Legal & compliance centre

Compliance programme

Framework hubs

HLD Group maps policies, controls, and evidence collection to industry and regulatory frameworks. Each hub lists applicable policies and programme status. Formal certifications and customer audit rights are defined in your agreement.

Commercial security frameworks

16 frameworks in programme

SOC 2

Trust Services Criteria

SOC 2 is a cybersecurity compliance framework for service and technology providers that handle customer data, driving continuous security processes to protect customer data.

Programme aligned

ISO 27001:2022

2022

ISO 27001 is a universal standard for organizations to establish, maintain, and continually improve their information security management system (ISMS).

Programme aligned

PCI DSS

4.0

Merchants or service providers that process, store, transmit, or impact cardholder data must meet PCI DSS requirements to safeguard cardholder data.

In scope — controls active

Cyber Essentials

UK government baseline certificate: five essential security controls and best practices against common online threats.

In scope — controls active

NYDFS NYCRR 500

New York Department of Financial Services cybersecurity requirements for protecting sensitive customer data and systems in scope.

Available for qualified engagements

FTC Safeguards Rule

Financial institutions under FTC jurisdiction must meet the Safeguards Rule to protect customer information security.

Available for qualified engagements

ISO 27017

Guidelines for information security controls applicable to cloud services for providers and customers.

Programme aligned

Microsoft SSPA

Microsoft Supplier Privacy and Assurance Standards for suppliers in Microsoft’s information supply chain, assessed against Data Protection Requirements (DPR).

Available for qualified engagements

NIS2

EU directive enhancing cybersecurity capabilities, cooperation, and risk management for essential and important entities.

In scope — controls active

Essential Eight

Australian Cyber Security Centre strategies to mitigate cyber threats and protect systems against common attacks.

Programme aligned

CIS Controls

Center for Internet Security Critical Security Controls — best practices and guidelines to safeguard organizations against cyber threats.

Programme aligned

SOX ITGC

Information Technology General Controls under Sarbanes-Oxley supporting integrity of financial reporting.

Available for qualified engagements

EU DORA

Digital Operational Resilience Act — operational resilience for EU financial institutions to withstand and recover from disruptions.

In scope — controls active

C5

Germany BSI Cloud Computing Compliance Criteria Catalogue — baseline for secure cloud services combining ISO 27001, CSA CCM, and German regulatory requirements.

Available for qualified engagements

TISAX

Trusted Information Security Assessment Exchange for automotive industry suppliers handling sensitive information.

Available for qualified engagements

MVSP

Minimum Viable Secure Product — minimal security checklist for B2B software and BPO suppliers.

Programme aligned

Federal security frameworks

10 frameworks in programme

CMMC 2.0

2.0

Cybersecurity Maturity Model Certification for DoD and federal agency contractors handling federal contract information and CUI.

Programme aligned

NIST 800-53 — High

Rev 5

Greatest control baseline for federal agencies and contractors when loss of sensitive data would have severe or catastrophic impact.

In scope — controls active

NIST 800-53 — Moderate

Rev 5

Moderate control baseline when loss of sensitive data would have sufficient but not catastrophic business impact.

Programme aligned

NIST 800-53 — Low

Rev 5

Lowest control baseline when loss of sensitive data would have minor business impact.

In scope — controls active

NIST 800-171

Rev 3

Protecting Controlled Unclassified Information (CUI) for federal and state agency contractors and subcontractors.

Programme aligned

NIST CSF 2.0

2.0

NIST Cybersecurity Framework helping organizations understand risk and improve cybersecurity programmes.

Programme aligned

FedRAMP

Federal Risk and Authorization Management Program for cloud service providers working with US federal government or federal data.

In scope — controls active

GovRAMP

Standardized cloud security for state, local, tribal, territorial governments and public institutions (formerly StateRAMP).

Available for qualified engagements

CJIS

Criminal Justice Information Services security policy for entities accessing US Justice Department sensitive information.

Available for qualified engagements

TX-RAMP

Texas Risk and Authorization Management Program for cloud services used by Texas state agencies and institutions.

Available for qualified engagements

Data privacy frameworks

5 frameworks in programme

AI frameworks

3 frameworks in programme

Additional frameworks

2 frameworks in programme