Secure Controls Framework
Download The SCF

Included Laws, Regulations & Frameworks (LRF)

The SCF maps to 200+ unique laws, regulations, and frameworks across five geographic categories: General, USA, EMEA, APAC, and Americas. When you implement SCF controls, you satisfy requirements across all mapped LRF simultaneously through Set Theory Relationship Mapping (STRM).

200+
Unique LRF Mapped
5
Geographic Regions
2026.1
Current SCF Version
how lrf coverage works

One Control Set. Hundreds of Security, Compliance & Resilience Mappings.

The SCF Authoritative Sources tab in the downloadable spreadsheet contains every mapped LRF. Each SCF control includes columns showing which specific LRF requirements that control satisfies. These Authoritative Sources are categorized by:

  • General Frameworks (univeral and not country/geo-specific)
  • USA - United States of America
  • EMEA - Europe, Middle East & Africa
  • APAC - Asia Pacific
  • Americas - Non-USA North, Central & South America

To understand the coverage for these Laws, Regulations and Frameworks (LRF), please read through how the SCF leverages Set Theory Relationship Mapping (STRM) according to NIST IR 8477 to demonstrate how SCF controls address targeted LRF requirements. The 2026.1 version of the SCF contains coverage for 250 unique LRF:

The practical result: if your organization needs to comply with GDPR, HIPAA, and NIST CSF 2.0 simultaneously, you implement a single tailored set of SCF controls rather than three separate compliance programs. Each control tells you exactly which requirements from each framework it addresses.

Browse by Region

Included Laws, Regulations & Frameworks

The SCF maps to 200+ cybersecurity and data privacy laws, regulations, and frameworks worldwide. Filter by region or search to find what you need.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
General
✓ STRM
AICPA
American Institute of Certified Public Accountants (AICPA) Privacy Management Framework (PMF) (2020)
View authoritative source (external link) ➔
General
✓ STRM
AICPA
American Institute of Certified Public Accountants (AICPA) Trust Services Criteria (2017)
View authoritative source (external link) ➔
Americas
✓ STRM
Argentina
Argentina - Protection of Personal Data (2018)
View authoritative source (external link) ➔
General
✓ STRM
APEC
Asia - Pacific Economic Cooperation (APEC) Privacy Framework (2015)
View authoritative source (external link) ➔
APAC
✓ STRM
Australia
Australia - Code of Practice - Securing the Internet of Things for Consumers (2020)
View authoritative source (external link) ➔
APAC
✓ STRM
Australia
Australia - Essential Eight maturity model and ISM mapping (2024)
View authoritative source (external link) ➔
APAC
✓ STRM
Australia
Australia - Information Security Manual (ISM) (March 2026)
View authoritative source (external link) ➔
APAC
✓ STRM
Australia
Australia - Privacy Principles (2026)
View authoritative source (external link) ➔
APAC
✓ STRM
Australia
Australia - Prudential Standard CPS 230 - Operational Risk Management (2023)
View authoritative source (external link) ➔
APAC
✓ STRM
Australia
Australia - Prudential Standard CPS 234 Information Security (2019)
View authoritative source (external link) ➔
EMEA
✓ STRM
Austria
Austria - Data Protection Act (2018)
View authoritative source (external link) ➔
Americas
✓ STRM
Bahamas
Bahamas - Data Protection Act (DPA) (2003)
View authoritative source (external link) ➔
EMEA
✓ STRM
Belgium
Belgium - Act of 30 July 2018
View authoritative source (external link) ➔
Americas
✓ STRM
Bermuda
Bermuda - Bermuda Monetary Authority (BMA) Insurance Sector Operational Cyber Risk Management Code of Conduct (2020)
View authoritative source (external link) ➔
Americas
✓ STRM
Brazil
Brazil - General Data Protection Law (LGPD) (2018)
View authoritative source (external link) ➔
General
✓ STRM
BSI
Bundesamt für Sicherheit in der Informationstechnik (BSI) - Standard 200-1 (v1.0)
View authoritative source (external link) ➔
Americas
✓ STRM
Canada
Canada - Office of the Superintendent of Financial Institutions Canada (OSFI) - Cyber Security Self-Assessment Guidance
View authoritative source (external link) ➔
Americas
✓ STRM
Canada
Canada - OSFI B-13 (2022)
View authoritative source (external link) ➔
Americas
✓ STRM
Canada
Canada - OSFI Cyber Security Self-Assessment Guidance
View authoritative source (external link) ➔
Americas
✓ STRM
Canada
Canada - Personal Information Protection and Electronic Documents Act (PIPEDA) (2000)
View authoritative source (external link) ➔
Americas
✓ STRM
Canada
Canada - Protecting controlled information in non-Government of Canada systems and organizations (ITSP.10.171) (2025)
View authoritative source (external link) ➔
General
✓ STRM
CIS
Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1
View authoritative source (external link) ➔
General
✓ STRM
CIS
Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1-IG1
View authoritative source (external link) ➔
General
✓ STRM
CIS
Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1-IG2
View authoritative source (external link) ➔

