Resources
Every claim on this site traces back to a primary source: a framework body's published text, a regulator's guidance document, or a named research report with a date. This page links directly to those sources so you can verify anything yourself instead of taking a control page's word for it.
Go to the primary source when you need the authoritative text for a legal or audit purpose, when a requirement's exact wording matters (a single word in an Article or clause can change its scope), or when you want to check whether guidance has changed since a page here was last verified. Come back to this site's control pages when you want that same requirement translated into what it means for a SaaS stack, what evidence auditors ask for, and how it maps across frameworks — work the primary source will not do for you.
The links below are grouped by framework, plus a research and enforcement section for breach statistics and fine data. None of these are affiliate links, and nothing here requires an account or email address to access.
SOC 2
- AICPA 2017 TSC with 2022 Revised Points of Focus
The governing criteria document for every SOC 2 examination. If a control page on this site cites a Trust Services Criterion, this is the source text it derives from.
ISO 27001
- ISO/IEC 27001:2022 standard
The official standard text, sold by ISO. Annex A control wording and clause numbering on this site follow this edition — buy it if you need the authoritative text for an internal audit or legal review.
GDPR
- GDPR text (article-by-article)
A free, article-by-article mirror of Regulation (EU) 2016/679, including recitals. Useful for reading an Article in full context rather than the excerpt quoted on a control or comparison page.
- EDPB guidelines
Official interpretive guidance from the European Data Protection Board — the body that resolves ambiguity in how Articles apply in practice. Check here before treating any GDPR requirement as settled.
HIPAA
- HHS HIPAA Security Rule
The Department of Health and Human Services' own summary and full text of the Security Rule (45 CFR Part 164, Subpart C), including guidance documents on specific safeguards.
- HHS OCR Breach Portal
The public record of reported breaches affecting 500+ individuals, maintained by OCR. Use it to check enforcement history for a covered entity or business associate, or to see what breach causes actually get reported.
Research & enforcement
- Verizon DBIR
The annual Data Breach Investigations Report, built from thousands of confirmed incidents. The primary source for breach-cause statistics cited across this site's guides and framework pages.
- IBM Cost of a Data Breach
IBM's annual study on average breach cost by industry, region, and root cause. Cite the specific year's edition — figures move enough year over year that an undated reference is not verifiable.
- CMS GDPR Enforcement Tracker
A maintained database of GDPR fines by authority, article violated, and amount. Use it to find precedent for a specific Article rather than relying on secondhand summaries of enforcement trends.
- NIST CSF 2.0
The NIST Cybersecurity Framework, a voluntary risk-management structure referenced by many ISO 27001 and SOC 2 implementations even though it is not itself an audited framework.