Compyl 26.1 Is Live — See What’s New and How GRC Just Got Faster.

GRC YOUR WAY

Frameworks

All Frameworks

Framework

Establish foundational cybersecurity protections against basic attacks.

Framework

Adopt strengthened cybersecurity controls to reduce risk from common threats.

Framework

Implement the highest level of Essential Eight controls to defend against sophisticated cyber threats.

Regulation

Australian regulation requiring financial institutions to manage information security risks.

Framework

Governance framework focused on trustworthy and responsible AI deployment.

Attestation / Assurance Program

Security and reliability review required for certain AWS partner programs.

Attestation / Assurance Program

Demonstrate cloud security transparency through Germany’s Cloud Computing Compliance Criteria Catalogue.

Regulation

The California Consumer Privacy Act is a law that allows any California consumers to see all the information a company has saved on them. 

Standard

Security configuration benchmark specifically for AWS cloud environments.

Framework

Implement prioritized security controls designed to defend against today’s most common cyber threats.

Regulation

FBI security requirements governing the protection of criminal justice information.

Framework

Align cloud security practices with the Cloud Security Alliance’s Cloud Controls Matrix.

Attestation / Assurance Program

Meet foundational cybersecurity requirements to protect Federal Contract Information (FCI).

Attestation / Assurance Program

Implement advanced cybersecurity controls required for handling Controlled Unclassified Information (CUI).

Standard

Implement security controls required for systems supporting the Centers for Medicare & Medicaid Services.

Standard

Meet CMS security and privacy requirements for systems handling healthcare exchange data.

Framework

Align IT governance and management practices with business objectives and risk management.

Regulation

Enhance California privacy protections and strengthen consumer data rights.

Framework

Cloud Security Alliance framework supporting GDPR compliance for cloud providers.

Attestation / Assurance Program

Cloud security assurance program demonstrating alignment with CSA security requirements.

Framework

Financial services cybersecurity framework aligned with multiple regulatory expectations.

Guidance / Model

Assess and improve cybersecurity maturity across critical infrastructure sectors.

Regulation

Improve transparency and accountability for digital platforms operating in the EU.

Regulation

Ensure financial institutions maintain resilient digital operations and strong ICT risk management.

Standard

Establish security requirements for trusted digital service providers and electronic trust services.

Regulation

European regulation establishing risk-based governance for artificial intelligence systems.

Framework

Modernized FedRAMP initiative focused on automated authorization and continuous security validation.

Framework

Protect highly sensitive federal data with the strictest cloud security requirements.

Framework

Demonstrate baseline security controls required for low-impact federal cloud systems.

Framework

Meet the most widely adopted security requirements for federal cloud service providers.

Framework

Cybersecurity assessment framework used by U.S. financial regulators.

Regulation

Protect personal information held by public sector organizations through privacy governance.

Regulation

Protect personal data and ensure privacy compliance for individuals within the European Union.

Regulation

Ensure financial institutions safeguard sensitive customer information.

Regulation

Protect consumer financial information through comprehensive security programs.

Regulation

By safeguarding health information, you demonstrate a commitment to preserving trust in your brand.

Framework

Comprehensive security and privacy framework used as the foundation for HITRUST certification programs.

Attestation / Assurance Program

Achieve essential cybersecurity protection with a foundational HITRUST certification.

Attestation / Assurance Program

Demonstrate strong cybersecurity hygiene through a streamlined, risk-based assurance framework.

Certification Standard

International certification standard for quality management systems.

Certification Standard

International certification standard for business continuity management systems.

Certification Standard

Establish a proven information security management system aligned with international standards.

Certification Standard

Establish and maintain a globally recognized information security management system (ISMS).

Standard

Apply additional security controls specifically designed for cloud services.

Standard

International standard for protecting personally identifiable information in public cloud services.

Standard

Ensure business continuity by preparing ICT systems to respond to and recover from disruptions.

Guidance / Model

Cybersecurity guidance standard focused on internet security and collaboration.

Certification Standard

Extend ISO 27001 to manage privacy information and support global data protection requirements.

Certification Standard

Implement governance and risk management practices for responsible artificial intelligence systems.

Regulation

Protect personal data and ensure privacy compliance within Brazil’s data protection law.

Standard

Microsoft compliance requirements for vendors handling Microsoft customer data.

Guidance / Model

Lightweight checklist defining baseline security requirements for SaaS vendors.

Guidance / Model

Understand attacker behaviors and improve defenses using a globally recognized threat knowledge base.

Guidance / Model

Map defensive cybersecurity techniques to strengthen protection against known attack methods.

Framework

Assess and improve cybersecurity resilience for critical national infrastructure organizations.

Regulation

Secure critical energy infrastructure by adhering to cybersecurity standards for the bulk electric system.

Regulation

Strengthen cybersecurity and resilience requirements for essential and important EU organizations.

Framework

Manage AI risks and promote trustworthy AI through structured governance and oversight.

Framework

Strengthen cybersecurity programs with a flexible framework for identifying, protecting, detecting, responding, and recovering from threats.

Framework

Risk management framework designed to help organizations manage privacy risks.

Guidance / Model

Guidance for integrating security into the software development lifecycle.

Standard

Security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems.

Standard

Comprehensive catalog of security and privacy controls for U.S. federal information systems.

Guidance / Model

Apply NIST guidance to implement the HIPAA Security Rule and strengthen healthcare cybersecurity.

Guidance / Model

Apply guidance for managing cybersecurity supply chain risks across organizations.

Regulation

Meet New York Department of Financial Services cybersecurity requirements for financial institutions.

Framework

Security framework designed for fintech and open finance organizations.

Regulation

Manage technology and cyber risks for Canadian financial institutions under OSFI guidance.

Standard

Protect payment card data and reduce fraud risk by implementing strong security controls.

Attestation / Assurance Program

Self-assessment questionnaire for merchants fully outsourcing card processing.

Attestation / Assurance Program

Self-assessment questionnaire for merchants hosting payment pages but outsourcing processing.

Regulation

Protect consumer financial information through strong privacy and safeguarding controls.

Framework

Unified control framework mapping multiple regulatory and security standards.

Attestation / Assurance Program

Close more deals and build customer trust by effectively proving your commitment to security.

Regulation

Controls supporting financial reporting integrity under the Sarbanes-Oxley Act.

Framework

Strengthen financial messaging security with SWIFT’s Customer Security Controls Framework.

Attestation / Assurance Program

Meet automotive industry security requirements for protecting sensitive information across supply chains.

Attestation / Assurance Program

Protect organizations from common cyber threats with the UK government’s baseline security framework.

Framework

Helps organizations manage compliance with multiple U.S. state privacy regulations as they continue to expand.

Standard

Ensure digital accessibility so websites and applications are usable by everyone.

Your business has evolved.

Your GRC should too.

Turn your data into deep GRC insights and guided automation with the flexibility you need to proactively manage risk, stay compliant and adapt to your needs—no heavy lift required.

Check out our latest content

Here's what you should know about security posture.

Security posture describes the overall strength and readiness of an organization’s cybersecurity systems, policies, and Security Posture and Security Posture Assessment...

A SIG Lite lands in your inbox Monday morning. 126 questions. The prospect wants it Security Questionnaires Shouldn’t Take Days

...

Annual reviews and cybersecurity scores are a solid foundation. But there are gaps that most Third-Party Risk Has Blind Spots. Here’s...

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies