Cybersecurity frameworks compared
| Framework | Publisher | Type | Certification or report? |
|---|---|---|---|
| NIST CSF 2.0 | NIST | Voluntary framework of outcomes | No formal certification |
| NIST SP 800-53 Rev 5 | NIST | Security and privacy control catalog | No certification; used for US federal system authorizations |
| NIST SP 800-171 | NIST | Requirements for protecting Controlled Unclassified Information (CUI) | No certification by NIST; the basis for CMMC Level 2 assessments of defense contractors |
| ISO/IEC 27001:2022 | ISO and IEC | Information security management system standard | Certification by an accredited certification body |
| SOC 2 | AICPA | Trust Services Criteria for service organizations | Attestation report issued by a CPA firm |
| PCI DSS | PCI Security Standards Council | Payment card data security standard | Report on Compliance or Self-Assessment Questionnaire |
| CIS Controls | Center for Internet Security | Prioritized set of safeguards | No formal certification |
| HITRUST CSF | HITRUST | Certifiable framework | HITRUST certification |
The Most Widely Used Cybersecurity Frameworks
These are the frameworks most commonly required by contracts, mentioned in regulatory guidance, and used by security teams as program baselines. All are mapped in the SCF's Common Controls Framework®.
NIST CSF 2.0
NIST Cybersecurity Framework, Version 2.0 (2024)
NIST SP 800-53
Security and Privacy Controls for Federal Systems
ISO 27001 / 27002
International Standard for Information Security Management
CIS Controls v8
Center for Internet Security Critical Security Controls
SOC 2
Service Organization Control 2: Trust Services Criteria
PCI DSS v4.0
Payment Card Industry Data Security Standard
HITRUST CSF
Health Information Trust Alliance Common Security Framework
Major Frameworks: Feature Comparison
How the most common cybersecurity frameworks compare across key features: cost, certifiability, privacy coverage, GRC breadth, and SCF mapping status.
.png)
%20(white).png)