Secure Controls Framework
Download The SCF

Included Laws, Regulations & Frameworks (LRF)

The SCF maps to 200+ unique laws, regulations, and frameworks across five geographic categories: General, USA, EMEA, APAC, and Americas. When you implement SCF controls, you satisfy requirements across all mapped LRF simultaneously through Set Theory Relationship Mapping (STRM).

how lrf coverage works

One Control Set. Hundreds of Security, Compliance & Resilience Mappings.

The SCF Authoritative Sources tab in the downloadable spreadsheet contains every mapped LRF. Each SCF control includes columns showing which specific LRF requirements that control satisfies. These Authoritative Sources are categorized by:

  • General Frameworks (univeral and not country/geo-specific)
  • USA - United States of America
  • EMEA - Europe, Middle East & Africa
  • APAC - Asia Pacific
  • Americas - Non-USA North, Central & South America

To understand the coverage for these Laws, Regulations and Frameworks (LRF), please read through how the SCF leverages Set Theory Relationship Mapping (STRM) according to NIST IR 8477 to demonstrate how SCF controls address targeted LRF requirements. The 2026.1 version of the SCF contains coverage for 250 unique LRF:

The practical result: if your organization needs to comply with GDPR, HIPAA, and NIST CSF 2.0 simultaneously, you implement a single tailored set of SCF controls rather than three separate compliance programs. Each control tells you exactly which requirements from each framework it addresses.

Browse by Region

Included Laws, Regulations & Frameworks

The SCF maps to 200+ cybersecurity and data privacy laws, regulations, and frameworks worldwide. Filter by region or search to find what you need.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
CIS
General
✓ STRM
Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1-IG2
View authoritative source (external link) ➔
CIS
General
✓ STRM
Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1-IG3
View authoritative source (external link) ➔
Switzerland
EMEA
✓ STRM
CHE - FINMA Circular 2023/1 - Operational Risks and Resilience - Banks
View authoritative source (external link) ➔
Chile
Americas
✓ STRM
Chile - Act 19628 - Protection of Personal Data (1999)
View authoritative source (external link) ➔
China
APAC
✓ STRM
China - Cybersecurity Law of the People's Republic of China (2017)
View authoritative source (external link) ➔
China
APAC
✓ STRM
China - Data Security Law of the People's Republic of China (2021)
View authoritative source (external link) ➔
China
APAC
✓ STRM
China - Decision on Strengthening Network Information Protection (2012)
View authoritative source (external link) ➔
China
APAC
✓ STRM
China - Personal Information Protection Law of the People's Republic of China (2021)
View authoritative source (external link) ➔
CSA
General
✓ STRM
Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) v4.1.0
View authoritative source (external link) ➔
CSA
General
✓ STRM
Cloud Security Alliance (CSA) Internet of Things Security Controls Framework v2
View authoritative source (external link) ➔
Colombia
Americas
✓ STRM
Colombia - Law 1581 (2012)
View authoritative source (external link) ➔
Luxembourg
EMEA
✓ STRM
Commission de Surveillance du Secteur Financier (CSSF) Circular 20/750 - ICT Risk Management (2020)
View authoritative source (external link) ➔
Luxembourg
EMEA
✓ STRM
Commission de Surveillance du Secteur Financier (CSSF) Circular 22/806 (as amended by Circulars CSSF 25/883 and 26/915) - Outsourcing Arrangements (2022)
View authoritative source (external link) ➔
COSO
General
✓ STRM
Committee of Sponsoring Organizations (COSO) (2013)
View authoritative source (external link) ➔
ISACA
General
✓ STRM
Control Objectives for Information and Related Technologies (COBIT) (2019)
View authoritative source (external link) ➔
CR
General
✓ STRM
Cyber Resilience Capability Maturity Model (CR-CMM) (2026)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - Digital Operational Resilience Act (2023)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - DORA Draft RTS on ICT Risk Management Framework and on Simplified ICT Risk Management Framework (JC 2023 86)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - European Banking Authority Guidelines on ICT and Security Risk Management (2025)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - European Union Agency for Cybersecurity NIS2 Annex (2024)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - European Union Agency for Cybersecurity NIS2 Directive (EU) 2022/2555)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - European Union Artificial Intelligence Act (Regulation (EU) 2024/1689)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - European Union Cyber Resilience Act (2024)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - European Union Cyber Resilience Act - Annex I (2024)
View authoritative source (external link) ➔

