📚 3,473 Controls · 330 Frameworks · Live Real-Time Scoring

Cloud + AI Compliance Encyclopedia

Attribute-level compliance scoring across AWS, GCP, Azure, and Kubernetes — including the industry-first productized AI Workload Compliance framework mapping NIST AI-RMF + EU AI Act + ISO/IEC 42001 + MITRE ATLAS to your live K8s AI/ML inventory. Connected accounts swept daily on Free, Starter and Team and hourly on Pro and Enterprise — sooner when the change watcher fires — and re-scored inside a 30-second SLA.

330
Frameworks
3,473
Controls
Daily → hourly
Cloud sweep (Pro+ hourly)
AI-First
EU AI Act Ready

Not sure which frameworks apply to you?

Pick where you operate, or what you sell. No form and no email — every option below is a link.

Where you operate

What you sell

Still unsure? The full catalog below is searchable by name, country, or sector — or read the region guide for where you operate.

🤖 Industry-First Productized Framework

AI Workload Compliance — built for the EU AI Act

EU AI Act high-risk obligations (Annex III) apply from 2 December 2027, with up to €15M / 3% of global-turnover penalties for high-risk AI systems lacking risk-management evidence. EchelonGraph's Tier 3 K8s watcher catches shadow AI workloads (KServe · Kubeflow · Argo Rollouts · KubeRay · Seldon · Run:ai) the moment they hit your cluster, then auto-maps them to NIST AI-RMF, EU AI Act Articles 9/15/16/17, ISO/IEC 42001, and MITRE ATLAS. No CSV exports. No quarterly snapshots. No competitor ships this productized today.

NIST AI-RMFEU AI Act Art 9EU AI Act Art 15EU AI Act Art 16EU AI Act Art 17ISO/IEC 42001:2023MITRE ATLAS
Explore AI Compliance →
12 controls · live mapped to your K8s
⚡ Continuous Cloud Sweeps — 30s Re-Score SLA

Posture-sweep cadence is plan-gated. Free, Starter and Team sweep each connected cloud account daily; Pro and Enterprise carry the continuous-scanning feature and sweep hourly, configurable down to every 15 minutes. On every plan a change watcher polling the provider audit logs pulls the next sweep forward when it sees something move. Once a change lands, a signed webhook re-scores all 3,473 controls inside a 30-second SLA — measured at about 11 seconds on our own estate on 2026-08-07. Compare to traditional CSPM tools running 24-hour crons: an hourly sweep is 24x more often, and roughly8,760x more often than an annual audit. Compliance evidence stays accurate between audits, not just on audit day.

<30s
Re-score SLA · ~11s observed
24×
vs nightly cron
In-Depth Guides

Control-by-control framework guides

Hand-written deep dives — every control with real-world attack scenarios, auditor questions, and Terraform remediation.

AI Governance

AI Threat Modelling

AI Application Security

Cloud Security

Audit Framework

International Standard

Industry Regulation

Privacy Regulation

Government Standard

Government

Security Baseline

Browse the full catalog
Browse all coverage

All 330 live-scored frameworks

Filter by region, industry, or category to find the frameworks that apply to you — each scored continuously against your live AWS, GCP, Azure & Kubernetes posture.

20 of these 330 have a written in-depth guide — look for the Guide badge. The rest are live-scored in the product; what you see here is the catalog entry we publish today.

330 of 330 frameworks

CIS AWS Foundations Benchmark

Guide
GlobalCross-Industry35 ctrls

CIS GCP Foundations Benchmark

Guide
GlobalCross-Industry28 ctrls

CIS Kubernetes Benchmark

Guide
GlobalCross-Industry26 ctrls

UK NCSC Cloud Security Principles

United KingdomCross-Industry14 ctrls

CSA Cloud Controls Matrix

GlobalCross-Industry13 ctrls

EUCS — European Cybersecurity Certification Scheme for Cloud Services

European UnionCross-Industry13 ctrls

NSA/CISA Kubernetes Hardening Guide

United StatesCross-Industry13 ctrls

K-CSAP — Cloud Security Assurance Program (Korea)

South KoreaGovernment & Public Sector12 ctrls

MeitY Cloud Services Empanelment & Security (India)

IndiaGovernment & Public Sector12 ctrls

ISO/IEC 27017

GlobalCross-Industry11 ctrls

Pod Security Standards

Guide
GlobalCross-Industry11 ctrls

ANSSI SecNumCloud

FranceCross-Industry9 ctrls

BSI C5

GermanyCross-Industry9 ctrls

CSA STAR

GlobalCross-Industry9 ctrls

NCA Cloud Cybersecurity Controls

Saudi ArabiaCross-Industry9 ctrls

ISO/IEC 27018

GlobalCross-Industry8 ctrls

Compliance requirements by region

Who enforces the rules where you operate, how fast you have to report a breach, and what they have actually fined people. 6 regions.

United States

4 business days (SEC, public companies)

The US has sector-specific regulations rather than a single data protection law. Federal agencies follow NIST, healthcare follows HIPAA, and payments follow PCI-DSS. California's CCPA/CPRA is the strongest state privacy law.

Mandatory

HIPAANIST 800-53PCI-DSSSOXCCPA/CPRA

Commonly expected

SOC 2CIS BenchmarksISO 27001

Key facts

  • No single federal privacy law — sector-specific approach
  • NIST CSF 2.0 widely adopted as voluntary baseline
  • FTC Act Section 5 covers unfair/deceptive practices
  • CCPA/CPRA: strongest state privacy law, covers 40M residents
  • SEC requires cybersecurity incident disclosure within 4 days

First 30 days

  1. Map data flows by sector — healthcare (HIPAA), payments (PCI-DSS), federal (NIST 800-53)
  2. Determine state-law exposure — CCPA (CA), CPA (CO), CTDPA (CT), TDPSA (TX), and 15+ others
  3. Wire SEC incident-disclosure runbook if you're a public company (4-day clock)

Enforcement actions on record

  • $5BMeta (FTC) (2019)
  • $700MEquifax (2019)
  • $350MT-Mobile (2022)
  • $115MAnthem (2018)

Enforced by FTC, SEC, HHS (HIPAA), State AGs. Extraterritorial reach: CCPA/CPRA: applies to any business that collects data on California residents, even if HQ'd outside the US

European Union

72 hours (GDPR Article 33)

The EU leads global data protection with GDPR's extraterritorial reach. NIS2 (2024) expands cybersecurity requirements to 18 sectors. DORA mandates ICT resilience for financial entities.

