Compliance Frameworks

Every framework your organization needs — in one platform.

Twenty-plus frameworks pre-built, mapped and included in every plan. Run HIPAA and NIST CSF simultaneously — collect evidence once, credit both. Don't see one you need? It can be deployed through the same bundle architecture.

Start Free Book a Demo
Included in every planAssessed simultaneouslyOne evidence setCross-framework mapping built in
G2 Summer 2026 High Performer badges — RealCISO ranked #1 vCISO platformSourceForge Leader Award, Summer 2026
4.8/5 · 223 reviews · Read reviews on SourceForge

4.8/5 across 223 reviews on SourceForge · #1 vCISO platform on G2, Summer 2026

The Problem

Real organizations have overlapping requirements

Most compliance tools are built around one or two frameworks — SOC 2 if you're a SaaS startup, HIPAA if you're healthcare, ISO 27001 if you're enterprise. But the healthcare SaaS company needs SOC 2 and HIPAA at once; the DoD contractor needs CMMC 2.0 and NIST 800-171; the financial-services firm needs SOC 2, NIST CSF and NYS DFS 500. RealCISO handles all of them — simultaneously, in one project, with one evidence set, and without a per-framework fee.

Supported Frameworks

All frameworks. One platform. One evidence set.

Every framework is assessed simultaneously and evidence is mapped automatically across all of them.

Cybersecurity

NIST Cybersecurity Framework 2.0

Govern, Identify, Protect, Detect, Respond, Recover — mapped to your controls, scored L1–L5, tracked over time. NIST CSF 1.1 remains available. RealCISO's CEO wrote Cybersecurity Risk Management: Mastering the Fundamentals Using the NIST Cybersecurity Framework (Wiley, 2021).

§ Cross-maps to CIS Controls, ISO 27001, SOC 2, HIPAA

Audit / B2B

SOC 2 (Trust Services Criteria)

Security, availability, processing integrity, confidentiality and privacy. Type I and Type II readiness, control implementation, evidence collection and an audit request list seeded from assessor requirements. Evidence mappings refreshed in August 2026 to align with auditor expectations.

§ Cross-maps to ISO 27001, NIST CSF, HIPAA

International

ISO/IEC 27001:2022

Annex A controls mapped, maturity scored L1–L5, risk register maintained against the ISMS. Live since July 2026 with mappings refreshed for auditors in August.

§ Cross-maps to SOC 2, NIST CSF

Healthcare

HIPAA Security Rule

Administrative, physical and technical safeguards for covered entities and business associates handling PHI — assessed, gap-analyzed and evidence-tracked.

§ Cross-maps to NIST CSF, SOC 2

Defense

CMMC 2.0

Levels 1 and 2 for the DoD supply chain, mapped to NIST SP 800-171 controls automatically: assessment, gap analysis, remediation tracking and evidence in one place.

§ Cross-maps to NIST 800-171, NIST 800-53

Defense

NIST SP 800-171 Rev. 3 & NIST 800-53

Controlled Unclassified Information for contractors, with SPRS scoring built in — every control carries its DoD Assessment Methodology weight so your running score matches what you would submit. 800-53 for federal information systems.

§ Cross-maps to CMMC 2.0, NIST CSF, FedRAMP

Baseline

CIS Controls v8

Eighteen prioritized controls organized into Implementation Groups 1–3 — the most actionable baseline for starting a program and the on-ramp to broader governance.

§ Cross-maps to NIST CSF and all frameworks

Payment

PCI-DSS

Payment card data security, including the SAQ-A and P2PE profiles, cross-mapped to the control sets most card-handling businesses also run.

§ Cross-maps to NIST 800-53, SOC 2, NIST CSF

Federal

FedRAMP & NIST RMF

Federal cloud authorization and the Risk Management Framework. Contact sales for authorization support specific to your cloud environment and agency scope.

