Logo Menu

Decision hubΒ·Reviewed

Which compliance framework do you need?

Start with the exact requirement in your next contract, questionnaire, or data flow. This hub compares 11 frameworks by trigger and by the proof each one produces.

A certificate, CPA report, legal obligation, self-assessed status, and agency authorization are not interchangeable. More than one row can apply.

Start with the requirement in front of you

Follow the row that matches the written request. Confirm scope and current status on the linked framework page before budgeting work.

  • Requirement A customer asks for an independent controls report Start with SOC 2 Type 2SOC 2 Type 1 Expected proof CPA attestation report; use Type 1 only when the requester accepts point-in-time coverage.
  • Requirement Procurement asks for an information security management-system certificate Start with ISO 27001 Expected proof Accredited management-system certificate with a defined scope.
  • Requirement Procurement asks for an AI management-system certificate Start with ISO 42001 Expected proof Accredited AI management-system certificate when certification is the stated requirement.
  • Requirement A BAA or health-data workflow creates US healthcare duties Start with HIPAAHITRUST Expected proof HIPAA is the legal obligation; add HITRUST only when the buyer names that certification.
  • Requirement A cloud service will be used by a US federal agency Start with FedRAMP Expected proof FedRAMP Certification for the service; the agency still makes its system ATO decision.
  • Requirement A defense solicitation or contract names CMMC, FCI, or CUI Start with CMMC Expected proof Follow the stated status and scope; current Phase I Level 1 and 2 paths are self-assessments.
  • Requirement You handle cardholder data or can affect its environment Start with PCI DSS Expected proof The applicable SAQ or QSA-led ROC, with an AOC, as set by the compliance-accepting entity.
  • Requirement A contract or counsel identifies GDPR scope for EU personal data Start with GDPR Expected proof An ongoing legal compliance program, not a general pan-EU certificate.
  • Requirement No outside party names an artifact; you need a governance baseline Start with NIST CSF Expected proof A voluntary maturity benchmark; NIST does not issue a certificate.

What is a compliance framework?

A compliance framework is a structured set of requirements or criteria used to manage security, privacy, risk, or legal duties. The name alone does not reveal the output: these 11 entries lead to reports, certificates, statuses, assessments, authorizations, or no issued artifact.

What changed in CMMC and FedRAMP in 2026?

Two federal programs changed after this hub's previous review. CMMC Phase II is suspended, while FedRAMP now calls its cloud-service outcome a Certification and separates it from an agency's Authorization to Operate decision.

Current as of August 11, 2026

On July 13, 2026, the Department suspended CMMC Phase II and kept Phase I Level 1 and Level 2 self-assessment requirements in place. Read the current Department CMMC notice β†— and the solicitation before assuming a C3PAO assessment is required.

FedRAMP launched its Consolidated Rules for 2026 on June 24, 2026. A FedRAMP Certification β†— applies to the cloud service offering; an agency still makes the ATO decision for its information system and use of that service.

11 maintained records

Which frameworks fit each obligation?

The groups below organize the library by legal or assurance context. Each range comes from the framework registry; open the explainer to see what the figure includes and which source supports it.

2 frameworks

US security attestation

2 frameworks

ISO certification

2 frameworks

US healthcare

2 frameworks

US federal & defense

1 framework

EU regulation

1 framework

Payments

1 framework

Voluntary frameworks

What proof does each framework produce?

The usable proof depends on the framework's authority and assessment model. Ask for the named artifact, its scope, issuer or decision-maker, assessment period, and current status; a vendor's β€œcertified” badge does not establish those facts.

Framework outputs derived from the canonical records, reviewed August 11, 2026.
Output Frameworks What to verify
CPA attestation report The report type, system scope, criteria, and reporting date or period.
Third-party certificate The certificate, scope, issuer, accreditation or program authority, and expiry date.
Federal cloud certification plus agency decision The service listing and certification profile; the agency separately authorizes its information system.
Self-assessed or certified program status The status, level, assessment type, scope, and affirmation required by the solicitation or contract.
Legal or contractual compliance evidence The specific evidence or validation method the regulator, contract, payment brand, or acquirer requires.
Voluntary maturity benchmark A documented profile or commissioned assessment; NIST itself issues no credential.

Can one compliance framework replace another?

One framework replaces another only when the requester explicitly accepts the alternative. A SOC 2 report does not create an ISO certificate or CMMC status; a certificate does not remove HIPAA, GDPR, PCI DSS, or contract-specific duties.

Operating evidence can still be reusable when the scope, population, period, and test satisfy both programs. Keep the deliverables separate. Use the SOC 2 vs ISO 27001 selector for that pair, or the current SOC 2 vs CMMC comparison for defense-contract questions.

How should you compare framework costs and timelines?

Choose the required artifact before comparing price. The ranges on this page can represent an audit fee, assessment, or wider program estimate, so they indicate order of magnitude rather than a like-for-like ranking.

CMMC and current FedRAMP paths have no universal program range in the registry. For the other frameworks, open the explainer and read the source note before using a number in a budget. SOC 2 buyers can use the SOC 2 audit cost guide; ISO buyers can separate implementation and certification-body fees in the ISO 27001 cost guide.

How are these framework records sourced?

Each framework has one validated registry record for its definition, outcome, buyer context, cost basis, sources, and verification date. Detail pages render those records directly, so a correction flows back into this hub instead of creating a second factual copy.

Official standards bodies and regulators control status and scope claims. Cost evidence may come from government data, published provider prices, or documented third-party estimates, with the basis stated on the detail page. Read the source-weighting methodology and report a stale record to hello@soc2auditors.org.

Contextual handoffs

Where do you go after choosing the framework?

Open the framework explainer first to verify scope. When the requirement is clear, use a provider page that matches the exact work instead of asking one firm to define both the need and the solution.

ISO 27001 buying paths

Combined-scope provider lists