Mandatory

GDPRNIS2 DirectiveDORAPCI-DSSePrivacy

Commonly expected

ISO 27001SOC 2CIS BenchmarksENISA Guidelines

Key facts

  • GDPR fines: up to €20M or 4% of global revenue
  • NIS2 (Oct 2024): 18 essential/important sectors must comply
  • DORA (Jan 2025): mandatory for all EU financial entities
  • Right to data portability and right to be forgotten
  • 72-hour breach notification mandatory

First 30 days

  1. Map all personal data processing activities (Article 30 ROPA)
  2. Determine if you're an Essential or Important entity under NIS2 (October 2024 deadline)
  3. Wire 72-hour breach notification runbook to your supervisory authority

Enforcement actions on record

  • €1.2BMeta (Ireland DPC) (2023)
  • €746MAmazon (CNPD) (2021)
  • €225MWhatsApp (2021)
  • €345MTikTok (2023)

Enforced by National DPAs, EDPB, ENISA. Extraterritorial reach: GDPR: applies to any organization processing personal data of EU residents, regardless of where the organization is headquartered (Article 3)

United Kingdom

72 hours (ICO, UK GDPR)

Post-Brexit, the UK maintains its own version of GDPR (UK GDPR) enforced by the ICO. Cyber Essentials is a government-backed certification scheme increasingly required for public sector contracts.

Mandatory

UK GDPRNIS RegulationsPCI-DSSComputer Misuse Act

Commonly expected

ISO 27001Cyber EssentialsSOC 2NCSC CAF

Key facts

  • UK GDPR mirrors EU GDPR with local adaptations
  • ICO can fine up to £17.5M or 4% of global turnover
  • Cyber Essentials: mandatory for government contracts handling sensitive data
  • NCSC Cyber Assessment Framework for critical infrastructure
  • Data adequacy agreement with EU (reviewed every 4 years)

First 30 days

  1. Self-certify Cyber Essentials Basic if pursuing UK government contracts
  2. Register with the ICO if you process personal data (most organizations must)
  3. Map any data transfers to/from EU under the UK-EU adequacy decision

Enforcement actions on record

  • £20MBritish Airways (2020)
  • £18.4MMarriott (2020)
  • £12.7MTikTok (2023)
  • £7.5MClearview AI (2022)

Enforced by ICO (Information Commissioner's Office), NCSC. Extraterritorial reach: UK GDPR: applies to any organization offering goods or services to UK residents, mirroring EU GDPR's extraterritorial scope

India

6 hours (CERT-In — the strictest globally)

India's DPDP Act (2023) is the country's first comprehensive data protection law covering 1.4 billion citizens. RBI mandates cybersecurity frameworks for banks, and CERT-In requires 6-hour breach reporting.

Mandatory

DPDP Act 2023IT Act 2000RBI Cybersecurity FrameworkSEBI Circular

Commonly expected

ISO 27001SOC 2CIS BenchmarksCERT-In Guidelines

Key facts

  • DPDP Act penalties: up to ₹250 crore (~$30M) per violation
  • CERT-In: 6-hour incident reporting requirement (strictest globally)
  • RBI: mandatory cybersecurity framework for banks and NBFCs
  • Data localization requirements for payment data (RBI)
  • Significant Data Fiduciaries must appoint DPO and conduct DPIAs

First 30 days

  1. Map data localization obligations — payment data must reside in India (RBI)
  2. Wire CERT-In 6-hour incident reporting (cyber.gov.in portal)
  3. Determine Significant Data Fiduciary status — triggers DPO + DPIA requirements

Enforcement actions on record

  • 16M+CERT-In incidents/yr (2024)
  • ₹50Cr+RBI cyber penalties (2023)
  • ₹1CrICICI fine (RBI) (2023)
  • ₹1.96CrIndian Bank (data leak) (2023)

Enforced by Data Protection Board of India, CERT-In, RBI, SEBI. Extraterritorial reach: DPDP Act: applies to any entity processing personal data of Indian citizens, including foreign companies offering goods or services in India

Asia Pacific

Varies — Singapore 72h, Australia 30 days, China promptly (no fixed clock)

APAC has diverse privacy laws: China's PIPL (2021) rivals GDPR in scope, Singapore's PDPA covers cross-border transfers, Japan's APPI was amended in 2022, and Australia is reforming its Privacy Act.

Mandatory

PDPA (Singapore)PIPL (China)APPI (Japan)Privacy Act (Australia)

Commonly expected

ISO 27001SOC 2CSA STARAPEC CBPR

Key facts

  • China PIPL: up to 5% of annual revenue or ¥50M
  • Singapore PDPA: fines up to S$1M (~$750K)
  • Japan APPI: criminal penalties including imprisonment
  • Australia Privacy Act reforms: expected 2025
  • APEC Cross-Border Privacy Rules (CBPR) for regional data flows

First 30 days

  1. Identify jurisdiction-specific obligations — laws differ significantly across APAC
  2. Wire cross-border data transfer agreements (PIPL, PDPA both require)
  3. Register DPO with each country's authority if locally required

Enforcement actions on record

  • ¥8.026B (~$1.2B)Didi (China CAC, PIPL) (2022)
  • AU$5.7M+Optus (Australia) (2024)
  • AU$5.7M+Medibank (Australia) (2024)
  • ¥30MYahoo Japan (APPI) (2022)

Enforced by CAC (China), PDPC (Singapore), PPC (Japan), OAIC (Australia). Extraterritorial reach: China PIPL has the broadest extraterritorial reach in APAC; PDPA (Singapore) and APPI (Japan) apply to any organization processing residents' data

Middle East & Africa

72 hours (UAE, Saudi Arabia)

The Middle East and Africa region is rapidly maturing its data protection landscape. UAE's PDPL (2021) and Saudi Arabia's PDPL (2023) introduce GDPR-style protections. South Africa's POPIA (2021) is the continent's most comprehensive privacy law with extraterritorial reach.

