Asurvo
Frameworks

Every framework you need. One workspace.

Asurvo ships prebuilt coverage for 16 frameworks, all live today — with one-to-many control mapping so you don't re-do work.

SecurityLive

ISO 27001

The international standard for information security management systems.

127 requirementsv2022
Framework details
SecurityLive

SOC 2

The de facto standard for SaaS companies serving North American enterprises.

61 requirementsvType II
Framework details
SecurityLive

NIST CSF

A voluntary framework for reducing cybersecurity risk across any organization.

107 requirementsv2.0
Framework details
IndustryLive

HIPAA

US regulation for the protection of health information.

88 requirementsv2013
Framework details
PrivacyLive

GDPR

The EU regulation governing data protection and privacy for individuals in the EU and EEA.

62 requirementsv2016/679
Framework details
FinancialLive

PCI DSS

The security standard for organizations that handle branded payment cards.

250 requirementsv4.0.1
Framework details
SecurityLive

NIST 800-53

The federal catalog of security and privacy controls for information systems.

1007 requirementsvRev. 5
Framework details
SecurityLive

NIST 800-171

Security requirements for protecting Controlled Unclassified Information (CUI).

110 requirementsvRev. 2
Framework details
SecurityLive

CMMC 2.0

The DoD certification framework for protecting sensitive unclassified information.

90 requirementsv2.0
Framework details
SecurityLive

CIS Controls

A prioritized set of defensive actions to stop the most common attacks.

153 requirementsv8.0
Framework details
PrivacyLive

ISO 27701

The standard for a Privacy Information Management System (PIMS).

108 requirementsv2025
Framework details
PrivacyLive

CCPA/CPRA

California's consumer privacy law and its CPRA amendments.

79 requirementsv2023
Framework details
SecurityLive

CSA CCM

The cybersecurity control framework purpose-built for cloud computing.

187 requirementsv4.0
Framework details
IndustryLive

HITRUST

A certifiable framework that harmonizes healthcare and security standards.

149 requirementsv11.0
Framework details
RegionalLive

NESA IA

The UAE national standard for information assurance across critical entities.

134 requirementsv2.0
Framework details
RegionalLive

SAMA CSF

The Saudi Central Bank framework for cyber security in financial institutions.

493 requirementsv1.0
Framework details

Need a framework we don't list?

Asurvo supports custom frameworks and internal control libraries out of the box. Tell us what you need.