ControlFrame tracks each framework by issuing authority, version, source provenance, catalog availability, and product standing. Where catalog text is licensed or public, candidate mappings are validated by a named reviewer and released only after the framework module’s required activation evidence is approved.
A source-backed learning instrument
Explore one real release from issuing source to normalized catalog, retained assessment context, and named human acceptance. Every station carries its own status; the path never fills a missing fact with a claim.
Open the Catalog ObservatoryRelease 5.2.0
The pathway that lets a web broker or issuer run the whole ACA enrollment experience on its own site instead of handing the consumer off to HealthCare.gov.
CMS's NIST-aligned security and privacy framework for ACA administering entities and applicable partner entities. Volume II supplies tailored control baselines and system security and privacy plan templates; applicability depends on entity type, law, regulation, or contract.
A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.
The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.
What a covered entity or business associate must tell individuals, the media, and HHS after a breach of unsecured protected health information, and how fast.
The federal rule governing permitted uses and disclosures of protected health information, minimum-necessary practices, notices, and individual privacy rights for covered entities and business associates.
The federal breach-notification rule for vendors of personal health records and related entities that are not covered by HIPAA, including applicable health apps and connected services.
HHS's voluntary healthcare-specific priorities for high-impact cybersecurity practices. The goals are guidance for improving sector resilience, not a regulation or certification.
HICP 2023 is voluntary healthcare-sector guidance on common cyber threats, recommended practices, and patient-safety-oriented resilience for organizations of different sizes.
CMS's minimum security and privacy control baseline for CMS information systems and CMS contractors. It is distinct from the Marketplace-focused ARC-AMPE baseline.
NIST's federal security and privacy control catalog, used directly or tailored by programs such as FedRAMP and CMS ARC-AMPE. CMMC Level 2 instead uses NIST SP 800-171 requirements.
The outcome-based vocabulary boards use to talk about cyber risk. Not certifiable — it organizes a program rather than testing one.
The international certifiable standard for an information security management system. Amendment 1:2024 added climate-change considerations to clauses 4.1 and 4.2. The 2013-edition certificate-transition deadline was 2025-10-31; no legitimate 2013-certified organization remains.
The first certifiable management system standard for AI — the ISO 27001 shape applied to how an organization builds and operates AI systems.
The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31.
The legacy FedRAMP certification path built on tailored NIST SP 800-53 Rev. 5 baselines and independent assessment, providing reusable security assurance for federal agency authorization decisions.
The DoD program that applies contract-specified safeguards and assessment requirements to contractor systems processing Federal Contract Information or Controlled Unclassified Information. The required level and assessment path may involve self-assessment, a C3PAO, or DIBCAC.
The EU's baseline for processing personal data — lawful basis, data-subject rights, controller and processor duties, and cross-border transfers.
The UK's post-Brexit data protection regime, materially reshaped by the Data (Use and Access) Act 2025 — new recognised legitimate interests, narrower automated-decision protections, and a pausable DSAR clock. The core amending provisions were brought into force by the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), effective 2026-02-05.
New York's cybersecurity regulation for banks, insurers, and other DFS-licensed entities — with a named CISO, board reporting, and 72-hour incident notice.
California's consumer privacy regime and the state laws that followed it. The 2026 CPPA regulations add automated decision-making rules, mandatory risk assessments, and certified cybersecurity audits.
The EU directive establishing a cybersecurity baseline for essential and important entities across 18 critical sectors, with management accountability and incident reporting. Operational obligations depend on each Member State's transposing law.
The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.
The EU's risk-tiered regime for AI systems — prohibited practices, high-risk obligations, general-purpose model duties, and transparency requirements.
The mandatory, auditable cybersecurity standards for the North American bulk electric system. NERC versions each CIP standard separately — there is no framework-wide version number.
SOX requires management and auditor assessment of internal control over financial reporting but does not prescribe one IT-control catalog. COBIT 2019 is licensed governance guidance often used to design and map IT general controls; neither this record nor COBIT is a SOX certification.
NIST's machine-readable format for control catalogs, baselines, system security plans, and assessment results. An interchange layer, not a regime you comply with.
FedRAMP's outcome-focused certification approach, centered on continuously maintained certification data, Key Security Indicators, and packages that remain human-readable and are machine-readable where required.