Mandatory

UAE PDPLSaudi Arabia PDPLPOPIA (South Africa)Bahrain PDPL

Commonly expected

ISO 27001SOC 2CSA STARNIST CSF

Key facts

  • UAE PDPL: fines up to AED 5M (~$1.36M) per violation
  • Saudi PDPL: fines up to SAR 5M (~$1.3M) + imprisonment
  • South Africa POPIA: fines up to ZAR 10M (~$550K) + 10yr prison
  • Bahrain PDPL: up to BHD 20K (~$53K) per violation
  • DIFC and ADGM have separate privacy frameworks for free zones

First 30 days

  1. Confirm whether your operations sit in DIFC, ADGM, or mainland UAE — different frameworks apply
  2. Map data residency obligations — Saudi PDPL requires localization for sensitive data
  3. Designate a DPO for Saudi PDPL if processing data of >5000 residents

Enforcement actions on record

  • PendingSaudi PDPL first enforcement (2024)
  • AED 100K avgUAE DIFC privacy fines (2023)
  • ZAR 5MSouth Africa Info Regulator (2023)
  • BHD 20K capBahrain PDPL penalties (2023)

Enforced by UAE Data Office, SDAIA (Saudi), Info Regulator (South Africa), PDP Authority (Bahrain). Extraterritorial reach: South Africa POPIA: applies extraterritorially to processing of personal information by responsible parties not domiciled in South Africa

Compliance requirements by industry

What your sector is actually held to, what it typically costs, and how breaches in it have happened. 5 industries.

Fintech & Banking

$500K–$5M / year (PCI + SOX audits + GLBA)

The most heavily regulated industry for compliance. Banks and fintech companies face overlapping requirements: PCI-DSS for card data, SOX for financial reporting, GLBA for customer privacy, and DORA for EU operational resilience.

Mandatory

PCI-DSSSOXGLBADORA (EU)

Commonly expected

SOC 2ISO 27001NIST CSF

Key risks

  • Customer financial data exposure (account numbers, SSNs)
  • Payment fraud and unauthorized transactions
  • Regulatory fines from multiple agencies simultaneously
  • Loss of banking license or charter
  • Reputational damage affecting customer deposits

Most common attack vectors

  1. Account takeover (credential stuffing + MFA bypass)
  2. BIN attacks on card processors
  3. Third-party API exposure (open banking)

Typical fine: $5M–$100M (PCI breach) · $50M+ (regulatory). Notable breach: Capital One (2019) — 100M records exposed via misconfigured AWS WAF (SSRF). $190M settlement + $80M OCC fine.

Healthcare

$1M–$10M / year (HIPAA + HITRUST + cyber insurance)

PHI (Protected Health Information) is among the most valuable data on the black market ($250–$1,000 per record). HIPAA violations carry both civil and criminal penalties, including imprisonment.

Mandatory

HIPAAHITRUST CSF

Commonly expected

SOC 2ISO 27001NIST CSF

Key risks

  • PHI exposure (records worth $250+ each on black market)
  • Ransomware attacks targeting hospital systems
  • Criminal penalties for intentional HIPAA violations
  • Loss of Medicare/Medicaid eligibility
  • Class-action lawsuits from affected patients

Most common attack vectors

  1. Ransomware (most-targeted vertical in 2024)
  2. Phishing leading to EHR account compromise
  3. Medical device exploits (insulin pumps, imaging)

Typical fine: $1.5M/year per HIPAA category · $250K criminal. Notable breach: Change Healthcare (2024) — ALPHV ransomware. ~190M Americans' PHI exposed. $872M revenue impact + $22M ransom paid. Disrupted US healthcare claims processing nationwide.

SaaS / Technology

$50K–$200K / year (SOC 2 Type II + ISO 27001 + audit fees)

SaaS companies process data for thousands of customers. SOC 2 has become a de-facto requirement — 90% of enterprise buyers require it. The multi-tenant nature of SaaS creates unique compliance challenges.

Mandatory

GDPR (if EU users)CCPA (if CA users)

Commonly expected

SOC 2 Type IIISO 27001CIS BenchmarksNIST CSF

Key risks

  • Multi-tenant data isolation failures
  • Supply chain attacks through CI/CD pipelines
  • Shadow IT and unauthorized data processing
  • Loss of enterprise deals without SOC 2 ($100K–$10M+)
  • GDPR cross-border transfer violations

Most common attack vectors

  1. Supply chain (CI/CD pipeline compromise, npm typosquats)
  2. Credential stuffing (compromised customer accounts)
  3. OAuth token abuse + session-hijack attacks

Typical fine: Revenue loss: $100K–$10M per lost enterprise deal. Notable breach: Okta (2023) — Customer support system breach via stolen session token. 134 customer environments affected. Stock dropped 11% on disclosure.

E-commerce & Retail

$100K–$1M / year (PCI assessments + ASV scans + privacy audits)

E-commerce handles both payment data (PCI-DSS) and consumer privacy data (GDPR/CCPA). Magecart-style attacks and supply chain compromises are the leading threat vectors.

Mandatory

PCI-DSSGDPR/CCPAConsumer Protection Laws

Commonly expected

SOC 2CIS BenchmarksISO 27001

Key risks

  • Credit card skimming (Magecart attacks)
  • Customer PII exposure in data breaches
  • Supply chain compromise through third-party scripts
  • Loss of payment processing ability due to PCI non-compliance
  • Consumer class-action lawsuits

Most common attack vectors

  1. Magecart / digital skimmers on checkout pages
  2. Account takeover during peak shopping seasons
  3. Third-party JavaScript supply-chain compromise

Typical fine: $5K–$100K/month (PCI) · $7.5K/violation (CCPA). Notable breach: Target (2013) — 40M cards + 70M customer records. Initial vector: HVAC vendor credentials. Total cost reached $202M including settlements + replacement-card costs.

