Decision hubΒ·Reviewed
Which compliance framework do you need?
Start with the exact requirement in your next contract, questionnaire, or data flow. This hub compares 11 frameworks by trigger and by the proof each one produces.
A certificate, CPA report, legal obligation, self-assessed status, and agency authorization are not interchangeable. More than one row can apply.
Start with the requirement in front of you
Follow the row that matches the written request. Confirm scope and current status on the linked framework page before budgeting work.
- Requirement A customer asks for an independent controls report Start with SOC 2 Type 2SOC 2 Type 1 Expected proof CPA attestation report; use Type 1 only when the requester accepts point-in-time coverage.
- Requirement Procurement asks for an information security management-system certificate Start with ISO 27001 Expected proof Accredited management-system certificate with a defined scope.
- Requirement Procurement asks for an AI management-system certificate Start with ISO 42001 Expected proof Accredited AI management-system certificate when certification is the stated requirement.
- Requirement A BAA or health-data workflow creates US healthcare duties Start with HIPAAHITRUST Expected proof HIPAA is the legal obligation; add HITRUST only when the buyer names that certification.
- Requirement A cloud service will be used by a US federal agency Start with FedRAMP Expected proof FedRAMP Certification for the service; the agency still makes its system ATO decision.
- Requirement A defense solicitation or contract names CMMC, FCI, or CUI Start with CMMC Expected proof Follow the stated status and scope; current Phase I Level 1 and 2 paths are self-assessments.
- Requirement You handle cardholder data or can affect its environment Start with PCI DSS Expected proof The applicable SAQ or QSA-led ROC, with an AOC, as set by the compliance-accepting entity.
- Requirement A contract or counsel identifies GDPR scope for EU personal data Start with GDPR Expected proof An ongoing legal compliance program, not a general pan-EU certificate.
- Requirement No outside party names an artifact; you need a governance baseline Start with NIST CSF Expected proof A voluntary maturity benchmark; NIST does not issue a certificate.