Cloudanix Achieves AWS Security Competency Status for Its CNAPP+ Platform and Just-in-Time Access Engine

Continuous Compliance, Mapped To Your Cloud

Compliance Frameworks

Cloudanix maps your AWS, Azure, GCP, OCI, and Kubernetes posture to the compliance frameworks that matter to you — from SOC 2, ISO 27001, and PCI DSS to regional standards like DPDPA, RBI, DORA, and more. Explore the frameworks we support.

APRA CPG 234

APRA prudential practice guide for information security.

View framework

APRA CPS 234

Australian Prudential Regulation Authority information security standard.

View framework

Brazil LGPD

Lei Geral de Proteção de Dados — Brazil's data protection law.

View framework

BSI C5

German Cloud Computing Compliance Criteria Catalogue.

View framework

CCPA / CPRA

California Consumer Privacy Act, as amended by the CPRA.

View framework

CIS Benchmarks

Center for Internet Security benchmarks for cloud and Kubernetes.

View framework

CIS Critical Security Controls v8

18 prioritized safeguards for cyber defense.

View framework

Cloudanix Best Practice

Cloudanix's baseline for securing cloud resources against misconfigurations.

View framework

CMMC 2.0 Level 2

Cybersecurity Maturity Model Certification for the US defense supply chain.

View framework

CSA Cloud Controls Matrix v4

Cloud Security Alliance control matrix — the basis of CSA STAR.

View framework

DORA

EU Digital Operational Resilience Act for financial entities.

View framework

DPDPA

India's Digital Personal Data Protection Act, 2023.

View framework

Essential Eight

ACSC baseline mitigation strategies against common cyber threats.

View framework

FedRAMP

US federal security authorization for cloud services.

View framework

FFIEC

US Federal Financial Institutions Examination Council guidance.

View framework

GDPR

EU General Data Protection Regulation for personal data.

View framework

Gramm-Leach-Bliley Act

GLBA Safeguards Rule for US financial institutions.

View framework

HIPAA

US law protecting the security and privacy of health information.

View framework

HITRUST CSF

Harmonized security and privacy framework across ISO, NIST, PCI, and HIPAA.

View framework

ISO 27001

The leading international information security management standard.

View framework

ISO/IEC 27017

Information security controls tailored for cloud services.

View framework

ISO/IEC 27018

Code of practice for protecting PII in public clouds.

View framework

ISO/IEC 27701

Privacy Information Management extension to ISO/IEC 27001.

View framework

K-ISMS-P

Korea Information Security & Personal Information Management certification.

View framework

KSA PDPL

Saudi Arabia Personal Data Protection Law.

View framework

MAS TRM

Monetary Authority of Singapore Technology Risk Management guidelines.

View framework

MAS TRMG Audit

Streamlined audits against the MAS Technology Risk Management Guidelines.

View framework

MITRE ATT&CK (Cloud)

Adversary tactics and techniques across IaaS, SaaS, and identity.

View framework

NERC CIP

Critical Infrastructure Protection for the North American power grid.

View framework

NIS2 Directive

EU cybersecurity directive across 18 critical sectors.

View framework

NIST

Security and privacy controls for risk management.

View framework

NIST Cybersecurity Framework

Risk-based approach to managing cybersecurity risk.

View framework

NIST SP 800-171

Protecting Controlled Unclassified Information in nonfederal systems.

View framework

NYDFS 23 NYCRR 500

New York State Department of Financial Services cybersecurity regulation.

View framework

PCI DSS

Payment Card Industry Data Security Standard.

View framework

RBI Cyber Security Framework (UCBs)

Reserve Bank of India cyber security framework for cooperative banks.

View framework

RBI Master Direction – IT Framework

Reserve Bank of India IT governance, risk, and controls.

View framework

Sarbanes-Oxley ITGC

IT General Controls supporting SOX Section 404 for US public companies.

View framework

SEBI Cloud Security Adoption Framework

SEBI cloud adoption controls for the Indian securities market.

View framework

SOC 1

Controls relevant to a service organization's financial reporting.

View framework

SOC 2

Trust service criteria for security, availability, and confidentiality.

View framework

StateRAMP

Security authorization for cloud used by US state and local governments.

View framework

SWIFT CSCF

Customer Security Controls Framework for the SWIFT network.

View framework

TISAX

Trusted Information Security Assessment Exchange for automotive.

View framework

UAE Information Assurance (NESA)

United Arab Emirates Information Assurance Standards.

View framework

UK NCSC Cyber Assessment Framework

Outcome-based framework for operators of essential services.

View framework