Frameworks
Four frameworks are covered on this site, and they are not interchangeable. SOC 2 is an attestation governed by the AICPA that a CPA firm issues about your controls. ISO/IEC 27001 is a certification against an international standard, issued by an accredited certification body. GDPR is a binding EU regulation with no certification at all — you either meet its requirements or you do not, and no one hands you a report saying so. HIPAA is a U.S. federal rule that applies based on what data you handle, not a choice you opt into. Confusing these categories is one of the most common early mistakes teams make when scoping a compliance program.
Each overview page below covers one framework in full: what it actually requires, who it applies to, how it is structured internally (Trust Services Categories for SOC 2, Annex A domains for ISO 27001, chapters and articles for GDPR, rule parts for HIPAA), and a map into this site's control-level reference pages for that framework.
Start here if you do not yet know which framework applies to your company, or if you know the name but not the structure underneath it. If you already know the specific control or article number you need, go directly to the control reference instead.
- SOC 2
AICPA attestation against the Trust Services Criteria — the default ask for US B2B SaaS procurement. A CPA firm examines how you design and operate controls for Security and any optional categories you select, then issues a restricted-use report that buyers request under NDA during vendor security review.
- ISO/IEC 27001
International ISMS certification under ISO/IEC 27001:2022 with 93 Annex A reference controls — widely recognized in EU, UK, and APAC procurement. An accredited certification body audits your management system through Stage 1 and Stage 2, then maintains oversight through surveillance on a multi-year cycle. SaaS teams typically reuse IAM, logging, change, and vendor controls from adjacent programs while adding risk methodology, Statement of Applicability discipline, internal audit, and management review as the distinctive ISMS lift.
- GDPR
Regulation (EU) 2016/679 — the General Data Protection Regulation — is the primary EU law governing processing of personal data. It defines roles (controller and processor), lawful bases, data-subject rights, breach notification, and Article 32 security-of-processing duties. Territorial scope can reach non-EU SaaS companies that offer services to people in the EEA or monitor their behavior. This hub orients product, security, and legal stakeholders; it is educational, not legal advice.
- HIPAA
HIPAA's Privacy, Security, and Breach Notification Rules at 45 CFR Part 164 govern protected health information (PHI) for covered entities and their business associates. The Security Rule's administrative, physical, and technical safeguards — including Required and Addressable implementation specifications — shape how health-tech SaaS protects electronic PHI (ePHI). A Business Associate Agreement (BAA) is contractual infrastructure, not a substitute for safeguards. This hub is educational orientation for product and security teams, not legal advice.