NIST's current recommended security requirements for Controlled Unclassified Information in non-federal systems. Contractual applicability is agreement-specific; CMMC Phase I continues to use Rev. 2 rather than automatically inheriting Rev. 3.
The FBI's security requirements for any agency or vendor that touches criminal justice information — the gate for public-safety software.
A prioritized, prescriptive set of defensive actions organized into three implementation groups — the practical starting list when a team has no framework yet.
The certifiable privacy information management system. The 2025 second edition made it standalone — an organization no longer needs a certified ISMS first.
NIST's voluntary, cross-sector reference for governing AI risk, structured as Govern, Map, Measure, and Manage. NIST AI 600-1 is a companion profile for generative AI, not a replacement version or certification.
Colorado's AI law, rewritten. SB 26-189 repealed and reenacted the 2024 statute, dropping the high-risk-AI regime for narrower notice and disclosure duties on automated decision-making technology used in consequential decisions.
Texas's AI law, narrowed before passage to intent-based prohibitions plus government-use rules, with a regulatory sandbox and AG enforcement.
Security duties attached to the product rather than the company — secure by design, a declared support period, an SBOM, and vulnerability reporting for anything with digital elements sold in the EU.
The secure software development practices federal software attestations are written against — the reference behind most supply-chain questionnaires.
The FTC's mandatory security program for non-banking financial institutions — encryption, MFA, penetration testing, and breach reporting for events over 500 customers.
What a public company must tell investors: a material cybersecurity incident on Form 8-K Item 1.05 within four business days, and its risk-management and board oversight annually under Reg S-K Item 106.
The report a service organization gives its customers' financial auditors, covering controls relevant to those customers' financial reporting. SSAE No. 23 layers quality-management alignment on top of the same AT-C 320 attestation standard, for engagements beginning on or after 2025-12-15.
Confidentiality rules for substance use disorder treatment records, now aligned with HIPAA on consent, notice, and enforcement.
The Cloud Security Alliance's cloud-control framework and companion assessment questionnaire for cloud providers and customers. CSA publishes 207 CCM v4.1 controls across 17 domains and 283 CAIQ questions; tracking them does not claim STAR registration, certification, or attestation.
NIST's voluntary framework for managing privacy risk through enterprise risk management. It is guidance, not a regulation or certification.
Cloud-specific information security guidance for both cloud customers and providers, extending ISO/IEC 27002 with shared-responsibility and cloud-control guidance. It is guidance, not a standalone certification or a claim about ControlFrame's cloud environment.
Privacy guidance for public-cloud providers acting as processors of personally identifiable information. It complements ISO/IEC 27001 and 27002; it is not a regulation, standalone certification, or claim that ControlFrame is certified.
International guidance for repeatable AI-system impact assessments across the system lifecycle. It complements ISO/IEC 42001, ISO/IEC 23894, and applicable AI laws; it is not an AI certification by itself.
The certifiable business continuity management system standard for preparing for, responding to, and recovering from disruption. Tracking it does not claim that ControlFrame or any customer holds ISO 22301 certification.
The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.
The professional standards for governing, managing, and performing internal audit. They assess the quality and conformance of an internal audit function; they are not criteria for certifying the audited company or its control environment.
The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.
The living technology-supervision reference used by US financial institution examiners, with current booklets, work programs, laws, and guidance. It is supervisory guidance, not a certification; the separate FFIEC Cybersecurity Assessment Tool was retired in 2025.
Generally accepted government auditing standards for financial audits, attestation engagements, reviews, and performance audits. They govern auditor and audit-organization quality; they do not certify the entity being audited.
The federal internal-control standard for designing, implementing, operating, and evaluating controls over operations, reporting, and compliance. It supplies auditable criteria for federal entities; it is not an organizational certification.
The federal audit methodology for assessing the design, implementation, and operating effectiveness of information-system controls under generally accepted government auditing standards. It is audit guidance, not an agency authorization or certification.
Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default.
A standardized assessment, authorization, and continuous-monitoring program for cloud services used by state and local governments, built on NIST SP 800-53 Rev. 5. Core, Ready, and Authorized are service-offering statuses—not company-wide certifications. StateRAMP rebranded to GovRAMP on 2025-02-14; StateRAMP, Inc. remains the legal entity operating under the GovRAMP name.
International guidance for integrating AI-specific risk management into organizations that develop, provide, deploy, or use AI systems. It complements ISO/IEC 42001 and is guidance, not a standalone certification.