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
General
✓ STRM
OWASP
Open Worldwide Application Security Project (OWASP) Top 10 (2025)
View authoritative source (external link)
General
✓ STRM
OECD
Organisation for Economic Co-operation and Development (EOCD) Privacy Principles
View authoritative source (external link)
General
✓ STRM
PCI SSC
Payment Card Industry Data Security Standard (PCI DSS) v4.01
View authoritative source (external link)
General
✓ STRM
PCI SSC
Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self-Assessment Questionnaire (SAQ) A
View authoritative source (external link)
General
✓ STRM
PCI SSC
Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self-Assessment Questionnaire (SAQ) A-EP
View authoritative source (external link)
General
✓ STRM
PCI SSC
Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self-Assessment Questionnaire (SAQ) B
View authoritative source (external link)
General
✓ STRM
PCI SSC
Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self-Assessment Questionnaire (SAQ) B-IP
View authoritative source (external link)
General
✓ STRM
PCI SSC
Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self-Assessment Questionnaire (SAQ) C
View authoritative source (external link)
General
✓ STRM
PCI SSC
Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self-Assessment Questionnaire (SAQ) C-VT
View authoritative source (external link)
General
✓ STRM
PCI SSC
Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self-Assessment Questionnaire (SAQ) D Merchant
View authoritative source (external link)
General
✓ STRM
PCI SSC
Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self-Assessment Questionnaire (SAQ) D Service Provider
View authoritative source (external link)
General
✓ STRM
PCI SSC
Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 - Self-Assessment Questionnaire (SAQ) P2PE
View authoritative source (external link)
General
✓ STRM
SCF
Secure Controls Framework (SCF) Data Privacy Management Principles (2025)
View authoritative source (external link)
General
Shared Assessments
Shared Assessments Standard Information Gathering (SIG) Questionnaire 2025
View authoritative source (external link)
General
✓ STRM
SWIFT
Society for Worldwide Interbank Financial Telecommunication Customer Security Controls Framework 2025
View authoritative source (external link)
General
✓ STRM
SPARTA
Space Attack Research & Tactic Analysis (SPARTA) Countermeasures
View authoritative source (external link)
General
✓ STRM
TISAX
Trusted Information Security Assessment Exchange (TISAX) 6.0.3
View authoritative source (external link)
General
✓ STRM
UL
UL 2900-1 - Software Cybersecurity for Network-Connectable Products, Part 1: General Requirements (2017)
View authoritative source (external link)
General
✓ STRM
UL
UL 2900-2-2 Ed. 1-2016 - Outline of Investigation for Software Cybersecurity for Network-Connectable Products, Part 2-2: Particular Requirements for Industrial Control Systems
View authoritative source (external link)
General
✓ STRM
United Nations
United Nations - Regulation No. 155 - Cyber security and cyber security management system (2021)
View authoritative source (external link)
General
✓ STRM
United Nations
United Nations - United Nations Economic Commission for Europe (UNECE) Working Party 29 (2020)
View authoritative source (external link)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
USA
✓ STRM
Federal
US - 33 CFR Part 101 Subpart F (up to date as of 4-17-2026)
View authoritative source (external link)
USA
✓ STRM
State
US - Alaska Personal Information Protection Act (PIPA) (2009)
View authoritative source (external link)
USA
✓ STRM
State
US - California Consumer Privacy Act (CCPA) (January 2026) - amended California Privacy Rights Act (CPRA)
View authoritative source (external link)
USA
✓ STRM
State
US - California SB1386 (2002)
View authoritative source (external link)
USA
✓ STRM
State
