The List of Applicable Frameworks gives an overview of the cybersecurity, compliance and industry-specific frameworks supported by CSFaaS. These frameworks help you align your governance, risk management and compliance activities with international standards and best practices.

In addition to this library, CSFaaS lets you create and customise your own frameworks to address specific organisational needs and regulatory requirements.

1. Framework and Translation Availability

The table below lists the frameworks available in the import library, with their region of application and language availability (EN, FR, ES). Use it as a quick reference when selecting the frameworks that apply to your organisation.

TypeFrameworkRegionENFRES
PrivacyNIST PF 1.0USYesNoYes
GDPREUYesYesYes
IAPP CIPMUS - EUYesNoNo
Risk ManagementNIST SP 800-37USYesNoNo
Organisational ManagementNIST SP 800-53 rev. 5USYesNoNo
NIST CSF 2.0USYesYesYes
NIST SP 1300 Small BusinessUSYesYesYes
ISO 9001:2015Global (ISO)YesYesYes
ISO 27001:2022Global (ISO)YesYesNo
NCA ECCSAYesNoNo
AICPA SOC2USYesNoNo
CCCS - Baseline Controls for SMECAYesNoNo
CyberFundamentals SmallBEYesYesNo
CyberFundamentals BasicBEYesYesNo
CyberFundamentals ImportantBEYesYesNo
CyberFundamentals EssentialBEYesYesNo
Maturity ModelCMMC 2.0USYesNoNo
HealthHIPAAUSYesNoNo
Financial SectorDORAEUYesYesYes
Critical InfrastructureNIS2EUYesNoNo
NCA CSCCSAYesNoNo
Artificial IntelligenceNIST AI 100-1USYesNoNo
ISO 42001:2023Global (ISO)YesNoNo
CloudNCA CCCSAYesNoNo
Data ProtectionNCA DCCSAYesNoNo
Social MediaNCA OSMACCSAYesNoNo
Operational TechnologyNCA OTCCSAYesNoNo
TeleworkNCA TCCSAYesNoNo
Bank Card IndustryPCI DSSUS - GlobalYesNoNo

2. Requesting a Framework

The library grows over time, and each framework can also gain new language versions. If a framework or a translation you need is not listed, contact the CSFaaS team: specific frameworks can be added on request.

Detailed summaries of each supported framework are available in the next section, in alphabetical order.