Overview
Cybersecurity "frameworks" are the named standards, regulations, and certifications that tell an organization what security to put in place and how it gets checked. They overlap heavily, which is why they are so easily confused. This page is a map across the three families that matter most to organizations doing business with — or alongside — the U.S. government: federal and government-contracting frameworks, industry and sector frameworks, and international standards and laws.
Keep one principle in mind throughout: every framework below sits on top of the generally-applicable legal baseline — the FTC Act, state breach and data-security laws, GLBA, and HIPAA — that already governs any business handling data. Frameworks are what a particular contract, customer, or market adds; they are not where your data-security duty begins.
How to read this page. The side-by-side comparison and the "which applies to me?" decision tree are at the bottom. The sections below explain each framework in plain language — what it is, who it binds, and how it is verified. Where a framework has its own detailed page on this site, follow the link.
Federal & Government-Contracting Frameworks
These are the frameworks a federal contract can require directly through its clauses.
FAR 52.204-21 — The FCI Baseline
The Federal Acquisition Regulation's basic safeguarding clause sets 15 minimum controls for any contractor system that handles Federal Contract Information (FCI) — non-public information generated for the government. It is the universal floor for federal contractors, with no dollar threshold; contracts solely for commercial off-the-shelf (COTS) items are the main carve-out. See the FAR baseline for the full list.
NIST SP 800-171 — The CUI Standard
When a contract involves Controlled Unclassified Information (CUI), NIST SP 800-171 is the standard you implement. A critical nuance as of 2026: DoD contracts under DFARS 252.204-7012 remain tied to Revision 2 and its 110 controls through a standing DoD class deviation that has no announced end date, even though NIST published Revision 3 in 2024. DoD has issued draft organization-defined parameters signaling an eventual move to Rev 3 for both DFARS and CMMC, but until your contract says otherwise, Rev 2's 110 controls in 14 families are what you must meet. Watch your contract language and SPRS guidance for the transition.
SPRS: the Supplier Performance Risk System, where DoD contractors post their NIST SP 800-171 self-assessment scores. A current score (generally within three years) is a condition of award on covered DoD contracts.
CMMC 2.0 — Verification, Not a New Standard
The Cybersecurity Maturity Model Certification does not invent new controls — it verifies that you have implemented NIST SP 800-171 (and, at Level 3, selected 800-172 enhanced controls). Its three levels:
- Level 1 — basic FCI safeguarding (the FAR 52.204-21 fifteen); annual self-assessment.
- Level 2 — full NIST SP 800-171; self-assessment or, for most CUI, a third-party (C3PAO) certification.
- Level 3 — Level 2 plus selected 800-172 controls; government-led (DIBCAC) assessment.
The CMMC program rule (32 C.F.R. Part 170) and the DFARS acquisition rule (48 CFR) took effect November 10, 2025, starting a phased rollout: Level 1/2 self-assessments in solicitations from Phase 1 (Nov 2025), Level 2 C3PAO certifications from Phase 2 (Nov 10, 2026), Level 3 from Phase 3 (Nov 2027), and full implementation by Phase 4 (Nov 2028). See the Defense industry page for the rollout timeline.
FISMA, FIPS 200 & NIST SP 800-53
The Federal Information Security Modernization Act (FISMA) requires federal agencies — and contractors operating information systems on their behalf — to secure those systems. FIPS 200 sets the minimum security requirements, and the control catalog is NIST SP 800-53 (Rev 5), tailored to a system's FIPS 199 impact level (Low/Moderate/High). Compliance is demonstrated through an agency Authorization to Operate (ATO) and ongoing continuous monitoring.
NIST Risk Management Framework (SP 800-37)
The RMF is the seven-step process — Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor — that agencies use to apply SP 800-53 controls and reach an ATO. It is the procedural backbone behind FISMA and FedRAMP rather than a control set of its own.