Government & Defense

$500K–$2M (FedRAMP authorization) + $100K–$500K / year (continuous monitoring)

Government compliance is the most stringent. CMMC 2.0 is now required for all DoD contractors. FedRAMP authorization takes 6-12 months and costs $500K–$2M for cloud providers wanting to serve federal agencies.

Mandatory

NIST 800-53FedRAMPCMMC 2.0FISMA

Commonly expected

CIS BenchmarksISO 27001CISA BODs

Key risks

  • Loss of government contracts (often company's largest revenue)
  • National security data exposure
  • CUI (Controlled Unclassified Information) mishandling
  • Debarment from future government contracting
  • Supply chain risks in defense industrial base

Most common attack vectors

  1. Supply-chain attacks on software vendors
  2. Spear-phishing of cleared personnel
  3. Targeted exploitation of edge devices (VPN, firewall)

Typical fine: Contract termination + False Claims Act ($11K+ per violation). Notable breach: SolarWinds (2020) — Supply-chain compromise via SUNBURST backdoor in Orion software updates. ~18,000 customers affected including 9 US federal agencies. SEC charged SolarWinds CISO with fraud — first ever.

What each framework requires — and what it costs to ignore

Plain-language guides to the 14 frameworks we are asked about most: who they apply to, the penalties for falling short, and the steps to get compliant. Every guide links through to the controls EchelonGraph scores for that framework.

SOC 2

Voluntary

SOC 2 is the gold standard for SaaS companies. Customers and enterprise buyers increasingly require SOC 2 reports before signing contracts. It demonstrates your commitment to security, availability, and data privacy.

Applies to

Global, North America · SaaS, Technology, Cloud Services, Fintech

Cost of non-compliance

Not legally required, but losing deals due to lack of SOC 2 compliance can cost $100K–$10M+ in revenue.

Key requirements

  • Security policies and procedures
  • Access control and authentication
  • System monitoring and alerting
  • Incident response plan
  • Change management process
  • Vendor risk management

How to comply

  1. Define and implement security policies (CC1–CC9)
  2. Implement continuous monitoring with tools like EchelonGraph
  3. Conduct annual SOC 2 Type II audit with a CPA firm
  4. Maintain evidence collection for 12-month observation period
What EchelonGraph checks for this framework →Official source ↗Reviewed AICPA TSC 2017 criteria, with revised points of focus (2022)

NIST SP 800-53

Legally required

NIST 800-53 is the most comprehensive security control framework in existence. Mandatory for US federal agencies and contractors. Used globally as a baseline for building security programs.

Applies to

United States, Global · Federal Government, Defense, Critical Infrastructure, Healthcare

Cost of non-compliance

Federal contracts can be terminated. CMMC certification (based on NIST) is required for DoD contractors — non-compliance means losing defense contracts worth millions.

Key requirements

  • ~300 base controls across 20 families (1,014 including control enhancements)
  • Risk assessment (RA) and authorization (CA)
  • Access control (AC) and audit (AU)
  • System and communications protection (SC)
  • Incident response (IR) and contingency planning (CP)

How to comply

  1. Categorize systems using FIPS 199
  2. Select baseline controls (Low/Moderate/High)
  3. Implement controls and document in SSP
  4. Assess controls and create POA&M for gaps
  5. Authorize system operation and continuously monitor

CIS Controls v8

Voluntary

CIS Benchmarks provide prescriptive, step-by-step hardening guides for every major platform (AWS, GCP, Azure, Linux, Windows, Kubernetes). They're the most actionable framework for DevOps teams.

Applies to

Global · Technology, SaaS, E-commerce, All Industries

Cost of non-compliance

No direct penalties, but CIS compliance is often required by cyber insurance policies. Failure to comply can increase premiums or void coverage.

Key requirements

  • IG1: Essential Cyber Hygiene (56 safeguards)
  • IG2: Managed security (130 safeguards)
  • IG3: Advanced security (153 safeguards)
  • Platform-specific benchmarks (AWS, GCP, Azure, K8s)
  • Automated assessment recommended

How to comply

  1. Start with IG1 (essential hygiene)
  2. Run automated CIS benchmark scans using EchelonGraph
  3. Remediate critical findings first (password policies, MFA, logging)
  4. Progress to IG2/IG3 based on risk profile
What EchelonGraph checks for this framework →Official source ↗Reviewed v8.1 (2024). Platform benchmarks move independently: CIS AWS Foundations 7.0.0, GCP 5.0.0, Azure 6.0.0, Kubernetes 2.0.1

PCI DSS 4.0

Legally required

If you store, process, or transmit credit card data, PCI-DSS compliance is non-negotiable. Card brands (Visa, Mastercard) require it, and non-compliance results in fines and potential loss of card processing ability.

Applies to

Global · E-commerce, Fintech, Retail, Banking, Payment Processing

Cost of non-compliance

PCI SSC itself levies no fines — it writes the standard and does not monitor implementation. Financial consequences flow from your acquiring bank under your merchant agreement, and the card brands do not publish a penalty schedule, so any specific dollar range you see quoted (including the widely-repeated $5,000-$100,000 per month) is not traceable to a primary source. What is documented: after a breach you face forensic investigation costs, card-reissuance and fraud liability passed through by your acquirer, and potential loss of the ability to process cards.

Key requirements

  • Build and maintain secure network (firewalls, encryption)
  • Protect cardholder data (encryption at rest and in transit)
  • Vulnerability management program
  • Strong access control measures (MFA, least privilege)
  • Regular monitoring and testing
  • Information security policy

How to comply

  1. Determine your PCI level (1–4 based on transaction volume)
  2. Complete SAQ (Self-Assessment Questionnaire) or engage a QSA
  3. Implement all 12 PCI-DSS requirements
  4. Conduct quarterly ASV scans and annual penetration tests

HIPAA

Legally required

HIPAA protects patients' health information (PHI). Any organization that handles PHI — from hospitals to health tech startups — must comply. Violations can result in criminal charges.

