control framework — it complements NIST CSF, ISO 27001, and SOC 2 by providing the threat-side reference that detection rules and red-team plans align to.

Can one platform satisfy several frameworks at once?+

Yes. Threatstealth's control library cross-maps each evidence artifact (MFA enforcement, encryption posture, logging coverage) to the equivalent control in every adopted framework, so the same check satisfies SOC 2 CC6.1, ISO 27001 A.5.15, PCI DSS Req. 7, and NIST CSF PR.AC at the same time.

Closed · Expert Access

Ready to see it in your environment?

Request a private security demo from the Threatstealth team.