Security teams rarely work from a single rulebook. They may use the NIST Cybersecurity Framework to organize the program, ISO/IEC 27001 to build a formal management system, SOC 2 reports to assess vendors, and laws such as HIPAA, GDPR, DORA, or NIS2 to meet legal obligations. Those names are often grouped together, even though they serve different purposes. Some provide guidance. Some can be certified or independently assessed. Others are contractual requirements, laws, or mandatory sector standards. Knowing the difference helps an organization choose the right starting point, budget for the right work, and collect evidence that will stand up to scrutiny. They also share a practical goal: understand what matters, reduce risk, prepare for incidents, and show that security controls continue to work as the business changes.
What is a cybersecurity framework?
A cybersecurity framework gives an organization a structured way to manage cyber risk. It helps technical teams and leaders agree on priorities, responsibilities, and desired outcomes.
Type | Purpose | Examples |
| Voluntary framework | Organizes risk management and security outcomes | NIST CSF, CIS Controls, COBIT |
| Certifiable standard | Defines requirements that can be audited for certification | ISO/IEC 27001 |
| Attestation | Reports on controls examined by an independent practitioner | SOC 2 |
| Industry or contractual requirement | Applies through an industry program or contract | PCI DSS, CMMC |
| Law or mandatory sector standard | Creates enforceable duties for organizations in scope | HIPAA, FISMA, GDPR, DORA, NIS2, NERC CIP |
The terms in this article have distinct meanings; the right combination depends on where the organization operates, the data it handles, the services it provides, and the commitments in its contracts. Many organizations map several obligations to one shared control environment. That reduces duplicate work and makes gaps easier to see.
Which industries and vendors are affected?
Some of these requirements apply directly to organizations within a defined legal or contractual scope. Others are voluntary and widely used because customers, regulators, or business partners expect them. The table below separates those situations so that vendor impact is not overstated.
Framework, standard, or regulation | Vendors and industries who may use it | What it means for vendors |
| NIST CSF 2.0 (National Institute of Standards and Technology Cybersecurity Framework) | Organizations in any sector. It is widely used by critical infrastructure, government, healthcare, financial services, technology, and other risk sensitive industries. | Suppliers may be asked to align with NIST CSF outcomes or provide evidence that supports a customer’s risk program. Use is usually voluntary unless a contract or policy requires it. |
| ISO/IEC 27001 (International Organization for Standardization) and (International Electrotechnical Commission) | Organizations in any industry seeking a certifiable ISMS. Adoption is commonly among SaaS, cloud technology, financial services, healthcare, professional services, and government suppliers. | A vendor may pursue certification to meet customer expectations. Customers should confirm the certificate’s scope covers the service they use. |
| CIS Controls (Center for Internet Security) | Organizations of any size, including smaller businesses that need a prioritized security baseline. | Vendors, managed service providers, and software companies may use the controls internally or be assessed against selected safeguards by customers. |
| SOC 2 (System and Organization Controls 2) | Service organizations whose customers need assurance about relevant controls, especially SaaS, cloud, data center, managed service, fintech, and business process providers. | Customers often request a SOC 2 report during vendor due diligence. The report covers only the systems, services, criteria, and period included in the examination. |
| COBIT 2019 (Control Objectives for Information and Related Technologies) | Large enterprises, public-sector bodies, and regulated organizations that need formal governance of information and technology. | Vendors are usually affected through the organization’s governance, procurement, oversight, and reporting requirements rather than through COBIT itself. |
| PCI DSS (Payment Card Industry Data Security Standard) | Merchants, processors, acquirers, issuers, service providers, and other entities that store, process, or transmit cardholder data or can affect the security of the cardholder data environment. | Payment gateways, hosting providers, managed service providers, call centers, and other suppliers may be directly in scope or responsible for specific shared controls. |
| NERC CIP (NERC Critical Infrastructure Protection) | Registered entities with applicable Bulk Electric System functions and assets, including certain generation, transmission, distribution, balancing, and reliability organizations in the United States and parts of Canada. | Technology and service vendors are generally affected through utility procurement and supply chain risk requirements. A vendor is directly subject only when it is itself a registered entity with applicable functions and assets. |