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
AICPA
General
✓ STRM
American Institute of Certified Public Accountants (AICPA) Privacy Management Framework (PMF) (2020)
View authoritative source (external link) ➔
AICPA
General
✓ STRM
American Institute of Certified Public Accountants (AICPA) Trust Services Criteria (2017)
View authoritative source (external link) ➔
APEC
General
✓ STRM
Asia - Pacific Economic Cooperation (APEC) Privacy Framework (2015)
View authoritative source (external link) ➔
BSI
General
✓ STRM
Bundesamt für Sicherheit in der Informationstechnik (BSI) - Standard 200-1 (v1.0)
View authoritative source (external link) ➔
CIS
General
✓ STRM
Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1
View authoritative source (external link) ➔
CIS
General
✓ STRM
Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1-IG1
View authoritative source (external link) ➔
CIS
General
✓ STRM
Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1-IG2
View authoritative source (external link) ➔
CIS
General
✓ STRM
Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1-IG3
View authoritative source (external link) ➔
CSA
General
✓ STRM
Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) v4.1.0
View authoritative source (external link) ➔
CSA
General
✓ STRM
Cloud Security Alliance (CSA) Internet of Things Security Controls Framework v2
View authoritative source (external link) ➔
COSO
General
✓ STRM
Committee of Sponsoring Organizations (COSO) (2013)
View authoritative source (external link) ➔
ISACA
General
✓ STRM
Control Objectives for Information and Related Technologies (COBIT) (2019)
View authoritative source (external link) ➔
CR
General
✓ STRM
Cyber Resilience Capability Maturity Model (CR-CMM) (2026)
View authoritative source (external link) ➔
GovRAMP
General
✓ STRM
Government Risk and Authorization Management Program (GovRAMP)
View authoritative source (external link) ➔
GovRAMP
General
✓ STRM
Government Risk and Authorization Management Program (GovRAMP) - Core Controls
View authoritative source (external link) ➔
GovRAMP
General
✓ STRM
Government Risk and Authorization Management Program (GovRAMP) - High
View authoritative source (external link) ➔
GovRAMP
General
✓ STRM
Government Risk and Authorization Management Program (GovRAMP) - Low
View authoritative source (external link) ➔
GovRAMP
General
✓ STRM
Government Risk and Authorization Management Program (GovRAMP) - Low+
View authoritative source (external link) ➔
GovRAMP
General
✓ STRM
Government Risk and Authorization Management Program (GovRAMP) - Moderate
View authoritative source (external link) ➔
IEC
General
✓ STRM
International Electrotechnical Commission 62443-4-2 Ed. 1.0 b:2019 - Security for industrial automation and control systems - Part 4-2: Technical security requirements for IACS components
View authoritative source (external link) ➔
IEC
General
✓ STRM
International Electrotechnical Commission (IEC) 62443-2-1:2024 - Security for industrial automation and control systems - Part 2-1: Security program requirements for IACS asset owners
View authoritative source (external link) ➔
IEC
General
✓ STRM
International Electrotechnical Commission (IEC) 62443-3-3:2013 - Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels
View authoritative source (external link) ➔
IEC
General
✓ STRM
International Electrotechnical Commission (IEC) 62443-4-1:2018 - Security for industrial automation and control systems - Part 4-1: Secure product development lifecycle requirements
View authoritative source (external link) ➔
IEC
General
✓ STRM
International Electrotechnical Commission (IEC) Technical Report 60601-4-5:2021 - Medical electrical equipment - Part 4-5: Guidance and interpretation - Safety-related technical security specifications
View authoritative source (external link) ➔

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Federal
USA
✓ STRM
USA - 33 CFR Part 101 Subpart F (up to date as of 4-17-2026)
View authoritative source (external link) ➔
State
USA
✓ STRM
USA - Alaska Personal Information Protection Act (PIPA) (2009)
View authoritative source (external link) ➔
State
USA
✓ STRM
USA - California Consumer Privacy Act (CCPA) (January 2026) - amended California Privacy Rights Act (CPRA)
View authoritative source (external link) ➔
State
USA
✓ STRM
USA - California SB1386 (2002)
View authoritative source (external link) ➔
State
USA
✓ STRM
USA - California SB327 (2018)
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Centers for Medicare & Medicaid Services MARS-E Document Suite, Version 2.0
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Children's Online Privacy Protection Act (COPPA) (2024)
View authoritative source (external link) ➔
State
USA
✓ STRM
USA - Colorado Privacy Act (2021)
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Cybersecurity & Infrastructure Security Agency (CISA) Cross-Sector Cybersecurity Performance Goals 2.0
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Cybersecurity & Infrastructure Security Agency (CISA) Secure Software Development Attestation Form (SSDAF) (2024)
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Cybersecurity & Infrastructure Security Agency (CISA) Trusted Internet Connections 3.0 Security Capabilities Catalog
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Data Privacy Framework (2023)
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Department of Energy (DOE) - Cybersecurity Capability Maturity Model version 2.1
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Department of Justice - Criminal Justice Information Services (CJIS) Security Policy v6.0
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Department of War (DoW) - Computer Emergency Response Team (CERT) Resilience Management Model (RMM) Version 1.2
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 1
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 1 Assessment Objectives
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 2
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 3
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Department of War (DoW) - Zero Trust Execution Roadmap v1.1
View authoritative source (external link) ➔
Federal
USA
✓ STRM
USA - Department of War (DoW) - Zero Trust Reference Architecture v2
View authoritative source (external link) ➔
USA - Federal
USA
✓ STRM
USA - DoW Brilliant at the Basics: Top 10 IT Cybersecurity Best Practices for DIB Partners
View authoritative source (external link) ➔
USA - Federal
USA
✓ STRM
USA - DoW Brilliant at the Basics: Top 10 OT Cybersecurity Best Practices for DIB Partners
View authoritative source (external link) ➔

