13 essential cybersecurity frameworks, standards, and regulations explained

top cybersecurity frameworks blog
emma-stevens-bio-portrait
Written by Emma Stevens
Senior Threat Intelligence Advisor

Security teams rarely work from a single rulebook. They may use the NIST Cybersecurity Framework to organize the program, ISO/IEC 27001 to build a formal management system, SOC 2 reports to assess vendors, and laws such as HIPAA, GDPR, DORA, or NIS2 to meet legal obligations. Those names are often grouped together, even though they serve different purposes. Some provide guidance. Some can be certified or independently assessed. Others are contractual requirements, laws, or mandatory sector standards. Knowing the difference helps an organization choose the right starting point, budget for the right work, and collect evidence that will stand up to scrutiny. They also share a practical goal: understand what matters, reduce risk, prepare for incidents, and show that security controls continue to work as the business changes.

What is a cybersecurity framework?

A cybersecurity framework gives an organization a structured way to manage cyber risk. It helps technical teams and leaders agree on priorities, responsibilities, and desired outcomes.

Type

Purpose

Examples

Voluntary frameworkOrganizes risk management and security outcomesNIST CSF, CIS Controls, COBIT
Certifiable standardDefines requirements that can be audited for certificationISO/IEC 27001
AttestationReports on controls examined by an independent practitionerSOC 2
Industry or contractual requirementApplies through an industry program or contractPCI DSS, CMMC
Law or mandatory sector standardCreates enforceable duties for organizations in scopeHIPAA, FISMA, GDPR, DORA, NIS2, NERC CIP

The terms in this article have distinct meanings; the right combination depends on where the organization operates, the data it handles, the services it provides, and the commitments in its contracts. Many organizations map several obligations to one shared control environment. That reduces duplicate work and makes gaps easier to see.

Which industries and vendors are affected?

Some of these requirements apply directly to organizations within a defined legal or contractual scope. Others are voluntary and widely used because customers, regulators, or business partners expect them. The table below separates those situations so that vendor impact is not overstated.

Framework, standard, or regulation

Vendors and industries who may use it 

What it means for vendors

NIST CSF 2.0 (National Institute of Standards and Technology Cybersecurity Framework) Organizations in any sector. It is widely used by critical infrastructure, government, healthcare, financial services, technology, and other risk sensitive industries.Suppliers may be asked to align with NIST CSF outcomes or provide evidence that supports a customer’s risk program. Use is usually voluntary unless a contract or policy requires it. 
ISO/IEC 27001 (International Organization for Standardization) and (International Electrotechnical Commission) Organizations in any industry seeking a certifiable ISMS. Adoption is commonly among SaaS, cloud technology, financial services, healthcare, professional services, and government suppliers.A vendor may pursue certification to meet customer expectations. Customers should confirm the certificate’s scope covers the service they use. 
CIS Controls (Center for Internet Security)Organizations of any size, including smaller businesses that need a prioritized security baseline. Vendors, managed service providers, and software companies may use the controls internally or be assessed against selected safeguards by customers. 
SOC 2 (System and Organization Controls 2)Service organizations whose customers need assurance about relevant controls, especially SaaS, cloud, data center, managed service, fintech, and business process providers.Customers often request a SOC 2 report during vendor due diligence. The report covers only the systems, services, criteria, and period included in the examination. 
COBIT 2019 (Control Objectives for Information and Related Technologies) Large enterprises, public-sector bodies, and regulated organizations that need formal governance of information and technology. Vendors are usually affected through the organization’s governance, procurement, oversight, and reporting requirements rather than through COBIT itself. 
PCI DSS (Payment Card Industry Data Security Standard) Merchants, processors, acquirers, issuers, service providers, and other entities that store, process, or transmit cardholder data or can affect the security of the cardholder data environment. Payment gateways, hosting providers, managed service providers, call centers, and other suppliers may be directly in scope or responsible for specific shared controls. 
NERC CIP (NERC Critical Infrastructure Protection) Registered entities with applicable Bulk Electric System functions and assets, including certain generation, transmission, distribution, balancing, and reliability organizations in the United States and parts of Canada.Technology and service vendors are generally affected through utility procurement and supply chain risk requirements. A vendor is directly subject only when it is itself a registered entity with applicable functions and assets. 
HIPAA Security Rule (health insurance portability and accountability act) U.S. health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically in connection with a covered transaction along with their business associates. A vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate may itself be a business associate. This can include cloud, billing, analytics, IT, security, and certain subcontracted services. 
FISMA and RMF (Federal Information Security Modernization ACT) and (Risk Management Framework)U.S. federal agencies and information systems used or operated by contractors or other organizations on an agency’s behalf. Cloud, software, hosting, and IT services providers may need to implement NIST controls and supply evidence when their systems fall within a federal authorization boundary or contract.
CMMC (Cybersecurity Maturity Model Certification) U.S. defense contractors and subcontractors when a solicitation of contract requires a CMMC status because they will process, store, or transmit FCI or CUI on unclassified systems. Contracts and subcontracts solely for commercially available off-the-shelf items are excluded from CMMC requirements. Requirements can flow down through the defence supply chain. The required level depends on the information handled and the terms of the solicitation or contract. 
GDPR (General Data Protection Regulation) Controllers and processors established in the EU. It can also cover organizations outside the EU when they offer goods or services to people in the EU or monitor their behavior there.Vendors that process personal data for an organization in scope may be processors or subprocessors with contractual and, in some cases, direct legal obligations.
DORA (Digital Operational Resilience Act) In-scope EU financial entities, including banks, insurers, investment firms, payment institutions, and certain crypto-asset service providers.Most ICT providers are affected through customer due diligence, contract, audit, information, and incident-support requirements. ICT providers designated as critical are also subject to direct EU oversight.
NIS2 (Network and Information Systems Directive) Essential and important entities across 18 EU sectors, including energy, transport, health, digital infrastructure, public administration, manufacturing of specified critical products, and certain digital services. Exact scope depends on national law.Some technology, cloud, data center, managed service, and managed security providers may be directly in scope. Other suppliers are affected through customer supply chain security reviews and contract requirements.

