Skip to content
compliancebase

Frameworks

Four frameworks are covered on this site, and they are not interchangeable. SOC 2 is an attestation governed by the AICPA that a CPA firm issues about your controls. ISO/IEC 27001 is a certification against an international standard, issued by an accredited certification body. GDPR is a binding EU regulation with no certification at all — you either meet its requirements or you do not, and no one hands you a report saying so. HIPAA is a U.S. federal rule that applies based on what data you handle, not a choice you opt into. Confusing these categories is one of the most common early mistakes teams make when scoping a compliance program.

Each overview page below covers one framework in full: what it actually requires, who it applies to, how it is structured internally (Trust Services Categories for SOC 2, Annex A domains for ISO 27001, chapters and articles for GDPR, rule parts for HIPAA), and a map into this site's control-level reference pages for that framework.

Start here if you do not yet know which framework applies to your company, or if you know the name but not the structure underneath it. If you already know the specific control or article number you need, go directly to the control reference instead.