| SOC 2 Type II | SaaS, service providers, vendors handling client data | Infrastructure logging, access controls, change management evidence | Internal policy sign-off, employee training records |
| HIPAA | Healthcare, medical practices, business associates | Encrypted storage/transit, BAA-covered hosting, access logging | Workforce training, breach notification decisions |
| GDPR | Any org processing EU resident data | Data residency configuration, encryption, deletion tooling | Legal basis for processing, DPA agreements |
| ISO 27001 | Enterprises, government contractors, vendors | Technical control implementation, monitoring, incident response | ISMS ownership, management review, internal audit |
| NIST CSF | Government agencies, critical infrastructure, contractors | Identify/Protect/Detect technical controls, backup and recovery | Governance function, risk acceptance decisions |
| PCI DSS | Any org storing, processing, or transmitting card data | Network segmentation, encrypted cardholder data environments | Merchant-level self-assessment, PCI SAQ submission |