1. NIST Cybersecurity Framework 2.0

The NIST Cybersecurity Framework 2.0, released in February 2024, provides outcomes-based guidance for managing cybersecurity risk. It is designed for organizations of any size and in any sector.

CSF-nist 2 cyber framework outline
Source: nist.gov

The framework is organized around six functions: 

  • Govern
  • Identify
  • Protect
  • Detect
  • Respond
  • Recover 

Govern, added in version 2.0, gives more attention to leadership oversight, policy, legal obligations, and supply chain risk. Current and Target Profiles help an organization describe its present state, its desired state, and the gaps it needs to address. NIST CSF does not prescribe a specific set of technical controls, and there is no formal NIST CSF certification. Organizations often map it to more detailed sources such as ISO/IEC 27001, the CIS Controls, and NIST SP 800-53.

Why it matters

NIST CSF 2.0 gives leaders and technical teams a common way to discuss risk. It is especially useful when an organization needs an overall structure before deciding which detailed controls to implement.

2. ISO/IEC 27001 and ISO/IEC 27002

ISO/IEC 27001:2022 sets requirements for an Information Security Management System, or ISMS. An ISMS brings risk assessment, policies, assigned responsibilities, control selection, measurement, and continual improvement into one managed program. Organizations can seek certification through an independent certification body.

ISO/IEC 27002:2022 provides guidance for selecting and implementing information security controls. Certification is issued against ISO/IEC 27001. ISO/IEC 27002 is supporting guidance and is not independently certifiable.

A certificate applies to a defined scope. Buyers should check whether that scope covers the service, location, or business unit they rely on. The Statement of Applicability can provide more detail about the controls the organization selected and the reasons for those decisions.

Why it matters

ISO/IEC 27001 can demonstrate that a structured security management system is operating within the certified scope. The scope determines how useful that assurance is to a customer.

3. CIS Critical Security Controls v8.1

The CIS Critical Security Controls v8.1 organizes practical defensive measures into 18 Controls and a more detailed set of Safeguards. They cover core work such as asset inventory, secure configuration, access management, vulnerability management, logging, and incident response. The Safeguards are grouped into three Implementation Groups. IG1 is the essential cyber hygiene baseline and the recommended starting point for every organization. IG2 and IG3 add safeguards for environments with greater complexity, more sensitive data, or higher risk.

Why it matters

The CIS Controls turn broad security goals into a practical work plan. They are a useful choice for teams that need to decide what to implement first and how to build from a basic baseline.

4. SOC 2

A SOC 2 examination is performed by an independent CPA firm. The resulting attestation report describes controls relevant to the AICPA Trust Services Criteria. Security is included in every SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are included when they are relevant to the engagement.

A Type I report evaluates the design of controls at a point in time. A Type II report also evaluates whether the controls operated effectively over a defined period. A useful review goes beyond the report type. It should consider the system boundary, the auditor's opinion, any exceptions, complementary user entity controls, and the treatment of subservice organizations.

Why it matters

A SOC 2 Type II report can provide valuable evidence about a vendor's control environment. Its value depends on whether the scope covers the service being purchased and whether the customer understands any responsibilities assigned to it.

5. COBIT 2019

COBIT 2019 is ISACA's framework for governing and managing enterprise information and technology. Its 40 governance and management objectives help organizations connect technology decisions with business goals, risk, performance, and accountability. COBIT is often paired with a more technical framework or control set. It helps define who makes decisions, who is accountable, and how technology performance and risk should be governed across the enterprise.