§ Cross-maps to NIST 800-53

AI Governance

NIST AI RMF

Govern, map, measure and manage AI risk alongside your existing security program.

§ Cross-maps to NIST CSF

Public companies

SEC Cybersecurity Rules

Incident disclosure and annual risk-management, strategy and governance disclosure readiness for public companies and foreign filers.

§ Cross-maps to NIST CSF

Financial & privacy

GDPR · GLBA · FTC Safeguards · NYS DFS Part 500 · IRS Publication 1075

Sector and privacy regulations pre-built and cross-mapped, so a financial-services or tax-data program does not start from a blank page.

§ Cross-maps to NIST CSF, ISO 27001

And more

Don't see one you need?

Every framework in RealCISO is a bundle of controls, risks and questions on the same architecture — 1,000+ controls pre-baked. Additional frameworks can be deployed on request. Ask us →

Cross-Framework Intelligence

One evidence node, every framework

Collect once. Credit everywhere. Expire once, flag everywhere.

One control satisfies multiple frameworks simultaneously. Your AWS CloudTrail configuration satisfies NIST CSF DE.CM-7, SOC 2 CC7.2 and HIPAA §164.312(b) at the same time. In RealCISO one evidence node has edges to all three controls across all three frameworks: collect it once and all three get credit; when it expires, all three are flagged at once. That is what a single-framework tool — or a flat list of controls — cannot do.

Answer once

Shared controls are answered a single time and credited to every selected framework. Framework Health shows each standard's progress separately so you always know which is behind.

Add frameworks without restarting

Add ISO 27001 to a SOC 2 environment and the shared controls are credited immediately; only the controls unique to the new framework need answers.

Maturity across all of them

L1–L5 maturity is scored per control, so the same control's maturity carries into every framework that uses it. How continuous assessment works →

Common Questions

Frameworks FAQ

What compliance frameworks does RealCISO support?

SOC 2, NIST CSF 2.0 and 1.1, ISO/IEC 27001:2022, HIPAA, CMMC 2.0 Levels 1 and 2, NIST SP 800-171 Rev. 3 with SPRS scoring, NIST 800-53, CIS Controls v8, PCI-DSS (including SAQ-A and P2PE), FedRAMP, NIST RMF, NIST AI RMF, SEC cybersecurity rules, IRS Publication 1075, GDPR, FTC Safeguards, GLBA and NYS DFS Part 500 — and additional frameworks can be deployed on request through the same bundle architecture.

Can I assess multiple frameworks at once?

Yes. Select several in one environment and answer each shared control once. Cross-framework control mapping credits the answer and its evidence to every framework it satisfies, and Framework Health reports each standard separately.

How does cross-framework evidence mapping work?

One piece of evidence is a node with edges to every control it satisfies across every framework. Your CloudTrail configuration satisfies NIST CSF DE.CM-7, SOC 2 CC7.2 and HIPAA §164.312(b) at once — collect it once, all three get credit; when it expires, all three are flagged.

Which framework should I start with?

The one a customer, regulator or insurer is asking for. If nobody is asking yet, NIST CSF 2.0 or CIS Controls v8 give a practical baseline you can grow from; SOC 2 when enterprise customers ask; HIPAA for PHI; CMMC 2.0 and NIST 800-171 for the DoD supply chain.

Can I add frameworks later without restarting?

Yes. Add ISO 27001 to an environment that already holds SOC 2 answers and the shared controls are credited immediately; only the controls unique to the new framework need new answers. Nothing is re-asked.

Does RealCISO charge per framework?

No. Every framework is included in every plan — no add-on fees, no per-framework tiers. Vanta and Drata price each additional framework as an upsell; RealCISO environments are multi-framework by design.

Explore the Platform

Go deeper on any capability

How a framework becomes a running program.

Trusted by 3,000+ Organizations

Every framework your organization needs — assessed simultaneously

Start free with any framework, add the rest when you need them, and never pay per framework.

Start Free Book a Demo