30+ standards, country by country
Pick a standard to see what Compliance Colleague covers, the questions you can ask, and what you can upload for review: policies, risk registers and control matrices, and network or data-flow diagrams.
Global
- PCI DSS v4.0.1
The Payment Card Industry Data Security Standard protects cardholder data wherever it is stored, processed or transmitted.
- ISO/IEC 27001:2022
ISO/IEC 27001 is the international standard for an information security management system (ISMS).
- ISO/IEC 27701 (privacy information management)
ISO/IEC 27701 extends an information security management system to privacy, with separate controls for PII controllers and processors.
- ISO/IEC 42001:2023 (AI management system)
ISO/IEC 42001 is the management-system standard for organizations that develop or use AI.
- SOC 2 (AICPA Trust Services Criteria)
SOC 2 reports on a service organization's controls against the AICPA Trust Services Criteria.
- SWIFT Customer Security Programme (CSCF v2026)
The SWIFT Customer Security Controls Framework sets the controls every SWIFT user attests to each year.
- WCAG 2.0, 2.1 and 2.2
The Web Content Accessibility Guidelines are the W3C's international accessibility standard, and the reference for laws such as EN 301 549, the European Accessibility Act, the ADA and Section 508.
United States
- NIST Cybersecurity Framework (CSF 2.0)
The NIST Cybersecurity Framework organizes cybersecurity risk management into six functions: Govern, Identify, Protect, Detect, Respond and Recover.
- NIST SP 800-53 Rev. 5
NIST SP 800-53 is the catalogue of security and privacy controls for US federal information systems.
- NIST AI Risk Management Framework (AI RMF 1.0)
The NIST AI RMF is a voluntary framework for managing AI risk across four functions: Govern, Map, Measure and Manage.
- FedRAMP
FedRAMP authorizes cloud services for US federal use.
- CMMC 2.0
The Cybersecurity Maturity Model Certification protects Federal Contract Information and Controlled Unclassified Information in the Defense Industrial Base.
- HIPAA (Privacy, Security and Breach Notification Rules)
HIPAA protects patient health information in the United States.
- CCPA / CPRA (California)
The California Consumer Privacy Act, as amended by the CPRA, gives Californians rights over their personal information.
- ITAR (22 CFR Parts 120-130)
The International Traffic in Arms Regulations control defense articles, services and technical data on the US Munitions List.
- EAR (Export Administration Regulations)
The Export Administration Regulations control dual-use items through the Commerce Control List.
- TSA Security Directives (pipelines and rail)
TSA Security Directives set cybersecurity requirements for pipelines, freight and passenger rail, and public transit.
- Section 508 (federal ICT accessibility)
Section 508 requires US federal ICT to be accessible.
EU & UK
- GDPR (EU and UK)
The General Data Protection Regulation governs personal data in the EU, and the UK GDPR in the UK.
- EU AI Act (Regulation (EU) 2024/1689)
The EU AI Act regulates AI systems by risk, from prohibited practices to high-risk systems and general-purpose AI models.
- NIS2 Directive (EU) 2022/2555
NIS2 sets cybersecurity risk management and incident reporting duties for essential and important entities across the EU.
- DORA (Regulation (EU) 2022/2554)
The Digital Operational Resilience Act sets ICT risk, incident, testing and third-party rules for EU financial entities.
- EU Cyber Resilience Act (Regulation (EU) 2024/2847)
The Cyber Resilience Act sets cybersecurity and vulnerability-handling requirements for products with digital elements sold in the EU.
- CSRD and ESRS (EU sustainability reporting)
The Corporate Sustainability Reporting Directive requires in-scope companies to report under the European Sustainability Reporting Standards.
India
- India Digital Personal Data Protection Act, 2023 and Rules, 2025
India's DPDP Act and the DPDP Rules, 2025 set out how Data Fiduciaries collect, use and protect personal data.
Australia & New Zealand
- Australian Privacy Act 1988 and the APPs
The Privacy Act 1988 and its 13 Australian Privacy Principles govern personal information in Australia.
- Australian Information Security Manual (ISM)
The ASD Information Security Manual sets the cybersecurity controls for Australian government systems.
- New Zealand Information Security Manual (NZISM)
The NZISM is the GCSB's information security manual for New Zealand government agencies.
Vietnam
- Vietnam Personal Data Protection Law (Law No. 91/2025/QH15)
Vietnam's Personal Data Protection Law and Decree 356/2025/ND-CP took effect on 1 January 2026.
Brazil
- LGPD (Brazil, Law 13,709/2018)
Brazil's Lei Geral de Proteção de Dados governs personal data processing in Brazil, enforced by the ANPD.
Arab Gulf States
- Saudi Arabia: PDPL, NCA ECC, SAMA and AI governance
Saudi Arabia combines a Personal Data Protection Law with National Cybersecurity Authority controls and SAMA rules for the financial sector.
- UAE: PDPL, DIFC, ADGM, CBUAE and IA Standard
The UAE runs separate data protection regimes onshore and in the DIFC and ADGM, alongside sector and cybersecurity rules.
- Qatar: PDPPL, QFC, NCSA NIA and QCB
Qatar has an onshore Personal Data Privacy Protection Law and a separate regime in the Qatar Financial Centre.
- Bahrain: PDPL, CBB Rulebook and NCSC
Bahrain's Personal Data Protection Law is supported by implementing Orders, and its financial sector follows the Central Bank of Bahrain Rulebook.
- Oman: PDPL, MTCIT, CBO and TRA cloud rules
Oman's Personal Data Protection Law and its Executive Regulation are enforced by the Ministry of Transport, Communications and IT.
- Kuwait: CITRA DPPR, NCSC and CBK
Kuwait has no general data protection law, so the rules depend on your sector.