NIST CSF 2.0
The NIST Cybersecurity Framework 2.0 (2024) organizes cybersecurity into six functions — Govern, Identify, Protect, Detect, Respond, Recover. It is voluntary and risk-based, not contractually mandated, and many organizations use it as the management layer that sits above their detailed control set (such as 800-171 or 800-53). Version 2.0 added the Govern function and broadened the framework's audience well beyond critical infrastructure.
FedRAMP & GovRAMP — Cloud Authorization
FedRAMP standardizes the security authorization of cloud services sold to federal agencies. It uses NIST SP 800-53 baselines by impact level, a third-party assessment (3PAO), and an agency or program authorization plus continuous monitoring. FedRAMP is modernizing through "FedRAMP 20x," a phased effort (in cohort testing as of 2026) to automate authorization using machine-readable Key Security Indicators and cut timelines from many months toward weeks. GovRAMP — the program formerly known as StateRAMP, rebranded in February 2025 — provides an analogous authorization path for state, local, education, and tribal governments. See the GovRAMP page.
Industry & Sector Frameworks
These bind organizations based on the kind of data or business they handle, regardless of any government contract.
PCI DSS v4.0.1 — Payment Card Data
The Payment Card Industry Data Security Standard applies to any organization that stores, processes, or transmits payment card data. It is enforced contractually by the card brands and acquiring banks, not by statute. The current version is v4.0.1, and as of March 31, 2025 every requirement — including the formerly "future-dated" controls for stronger authentication, e-commerce script protection, and authenticated internal vulnerability scanning — is mandatory.
HIPAA Security Rule — Health Information
The HIPAA Security Rule (45 C.F.R. Part 164) requires healthcare "covered entities" and their "business associates" to safeguard electronic protected health information (ePHI). HHS's Office for Civil Rights published a Notice of Proposed Rulemaking in January 2025 to modernize the rule — including making most "addressable" specifications mandatory — but no final rule had issued as of mid-2026. It also appears on the legal baseline because it binds healthcare businesses independent of any contract.
GLBA Safeguards Rule — Financial Institutions
The Gramm-Leach-Bliley Act Safeguards Rule (16 C.F.R. Part 314) requires "financial institutions," broadly defined by the FTC to include many non-bank businesses, to maintain a written information-security program. Since May 2024, covered entities must report breaches affecting 500 or more consumers to the FTC within 30 days.
SOC 2 — Service Organizations
SOC 2 is an attestation report, performed by a CPA firm against the AICPA Trust Services Criteria (the 2017 criteria with revised points of focus, 2022). It evaluates a service organization's controls across up to five categories — Security, Availability, Processing Integrity, Confidentiality, and Privacy — and is the de facto trust artifact that SaaS and cloud vendors provide to enterprise customers. It is a report, not a certification or a fixed control list.
HITRUST CSF — Certifiable, Healthcare-Centric
The HITRUST CSF is a certifiable framework that harmonizes many authoritative sources (HIPAA, NIST, ISO, PCI DSS, and others) into one prescriptive control set, widely used in healthcare and by vendors that serve it. Releases are frequent; v11.7.0 shipped in December 2025, adding mappings to sources such as FedRAMP 20x Key Security Indicators. HITRUST offers tiered assessments (e1, i1, r2) of increasing rigor.
CIS Controls v8.1 — Prioritized Safeguards
The CIS Critical Security Controls are a prioritized, vendor-neutral set of safeguards maintained by the Center for Internet Security. The current release, v8.1 (2024), organizes 18 controls into three Implementation Groups (IG1–IG3) so smaller organizations can start with the essentials. CIS publishes mappings to NIST CSF, NIST SP 800-53, and ISO/IEC 27001, making it a practical on-ramp to the heavier frameworks.
NERC CIP — Bulk Electric System
The NERC Critical Infrastructure Protection standards are mandatory, enforceable cybersecurity requirements for owners and operators of the North American bulk electric system, overseen by FERC. They are a sector-specific regime rather than a general-purpose framework.
International Frameworks & Laws
These reach organizations that operate, sell, or hold data across borders — especially in the EU.