| HIPAA Security Rule (health insurance portability and accountability act) | U.S. health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically in connection with a covered transaction along with their business associates. | A vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate may itself be a business associate. This can include cloud, billing, analytics, IT, security, and certain subcontracted services. |
| FISMA and RMF (Federal Information Security Modernization ACT) and (Risk Management Framework) | U.S. federal agencies and information systems used or operated by contractors or other organizations on an agency’s behalf. | Cloud, software, hosting, and IT services providers may need to implement NIST controls and supply evidence when their systems fall within a federal authorization boundary or contract. |
| CMMC (Cybersecurity Maturity Model Certification) | U.S. defense contractors and subcontractors when a solicitation of contract requires a CMMC status because they will process, store, or transmit FCI or CUI on unclassified systems. Contracts and subcontracts solely for commercially available off-the-shelf items are excluded from CMMC requirements. | Requirements can flow down through the defence supply chain. The required level depends on the information handled and the terms of the solicitation or contract. |
| GDPR (General Data Protection Regulation) | Controllers and processors established in the EU. It can also cover organizations outside the EU when they offer goods or services to people in the EU or monitor their behavior there. | Vendors that process personal data for an organization in scope may be processors or subprocessors with contractual and, in some cases, direct legal obligations. |
| DORA (Digital Operational Resilience Act) | In-scope EU financial entities, including banks, insurers, investment firms, payment institutions, and certain crypto-asset service providers. | Most ICT providers are affected through customer due diligence, contract, audit, information, and incident-support requirements. ICT providers designated as critical are also subject to direct EU oversight. |
| NIS2 (Network and Information Systems Directive) | Essential and important entities across 18 EU sectors, including energy, transport, health, digital infrastructure, public administration, manufacturing of specified critical products, and certain digital services. Exact scope depends on national law. | Some technology, cloud, data center, managed service, and managed security providers may be directly in scope. Other suppliers are affected through customer supply chain security reviews and contract requirements. |
1. NIST Cybersecurity Framework 2.0
The NIST Cybersecurity Framework 2.0, released in February 2024, provides outcomes-based guidance for managing cybersecurity risk. It is designed for organizations of any size and in any sector.
The framework is organized around six functions:
- Govern
- Identify
- Protect
- Detect
- Respond
- Recover
Govern, added in version 2.0, gives more attention to leadership oversight, policy, legal obligations, and supply chain risk. Current and Target Profiles help an organization describe its present state, its desired state, and the gaps it needs to address. NIST CSF does not prescribe a specific set of technical controls, and there is no formal NIST CSF certification. Organizations often map it to more detailed sources such as ISO/IEC 27001, the CIS Controls, and NIST SP 800-53.
Why it matters
NIST CSF 2.0 gives leaders and technical teams a common way to discuss risk. It is especially useful when an organization needs an overall structure before deciding which detailed controls to implement.
2. ISO/IEC 27001 and ISO/IEC 27002
ISO/IEC 27001:2022 sets requirements for an Information Security Management System, or ISMS. An ISMS brings risk assessment, policies, assigned responsibilities, control selection, measurement, and continual improvement into one managed program. Organizations can seek certification through an independent certification body.
ISO/IEC 27002:2022 provides guidance for selecting and implementing information security controls. Certification is issued against ISO/IEC 27001. ISO/IEC 27002 is supporting guidance and is not independently certifiable.
A certificate applies to a defined scope. Buyers should check whether that scope covers the service, location, or business unit they rely on. The Statement of Applicability can provide more detail about the controls the organization selected and the reasons for those decisions.
Why it matters
ISO/IEC 27001 can demonstrate that a structured security management system is operating within the certified scope. The scope determines how useful that assurance is to a customer.