The Most Widely Used Cybersecurity Frameworks
These are the frameworks most commonly required by contracts, mentioned in regulatory guidance, and used by security teams as program baselines. All are mapped in the SCF CCF™.
NIST CSF 2.0
NIST Cybersecurity Framework, Version 2.0 (2024)
NIST SP 800-53
Security and Privacy Controls for Federal Systems
ISO 27001 / 27002
International Standard for Information Security Management
CIS Controls v8
Center for Internet Security Critical Security Controls
SOC 2
Service Organization Control 2: Trust Services Criteria
PCI DSS v4.0
Payment Card Industry Data Security Standard
HITRUST CSF
Health Information Trust Alliance Common Security Framework
Major Frameworks: Feature Comparison
How the most common cybersecurity frameworks compare across key features: cost, certifiability, privacy coverage, GRC breadth, and SCF mapping status.
.png)
%20(white).png)