ISO/IEC 27001:2022 — The ISMS Standard
ISO/IEC 27001 is the leading international standard for an Information Security Management System (ISMS). It is voluntary but frequently required by commercial and international partners, and it offers something U.S. frameworks generally do not: an accredited third-party certification. The 2022 revision restructured Annex A into 93 controls across four themes (organizational, people, physical, technological); organizations certified to the 2013 version had to transition by October 31, 2025.
EU General Data Protection Regulation (GDPR)
The GDPR governs the processing of EU residents' personal data and reaches any organization worldwide that offers goods or services to, or monitors, people in the EU. It is a data-protection law rather than a security control set, but it carries a "security of processing" obligation (Article 32) and large fines for breaches.
EU NIS2 Directive
NIS2 raises baseline cybersecurity and incident-reporting obligations for "essential" and "important" entities across critical sectors in the EU. Member States were to transpose it into national law by October 17, 2024, though transposition has lagged in several states. U.S. companies with EU operations or EU critical-sector customers can be pulled into its scope.
DORA — EU Financial Sector
The Digital Operational Resilience Act sets ICT risk-management, incident-reporting, resilience-testing, and third-party-oversight requirements for EU financial entities and their critical ICT providers. It has applied since January 17, 2025.
Other International Instruments
The EU Cybersecurity Act (Reg. 2019/881) established the EU's cybersecurity certification framework and ENISA's mandate. The Council of Europe Convention on Cybercrime ("Budapest Convention," ETS No. 185) harmonizes cybercrime law internationally — context for contractors operating abroad, not a control set. The PRC Personal Information Protection Law (PIPL) governs personal-data handling in and out of China and can bind multinationals with Chinese operations.
Side-by-Side Comparison
| Framework | Who it binds | What it covers | How it is verified | Applies if |
|---|---|---|---|---|
| FAR 52.204-21 | All federal contractors with FCI | 15 basic FCI safeguards | Annual self-assessment (CMMC Level 1 for DoD) | Contract includes the clause and FCI flows through your systems |
| NIST SP 800-171 | Federal contractors with CUI | 110 CUI protection controls | SPRS self-assessment; C3PAO for DoD CMMC Level 2 | Contract requires DFARS 252.204-7012 or CMMC Level 2 |
| CMMC | DoD contractors | Levels 1-3 (FCI to CUI to enhanced CUI) | Self-assessment (L1/some L2) or C3PAO (L2/L3) | DoD solicitation includes DFARS 252.204-7021 |
| NIST CSF | Voluntary; CISA-recommended | Risk-based cybersecurity outcomes | Self-assessed or third-party | No federal mandate; common in civilian agency guidance |
| FedRAMP | Cloud service providers selling to agencies | NIST SP 800-53 cloud controls | Third-party assessment organization (3PAO) | Offering a cloud service to a federal agency |
| ISO/IEC 27001 | Voluntary; international standard | ISMS with 93 Annex A controls | Accredited third-party certification | Commercial/international partner requirement |
Which Applies to Me? Decision Tree
1. Federal contract or subcontract? No: FAR/CMMC do not apply. Yes: continue. 2. Contract involves FCI? No: FAR 52.204-21 does not apply. Yes: FAR 52.204-21 applies (15 safeguards). 3. Contract involves CUI? No: stop at FAR 52.204-21. Yes: NIST SP 800-171 applies (DFARS 252.204-7012). 4. DoD contract? No: CMMC does not apply. Yes: CMMC applies; check solicitation for level (1, 2, or 3). 5. Offering a cloud service to an agency? FedRAMP may apply; confirm with the agency. 6. EU operations or EU customers? GDPR and potentially NIS2/DORA may apply.
Note (updated July 2026): On May 13, 2026, NIST finalized **SP 800-172 Revision 3** and its companion SP 800-172A Revision 3, expanding enhanced CUI requirements from 39 to roughly 115. CMMC Level 3 has not yet adopted Rev 3 — it still references the February 2021 edition, so the control mappings on this page remain current for compliance today. With both 800-171 Rev 3 and 800-172 Rev 3 now final, a single future DoD rulemaking could update CMMC Levels 2 and 3 together. These control IDs will be refreshed once DoD acts.