Applies to

United States · Healthcare, Health Insurance, Health IT, Pharmaceuticals

Cost of non-compliance

Civil penalties are inflation-adjusted annually (45 CFR 102.3). Current per-violation ranges: Tier 1 (no knowledge) $145–$73,011; Tier 2 (reasonable cause) $1,461–$73,011; Tier 3 (wilful neglect, corrected) $14,602–$73,011; Tier 4 (wilful neglect, uncorrected) $73,011–$2,190,294, which is also the annual cap per identical provision. Note the annual caps differ BY TIER ($25,000 / $100,000 / $250,000 / $2,190,294). Criminal penalties reach $250,000 and 10 years, but only where the disclosure was for commercial advantage, personal gain or malicious harm.

Key requirements

  • Privacy Rule: limits use/disclosure of PHI
  • Security Rule: administrative, physical, technical safeguards
  • Breach Notification Rule: 60-day notification requirement
  • BAA (Business Associate Agreements) with vendors
  • Risk analysis and management

How to comply

  1. Conduct a comprehensive risk analysis
  2. Implement required safeguards (access controls, encryption, audit logs)
  3. Execute BAAs with all vendors handling PHI
  4. Train workforce on HIPAA requirements annually
  5. Establish breach notification procedures
What EchelonGraph checks for this framework →Official source ↗Reviewed 2024 (proposed updates to Security Rule pending)

ISO/IEC 27001:2022

Voluntary

ISO 27001 is the international gold standard for Information Security Management Systems (ISMS). It's recognized by 170+ countries and increasingly required in enterprise procurement and government tenders.

Applies to

Global, Europe, Asia Pacific · All Industries, Technology, Financial Services, Government

Cost of non-compliance

Not legally mandated (except in some countries), but losing ISO 27001 certification can result in loss of enterprise contracts, government tenders, and customer trust.

Key requirements

  • ISMS establishment and scope definition
  • Risk assessment and treatment methodology
  • 93 controls across 4 themes (Organizational, People, Physical, Technological)
  • Statement of Applicability (SoA)
  • Management review and continual improvement

How to comply

  1. Define ISMS scope and information security policy
  2. Conduct risk assessment using a recognized methodology
  3. Implement Annex A controls and create SoA
  4. Conduct internal audit and management review
  5. Engage accredited certification body for Stage 1 + Stage 2 audit

GDPR

Legally required

GDPR applies to ANY organization processing data of EU residents — even if you're based outside the EU. It's the most consequential data protection law globally, with extraterritorial reach.

Applies to

European Union, EEA, United Kingdom · All Industries processing EU data

Cost of non-compliance

Up to €20 million or 4% of global annual revenue, whichever is higher. Meta was fined €1.2 billion in 2023.

Key requirements

  • Lawful basis for processing personal data
  • Data Protection Impact Assessments (DPIAs)
  • Data Subject Rights (access, deletion, portability)
  • 72-hour breach notification
  • Data Protection Officer (DPO) appointment
  • Data processing agreements with processors

How to comply

  1. Map all personal data processing activities (ROPA)
  2. Establish lawful basis for each processing activity
  3. Implement privacy by design and by default
  4. Appoint a DPO if required
  5. Establish data breach response procedures
What EchelonGraph checks for this framework →Official source ↗Reviewed 2018 (regulatory guidance continuously updated)

MITRE ATT&CK

Voluntary

MITRE ATT&CK is the world's most comprehensive knowledge base of adversary tactics and techniques. Security teams use it to build detection rules, conduct red team exercises, and measure security coverage.

Applies to

Global · Cybersecurity, SOC Teams, Threat Intelligence, Incident Response

Cost of non-compliance

No direct penalties. However, SOC teams without ATT&CK coverage mapping are effectively flying blind — unable to measure or communicate defensive capabilities.

Key requirements

  • 14 tactics (Reconnaissance → Impact)
  • 201+ techniques and sub-techniques
  • Enterprise, Mobile, and ICS matrices
  • Mapping detection coverage to ATT&CK techniques
  • Threat-informed defense strategy

How to comply

  1. Map existing detections to ATT&CK techniques
  2. Identify coverage gaps across the kill chain
  3. Prioritize high-impact techniques relevant to your threat model
  4. Build detection rules for priority techniques
  5. Conduct purple team exercises to validate coverage
Official source ↗Reviewed v15.1 (April 2024)

NIST Cybersecurity Framework 2.0

Voluntary

NIST CSF (Cybersecurity Framework) provides a risk-based approach to managing cybersecurity. Unlike NIST 800-53 (which is control-heavy), CSF focuses on outcomes: Govern, Identify, Protect, Detect, Respond, Recover.

Applies to

United States, Global · All Industries, Critical Infrastructure, Technology

Cost of non-compliance

Not legally mandated for the private sector, but increasingly referenced in insurance underwriting, board governance and regulatory guidance. Note that the SEC's cybersecurity disclosure rules are framework-neutral — they require disclosure of your processes, not alignment with CSF or any named framework.

Key requirements

  • 6 core functions: Govern, Identify, Protect, Detect, Respond, Recover
  • Risk assessment and prioritization
  • Supply chain risk management
  • Organizational context and governance
  • Continuous improvement process

How to comply

  1. Create an organizational profile mapping current vs target state
  2. Identify and assess cyber risks using CSF categories
  3. Implement priority actions across all 6 functions
  4. Monitor and measure progress toward target profile
Official source ↗Reviewed 2.0 (February 2024)

India DPDP Act

Legally required

India's Digital Personal Data Protection Act (2023) is the country's first comprehensive data protection law. With 1.4 billion citizens online, it applies to any entity processing Indian citizens' data — including companies outside India.

