Frameworks we automate

31 frameworks and regulations, cross-mapped so one control counts everywhere it applies. Pick one for the expert guide.

ISO 42001

The world's first certifiable standard for AI governance. Compriska was built for it.

Read the guide →
SOC 2

The report every B2B deal asks for. Get audit-ready without the spreadsheet grind.

Read the guide →
ISO 27001

The global gold standard for security programs, certifiable and built to last.

Read the guide →
HIPAA

Handle protected health information like the regulated asset it is.

Read the guide →
GDPR

Privacy compliance for anyone with users in Europe — which is nearly everyone.

Read the guide →
PCI DSS

Twelve requirements, four levels, zero tolerance for stored card data mistakes.

Read the guide →
NIST CSF

The common language of security programs — now with governance at the center.

Read the guide →
CIS Controls

The prioritized to-do list of security — start where attacks actually happen.

Read the guide →
EU AI Act

The world's first comprehensive AI law — phasing in now, reaching far beyond Europe.

Read the guide →
NIST AI RMF

America's voluntary blueprint for trustworthy AI — the vocabulary your enterprise customers now speak.

Read the guide →
SOC 1

The report you need when your service touches your customers' financial statements.

Read the guide →
SOC 3

The public, shareable version of your SOC 2 — marketing-friendly trust.

Read the guide →
ISO 27701

The privacy extension to ISO 27001 — one certified system for security and privacy.

Read the guide →
ISO 27017

Cloud-specific security controls that tell cloud buyers you speak their language.

Read the guide →
ISO 27018

The cloud-processor privacy code of practice enterprise DPAs love to see.

Read the guide →
ISO 22301

Certified proof that your business survives bad days — increasingly demanded by regulators.

Read the guide →
NIST 800-53

The 1,000-control catalog behind FedRAMP and federal systems — tamed by good tooling.

Read the guide →
NIST 800-171

110 requirements every defense-supply-chain company must meet — and now prove, under CMMC.

Read the guide →
CMMC

The DoD's verification regime — defense contracts now hinge on certified, not claimed, security.

Read the guide →
FedRAMP

The authorization that opens the US federal market — heavyweight, but a moat once you hold it.

Read the guide →
HITRUST

Healthcare's favorite security certification — HIPAA assurance with an actual certificate.

Read the guide →
CCPA/CPRA

America's de facto national privacy law — plus the growing pack of state laws behind it.

Read the guide →
NYDFS 500

New York's financial-services security regulation — annually certified, personally attested.

Read the guide →
DORA

Europe's operational-resilience law for finance — and a direct reach into ICT vendors.

Read the guide →
NIS2

Europe's baseline cybersecurity law for essential sectors — with personal management liability.

Read the guide →
Cyber Essentials

The UK's entry-level certification — mandatory for much government work, cheap credibility everywhere.

Read the guide →
SOX ITGC

The IT controls behind financial reporting — where going public meets your access reviews.

Read the guide →
GLBA

The FTC's security rule for anyone touching consumer financial data — broader than you think.

Read the guide →
Essential Eight

Australia's eight mitigation strategies — the security baseline Australian buyers ask about first.

Read the guide →
CPS 234

The Australian financial regulator's security standard — reaching every vendor that touches regulated data.

Read the guide →
CJIS

The FBI's security policy for criminal justice data — strict, specific, and non-negotiable for gov-tech.

Read the guide →

See Compriska in action

A 30-minute walkthrough of the platform, tailored to your frameworks and industry.

Book a demo