Compliance Frameworks
Regulatory and security frameworks expressed as amalgamations of member standards and controls. Each framework links to the standards it is built from.
See your compliance posture across 14 standards
DORA, CRA, ISO 27001, SOC 2, NIST, PCI DSS, the EU AI Act and more — exactly which control areas Vibgrate assesses automatically, framed as honest readiness signals (not an attestation).
View compliance postureISO/IEC 27001:2022
Information security management system (ISMS) certification. Anchored by Annex A controls and implemented with ISO/IEC 27002 guidance.
SOC 2 (Trust Services Criteria)
AICPA attestation against the Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy). Type II evidences operating effectiveness over a window.
PCI DSS 4.0
Security requirements for organizations that store, process, or transmit cardholder data.
NIST Cybersecurity Framework 2.0
Govern/Identify/Protect/Detect/Respond/Recover framework for managing cybersecurity risk, with the control catalog supplied by NIST SP 800-53.
HIPAA Security Rule
U.S. safeguards for electronic protected health information (ePHI): administrative, physical, and technical controls.
GDPR (EU 2016/679)
EU regulation governing the processing of personal data, including data-subject rights, lawful basis, and security of processing (Art. 32).