Applies to

India · All Industries operating in India, Technology, BPO/IT Services

Cost of non-compliance

NOT YET ENFORCEABLE — the penalty provisions (ss.33-34) commence around May 2027. When they do, the Schedule sets per-breach ceilings, not one flat cap: ₹250 crore (~US$26M) applies specifically to failing to take reasonable security safeguards (s.8(5)); ₹200 crore for breach-notification failure and for children's data; ₹150 crore for Significant Data Fiduciary duties; and ₹50 crore for any other contravention. There is no turnover-based element. What IS live today is the CERT-In direction of 28 April 2022 requiring cyber incidents — including data breaches and leaks — to be reported within 6 hours.

Key requirements

  • Consent-based data processing with clear notice
  • Data Principal rights (access, correction, erasure, grievance)
  • Data Fiduciary obligations (purpose limitation, data minimization)
  • Cross-border transfers permitted by default — the Government may notify restricted countries (s.16); none notified to date
  • Data Protection Board established Nov 2025 (members not yet appointed)
  • Significant Data Fiduciary obligations (DPO, audit, DPIA)

How to comply

  1. Map all personal data processing activities
  2. Implement consent management system
  3. Appoint Data Protection Officer (if Significant Data Fiduciary)
  4. Establish grievance redressal mechanism
  5. Meet the CERT-In 6-hour incident report today; prepare for DPDP Rule 7 (Board notice without delay, detailed report within 72 hours) from ~May 2027
What EchelonGraph checks for this framework →Official source ↗Reviewed November 2025 — DPDP Rules notified 13 Nov 2025; most obligations and all penalties commence ~May 2027

ISMS-P (Korea)

Legally required

ISMS-P (Information Security and Personal Information Protection Management System) is South Korea's certification combining ISO 27001-style controls with the Personal Information Protection Act (PIPA). Certification is mandatory for defined categories under Article 47(2) of the Network Act: qualifying ISPs and MVNOs, IDC operators, and entities crossing the Enforcement Decree thresholds (ICT-services revenue of at least KRW 10bn, or a daily average of 1,000,000 users, or revenue of at least KRW 150bn for tertiary hospitals and universities with 10,000+ students). Cloud providers are not named as a category — Korean cloud has its own CSAP scheme.

Applies to

South Korea · Technology, Telecommunications, Financial Services, E-commerce

Cost of non-compliance

Failing to obtain the required certification carries an administrative fine (과태료) of up to KRW 30 million (~US$21,000) under Article 76(1) of the Network Act. Separately, PIPA Article 64-2 allows a surcharge of up to 3% of TOTAL revenue, calculated on total revenue excluding revenue unrelated to the violation — or up to KRW 2 billion where revenue cannot be computed.

Key requirements

  • 101 control items across 3 areas and 21 sub-fields (16 management system + 64 protection measures + 21 personal-information lifecycle)
  • Management system establishment and operation
  • Personal information lifecycle management
  • Technical protection measures
  • Physical security controls
  • Annual certification audit

How to comply

  1. Establish ISMS scope covering all information assets
  2. Implement 104 control items across 16 domains
  3. Conduct risk assessment and treatment
  4. Apply for certification through KISA-accredited auditor
  5. Maintain certification with annual surveillance audits

NIS2 Directive

Legally required

NIS2 is the EU's landmark cybersecurity directive effective October 2024, replacing NIS1. It covers 18 essential and important sectors, imposes personal liability on senior management, and requires 24-hour early warning for significant incidents. Non-compliance can result in fines up to €10M or 2% of global turnover.

Applies to

European Union, EEA · Energy, Transport, Banking, Health, Digital Infrastructure, ICT Service Management, Public Administration, Manufacturing

Cost of non-compliance

Essential entities: up to €10M or 2% of global annual turnover. Important entities: up to €7M or 1.4% of turnover. Senior management can be held personally liable and temporarily banned from management roles.

Key requirements

  • Risk management measures (technical, operational, organizational)
  • 24-hour early warning + 72-hour incident notification
  • Supply chain security assessment and management
  • Business continuity and crisis management planning
  • Senior management accountability and cybersecurity training
  • Regular security audits and vulnerability assessments

How to comply

  1. Determine if your organization is an essential or important entity
  2. Conduct comprehensive risk assessment across all ICT systems
  3. Implement risk management measures per Article 21
  4. Establish incident response and 24-hour reporting capability
  5. Assess and manage supply chain cybersecurity risks
  6. Train senior management on cybersecurity governance
Official source ↗Reviewed 2024 (transposition deadline: October 17, 2024)

DORA (Digital Operational Resilience Act)

Legally required

DORA (Digital Operational Resilience Act) is an EU regulation enforceable since January 2025 that mandates ICT resilience for the entire financial sector. Unlike NIS2 (a directive), DORA is directly applicable in all EU member states without transposition. It introduces oversight of critical ICT third-party providers.

Applies to

European Union · Banking, Insurance, Investment Firms, Payment Institutions, Crypto-Asset Providers, ICT Third-Party Providers

Cost of non-compliance

DORA itself sets no fine amounts for financial entities. Article 50 requires each Member State to lay down 'effective, proportionate and dissuasive' penalties, so the ceiling depends on where you are supervised — check your national implementing law. The one amount fixed in the Regulation applies to designated CRITICAL ICT third-party providers: a periodic penalty payment of up to 1% of average DAILY worldwide turnover, charged daily for up to six months (Article 35(6)–(8)). That is a daily coercive payment to compel compliance, not a one-off fine.

