HomeFrameworks

Frameworks

Find the standard you need to understand.

Each page explains, in plain words, what the standard is, whether it applies to you, what you have to write down, who checks it and who can help.

Share
Sponsored
Find
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Compare the Modern WayFind the right firm
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

How to use this section

If a customer, auditor, insurer or contract gave you a name, start with the eight below or search any page for it. If you only know your industry, open the family it belongs to. If you do not know which rules apply at all, start from your business type instead; the obligations index names the standards for you.

Start here

The standards people ask about most.

Eight names that come up in almost every contract, audit or customer questionnaire. Each explainer says what the standard is, who has to follow it, what you must write down, and who checks it.

StandardSOC 2

A report from a CPA firm on how a company protects customer data. Customers ask for it before they sign; there is no certificate, only the report.

Checked by: A licensed CPA firm (independent certified public accountants) perform
StandardISO 27001

The international standard for running information security as a managed system. An accredited registrar certifies it; consultants help you build it.

Checked by: An accredited certification body (registrar) operating under ISO/IEC 1
StandardHIPAA

US rules for protecting patient health information. There is no certification; the Office for Civil Rights checks your policies and records after a complaint or breach.

Checked by: Government enforcement only. OCR investigates complaints and breach re
StandardISO 9001

The quality management standard most manufacturers and service firms are asked for by customers. A registrar audits it and issues a certificate every three years.

Checked by: Accredited certification body (registrar) accredited to ISO/IEC 17021-
StandardPCI DSS

The card brands' security rules for anyone who takes card payments. Small merchants self-assess; larger ones use a qualified assessor.

Checked by: A PCI SSC qualified Qualified Security Assessor (QSA) company with cer
StandardCMMC/NIST 800-171

The Department of Defense's cybersecurity requirement for contractors that handle controlled information. Assessed by accredited third parties from late 2026.

Checked by: Level 1 and Level 2 (self): the organization's own assessment with sen
StandardOSHA written programs

The safety plans US employers must keep in writing, such as hazard communication and emergency action. Inspectors ask for the document and the training records.

Checked by: OSHA compliance safety and health officers, or State Plan inspectors (
StandardGDPR

The European Union's data protection law. It applies to any business that handles EU residents' data, wherever the business sits.

Checked by: No mandatory assessor. Supervisory authorities (for example CNIL, the

Need a hand implementing it?

Find a Consultant Who Does This Work

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Keep Your Written Policies in One Place

Whatever you are working toward, AllyMatter gets your policies approved, keeps every version and records who has read each one.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.