Home  ›  Standards, Frameworks & Regulations

ALIGNED TO THE STANDARDS YOUR REGULATORS AND AUDITORS EXPECT

GRC programs for your standards, frameworks, and regulations

Most of compliance is shared across GRC frameworks. The 20% that's unique to you is where we excel.

THE 80/20 OF COMPLIANCE

Most of compliance is shared. The hard part is what's unique to you

80%

Shared foundation

20%

Your environment

The 80%: requirements are largely the same across all standards, frameworks, and regulations.

The 20%: what’s unique to you, planned and operated properly. This is where SimpliGRC excels.

STANDARDS, FRAMEWORKS, REGULATIONS

Everything we develop, implement, assess and audit against

Four groups, one control set: so evidence is captured once and reused everywhere

WHAT YOU ANSWER TO

Standards

Frameworks

Regulations

WHAT WE DELIVER

GRC Programs

The services that put the standards, frameworks and regulations into practice

THE STANDARDS WE COVER

WHAT WE COVER

Deep across the standards that matter — unified by one method

Each family below expands into the specific we assess, implement and certify against.

NIST

Risk-based cybersecurity grounded in U.S. federal guidance — pragmatic for any enterprise.

NIST CSF 2.0

Cybersecurity Framework

Outcome-based cybersecurity organized around Govern, Identity, Protect, Detect, Respond and Recover

NIST RMF

Risk Management Framework (SP 800-37)

A repeatable process to categorize, select, implement, assess, authorize and monitor controls

SP 800-S3 / 800-30

Controls & Risk Assesment

The federal control catalogue and risk-assessment guidance that underpin the RMF

ISO/IEC

Internationally certificate management systems for security, privacy, continuity and risk.

ISO/IEC 27001

Information Security (ISMS)

Certifiable requirements for an information security management system

ISO/IEC 27701

Privacy Information (PIMS)

Privacy extension to ISO 27001, aligned to GDPR and global privacy law

ISO/IEC 27005

Information Security Risk

Guidance for managing information security risk in support of ISO 27001

ISO/IEC 22301

Business Continuity (BCMS)

Management system requirements for operational resilience and continuity

ISO 31000

Enterprise Risk Management

Principles and guidelines for enterprise-wide risk management

Regulatory & Sector

Map your controls once, then satisfy the regulations and sector mandates you answer to.

DORA

EU digital operational resilience

ICT risk management and resilience testing for EU financial entities

GDPR

EU data protection

Data protection and privacy obligations for personal data in the EU

NERC CIP

Energy & critical infrastructure

Critical Infrastructure Protection standards for the bulk electric system

TSA

Transportation security directives

Cybersecurity directives for pipelines, rail and aviation operations

MAP ONCE, SATISFY MANY

One control set. Every mandate you answer to

Frameworks overlap far more than they differ. We map your controls once and crosswalk them across every standard and regulation you're accountable for.

Assess once

A single control assessment mapped to every framework you are accountable for: no duplicate questionnaires

Map across

Crosswalks between NIST, ISO and regulatory mandates eliminate redundant work and conflicting evidence

Prove continuity

Evidence captured once is reused for every audit and cycle, keeping you audit-ready year-round

See where you stand against every framework

Start with a maturity assessment to the standards and regulations that apply to you.