Key requirements

  • ICT risk management framework with governance structure
  • ICT-related incident classification and reporting
  • Digital operational resilience testing (TLPT for systemically important entities)
  • ICT third-party risk management and contractual requirements
  • Information sharing arrangements between financial entities
  • Oversight framework for critical ICT third-party providers

How to comply

  1. Establish ICT risk management framework with board oversight
  2. Implement incident classification and reporting to competent authority
  3. Develop and execute digital resilience testing program
  4. Review and update all ICT third-party contracts for DORA compliance
  5. Conduct threat-led penetration testing (TLPT) if systemically important
  6. Participate in information sharing arrangements
Official source ↗Reviewed 2025 (enforceable since January 17, 2025)

CMMC 2.0 Level 2

Legally required

CMMC 2.0 (Cybersecurity Maturity Model Certification) is now required for all DoD contractors handling CUI (Controlled Unclassified Information) or FCI (Federal Contract Information). The final rule took effect December 2024. Without CMMC certification, organizations cannot bid on DoD contracts — a $400B+ annual market.

Applies to

United States · Defense, Aerospace, Government Contractors, Defense Industrial Base

Cost of non-compliance

Loss of eligibility for the DoD contracts that carry the requirement, plus False Claims Act exposure for misrepresenting your status: $14,308–$28,619 per claim plus treble damages (28 CFR 85.5), and potential debarment. Status as of August 2026: DoD suspended CMMC Phase II on 13 July 2026, so requiring activities may currently designate only Level 1 (Self) or Level 2 (Self) assessment — not third-party certification. Verify the current phase before relying on this.

Key requirements

  • Level 1 (Foundational): 15 practices based on FAR 52.204-21 (self-assessment)
  • Level 2 (Advanced): 110 practices aligned to NIST SP 800-171r2 (C3PAO assessment)
  • Level 3 (Expert): 110+ practices based on NIST SP 800-172 (government-led assessment)
  • POA&M (Plan of Action and Milestones) for any gaps
  • Annual affirmation of compliance
  • Continuous monitoring and incident reporting

How to comply

  1. Determine required CMMC level based on contract requirements
  2. Scope your CUI/FCI environment and asset inventory
  3. Implement NIST SP 800-171r2 controls for Level 2
  4. Conduct gap assessment and create POA&M
  5. Engage C3PAO (Certified Third-Party Assessment Organization) for Level 2
  6. Achieve certification and maintain annual affirmation
What EchelonGraph checks for this framework →Official source ↗Reviewed 2.0 (Final rule effective December 16, 2024)
⚙️

How we score compliance

Every score is produced by a pure-function evaluator run against your real cloud state on every scan cycle — never a questionnaire and never a self-assessment. Each control returns one of four verdicts, scored independently per cloud provider:

Pass (1.0)Fail (0.0)Partial (0.5)N/A (excluded from the denominator)
See every control in all 11 scored frameworks mapped to the exact signal it reads →

