Frameworks
Overview pages for SOC 2, ISO/IEC 27001, GDPR, and HIPAA — what each framework is, when it applies, and how to navigate the control reference.
- SOC 2
AICPA attestation against the Trust Services Criteria — the default ask for US B2B SaaS procurement. A CPA firm examines how you design and operate controls for Security and any optional categories you select, then issues a restricted-use report that buyers request under NDA during vendor security review.
- ISO/IEC 27001
International ISMS certification under ISO/IEC 27001:2022 with 93 Annex A reference controls — widely recognized in EU, UK, and APAC procurement. An accredited certification body audits your management system through Stage 1 and Stage 2, then maintains oversight through surveillance on a multi-year cycle. SaaS teams typically reuse IAM, logging, change, and vendor controls from adjacent programs while adding risk methodology, Statement of Applicability discipline, internal audit, and management review as the distinctive ISMS lift.
- GDPR
Regulation (EU) 2016/679 — the General Data Protection Regulation — is the primary EU law governing processing of personal data. It defines roles (controller and processor), lawful bases, data-subject rights, breach notification, and Article 32 security-of-processing duties. Territorial scope can reach non-EU SaaS companies that offer services to people in the EEA or monitor their behavior. This hub orients product, security, and legal stakeholders; it is educational, not legal advice.
- HIPAA
HIPAA's Privacy, Security, and Breach Notification Rules at 45 CFR Part 164 govern protected health information (PHI) for covered entities and their business associates. The Security Rule's administrative, physical, and technical safeguards — including Required and Addressable implementation specifications — shape how health-tech SaaS protects electronic PHI (ePHI). A Business Associate Agreement (BAA) is contractual infrastructure, not a substitute for safeguards. This hub is educational orientation for product and security teams, not legal advice.