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Austria
EMEA
✓ STRM
Austria - Data Protection Act (2018)
View authoritative source (external link) ➔
Belgium
EMEA
✓ STRM
Belgium - Act of 30 July 2018
View authoritative source (external link) ➔
Switzerland
EMEA
✓ STRM
CHE - FINMA Circular 2023/1 - Operational Risks and Resilience - Banks
View authoritative source (external link) ➔
Luxembourg
EMEA
✓ STRM
Commission de Surveillance du Secteur Financier (CSSF) Circular 20/750 - ICT Risk Management (2020)
View authoritative source (external link) ➔
Luxembourg
EMEA
✓ STRM
Commission de Surveillance du Secteur Financier (CSSF) Circular 22/806 (as amended by Circulars CSSF 25/883 and 26/915) - Outsourcing Arrangements (2022)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - Digital Operational Resilience Act (2023)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - DORA Draft RTS on ICT Risk Management Framework and on Simplified ICT Risk Management Framework (JC 2023 86)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - European Banking Authority Guidelines on ICT and Security Risk Management (2025)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - European Union Agency for Cybersecurity NIS2 Annex (2024)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - European Union Agency for Cybersecurity NIS2 Directive (EU) 2022/2555)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - European Union Artificial Intelligence Act (Regulation (EU) 2024/1689)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - European Union Cyber Resilience Act (2024)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - European Union Cyber Resilience Act - Annex I (2024)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - European Union General Data Protection Regulation (2016)
View authoritative source (external link) ➔
EU
EMEA
✓ STRM
EU - Second Payment Services Directive (PSD2) (2015)
View authoritative source (external link) ➔
Germany
EMEA
✓ STRM
Germany - Banking Supervisory Requirements for IT (2017)
View authoritative source (external link) ➔
Germany
EMEA
✓ STRM
Germany - Cloud Computing Compliance Controls Catalogue (C5) (2026)
View authoritative source (external link) ➔
Germany
EMEA
✓ STRM
Germany - Federal Data Protection Act (2017)
View authoritative source (external link) ➔
Greece
EMEA
✓ STRM
Greece - Protection of Individuals with Regard to the Processing of Personal Data (2472/1997)
View authoritative source (external link) ➔
Hungary
EMEA
✓ STRM
Hungary - Act CXII of 2011
View authoritative source (external link) ➔
Israel
EMEA
✓ STRM
Ireland - Cybersecurity Methodology for an Organization (CMO) v2.0
View authoritative source (external link) ➔
Ireland
EMEA
✓ STRM
Ireland - Data Protection Act (DPA) (2018)
View authoritative source (external link) ➔
Israel
EMEA
✓ STRM
Israel - Protection of Privacy Law, 5741 (2025)
View authoritative source (external link) ➔
Italy
EMEA
✓ STRM
Italy - Personal Data Protection Code (2018)
View authoritative source (external link) ➔

