Skip to main content
Regon Security
REGONSECURITY
Framework Library

Every Framework, One Platform

390+ standards and benchmarks, from NIST and CIS through to HIPAA and the EU AI Act. All assessed in real time, with the evidence collected automatically.

390+
Standards & Benchmarks
300+
CIS Benchmarks
80+
Regulatory & Industry Standards
SOC 2ISO 27001HIPAAPCI DSS v4.0GDPRNIST CSF 2.0CIS ControlsDORAFedRAMPEU AI ActNIST AI RMFISO 42001SOXNIST 800-53NIST 800-171UK Cyber EssentialsAustralia Essential 8SOC 2ISO 27001HIPAAPCI DSS v4.0GDPRNIST CSF 2.0CIS ControlsDORAFedRAMPEU AI ActNIST AI RMFISO 42001SOXNIST 800-53NIST 800-171UK Cyber EssentialsAustralia Essential 8
CMMC 2.0NIS2EU Cyber Resilience ActMITRE ATT&CKMITRE D3FENDOWASP Top 10OWASP LLM Top 10CSA CCMNYDFS Part 500MAS TRMRBI Cyber Security FrameworkLGPDPIPEDAAPPIDPDPAPDPANZ Privacy ActFDA 21 CFR Part 11HITECHBSI C5CMMC 2.0NIS2EU Cyber Resilience ActMITRE ATT&CKMITRE D3FENDOWASP Top 10OWASP LLM Top 10CSA CCMNYDFS Part 500MAS TRMRBI Cyber Security FrameworkLGPDPIPEDAAPPIDPDPAPDPANZ Privacy ActFDA 21 CFR Part 11HITECHBSI C5

What the catalogue actually covers

Grouped by what carrying each class of standard lets you do, rather than by alphabet. CIS benchmarks are counted separately — these are the regulatory and industry standards.

Regional & national

10+

These are the standards that let you operate on someone else's ground. A regulator, a ministry or a national scheme decides whether you may sell, host or process there at all — and each jurisdiction writes its own rules. Carrying them is what turns a market from closed to open.

  • NIS2 DirectiveEU
  • EU Cyber Resilience ActEU
  • EU Data ActRegulation (EU) 2023/2854
  • EU Data Governance ActEU
  • BSI C5 — Cloud Computing Compliance CriteriaGermany
  • Cyber EssentialsUnited Kingdom
  • Australian Essential EightAustralia
  • Australian Information Security ManualAustralia
  • Cybersecurity Management Guidelines for Enterprise ExecutivesJapan
  • FBI CJIS Security PolicyUnited States
  • CMMC 2.0US defence supply chain
  • FedRAMPUS federal — Low, Moderate and High baselines

Cyber security posture

30+

This is where you show what you actually do, not what you promise. A security framework is the evidence that your controls exist, are configured, and still hold today — the difference between saying you take a customer's data seriously and being able to prove it under scrutiny.

  • ISO/IEC 27001:2022
  • SOC 2 Type IITrust Services Criteria
  • NIST Cybersecurity FrameworkCSF 1.1 and 2.0
  • NIST SP 800-53Rev 3 through 5.1, Low / Moderate / High
  • NIST SP 800-171Revision 3
  • NIST SP 800-30Risk assessment
  • NIST SP 800-37Risk Management Framework
  • NIST SP 800-39Organisational risk
  • NIST SP 800-63-4Digital identity
  • Cloud Security Alliance CCMv3.0.1 and v4.0
  • MITRE ATT&CK for Enterprise
  • MITRE D3FEND
  • OWASP Top 102017 and 2021
  • OWASP API Security Top 102023
  • OWASP Mobile Top 102024
  • OWASP Kubernetes Top 102022
  • OWASP Docker Top 10
  • OWASP Serverless Top 10
  • OWASP Top 10 CI/CD Security Risks

Financial services

8+

Money attracts both scrutiny and attackers. These regimes are how a bank, a processor or a counterparty satisfies itself that you can be trusted with transactions — and in most of them the obligation is continuous, not a certificate you renew once a year.

Healthcare & life sciences

5+

Health data outlives the systems that hold it, and the harm from getting it wrong lands on a person rather than a balance sheet. These standards are how you demonstrate that you understand what is at stake when the record is someone's body.

Privacy & data protection

12+

Privacy law follows the person, not the server. If you hold data about someone in Brazil, Japan or Canada, their national regime applies wherever you process it — so coverage here decides whose customers you can safely take on.

AI governance

7+

AI regulation arrived faster than most compliance programmes were built to absorb, and it asks questions the older frameworks never posed: what the model does, on what data, with what oversight. Carrying these now is the difference between adopting AI deliberately and retrofitting an explanation later.

Platform hardening

4+

Frameworks describe intent; hardening baselines describe the machine. These are the line-by-line configurations a defence or government auditor expects on the operating systems actually running your workloads.

Framework Intelligence

Multi-Framework Assessment

Assess against multiple frameworks simultaneously. One scan, all standards.

Auto Updates

Frameworks update automatically when standards change. Always current.

Requirement Mapping

For regulatory and industry standards, rules are derived from the requirement as written. Not hardcoded rules.

Custom Frameworks

Build your own framework with the Custom Auditing Engine. Your policies, your rules.

Custom Auditing Engine

Auto-map rules to any framework from the requirement as written.

GDPR framework with automatic rule mapping

Need a Custom Framework?

The Custom Auditing Engine lets you define your own rules, create custom patterns, and map to any internal standard or regulatory requirement.

Schedule a Demo