Compliance questions, answered

What cloud security compliance frameworks does EchelonGraph cover?
EchelonGraph live-scores 300+ compliance frameworks across AWS, GCP, Azure, and Kubernetes. The Compliance Encyclopedia provides in-depth, control-by-control guides for the major ones — CIS Benchmarks (AWS, GCP, Azure, Kubernetes), Pod Security Standards, SOC 2 Type II, ISO/IEC 27001:2022, HIPAA, PCI DSS v4.0, GDPR, NIST SP 800-53, NIST CSF 2.0, FedRAMP, CMMC 2.0, CIS Controls v8, plus the industry-first AI Workload Compliance framework (NIST AI-RMF, EU AI Act, ISO 42001, MITRE ATLAS). Each guide includes automated detection rules, CLI verification commands, Terraform remediation code, real-world attack scenarios, MITRE ATT&CK mapping, cost-of-non-compliance data, and auditor questions. The full live-scored catalog — including NIS2, DORA, SWIFT CSP, HITRUST, NIST 800-171, and 80+ more — is browsable in the framework explorer above.
How is EchelonGraph's compliance encyclopedia different from other tools?
Unlike documentation-only resources, every control in EchelonGraph's encyclopedia maps to an automated scanner rule. Each control page includes: (1) Real-world attack scenarios showing exactly how non-compliance is exploited, (2) Dollar-figure cost of non-compliance with real breach case studies, (3) Terraform/IaC remediation code you can copy-paste, (4) MITRE ATT&CK technique mapping for threat modeling, (5) Auditor questions to prepare for SOC 2, ISO 27001, and PCI assessments, and (6) Manual vs automated effort estimates.
Which cloud providers does EchelonGraph scan for compliance?
EchelonGraph scans AWS, Google Cloud (GCP), and Microsoft Azure. CIS Benchmark controls are provider-specific (CIS AWS v2.0, CIS GCP v2.0, CIS Azure v2.0), while framework controls like SOC 2, ISO 27001, HIPAA, PCI DSS, and NIST 800-53 are mapped across all three providers. The scanner runs 440+ detection rules continuously across all connected cloud accounts.
How many security controls does EchelonGraph's compliance encyclopedia include?
The encyclopedia includes 3,473 security controls across 330 frameworks (CIS AWS/GCP/Azure, CIS Kubernetes v1.9, Pod Security Standards, AI Workload Compliance, SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, NIST 800-53). Controls are categorized by severity (critical, high, medium, low) and each includes cross-framework references — for example, a single IAM control may map to SOC 2 CC6.1, ISO 27001 A.9.4.2, NIST AC-2, and PCI DSS 8.3.1 simultaneously.
What is AI Workload Compliance and why is it unique?
AI Workload Compliance is EchelonGraph's industry-first productized framework mapping NIST AI Risk Management Framework, EU AI Act Articles 9/15/16/17, ISO/IEC 42001:2023, and MITRE ATLAS to your live Kubernetes AI/ML workload inventory (KServe InferenceService, Kubeflow Notebook, Argo Rollouts, KubeRay RayCluster, Seldon SeldonDeployment, Run:ai RunaiJob). Our Tier 3 K8s watcher's first-class CRD watch turns shadow AI from an audit-week panic into a real-time signal — the data-science team's GPU pod that bypassed your CI gate appears in the Asset Inventory within seconds. No competitor ships this productized today; major SaaS CSPM vendors require manual CSV exports + custom queries to assemble a comparable view.
How does live real-time compliance scoring work?
Every successful asset upsert (cloud scanner discovers a new S3 bucket, Tier 3 watcher observes a new K8s Pod) fires a signed POST to the compliance engine's notify webhook with a per-tenant 30-second debounce. A full pass over all 3,473 controls runs inside a 30-second SLA — measured at about 11 seconds on our own estate on 2026-08-07. Separately, how quickly we NOTICE a cloud change is the sweep interval, not the re-score, and that interval is plan-gated: Free, Starter and Team sweep each connected account daily, while Pro and Enterprise sweep hourly and can be set as often as every 15 minutes. On every plan a change watcher polling the provider audit logs pulls the next sweep forward when it sees something move. Compare this to traditional CSPM tools that re-score on a 24-hour cron — meaning a misconfigured IAM role provisioned at 9am is invisible until tomorrow's report. An hourly sweep is 24x more often than a nightly cron (24 sweeps a day against one) and roughly 8,760x more often than an annual audit.
How is EchelonGraph's compliance scoring different from questionnaire-based tools?
Most GRC tools score compliance from human-filled questionnaires that drift the moment an engineer ships a change. EchelonGraph scores from attribute-level cloud + Kubernetes posture: every CIS AWS S3 bucket is checked against block_public_acls/encryption/versioning attributes; every IAM user against mfa_enabled and access-key age; every K8s Pod against priv_count + host_network + runasnonroot_count. The compliance dashboard's evidence text names the offending resources — 'public-bucket-2 fails CIS-AWS-2.1.1', not 'CIS-AWS-2.1.1: Partial'.
What's the difference between SOC 2 and ISO 27001?
SOC 2 is a US-originated attestation focused on Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy) — audited annually by a CPA firm and most common in SaaS sales cycles. ISO 27001 is an international certification covering an Information Security Management System (ISMS) with 93 controls across 4 themes; recognized in 170+ countries and increasingly required in EU and APAC enterprise procurement. Many companies pursue both — they share ~60% control overlap, so the marginal cost of adding the second is lower than the first.
How long does SOC 2 Type II certification take?
Typical timeline is 6–12 months end-to-end. First 3–6 months are spent designing and implementing controls (policies, access management, monitoring). Then a continuous 6-month observation window is required for Type II evidence collection. After the observation window, the audit itself runs 2–4 weeks. Companies using automated evidence collection (EchelonGraph, Vanta, Drata) typically cut the prep time by 30–50% versus manual approaches.
What are the penalties for a GDPR violation?
Up to €20 million or 4% of global annual turnover — whichever is higher. The largest GDPR fine to date was €1.2 billion against Meta in 2023 for unlawful US data transfers. Smaller violations (failure to honor data subject rights, late breach notification) typically draw fines of €50K–€5M. GDPR applies extraterritorially: any organization processing EU residents' personal data is in scope, regardless of where the organization is headquartered.
Who needs to comply with HIPAA?
Two categories: Covered Entities (healthcare providers, health plans, healthcare clearinghouses) and their Business Associates (any vendor handling Protected Health Information on behalf of a Covered Entity — including cloud providers, billing services, IT vendors, and software platforms). If you store, process, or transmit Protected Health Information (PHI) for a covered entity, you need a signed Business Associate Agreement (BAA) and HIPAA-compliant safeguards. Violations can carry criminal penalties up to $250,000 and 10 years' imprisonment.
When does the EU AI Act apply to my company?
Enforcement is phased. Prohibited AI practices (social scoring, biometric categorisation for sensitive attributes, etc.) have been banned since 2 February 2025, and breaching those carries the Act's top tier of €35 million or 7% of global turnover (Article 99(3)). General-purpose AI model rules applied from 2 August 2025. Since 2 August 2026 the Article 50 transparency obligations apply — chatbot disclosure, deepfake labelling, machine-readable marking of synthetic content. The high-risk obligations (Article 9 risk management, Article 15 accuracy/robustness/cybersecurity, Article 16 provider obligations, Article 43 conformity assessment) were extended by Regulation (EU) 2026/1744 and now apply from 2 December 2027 for Annex III systems, and 2 August 2028 for Annex I product-embedded systems. High-risk breaches carry up to €15 million or 3% of global turnover (Article 99(4)), not the €35M tier. The Act applies extraterritorially: any AI system whose outputs are used in the EU is in scope.
What is NIS2 and which sectors does it cover?
NIS2 is the EU's updated cybersecurity directive, in force from October 2024. It expanded scope from NIS1's 7 sectors to 18, splitting them into Essential entities (energy, transport, banking, financial market infrastructures, healthcare, water, digital infrastructure, ICT service management, public administration, space) and Important entities (postal/courier, waste management, chemicals, food, manufacturing, digital providers, research). Senior management can be held personally liable, and fines reach €10 million or 2% of global turnover for Essential entities.
How are CIS Benchmarks different from CIS Controls?
CIS Controls are 18 prioritized, organization-level safeguards (formerly known as the SANS Top 20) — they tell you WHAT to do at a strategic level. CIS Benchmarks are platform-specific, prescriptive hardening guides — step-by-step technical configurations for AWS, GCP, Azure, Kubernetes, Linux, Windows, Docker, and dozens more. Most cloud security tools (including EchelonGraph) automate the CIS Benchmarks because they're directly actionable. Think of it as: Controls are the strategy, Benchmarks are the playbooks.
Is NIST Cybersecurity Framework (CSF) mandatory in the United States?
Not legally mandated for the private sector — but heavily incentivized. NIST CSF 2.0 (released February 2024) is referenced in SEC cybersecurity disclosure requirements for public companies, FTC enforcement actions, state breach notification laws, and an increasing number of insurance underwriting questionnaires. For federal contractors and agencies, NIST SP 800-53 (the control catalog CSF maps to) is mandatory. For CMMC-required defense contractors, NIST SP 800-171 controls are required.

Beyond Documentation — Automated Compliance

EchelonGraph automatically detects compliance violations across your entire cloud infrastructure. 440+ rules running continuously — not just documentation.

Start Free →