Guide · September 2026

Which compliance framework do I need?

Nine times out of ten, the answer is whoever is asking. Match your trigger to the framework below, then open the directory that covers it.

The trigger map

If this is your situationThe framework
An enterprise customer asked for your security reportSOC 2 — attestation of your controls by a licensed CPA firmDirectory →
You store, process, or transmit cardholder dataPCI DSS — the card brands' security standard, validated by a QSA or self-assessmentDirectory →
You handle protected health informationHIPAA — safeguards for PHI; applies to covered entities and business associatesDirectory →
A bank or partner asked about your financial-reporting controlsSOC 1 (SSAE 18) — attestation over controls relevant to financial reportingDirectory →
You hold (or want) defense contractsCMMC — cybersecurity maturity required across the defense industrial baseDirectory →
International customers want an ISO certificateISO 27001 — certification of your information security management systemDirectory →
Buyers ask how you govern your AI systemsISO 42001 / NIST AI RMF — AI management system certification and risk frameworkDirectory →
You run nonclinical safety studies for regulatorsGLP — Good Laboratory Practice for labs supporting regulatory submissionsDirectory →
You want a security program, but no one named a certificateNIST CSF — the Cybersecurity Framework for building and measuring a programDirectory →

Three things buyers get wrong

Still torn between two?

Read SOC 2 vs ISO 27001 vs PCI DSS, compared — the three frameworks buyers confuse most, side by side.

Know your framework? Get quotes

Matched providers for your framework, scoped to your size and timeline. Free, no obligation.

Get a free quote