US - California SB327 (2018)
View authoritative source (external link)
USA
✓ STRM
Federal
US - Centers for Medicare & Medicaid Services MARS-E Document Suite, Version 2.0
View authoritative source (external link)
USA
✓ STRM
Federal
US - Children's Online Privacy Protection Act (COPPA) (2024)
View authoritative source (external link)
USA
✓ STRM
State
US - Colorado Privacy Act (2021)
View authoritative source (external link)
USA
✓ STRM
Federal
US - Cybersecurity & Infrastructure Security Agency (CISA) Cross-Sector Cybersecurity Performance Goals 2.0
View authoritative source (external link)
USA
✓ STRM
Federal
US - Cybersecurity & Infrastructure Security Agency (CISA) Secure Software Development Attestation Form (SSDAF) (2024)
View authoritative source (external link)
USA
✓ STRM
Federal
US - Cybersecurity & Infrastructure Security Agency (CISA) Trusted Internet Connections 3.0 Security Capabilities Catalog
View authoritative source (external link)
USA
✓ STRM
Federal
US - Data Privacy Framework (2023)
View authoritative source (external link)
USA
✓ STRM
Federal
US - Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012
View authoritative source (external link)
USA
✓ STRM
Federal
US - Department of Energy (DOE) - Cybersecurity Capability Maturity Model version 2.1
View authoritative source (external link)
USA
✓ STRM
Federal
US - Department of Justice - Criminal Justice Information Services (CJIS) Security Policy v6.0
View authoritative source (external link)
USA
✓ STRM
Federal
US - Department of War (DoW) - Computer Emergency Response Team (CERT) Resilience Management Model (RMM) Version 1.2
View authoritative source (external link)
USA
✓ STRM
Federal
US - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 1
View authoritative source (external link)
USA
✓ STRM
Federal
US - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 1 Assessment Objectives
View authoritative source (external link)
USA
✓ STRM
Federal
US Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 2
View authoritative source (external link)
USA
✓ STRM
Federal
US Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 3
View authoritative source (external link)
USA
✓ STRM
Federal
US - Department of War (DoW) - Zero Trust Execution Roadmap v1.1
View authoritative source (external link)
USA
✓ STRM
Federal
US - Department of War (DoW) - Zero Trust Reference Architecture v2
View authoritative source (external link)
USA
✓ STRM
Federal
US - Executive Order (EO) 14028 - Improving the Nation's Cybersecurity
View authoritative source (external link)
USA
✓ STRM
Federal
US - Fair & Accurate Credit Transactions Act (FACTA) & Fair Credit Reporting Act (FCRA) (2023)
View authoritative source (external link)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
EMEA
✓ STRM
Qatar
Qatar - Personal Data Privacy Protection Law (PDPPL) (2020)
View authoritative source (external link)
EMEA
✓ STRM
Russia
Russia - Federal Law No. 152-FZ (2025)
View authoritative source (external link)
EMEA
✓ STRM
Saudi Arabia
Saudi Arabia - Critical Systems Cybersecurity Controls (CSCC – 1: 2019)
View authoritative source (external link)
EMEA
✓ STRM
Saudi Arabia
Saudi Arabia - Cybersecurity Guidelines for Internet of Things (CGIoT - 1:2024)
View authoritative source (external link)
EMEA
✓ STRM
Saudi Arabia
Saudi Arabia - Essential Cybersecurity Controls (ECC – 1 : 2018)
View authoritative source (external link)
EMEA
✓ STRM
Saudi Arabia
Saudi Arabia - Operational Technology Cybersecurity Controls (OTCC-1: 2022)
View authoritative source (external link)
EMEA
✓ STRM
Saudi Arabia
Saudi Arabia - Personal Data Protection Law (PDPL) (2023)
View authoritative source (external link)
EMEA
✓ STRM
Saudi Arabia
Saudi Arabia - SACS-002 Third Party Cybersecurity Standard (2022)
View authoritative source (external link)
EMEA
✓ STRM
Saudi Arabia
Saudi Arabia - Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework Version 1.0 (2017)
