
Coalfire® supported frameworks
Support for over 100 compliance frameworks

Coalfire supports four times more global regulatory and compliance frameworks than our competitors. With over 20 years of experience, seasoned team expertise, and Compliance Essentials automation platform, we enable seamless coordination across multiple frameworks, simplifying your path to regulatory compliance success.
Global Compliance Expertise: Ensuring Compliance Anywhere, Anytime
Leverage Coalfire's comprehensive compliance framework support to more efficiently achieve results.

Coalfire Supported Frameworks
United States
AI Governance & Model Safety
NIST AI RMF
OWASP Top 10 for LLMs v1.11
NIST Cybersecurity Framework (CSF)
NIST Privacy Framework
NIST SP 800-30
NIST SP 800-37
NIST SP 800-39
NIST SP 800-53
NIST SP 800-61
NIST SP 800-34
NIST SP 800-171
NIST SP 800-218
NIST IR 8286D
NIST 800-161
23 CRR-NY 500
NYS Hospital Cybersecurity Regulation 405.46 Title 10
CPSA
SLC
Government Cloud & Sovereignty Requirements
FedRAMP
StateRAMP
TX-RAMP
CJIS
Healthcare Requirements
CMS Business Assessment
CMS EDE
CMS ARS
MARS-E
ARC-AMPE
Industry-Specific Requirements
CMMC
CMMI
DFARS
DoD
DEA EPCS
FFIEC
CMS Programs
HITRUST
ITAR
SOC 1
SOC 2
SOC 3
SOC for Cybersecurity
Privacy & Data Protection
CCPA
US State Privacy Laws
GLBA
HIPAA
Health Information Act (HIA)
TEFCA
European Union
AI Governance & Model Safety
EU AI Act
DORA (Digital Operational Resilience Act)
EU CRA (Cyber Resilience Act)
Government Cloud & Sovereignty Requirements
None at the EU level. See the regional list below.
Industry-Specific Requirements
DORA for financial services, otherwise sector-specific at country level.
Privacy & Data Protection
GDPR (General Data Protection Regulation)
Note: Many EU countries also adopt ENS/BIO/TISAX-style national programs. See the list below for country-specific regulations.
Global
ISO 27001
ISO 27017
ISO 27018
ISO 20000-1
ISO 22301
ISO 50001
ISO 45001
ISO 9001
ISO 14001
ISAE 3402
CSA STAR Attestation
CSA STAR Certification
NCSC CAF v3.1
NCSC Cyber Security v3.1
Industry-Specific Requirements
PCI P2PE
PCI PA-P2PE
PCI SSF
QPA
3-DS
SWIFT
Microsoft SSPA DPR
OWASP SAMM
Privacy & Data Protection
ISO 27701
APAC + Middle East + Europe — Country Specific
Australia
Government Cloud & Sovereignty Requirements
IRAP
Essential 8
Austria
CyberTrust
Belgium
CyFun
Canada
CCCS ITSG-33
Dubai/UAE
Government Cloud & Sovereignty Requirements
DESC
France
Industry-Specific Requirements
HDS
SecNumCloud
Germany
BSI C5
IT-Grundschutz
Industry-Specific Requirements
TISAX
Ireland
CyFun
India
CERT-IN
MeitY
Italy
ACN
Japan
Government Cloud & Sovereignty Requirements
ISMAP
Netherlands
Government Cloud & Sovereignty Requirements
ABDO
BIO (Baseline Informatiebeveiliging Overheid)
Portugal
QNRCS
Saudi Arabia
Government Cloud & Sovereignty Requirements
CCC
ECC
SAMA CSF
Singapore
Government Cloud & Sovereignty Requirements
MTCS
Spain
ENS
Switzerland
DTL
UK
Cyber Essentials+
Crown Commercial Services
MoD compliance requirements
Coalfire provides a combination of assessment and advisory services for the frameworks listed above, including those offered through our global partners.
Contact us to learn more.
Our Top Frameworks
FedRAMP
FedRAMP empowers agencies to confidently use modern cloud technologies, emphasizing security and the protection of federal information. Coalfire, a market leader as a FedRAMP Third Party Assessment Organization (3PAO) and advisory firm, provides expert-led services including FedRAMP advisory, security control assessments, vulnerability scans, and penetration testing to help Cloud Service Providers (CSPs) successfully expand into federal markets.
PCI
PCI (Payment Card Industry) Security Standards are technical and operational requirements set by the PCI Security Standards Council (PCI SSC) to protect cardholder data. The PCI DSS (Data Security Standard) applies to all entities that store, process, transmit, and may impact cardholder data security.
HITRUST
The foundation of the HITRUST Assurance Program is the HITRUST Framework (HITRUST CSF). It provides a comprehensive, flexible, and efficient approach to compliance and risk management that has been adopted on a global scale.
ISO
ISO 27001 is a universal standard built for organizations around the globe to establish, maintain, and continually improve their information security management system (ISMS).
SOC
System and Organization Controls report (SOC 1, SOC 2, or SOC 3) is a widely recognized examination that helps promote trust and confidence in your organization’s cybersecurity and financial controls. SOC reports conform to prescribed reporting standards issued by the American Institute of CPAs (AICPA). Coalfire Controls, an affiliate of Coalfire, is a fully licensed, accredited CPA firm with experienced cybersecurity professionals who can examine and report on your organization's controls that protect sensitive data.
NIST CYBERSECURITY FRAMEWORK (CSF)
The U.S. National Institute of Standards and Technology (NIST) developed the NIST Cybersecurity Framework (also known as the NIST Risk Management Framework) in response to a 2013 initiative from former President Obama. The initiative called for the government and the private sector to collaborate in the fight against cyber risk.
NIST AI RMF
For organizations that are incorporating AI into their products and processes, Secureframe helps with NIST AI RMF compliance and risk management associated with AI systems.
CSA STAR ATTESTATION
The Security, Trust, Assurance, and Risk (STAR) Registry is a publicly accessible registry that documents the security and privacy controls provided by popular cloud computing offerings.
STAR encompasses the key principles of transparency, rigorous auditing, and harmonization of standards outlined in the Cloud Controls Matrix (CCM).
DORA
EU Digital Operational Resilience Act (DORA) is a regulation aimed at enhancing the operational resilience of financial institutions in the European Union in order to withstand and recover from various disruptions and threats.
IRAP
The Australian Signals Directorate (ASD), via the Infosec Registered Assessors Program (IRAP), provides organizations with access to cyber security professionals to conduct high-quality, independent security assessment services.
An IRAP security assessment helps organizations understand their system’s security strengths and weaknesses and provides recommendations that can be utilized as part of their organizational security program.
Contact Us
Grab a free consultation with one of our compliance experts across 100+ frameworks. Ask how you can cut costs and time with streamlined operations through our Compliance Essentials platform.
