Supporting 50+ Global Regulatory Frameworks and Standards
DigitalXForce tests each control and maps it to every framework that requires it, so one tested control reports its status to all of those frameworks without manual evidence collection. This page shows the most requested frameworks. The full list is available on request.

ISO 27001

SOC 2

NIST 800-171 (Special Publication 800-171)

The Health Insurance Portability and Accountability Act (HIPAA)
The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting the confidentiality, integrity, and availability of health information. It applies to covered entities (like healthcare providers and insurers) and business associates that handle ePHI on their behalf.

The Payment Card Industry Data Security Standard (PCI DSS)

GDPR-L1 (General Data Protection Regulation, Level 1)

GDPR-L2 (General Data Protection Regulation, Level 2)

NIST Cybersecurity Framework (CSF) 2.0

EU AI Act

CMMC-FOUNDATIONAL (L1)

CMMC-ADVANCED (L2)

Health Information Trust Alliance (HITRUST)

CIS (Center for Internet Security)

FedRAMP (Federal Risk and Authorization Management Program)

The Secure Controls Framework (SCF)

The Federal Information Security Modernization Act (FISMA)

Minimum Acceptable Risk Standards for Exchanges (MARS-E)

The Authorization to Operate Risk Criteria: Annual Maturity and Performance Evaluation (ARC-AMPE)
The Authorization to Operate Risk Criteria: Annual Maturity and Performance Evaluation (ARC-AMPE) is a CMS-driven cybersecurity and privacy assessment model. It provides a structured methodology for evaluating the maturity, effectiveness, and performance of security and privacy programs in systems that interact with Centers for Medicare & Medicaid Services (CMS).

The Gramm-Leach-Bliley Act (GLBA)
The Gramm-Leach-Bliley Act (GLBA), also known as the Financial Services Modernization Act, mandates that financial institutions implement controls to safeguard non-public personal information (NPI). It applies to banks, credit unions, insurance companies, and any organization significantly involved in offering financial products or services.

The Saudi Arabian Monetary Authority Cybersecurity Framework (SAMA CSF)

The National Electronic Security Authority (NESA)
The National Electronic Security Authority (NESA) is a national cybersecurity standard developed to protect the UAE’s critical information infrastructure by guiding organizations in implementing strong, risk-based security controls.

The Federal Financial Institutions Examination Council (FFIEC)

The Digital Operational Resilience Act (DORA)

The Network and Information Security Directive 2 (NIS 2)

The Cyber Risk Institute (CRI)

Data Cybersecurity Controls (DCC)

Critical System Cybersecurity Controls (CSCC)

The Telework Cybersecurity Controls (TCC)
The Telework Cybersecurity Controls (TCC) framework provides a structured approach to safeguarding remote and hybrid workforces. Developed to address the surge in teleworking, TCC prioritizes endpoint security, secure connectivity, identity management, and data protection beyond traditional network perimeters.

The Essential Cybersecurity Controls (ECC)

The Abu Dhabi Healthcare Information and Cybersecurity Standard (ADHICS)

The NIST Privacy Framework (PF)

IRS Publication 1075

Cybersecurity Standards for Telecom (CST)

The Cybersecurity Requirements Framework (CRF)

The Qatar Cybersecurity Framework (QCSF)
The Qatar Cybersecurity Framework (QCSF) is a national cybersecurity framework developed to protect Qatar’s critical infrastructure and digital economy by enforcing standardized security controls, governance, and risk management practices across sectors.

The Cloud Cybersecurity Controls (CCC)

The National Information Assurance (NIA)

The Information Security Regulations (ISR)

The Abu Dhabi Global Market (ADGM)
Questions about frameworks and standards
How many frameworks and standards does DigitalXForce support?
DigitalXForce supports 50+ global regulatory frameworks and standards. The Frameworks page shows the most requested ones, and the full list is available on request.
How does one tested control report to several frameworks?
DigitalXForce tests each control and maps it to every framework that requires it, so one tested control reports its status to all of those frameworks without manual evidence collection.
Which frameworks does this page show?
The page shows the most requested frameworks, including ISO 27001, SOC 2, NIST CSF 2.0 and the EU AI Act.
What is Continuous Control Assurance?
Continuous Control Assurance (CCA) uses evidence, monitoring and validation to determine whether controls continue to operate as expected. Continuous Control Monitoring (CCM) is a capability within CCA that monitors the conditions, evidence and signals associated with controls.
Does DigitalXForce issue SOC 2 reports?
DigitalXForce does not certify, attest or issue SOC 2 reports, because an independent CPA firm does. The platform prepares organizations for SOC 2 and can review SOC 2 reports with automation and AI.
How do I get the full list of frameworks?
Request a demo and ask for the full list of 50+ frameworks and standards.



