50+ Compliance Frameworks, One Platform
GetCybr gives MSPs and vCISO teams one platform for ISO 27001, SOC 2, NIS2, DORA, CMMC, NCA, HIPAA, PCI DSS, and more, with cross-framework mapping and audit-ready reporting.
Global Standards
ISO 27001
ISO 27001:2022
Automate your information security management system (ISMS) with 93 Annex A controls — the global gold standard for security certification.
SOC 2
SOC 2 Type I & II
Streamline SOC 2 compliance across Trust Service Criteria — security, availability, processing integrity, confidentiality, and privacy controls.
NIST CSF
NIST Cybersecurity Framework (CSF)
Manage cybersecurity risk with the NIST CSF — standards and best practices for identifying, protecting, detecting, responding to, and recovering from threats.
NIST 800-53
NIST 800-53
Comprehensive catalogue of security and privacy controls for federal systems — automate control assessments and manage compliance across your organisation.
CIS Controls
CIS Controls v8
Prioritised cybersecurity controls across three implementation groups — streamline threat defence and automate compliance tracking for your organisation.
ISO 22301
ISO 22301
Build organisational resilience with ISO 22301 — manage disaster recovery plans and automate business continuity compliance during disruptions.
NIST 800-171
NIST SP 800-171
Protecting Controlled Unclassified Information (CUI) in non-federal systems — 110 security requirements aligned with CMMC 2.0 compliance.
ISO 42001
ISO/IEC 42001
AI management system standard — governance, risk management, and responsible AI practices for organisations developing or deploying AI systems.
European Union
GDPR
General Data Protection Regulation
Automate GDPR compliance — manage consent, data subject rights, and privacy obligations for any organisation processing EU residents' personal data.
NIS2
NIS2 Directive
EU directive on cybersecurity for essential and important entities — network and information security across critical sectors.
DORA
Digital Operational Resilience Act
EU regulation ensuring financial entities can withstand, respond to, and recover from ICT-related disruptions and threats.
UK GDPR
UK GDPR & Data Protection Act 2018
Post-Brexit UK data protection regulation — mirroring EU GDPR requirements for organisations processing UK residents' personal data.
United States
HIPAA
HIPAA
Automate HIPAA compliance and protect PHI — required for healthcare organisations and business associates handling sensitive patient health information.
PCI DSS
PCI DSS v4.0
Manage cardholder data security and meet PCI DSS v4.0 deadlines — required compliance for any organisation that accepts, processes, or stores credit card data.
CMMC
CMMC 2.0
Achieve CMMC 2.0 certification and protect CUI — built on NIST 800-171 requirements and mandatory for all DoD contractors in the Defence Industrial Base.
FedRAMP
FedRAMP
Streamline your FedRAMP ATO (Authority to Operate) — standardised cloud security assessment for services used by US federal government agencies.
CCPA
CCPA / CPRA
Automate data privacy compliance and manage consumer rights — California residents' right to know, delete, and opt-out under CCPA and CPRA.
StateRAMP
StateRAMP
Standardised cloud security verification for US state and local government — aligned with FedRAMP controls for sub-federal procurement.
Middle East
NCA
NCA Frameworks
Saudi National Cybersecurity Authority frameworks — ECC, plus mapping support for CSCC, DCC, OTCC, TCC, and OSMACC. Mandatory for organisations operating in Saudi Arabia.
UAE IA
UAE IA Standard
UAE Information Assurance Standards — manage cybersecurity controls, risk governance, and compliance for government and critical infrastructure entities.
Industry & Sector
COBIT
COBIT 2019
Strengthen IT governance and streamline audit readiness with COBIT 2019 — aligning IT strategy, risk management, and business objectives across the enterprise.
ISO 9001
ISO 9001
Manage quality processes and accelerate ISO 9001 certification — drive continuous process improvement and ensure consistent quality in products and services.
Cyber Essentials
Cyber Essentials
UK government-backed scheme (NCSC, delivered by IASME) covering five technical controls — required for many UK government contracts under PPN 014, renewed every 12 months.
CSA STAR
CSA STAR
Cloud Security Alliance assurance program — security, trust, and risk assessment for cloud service providers and their customers.
GetCybr also offers dedicated compliance platforms forISO 27001,SOC 2,HIPAA,CMMC,NIST CSF,NIS2,DORA,Cyber Essentials,ECC / NCA, andMAS TRM, with automated gap analysis, policy documentation, and audit-ready reporting.
Need a Framework We Don't List?
Custom framework support is part of the Brand add-on bundle ($99/account/month) on Standard. Enterprise bundles Brand and Connect, adds a separately quoted edition fee, and therefore has an incomplete final total. Define your own controls, evidence requirements, and assessment criteria — or let our team help you build it.
The full framework catalog is available on both Standard and Enterprise. Choose the offering that fits how your practice delivers custom control sets.
Help Center
FAQs have moved to the Help Center
Find current answers for the topics covered on this page in our consolidated FAQ.
Frameworks We Support
Logos of the compliance frameworks and standards supported by GetCybr.
ISO 27001
SOC 2
NIST CSF
NIST 800-53
CIS Controls
ISO 22301
NIST 800-171
ISO 42001
GDPR
NIS2
DORA
UK GDPR
HIPAA
PCI DSS
CMMC
FedRAMP
CCPA
StateRAMP
NCA
UAE IA
COBIT
ISO 9001
Cyber Essentials
CSA STAR
MAS TRMNot Ready for a Demo?
Get weekly vCISO insights, compliance updates, and threat intelligence.
No spam. Unsubscribe anytime.
Ready to Deliver Multi-Framework Compliance?
See how GetCybr automates compliance across 50+ frameworks for your entire client portfolio. Book a 30-minute walkthrough.