Why it matters

COBIT is useful when cybersecurity work needs stronger ties to enterprise governance, executive ownership, and board reporting.

6. PCI DSS 4.0.1

The Payment Card Industry Data Security Standard applies to entities that store, process, or transmit cardholder data or sensitive authentication data. It also covers entities that can affect the security of the cardholder data environment. The PCI Security Standards Council maintains the standard, while payment brands and acquiring banks manage compliance programs and enforcement. PCI DSS v4.0.1 is the active version. It clarified v4.0 without adding or removing requirements. Requirements that were initially future-dated took effect on March 31, 2025. Areas of focus include multifactor authentication, payment-page script security, vulnerability management, targeted risk analysis, and clear responsibility for controls shared with service providers.

Why it matters

Cardholder data can move through systems and providers that sit outside the obvious payment application. Organizations need a current view of that environment and evidence that required controls work throughout the year.

7. NERC Critical Infrastructure Protection standards

The North American Electric Reliability Corporation Critical Infrastructure Protection standards, commonly called NERC CIP, are mandatory reliability standards for applicable entities and Bulk Electric System cyber systems in the United States and parts of Canada. They address topics such as asset identification, electronic and physical security, personnel and training, incident response, configuration management, vulnerability assessments, recovery planning, and supply chain risk. The requirements that apply depend on an entity's functions and the impact classification of its systems.

Why it matters

For organizations in scope, cyber risk can affect the reliability of the electric grid. NERC CIP therefore requires documented, repeatable controls and can carry significant penalties when those requirements are not met.

8. HIPAA Security Rule

The HIPAA Security Rule is a U.S. federal regulation that protects electronic protected health information, or ePHI. It applies to covered entities and business associates and requires appropriate administrative, physical, and technical safeguards. Regulated organizations must conduct risk analyses and manage identified risks. They also need appropriate access controls, audit controls, contingency planning, and business associate agreements. HHS proposed substantial changes to the Security Rule in late 2024, with publication in January 2025. As of September 2026, HHS still identifies those changes as a proposed rule and states that the current Security Rule remains in effect.

Why it matters

HIPAA security work starts with knowing where ePHI is created, stored, processed, and transmitted. That includes understanding which business associates can access it and how risk decisions are documented over time.

9. FISMA and the NIST Risk Management Framework

The Federal Information Security Modernization Act, or FISMA, requires U.S. federal agencies to maintain agency-wide information security programs. Its requirements also cover information systems used or operated by contractors or other organizations on behalf of an agency. A company does not fall under FISMA simply because it handles some form of federal data, although other contractual security requirements may still apply. FISMA implementation relies heavily on NIST standards. NIST SP 800-53 provides the control catalog, while the NIST Risk Management Framework sets out a seven-step process: 

  1. Prepare
  2. Categorize
  3. Select
  4. Implement
  5. Assess
  6. Authorize
  7. Monitor.

Why it matters

An Authorization to Operate reflects a risk decision about a defined system. Maintaining that authorization requires continued monitoring because systems, suppliers, vulnerabilities, and threats change.

10. Cybersecurity Maturity Model Certification

The Cybersecurity Maturity Model Certification program applies to U.S. defense contractors and subcontractors that handle Federal Contract Information, or FCI, and Controlled Unclassified Information, or CUI. CMMC requirements are placed into solicitations and contracts. The model has three levels. Level 1 addresses basic safeguarding of FCI. Level 2 aligns with the 110 security requirements in NIST SP 800-171 Revision 2 for protecting CUI. Level 3 adds selected requirements from NIST SP 800-172 for the most sensitive programs. The implementation status changed on July 13, 2026, when the department suspended Phase II and began a review of the program. CMMC remains in Phase I. During the suspension, new requirements may call only for Level 1 self-assessments or Level 2 self-assessments. The department may also conduct selected government-led assessments. Requirements in DFARS 252.204-7012 for safeguarding covered defense information remain in effect.

Why it matters

Contractors should read each solicitation and contract carefully. They also need to know where FCI and CUI flow and ensure that applicable safeguarding requirements reach subcontractors.

11. General Data Protection Regulation

The European Union's General Data Protection Regulation, or GDPR, applies to organizations established in the EU. It can also apply to an organization outside the EU when that organization offers goods or services to people in the EU or monitors their behavior there. Holding information about an EU citizen does not by itself establish that GDPR applies. GDPR requires technical and organizational measures appropriate to the risk. It also supports principles such as data minimization and data protection by design. When a personal data breach occurs, a controller generally must notify the relevant supervisory authority within 72 hours of becoming aware of it. Notification is not required when the breach is unlikely to create a risk to people's rights and freedoms. For the most serious infringements, fines can reach EUR 20 million or 4 percent of total worldwide annual turnover from the preceding financial year, whichever is higher.