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Australia
APAC
✓ STRM
Australia - Cloud Controls Matrix (June 2026)
View authoritative source (external link) ➔
Australia
APAC
✓ STRM
Australia - Code of Practice - Securing the Internet of Things for Consumers (2020)
View authoritative source (external link) ➔
Australia
APAC
✓ STRM
Australia - Essential Eight maturity model and ISM mapping (2024)
View authoritative source (external link) ➔
Australia
APAC
✓ STRM
Australia - Information Security Manual (ISM) (June 2026)
View authoritative source (external link) ➔
Australia
APAC
✓ STRM
Australia - Privacy Principles (2026)
View authoritative source (external link) ➔
Australia
APAC
✓ STRM
Australia - Prudential Standard CPS 230 - Operational Risk Management (2023)
View authoritative source (external link) ➔
Australia
APAC
✓ STRM
Australia - Prudential Standard CPS 234 Information Security (2019)
View authoritative source (external link) ➔
Australia
APAC
✓ STRM
Australia - Security of Critical Infrastructure Act 2018 (Compilation No. 9, 4 June 2026)
View authoritative source (external link) ➔
China
APAC
✓ STRM
China - Cybersecurity Law of the People's Republic of China (2017)
View authoritative source (external link) ➔
China
APAC
✓ STRM
China - Data Security Law of the People's Republic of China (2021)
View authoritative source (external link) ➔
China
APAC
✓ STRM
China - Decision on Strengthening Network Information Protection (2012)
View authoritative source (external link) ➔
China
APAC
✓ STRM
China - Personal Information Protection Law of the People's Republic of China (2021)
View authoritative source (external link) ➔
Hong Kong
APAC
✓ STRM
Hong Kong - Personal Data Ordinance (2022)
View authoritative source (external link) ➔
India
APAC
✓ STRM
India Digital Personal Data Protection Act (2023)
View authoritative source (external link) ➔
India
APAC
✓ STRM
India - Information Technology Rules (Privacy Rules) (2011)
View authoritative source (external link) ➔
India
APAC
✓ STRM
India - SEBI Cybersecurity and Cyber Resilience Framework (2024)
View authoritative source (external link) ➔
Japan
APAC
✓ STRM
Japan - Act on the Protection of Personal Information (2020)
View authoritative source (external link) ➔
Japan
APAC
✓ STRM
Japan - Information System Security Management and Assessment Program (ISMAP)
View authoritative source (external link) ➔
Malaysia
APAC
✓ STRM
Malaysia - Personal Data Protection Act (PDPA) (2010)
View authoritative source (external link) ➔
Malaysia
APAC
✓ STRM
Malaysia - Risk Management in Technology (RMiT) (2025)
View authoritative source (external link) ➔
New Zealand
APAC
✓ STRM
New Zealand - HISF MicroSmall (2023)
View authoritative source (external link) ➔
New Zealand
APAC
✓ STRM
New Zealand - HISF MLHSP (2023)
View authoritative source (external link) ➔
New Zealand
APAC
✓ STRM
New Zealand - HISO 10029:2024 NZ Health Information Security Framework Guidance for Suppliers
View authoritative source (external link) ➔
New Zealand
APAC
✓ STRM
New Zealand - Information Security Manual (ISM) v3.9
View authoritative source (external link) ➔

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Argentina
Americas
✓ STRM
Argentina - Protection of Personal Data (2018)
View authoritative source (external link) ➔
Bahamas
Americas
✓ STRM
Bahamas - Data Protection Act (DPA) (2003)
View authoritative source (external link) ➔
Bermuda
Americas
✓ STRM
Bermuda - Bermuda Monetary Authority (BMA) Insurance Sector Operational Cyber Risk Management Code of Conduct (2020)
View authoritative source (external link) ➔
Brazil
Americas
✓ STRM
Brazil - General Data Protection Law (LGPD) (2018)
View authoritative source (external link) ➔
Canada
Americas
✓ STRM
Canada - OSFI B-13 (2022)
View authoritative source (external link) ➔
Canada
Americas
✓ STRM
Canada - OSFI Cyber Security Self-Assessment Guidance
View authoritative source (external link) ➔
Canada
Americas
✓ STRM
Canada - Personal Information Protection and Electronic Documents Act (PIPEDA) (2000)
View authoritative source (external link) ➔
Canada
Americas
✓ STRM
Canada - Protecting controlled information in non-Government of Canada systems and organizations (ITSP.10.171) (2025)
View authoritative source (external link) ➔
Chile
Americas
✓ STRM
Chile - Act 19628 - Protection of Personal Data (1999)
View authoritative source (external link) ➔
Colombia
Americas
✓ STRM
Colombia - Law 1581 (2012)
View authoritative source (external link) ➔
Mexico
Americas
✓ STRM
Mexico - Federal Law on Protection of Personal Data held by Private Parties (2010)
View authoritative source (external link) ➔

No matching frameworks found. Try a different search term or filter.

Practical Application

How To Use the LRF Coverage in Your Program

Understanding which LRF are mapped to the SCF allows you to use the framework as a single source of truth for your compliance program. Here’s how practitioners apply LRF coverage in real-world programs.

01

Identify Your MCR

Determine which laws, regulations and frameworks apply to your organization. Each applicable LRF represents a Minimum Compliance Requirement (MCR) that must be satisfied.

02

Filter Controls by LRF

Use the SCF spreadsheet to filter controls by your applicable LRF. Every control mapped to that framework represents a requirement you need to address in your program.

03

Satisfy Multiple LRF Simultaneously

Because multiple LRF map to the same SCF controls, implementing a single control can satisfy requirements across several frameworks at once, dramatically reducing compliance effort.

Don’t See a Framework?

The SCF is a volunteer-maintained, open-source project. If a framework you need isn’t currently mapped, you can contribute to the project or contact the SCF team to request coverage. New LRF mappings are added with each quarterly release.