The Cloud Security Alliance's vendor-neutral control framework for cloud-based AI systems, with implementation and auditing guidance plus the companion AI-CAIQ. It is a control catalog, not by itself a certification or STAR for AI designation.
The Cloud Security Alliance's cloud-assurance program and public registry. Level 1 is a CCM/CAIQ self-assessment; Level 2 is a third-party certification or attestation path. Tracking STAR does not place ControlFrame or any customer on the registry.
A quarterly updated standard and certification program for AI agents covering data and privacy, security, safety, reliability, accountability, and societal risk. Only AIUC can issue its certificate; registry inclusion makes no certification claim.
OWASP's current community-driven guide to the most critical security risks for applications powered by large language models. It is security guidance, not a compliance certification or organizational assurance report.
OWASP's peer-reviewed risk framework for autonomous and agentic AI applications, including systems that plan, use tools, hold memory, or coordinate multi-step workflows. It is guidance, not a certification.
The UK government-backed certification scheme for five foundational technical controls. Cyber Essentials is questionnaire-based; Cyber Essentials Plus adds independent technical verification. Tracking the requirements does not claim either certificate.
The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.
The ENX-governed assessment and exchange mechanism for automotive information security, based on the VDA Information Security Assessment catalog. A TISAX label is scope- and site-specific; it is not an ISO certificate or a company-wide platform claim.
Australia's cross-industry prudential standard for operational risk, continuity of critical operations, and material service-provider risk at APRA-regulated entities. It is a binding supervisory standard, not a certification.
Texas's risk and authorization management program for cloud services used by state agencies and public higher education. Level 1, Level 2, and Provisional are service-offering certifications—not company-wide certifications.
The US public-company regime for management assessment and, where applicable, independent audit of internal control over financial reporting. SOX does not prescribe one universal IT-control catalog, and registry tracking is not an audit opinion.
The controls catalog underlying ISO/IEC 27001 Annex A — a genuinely separate, currently published standard, not a duplicate of 27001. Buyers who ask for '27001 evidence' routinely cite 27002 control numbers.
The PCI Software Security Framework standard for payment software design and development, replacing the retired PA-DSS lineage. Part of the family beyond bare PCI DSS that a payments-processing SaaS enterprise is routinely asked about.
PCI SSC's standard for validated point-to-point encryption solutions that can reduce a merchant's PCI DSS scope. Part of the payments family beyond bare PCI DSS.
PCI SSC's security requirements for 3-D Secure environments (issuer/ACS, 3DS Server, and DS components) that support cardholder authentication.
PCI SSC's requirements for the secure management, processing, and transmission of personal identification number (PIN) data during payment transactions.
PCI SSC's physical- and logical-security requirements for card production and provisioning facilities (two companion documents under one program).
PCI SSC's standard for accepting PINs on commercial off-the-shelf mobile devices via a software-based PIN-entry application. In its formal sunset window now, with MPoC as the designated successor.
PCI SSC's standard for accepting contactless card payments on a commercial off-the-shelf mobile device without a separate secure card reader. In its formal sunset window now, with MPoC as the designated successor.
PCI SSC's consolidated standard for accepting PIN and contactless payments on commercial off-the-shelf mobile devices, absorbing the sunsetting SPoC and CPoC standards into one framework.
A model law for insurance-sector information security programs, incident response, and breach notification, adopted individually by roughly 25-28 US states as of 2026. It becomes enforceable law only where a state has enacted its own version — the requirements can vary state to state.
Texas's comprehensive consumer-privacy statute, pulled out of the generic state-privacy bundle because of its own enforcement record — the Texas AG has reached the two largest single-state privacy settlements in US history — and because TRAIGA now amends it with AI-specific processor duties.
The first US law protecting consumer health data that falls outside HIPAA, with a private right of action — an increasingly distinct healthcare-SaaS ask, separate from HIPAA itself.
The IRS's safeguard requirements for any agency, contractor, or state/local entity that receives federal tax information — relevant to any government contractor or CMS-adjacent SaaS vendor handling federal tax data.
The Federal Information Security Modernization Act of 2014 — the statutory authority a federal RFP names, implemented operationally through NIST SP 800-53 and the NIST Cybersecurity Framework, both already tracked as their own registry entries.
AICPA's board- and enterprise-risk-oriented cybersecurity examination, distinct from SOC 2 — a description of an entity's cybersecurity risk-management program plus an opinion on its effectiveness, rather than a controls report for a specific service.
