Continuous Compliance, Mapped To Your Cloud
Compliance Frameworks
Cloudanix maps your AWS, Azure, GCP, OCI, and Kubernetes posture to the compliance frameworks that matter to you — from SOC 2, ISO 27001, and PCI DSS to regional standards like DPDPA, RBI, DORA, and more. Explore the frameworks we support.
APRA CPG 234
APRA prudential practice guide for information security.
View frameworkAPRA CPS 234
Australian Prudential Regulation Authority information security standard.
View frameworkBrazil LGPD
Lei Geral de Proteção de Dados — Brazil's data protection law.
View frameworkBSI C5
German Cloud Computing Compliance Criteria Catalogue.
View frameworkCCPA / CPRA
California Consumer Privacy Act, as amended by the CPRA.
View frameworkCIS Benchmarks
Center for Internet Security benchmarks for cloud and Kubernetes.
View frameworkCIS Critical Security Controls v8
18 prioritized safeguards for cyber defense.
View frameworkCloudanix Best Practice
Cloudanix's baseline for securing cloud resources against misconfigurations.
View frameworkCMMC 2.0 Level 2
Cybersecurity Maturity Model Certification for the US defense supply chain.
View frameworkCSA Cloud Controls Matrix v4
Cloud Security Alliance control matrix — the basis of CSA STAR.
View frameworkDORA
EU Digital Operational Resilience Act for financial entities.
View frameworkDPDPA
India's Digital Personal Data Protection Act, 2023.
View frameworkEssential Eight
ACSC baseline mitigation strategies against common cyber threats.
View frameworkFedRAMP
US federal security authorization for cloud services.
View frameworkFFIEC
US Federal Financial Institutions Examination Council guidance.
View frameworkGDPR
EU General Data Protection Regulation for personal data.
View frameworkGramm-Leach-Bliley Act
GLBA Safeguards Rule for US financial institutions.
View frameworkHIPAA
US law protecting the security and privacy of health information.
View frameworkHITRUST CSF
Harmonized security and privacy framework across ISO, NIST, PCI, and HIPAA.
View frameworkISO 27001
The leading international information security management standard.
View frameworkISO/IEC 27017
Information security controls tailored for cloud services.
View frameworkISO/IEC 27018
Code of practice for protecting PII in public clouds.
View frameworkISO/IEC 27701
Privacy Information Management extension to ISO/IEC 27001.
View frameworkK-ISMS-P
Korea Information Security & Personal Information Management certification.
View frameworkKSA PDPL
Saudi Arabia Personal Data Protection Law.
View frameworkMAS TRM
Monetary Authority of Singapore Technology Risk Management guidelines.
View frameworkMAS TRMG Audit
Streamlined audits against the MAS Technology Risk Management Guidelines.
View frameworkMITRE ATT&CK (Cloud)
Adversary tactics and techniques across IaaS, SaaS, and identity.
View frameworkNERC CIP
Critical Infrastructure Protection for the North American power grid.
View frameworkNIS2 Directive
EU cybersecurity directive across 18 critical sectors.
View frameworkNIST
Security and privacy controls for risk management.
View frameworkNIST Cybersecurity Framework
Risk-based approach to managing cybersecurity risk.
View frameworkNIST SP 800-171
Protecting Controlled Unclassified Information in nonfederal systems.
View frameworkNYDFS 23 NYCRR 500
New York State Department of Financial Services cybersecurity regulation.
View frameworkPCI DSS
Payment Card Industry Data Security Standard.
View frameworkRBI Cyber Security Framework (UCBs)
Reserve Bank of India cyber security framework for cooperative banks.
View frameworkRBI Master Direction – IT Framework
Reserve Bank of India IT governance, risk, and controls.
View frameworkSarbanes-Oxley ITGC
IT General Controls supporting SOX Section 404 for US public companies.
View frameworkSEBI Cloud Security Adoption Framework
SEBI cloud adoption controls for the Indian securities market.
View frameworkSOC 1
Controls relevant to a service organization's financial reporting.
View frameworkSOC 2
Trust service criteria for security, availability, and confidentiality.
View frameworkStateRAMP
Security authorization for cloud used by US state and local governments.
View frameworkSWIFT CSCF
Customer Security Controls Framework for the SWIFT network.
View frameworkTISAX
Trusted Information Security Assessment Exchange for automotive.
View frameworkUAE Information Assurance (NESA)
United Arab Emirates Information Assurance Standards.
View frameworkUK NCSC Cyber Assessment Framework
Outcome-based framework for operators of essential services.
View framework