View authoritative source (external link)
EMEA
✓ STRM
Serbia
Serbia - Act of 9 November 2018 on Personal Data Protection (Official Gazette No. 87/18)
View authoritative source (external link)
EMEA
✓ STRM
South Africa
South Africa - Protection of Personal Information Act (POPIA) (2013)
View authoritative source (external link)
EMEA
✓ STRM
Spain
Spain - ICT Security Guide CCN-STIC 825 (2026)
View authoritative source (external link)
EMEA
✓ STRM
Spain
Spain - Royal Decree 311/2022
View authoritative source (external link)
EMEA
✓ STRM
Switzerland
Switzerland - Federal Act on Data Protection (FADP) (2025)
View authoritative source (external link)
EMEA
✓ STRM
Turkey
Turkey - Law on the Protection of Personal Data (LPPD) (2016)
View authoritative source (external link)
EMEA
✓ STRM
UAE
UAE - National Information Assurance Framework (NIAF) (2023)
View authoritative source (external link)
EMEA
✓ STRM
United Kingdom
UK - Cyber Assessment Framework (CAF) v4.0
View authoritative source (external link)
EMEA
✓ STRM
United Kingdom
UK - Cyber Assessment Framework for Aviation Guidance (CAP1850) (2020)
View authoritative source (external link)
EMEA
✓ STRM
United Kingdom
UK - Cyber Essentials: Requirements for IT Infrastructure v3.3
View authoritative source (external link)
EMEA
✓ STRM
United Kingdom
UK - Data Protection Act (DPA) (2018)
View authoritative source (external link)
EMEA
✓ STRM
United Kingdom
UK - Ministry of Defence Standard (DEFSTAN) 05-138 (2024)
View authoritative source (external link)
EMEA
✓ STRM
United Kingdom
UK - Ministry of Defence Standard (DEFSTAN) 05-138 (2024) - L0
View authoritative source (external link)
EMEA
✓ STRM
United Kingdom
UK - Ministry of Defence Standard (DEFSTAN) 05-138 (2024) - L1
View authoritative source (external link)
EMEA
✓ STRM
United Kingdom
UK - Ministry of Defence Standard (DEFSTAN) 05-138 (2024) - L2
View authoritative source (external link)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
APAC
✓ STRM
Australia
Australia - Code of Practice - Securing the Internet of Things for Consumers (2020)
View authoritative source (external link)
APAC
✓ STRM
Australia
Australia - Essential Eight maturity model and ISM mapping (2024)
View authoritative source (external link)
APAC
✓ STRM
Australia
Australia - Information Security Manual (ISM) (March 2026)
View authoritative source (external link)
APAC
✓ STRM
Australia
Australia - Privacy Principles (2026)
View authoritative source (external link)
APAC
✓ STRM
Australia
Australia - Prudential Standard CPS 230 - Operational Risk Management (2023)
View authoritative source (external link)
APAC
✓ STRM
Australia
Australia - Prudential Standard CPS 234 Information Security (2019)
View authoritative source (external link)
APAC
✓ STRM
China
China - Cybersecurity Law of the People's Republic of China (2017)
View authoritative source (external link)
APAC
✓ STRM
China
China - Data Security Law of the People's Republic of China (2021)
View authoritative source (external link)
APAC
✓ STRM
China
China - Decision on Strengthening Network Information Protection (2012)
View authoritative source (external link)
APAC
✓ STRM
China
China - Personal Information Protection Law of the People's Republic of China (2021)
View authoritative source (external link)
APAC
✓ STRM
Hong Kong
Hong Kong - Personal Data Ordinance (2022)
View authoritative source (external link)
APAC
✓ STRM
India
India Digital Personal Data Protection Act (2023)
View authoritative source (external link)
APAC
✓ STRM
India
India - Information Technology Rules (Privacy Rules) (2011)
View authoritative source (external link)
APAC
✓ STRM
India
India - SEBI Cybersecurity and Cyber Resilience Framework (2024)
View authoritative source (external link)
APAC
✓ STRM
Japan
Japan - Act on the Protection of Personal Information (2020)
View authoritative source (external link)
APAC
✓ STRM
Japan