Why it matters

Organizations need to know what personal data they process, where it goes, which processors and subprocessors handle it, and who will make time-sensitive breach decisions.

12. Digital Operational Resilience Act

The EU's Digital Operational Resilience Act, or DORA, has applied since January 17, 2025. It sets common digital operational resilience requirements for financial entities within its scope. DORA covers ICT risk management, incident reporting, resilience testing, and third-party risk. Financial entities must maintain a Register of Information for contractual arrangements with ICT providers. They also need to perform due diligence, address concentration and dependency risk, include required terms in relevant contracts, and conduct threat-led penetration testing when the rules apply to them. The framework also creates an EU oversight regime for ICT providers designated as critical.

Why it matters

A financial entity remains accountable for resilience when an important service is outsourced. It needs a reliable view of critical providers, subcontracting arrangements, concentrations, incidents, and exit plans.

13. NIS2 Directive

The NIS2 Directive establishes a common cybersecurity baseline across 18 critical sectors in the EU. Member states were required to transpose it into national law by October 17, 2024. Registration, supervision, enforcement, and some scope details depend on each country's implementing law. NIS2 distinguishes between essential and important entities based on factors such as sector, size, and critical role. Required measures cover incident handling, business continuity, supply chain security, vulnerability handling, access control, encryption, and multifactor authentication where appropriate. Management bodies must approve and oversee cybersecurity risk measures, and their members must receive training. A significant incident generally triggers an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month of that notification. For financial entities, DORA takes precedence where its sector-specific requirements overlap with NIS2.

Why it matters

NIS2 makes cyber risk a leadership responsibility and gives organizations little time to report significant incidents. Companies should confirm their status under each relevant national law and test their reporting process before an incident occurs.

How to choose and use the right cybersecurity frameworks

1. Start with scope 

Identify the laws, sector rules, contracts, customer commitments, data types, and locations that apply to the organization. This establishes which requirements are mandatory and which frameworks could help organize the work.

2. Choose a core structure 

NIST CSF 2.0 or an ISO/IEC 27001 ISMS can provide the backbone for governance and risk management. A more detailed control set, such as the CIS Controls or NIST SP 800-53, can guide implementation.

3. Map obligations to shared controls 

One well-designed control may support several requirements. A central mapping shows where evidence can be reused and where a regulation requires something unique.

4. Test and monitor 

Policies and diagrams describe intended controls. Technical testing, internal review, independent assessment, and ongoing monitoring show whether those controls work and whether the environment has changed.

5. Report what matters

Leadership needs a clear view of material exposure, business impact, ownership, deadlines, and progress. A long compliance checklist is much less useful when it does not show where action is needed.

The real goal is defensible, continuous risk management

Frameworks, certifications, and reports provide valuable structure and evidence. Each also has a defined scope and a point-in-time or period-of-time boundary. Meanwhile, assets, cloud services, vulnerabilities, suppliers, and threats keep changing. The practical challenge is to connect written requirements with the systems and relationships that create exposure. A defensible program can show what applies, what is in scope, which controls address the risk, whether those controls work, and how the organization responds when conditions change.

How Bitsight helps

Bitsight adds an outside-in view of cyber risk to the internal evidence an organization already collects. That evidence can help teams see changes between formal assessments and focus their follow-up work. Bitsight does not certify compliance or replace legal advice, audits, regulator-required assessments, or internal control testing.

See the external attack surface

Bitsight External Attack Surface Management helps organizations discover internet-facing assets, identify externally observable exposures, and prioritize vulnerabilities. This can reveal assets or issues that are missing from internal inventories and help teams direct remediation to the places that need attention.

Monitor third-party risk

Bitsight Third-Party Risk Management provides ongoing external insight into vendors and their broader technology relationships. Risk teams can use it to identify changes between scheduled reviews, investigate emerging vulnerabilities, and decide which vendors require faster follow-up.

Prioritize action and explain progress

Consistent metrics, benchmarks, exposure data, and historical trends can help teams decide where limited resources will have the greatest effect. They can also make reporting clearer by showing leaders what changed, what improved, and what still requires action. The result is a stronger connection between framework requirements and day-to-day risk decisions. The framework defines the outcomes and obligations. Continuous evidence helps the organization see where exposure is changing and respond sooner.

Bitsight cta background color
40 Questions ebook new cover

40 questions you should have in your vendor security assessment

Prioritize which vendors need the most attention with an in-depth security assessment – such as those with low security ratings, or critical vendors that maintain constant contact with your company’s systems.

 

Get the guide

Bitsight cta background color