Frameworks we automate
31 frameworks and regulations, cross-mapped so one control counts everywhere it applies. Pick one for the expert guide.
The world's first certifiable standard for AI governance. Compriska was built for it.
The report every B2B deal asks for. Get audit-ready without the spreadsheet grind.
The global gold standard for security programs, certifiable and built to last.
Handle protected health information like the regulated asset it is.
Privacy compliance for anyone with users in Europe — which is nearly everyone.
Twelve requirements, four levels, zero tolerance for stored card data mistakes.
The common language of security programs — now with governance at the center.
The prioritized to-do list of security — start where attacks actually happen.
The world's first comprehensive AI law — phasing in now, reaching far beyond Europe.
America's voluntary blueprint for trustworthy AI — the vocabulary your enterprise customers now speak.
The report you need when your service touches your customers' financial statements.
The public, shareable version of your SOC 2 — marketing-friendly trust.
The privacy extension to ISO 27001 — one certified system for security and privacy.
Cloud-specific security controls that tell cloud buyers you speak their language.
The cloud-processor privacy code of practice enterprise DPAs love to see.
Certified proof that your business survives bad days — increasingly demanded by regulators.
The 1,000-control catalog behind FedRAMP and federal systems — tamed by good tooling.
110 requirements every defense-supply-chain company must meet — and now prove, under CMMC.
The DoD's verification regime — defense contracts now hinge on certified, not claimed, security.
The authorization that opens the US federal market — heavyweight, but a moat once you hold it.
Healthcare's favorite security certification — HIPAA assurance with an actual certificate.
America's de facto national privacy law — plus the growing pack of state laws behind it.
New York's financial-services security regulation — annually certified, personally attested.
Europe's operational-resilience law for finance — and a direct reach into ICT vendors.
Europe's baseline cybersecurity law for essential sectors — with personal management liability.
The UK's entry-level certification — mandatory for much government work, cheap credibility everywhere.
The IT controls behind financial reporting — where going public meets your access reviews.
The FTC's security rule for anyone touching consumer financial data — broader than you think.
Australia's eight mitigation strategies — the security baseline Australian buyers ask about first.
The Australian financial regulator's security standard — reaching every vendor that touches regulated data.
The FBI's security policy for criminal justice data — strict, specific, and non-negotiable for gov-tech.
See Compriska in action
A 30-minute walkthrough of the platform, tailored to your frameworks and industry.
Book a demo