The live Reference library is the source for framework import availability. Open Frameworks → Add framework, keep Reference library selected and search by name.

Each entry identifies a reference and language and shows supporting information such as complexity and requirement count. These are catalogue descriptions; they are not proof of legal applicability, complete implementation or a certification outcome.

Add a framework drawer filtered to the English ISO 27001:2022 reference, with its edition, language and import action.
Search the reference library and verify the edition and language before importing. Open full size.

References and languages

The reviewed library includes references from AICPA, the Canadian Centre for Cyber Security, CMMC, CCB CyberFundamentals, EU legislation, HIPAA-related NIST guidance, IAPP, ISO, Saudi NCA, NIST and PCI SSC. Languages vary by entry.

For example, the reviewed CyFun 2025 Basic, Important and Essential entries are available in English and French; the Small entries are labelled 2023. Other families have their own edition and language combinations. Select the actual entry rather than assuming that every framework is available in English, French and Spanish.

Distinguish catalogue and publisher editions

A publisher may have released a newer edition while the catalogue still offers an earlier one. The reviewed library labels NCA ECC as 2018 and CCC as 2020, whereas the publisher has issued updated references. Check the corresponding summary and publisher page before adopting either as your programme baseline.

Likewise, a framework summary in this documentation does not guarantee an import entry. ISO/IEC 42001 was not listed in the reviewed library. Availability can change; verify the live list when you begin.

Missing references

Contact CSFaaS with the publisher, exact reference, required edition and language. Alternatively, use Start blank for a custom structure with clear attribution and appropriate source permissions. Review the imported structure and edition before assigning assessment work.