Japan - Information System Security Management and Assessment Program (ISMAP)
View authoritative source (external link)
APAC
✓ STRM
Malaysia
Malaysia - Personal Data Protection Act (PDPA) (2010)
View authoritative source (external link)
APAC
✓ STRM
Malaysia
Malaysia - Risk Management in Technology (RMiT) (2025)
View authoritative source (external link)
APAC
✓ STRM
New Zealand
New Zealand - HISF MicroSmall (2023)
View authoritative source (external link)
APAC
✓ STRM
New Zealand
New Zealand - HISF MLHSP (2023)
View authoritative source (external link)
APAC
✓ STRM
New Zealand
New Zealand - HISO 10029:2024 NZ Health Information Security Framework Guidance for Suppliers
View authoritative source (external link)
APAC
✓ STRM
New Zealand
New Zealand - Information Security Manual (ISM) v3.9
View authoritative source (external link)
APAC
✓ STRM
New Zealand
New Zealand - Privacy Act (2020)
View authoritative source (external link)
APAC
✓ STRM
Philippines
Philippines - Data Privacy Act (DPA) (2012)
View authoritative source (external link)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Americas
✓ STRM
Argentina
Argentina - Protection of Personal Data (2018)
View authoritative source (external link)
Americas
✓ STRM
Bahamas
Bahamas - Data Protection Act (DPA) (2003)
View authoritative source (external link)
Americas
✓ STRM
Bermuda
Bermuda - Bermuda Monetary Authority (BMA) Insurance Sector Operational Cyber Risk Management Code of Conduct (2020)
View authoritative source (external link)
Americas
✓ STRM
Brazil
Brazil - General Data Protection Law (LGPD) (2018)
View authoritative source (external link)
Americas
✓ STRM
Canada
Canada - Office of the Superintendent of Financial Institutions Canada (OSFI) - Cyber Security Self-Assessment Guidance
View authoritative source (external link)
Americas
✓ STRM
Canada
Canada - OSFI B-13 (2022)
View authoritative source (external link)
Americas
✓ STRM
Canada
Canada - OSFI Cyber Security Self-Assessment Guidance
View authoritative source (external link)
Americas
✓ STRM
Canada
Canada - Personal Information Protection and Electronic Documents Act (PIPEDA) (2000)
View authoritative source (external link)
Americas
✓ STRM
Canada
Canada - Protecting controlled information in non-Government of Canada systems and organizations (ITSP.10.171) (2025)
View authoritative source (external link)
Americas
✓ STRM
Chile
Chile - Act 19628 - Protection of Personal Data (1999)
View authoritative source (external link)
Americas
✓ STRM
Colombia
Colombia - Law 1581 (2012)
View authoritative source (external link)
Americas
✓ STRM
Mexico
Mexico - Federal Law on Protection of Personal Data held by Private Parties (2010)
View authoritative source (external link)

No matching frameworks found. Try a different search term or filter.

Practical Application

How To Use the LRF Coverage in Your Program

Understanding which LRF are mapped to the SCF allows you to use the framework as a single source of truth for your compliance program. Here’s how practitioners apply LRF coverage in real-world programs.

01

Identify Your MCR. Determine which laws, regulations and frameworks apply to your organization. Each applicable LRF represents a Minimum Compliance Requirement (MCR) that must be satisfied.

02

Filter Controls by LRF. Use the SCF spreadsheet to filter controls by your applicable LRF. Every control mapped to that framework represents a requirement you need to address in your program.

03

Satisfy Multiple LRF Simultaneously. Because multiple LRF map to the same SCF controls, implementing a single control can satisfy requirements across several frameworks at once, dramatically reducing compliance effort.

Don’t See a Framework?

The SCF is a volunteer-maintained, open-source project. If a framework you need isn’t currently mapped, you can contribute to the project or contact the SCF team to request coverage. New LRF mappings are added with each quarterly release.