Compliance programme
Framework hubs
HLD Group maps policies, controls, and evidence collection to industry and regulatory frameworks. Each hub lists applicable policies and programme status. Formal certifications and customer audit rights are defined in your agreement.
Commercial security frameworks
16 frameworks in programme
SOC 2
Trust Services Criteria
SOC 2 is a cybersecurity compliance framework for service and technology providers that handle customer data, driving continuous security processes to protect customer data.
ISO 27001:2022
2022
ISO 27001 is a universal standard for organizations to establish, maintain, and continually improve their information security management system (ISMS).
PCI DSS
4.0
Merchants or service providers that process, store, transmit, or impact cardholder data must meet PCI DSS requirements to safeguard cardholder data.
Cyber Essentials
UK government baseline certificate: five essential security controls and best practices against common online threats.
NYDFS NYCRR 500
New York Department of Financial Services cybersecurity requirements for protecting sensitive customer data and systems in scope.
FTC Safeguards Rule
Financial institutions under FTC jurisdiction must meet the Safeguards Rule to protect customer information security.
ISO 27017
Guidelines for information security controls applicable to cloud services for providers and customers.
Microsoft SSPA
Microsoft Supplier Privacy and Assurance Standards for suppliers in Microsoft’s information supply chain, assessed against Data Protection Requirements (DPR).
NIS2
EU directive enhancing cybersecurity capabilities, cooperation, and risk management for essential and important entities.
Essential Eight
Australian Cyber Security Centre strategies to mitigate cyber threats and protect systems against common attacks.
CIS Controls
Center for Internet Security Critical Security Controls — best practices and guidelines to safeguard organizations against cyber threats.
SOX ITGC
Information Technology General Controls under Sarbanes-Oxley supporting integrity of financial reporting.
EU DORA
Digital Operational Resilience Act — operational resilience for EU financial institutions to withstand and recover from disruptions.
C5
Germany BSI Cloud Computing Compliance Criteria Catalogue — baseline for secure cloud services combining ISO 27001, CSA CCM, and German regulatory requirements.
TISAX
Trusted Information Security Assessment Exchange for automotive industry suppliers handling sensitive information.
MVSP
Minimum Viable Secure Product — minimal security checklist for B2B software and BPO suppliers.
Federal security frameworks
10 frameworks in programme
CMMC 2.0
2.0
Cybersecurity Maturity Model Certification for DoD and federal agency contractors handling federal contract information and CUI.
NIST 800-53 — High
Rev 5
Greatest control baseline for federal agencies and contractors when loss of sensitive data would have severe or catastrophic impact.
NIST 800-53 — Moderate
Rev 5
Moderate control baseline when loss of sensitive data would have sufficient but not catastrophic business impact.
NIST 800-53 — Low
Rev 5
Lowest control baseline when loss of sensitive data would have minor business impact.
NIST 800-171
Rev 3
Protecting Controlled Unclassified Information (CUI) for federal and state agency contractors and subcontractors.
NIST CSF 2.0
2.0
NIST Cybersecurity Framework helping organizations understand risk and improve cybersecurity programmes.
FedRAMP
Federal Risk and Authorization Management Program for cloud service providers working with US federal government or federal data.
GovRAMP
Standardized cloud security for state, local, tribal, territorial governments and public institutions (formerly StateRAMP).
CJIS
Criminal Justice Information Services security policy for entities accessing US Justice Department sensitive information.
TX-RAMP
Texas Risk and Authorization Management Program for cloud services used by Texas state agencies and institutions.
Data privacy frameworks
5 frameworks in programme
HIPAA
Health Insurance Portability and Accountability Act for plans, providers, insurers, and organizations handling PHI.
ISO 27701
Privacy extension to ISO 27001 for establishing and improving a privacy information management system (PIMS).
GDPR
General Data Protection Regulation for organizations handling EU and UK personal data.
CCPA
California Consumer Privacy Act for businesses collecting personal data of California residents.
CPRA
California Privacy Rights Act amending CCPA with enhanced consumer rights and CPPA enforcement.
AI frameworks
3 frameworks in programme
NIST AI RMF
NIST AI Risk Management Framework for organizations incorporating AI into products and processes.
ISO 42001
Management system standard for responsible development and use of AI systems.
EU AI Act
EU risk-based framework for AI systems with strict rules for high-risk use to ensure safety, ethics, and fundamental rights.
Additional frameworks
2 frameworks in programme
Custom frameworks
Tailored control sets mapped to your contractual, industry, and regulatory obligations using HLD’s control library and evidence programme.
ISO 9001
Quality Management System (QMS) standard providing a structured framework for organizational quality.