A missing framework enters governed intake: confirm the authority and catalog licensing, validate parsed controls and candidate mappings, then release the module only after its product standing and activation evidence are approved.
Request a framework review| Module | Standing | Registry status | Control units | Open |
|---|---|---|---|---|
CMS Enhanced Direct Enrollmentrepository-verified reference Year 9 (PY 2026–PY 2027) · CMS — Direct Enrollment Partners | Implemented 9 evidence lanes | Beta · catalog on disk | 1,155ingested | Open module |
ARC-AMPE v1.02 · CMS — Direct Enrollment Entity Resources | Onboardable 10 evidence lanes | Beta · catalog on disk | 308ingested | Open module |
HITRUST CSF v11.8.0 · HITRUST Alliance | Acquisition required | Roadmap · modelled | Control count not on record | Open module |
SOC 2 2017 TSC (revised points of focus, 2022) · AICPA — Trust Services Criteria (TSP section 100) | Implemented 9 evidence lanes | Beta · catalog on disk | 33ingested | Open module |
HIPAA Security Rule 45 CFR Part 164 Subparts A and C · HHS Office for Civil Rights | Onboardable 5 evidence lanes | Beta · catalog on disk | 65ingested | Open module |
NIST Cybersecurity Framework 2.0 · NIST Cybersecurity Framework | Acquisition required | Roadmap · modelled | Control count not on record | Open module |
ISO/IEC 27001 2022 (Amd 1:2024) · ISO/IEC 27001:2022 | Onboardable 5 evidence lanes | Roadmap · modelled | Control count not on record | Open module |
ISO/IEC 42001 2023 · ISO/IEC 42001:2023 | Acquisition required | Roadmap · modelled | Control count not on record | Open module |
PCI DSS v4.0.1 · PCI Security Standards Council | Onboardable 12 evidence lanes | Beta · catalog on disk | 250ingested | Open module |
FedRAMP (Rev. 5 baselines) Rev. 5 · FedRAMP | Acquisition required | Roadmap · modelled | Control count not on record | Open module |
Control units are the regime’s native units and carry their basis on hover — ingested means a control set is on disk or in a blueprint; published means the authority states the figure and we have not ingested the text. Evidence state is a tenant fact: it is shown inside the workspace against the tenant’s own catalog, never on this public page. Registry status follows the registry’s own contract: Beta — Parsed catalog: a source-pinned control or requirement catalog for this regime exists in the repo. `catalogPath` is non-null and `controlCount` is real. This does not mean tenant workflows are activated or that an assurance outcome has been earned. Roadmap — Modeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested. Planned — Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
No tenant-authored frameworks in this session. Bring a control catalog — a CSV export or an OSCAL JSON file — and it joins the library above without a release. A PCI DSS v4.0.1 excerpt and an explicitly archived NIST SP 800-53 Rev. 5 Release 5.1.1 parser fixture are loadable from the import desk; the source-pinned Release 5.2.0 catalog is available in the public Observatory, not as a tenant onboarding template.
| Framework | Control reference | Control title | Review standing |
|---|---|---|---|
| CMS EDE | Y9 · UI-3.2 | Consumer consent flow and retained confirmation | Native · accepted |
| CMS EDE | Y5 · AUD-1.1 | Enrollment transaction audit record | Native · accepted |
| NIST CSF 2.0 | DE.CM-09 | Computing activity and technology usage monitoring | Candidate · reviewer confirmation pending |
| NIST CSF 2.0 | PR.DS-01 | Confidentiality, integrity, and availability of data at rest | Candidate · reviewer confirmation pending |
| HIPAA | 164.312(b) | Audit controls | Candidate · reviewer confirmation pending |
| HIPAA | 164.312(c)(1) | Integrity | Candidate · reviewer confirmation pending |
Accepted once under the native regime; proposed, not presumed, under the next one. A named reviewer accepts or rejects every candidate mapping before it counts. Inspect the control crosswalk
CMS retired MARS-E 2.2 and replaced it with ARC-AMPE — a different NIST catalog under the same program name. Two control families in the new baseline have no Rev 4 ancestor at all, so no legacy artifact can answer them. The diff is derived from the two catalogs rather than announced; what it costs an evidence program is projected on the change page, in a labeled synthetic-reference mode or against a tenant’s own catalogs.