| Shipped in the box: free, MIT |
| SOC 2: Trust Services Criteria | SaaS selling to enterprise | Included |
| ISO/IEC 27001:2022: Annex A | International certification | Included |
| PCI DSS v4.0.1 | Card data environments | Included |
| Attestation and assurance |
| SOC 2 Type II: operating-effectiveness overlay | Observation-window evidence, sampling and population design on top of the shipped criteria | Catalogue |
| SOC 1: ICFR (SSAE 18) | Payroll, billing and anything touching a client's financial statements | Commission |
| SOC 3 | A public-facing report derived from the SOC 2 scope | Commission |
| CSA STAR Level 2: CCM v4 | Cloud providers answering CAIQ, and the customers auditing them | Commission |
| HITRUST CSF: e1 / i1 baselines | Healthcare vendors whose customers demand HITRUST specifically | Commission |
| ISO management systems |
| ISO/IEC 42001:2023: AI management systems | Anyone shipping AI features and being asked how they govern them | Catalogue |
| ISO/IEC 27017:2015: cloud security controls | Cloud service providers and the customers relying on them | Catalogue |
| ISO/IEC 27018:2019: PII in public clouds | Processors handling personal data on behalf of controllers | Catalogue |
| ISO/IEC 27701:2019: privacy information management | Extending an ISO 27001 ISMS to cover privacy | Catalogue |
| ISO 22301:2019: business continuity | Continuity and resilience obligations in enterprise contracts | Catalogue |
| ISO/IEC 27002:2022: implementation guidance | Teams that want the guidance modelled alongside Annex A | Commission |
| ISO 9001:2015: quality management | Manufacturing and services, usually alongside 27001 | Commission |
| Healthcare and privacy |
| HIPAA: Security and Breach Notification Rules | US covered entities and their business associates | Catalogue |
| FIPPA: Ontario provincial | Ontario public bodies and their service providers | Catalogue |
| MFIPPA: Ontario municipal | Municipalities, police services boards, school boards | Catalogue |
| PHIPA: Ontario personal health information | Health information custodians and their agents | Catalogue |
| PIPEDA: Canadian federal private sector | Commercial activity across provincial borders | Catalogue |
| Quebec Law 25 | Anyone holding personal information of Quebec residents | Catalogue |
| GDPR: Articles 5, 24-32 and records of processing | EU/UK data subjects, wherever you are hosted | Catalogue |
| CCPA / CPRA | California consumer data at threshold volumes | Catalogue |
| Government, defence and public sector |
| NIST CSF 2.0 | A common language for boards and for supplier questionnaires | Catalogue |
| NIST SP 800-53 Rev. 5: Low / Moderate / High | US federal systems and anything modelled on them | Catalogue |
| NIST SP 800-171 Rev. 2: CUI | Defence supply chain holding controlled unclassified information | Catalogue |
| CMMC Level 2 | DoD contractors, assessed against 800-171 | Catalogue |
| CCCS ITSG-33 Annex 3A: PBMM profile | Canadian federal departments and their suppliers | Catalogue |
| Protected B: Canadian government handling | Suppliers processing Protected B information | Commission |
| FedRAMP Moderate (Rev. 5 overlay) | Selling cloud services to US federal agencies | Catalogue |
| StateRAMP · TX-RAMP | Selling cloud services to state or Texas agencies | Commission |
| Sector and financial |
| CIS Controls v8.1: IG1 / IG2 / IG3 | A practical hardening baseline that maps cleanly to everything else | Catalogue |
| SOX ITGC | IT general controls for public-company financial reporting | Catalogue |
| OSFI B-13: technology and cyber risk | Canadian federally regulated financial institutions | Catalogue |
| NY DFS Part 500 | Financial services licensed in New York | Commission |
| GLBA Safeguards Rule · FFIEC CAT | US financial institutions and non-bank lenders | Commission |
| NERC CIP | Bulk electric system operators | Commission |
| TISAX / VDA ISA | Automotive supply chain | Commission |
| Your own control set or a customer's security addendum | Anything you have to evidence line by line and cannot buy off a shelf | Bespoke |