Cybersecurity frameworks are voluntary best-practice guidance — not laws. But they define the industry standard for "reasonable" security and are increasingly required by contract, regulation, or as a condition of doing business. Here is what the major frameworks actually are, what they require, and how the SCF CCF™ supersedes them all.
These are the frameworks most commonly required by contracts, mentioned in regulatory guidance, and used by security teams as program baselines. All are mapped in the SCF CCF™.
NIST Cybersecurity Framework, Version 2.0 (2024)
Security and Privacy Controls for Federal Systems
International Standard for Information Security Management
Center for Internet Security Critical Security Controls
Service Organization Control 2 — Trust Services Criteria
Payment Card Industry Data Security Standard
Health Information Trust Alliance Common Security Framework
How the most common cybersecurity frameworks compare across key features — cost, certifiability, privacy coverage, GRC breadth, and SCF mapping status.
Download the SCF CCF™ and access all 1,400+ controls with full crosswalk mappings to every framework on this page — and 88 more.