AuditXYZ

Security & Governance Frameworks

Comprehensive guide to security and governance frameworks including ISO 27001, SOC 2, NIST CSF, CMMC, NIS2, DORA, and more. Learn which framework fits your organization's security posture and compliance requirements.

22 frameworks

SOC 2

SOC 2: The Complete Guide to Compliance

$15,000–$120,000

SOC 2 is the leading security compliance framework for SaaS companies selling to US enterprises. This guide covers Type I vs Type II, trust service criteria, costs, and the audit process.

Learn more

ISO 27001

ISO 27001: The Complete Guide to Certification

$20,000–$150,000

ISO 27001 is the international gold standard for information security management. This guide covers everything from scoping to certification, with real costs, timelines, and practical implementation advice.

Learn more

NIST CSF

NIST Cybersecurity Framework (CSF): Complete Guide

$10,000–$100,000

The NIST Cybersecurity Framework provides a flexible, risk-based approach to managing cybersecurity risk. Learn how CSF 2.0 helps organizations of all sizes improve their security posture.

Learn more

CMMC

CMMC: Cybersecurity Maturity Model Certification Guide

$20,000–$300,000

CMMC 2.0 is the DoD's framework for verifying cybersecurity practices among defense contractors. Learn about the three certification levels and how to prepare for assessment.

Learn more

CIS Controls

CIS Critical Security Controls: Implementation Guide

$5,000–$75,000

CIS Critical Security Controls provide a prioritized set of 18 cybersecurity best practices. Learn how to implement CIS Controls v8.1 based on your organization's size and resources.

Learn more

COBIT

COBIT 2019: IT Governance Framework Guide

$25,000–$200,000

COBIT 2019 is a leading IT governance framework that aligns IT with business objectives. Learn how its 40 governance and management objectives improve enterprise IT performance.

Learn more

COSO

COSO Internal Control Framework: Complete Guide

$25,000–$250,000

COSO Internal Control - Integrated Framework is the standard for designing and evaluating internal controls, especially for SOX compliance. Learn its five components and 17 principles.

Learn more

Cyber Essentials

Cyber Essentials: UK Government Cybersecurity Certification

$500–$10,000

Cyber Essentials is the UK government-backed certification covering five essential cybersecurity controls. Learn about basic and Plus certification levels and their requirements.

Learn more

DORA

DORA: Digital Operational Resilience Act Guide

$50,000–$500,000

DORA establishes ICT risk management and resilience requirements for EU financial entities. Learn how to comply with this regulation covering testing, incidents, and third-party risk.

Learn more

Essential Eight

Essential Eight: Australian Cybersecurity Maturity Model

$10,000–$100,000

The Essential Eight is Australia's prioritized cybersecurity mitigation strategies from ASD. Learn how to implement these eight controls across four maturity levels.

Learn more

IRAP

IRAP: Australian Government Security Assessment Guide

$50,000–$300,000

IRAP is Australia's framework for assessing ICT systems handling government data. Learn how IRAP assessments work and what cloud providers need to serve Australian government clients.

Learn more

ISO 22301

ISO 22301: Business Continuity Management Guide

$20,000–$120,000

ISO 22301 is the international standard for business continuity management systems. Learn how to build organizational resilience through structured continuity planning and testing.

Learn more

ISO 27002

ISO 27002: Guide to Information Security Controls

$5,000–$50,000

ISO 27002 provides detailed implementation guidance for the 93 information security controls referenced by ISO 27001. Learn how to use it as your control selection and implementation companion.

Learn more

ISO 27017

ISO 27017: Cloud Security Controls Guide

$15,000–$80,000

ISO 27017 provides cloud-specific security controls and implementation guidance for cloud service providers and customers. Learn how it extends ISO 27001 for cloud environments.

Learn more

ISO 27018

ISO 27018: Protecting Personal Data in the Cloud

$15,000–$75,000

ISO 27018 sets controls for protecting personally identifiable information in public cloud services. Learn how it helps cloud providers demonstrate PII protection compliance.

Learn more

ISO 27701

ISO 27701: Privacy Information Management System Guide

$25,000–$150,000

ISO 27701 extends ISO 27001 with a privacy information management system (PIMS). Learn how it helps organizations demonstrate GDPR compliance and manage personal data responsibly.

Learn more

ISO 31000

ISO 31000: Risk Management Framework Guide

$10,000–$80,000

ISO 31000 provides universal risk management principles and guidelines applicable to any organization. Learn how to implement a structured approach to identifying and treating risks.

Learn more

NIS2

NIS2 Directive: EU Cybersecurity Regulation Guide

$30,000–$250,000

NIS2 is the EU directive expanding cybersecurity obligations to more sectors and introducing stricter incident reporting. Learn who it affects and what compliance requires.

Learn more

NIST 800-171

NIST SP 800-171: Protecting Controlled Unclassified Information

$30,000–$300,000

NIST SP 800-171 defines 110 security requirements for protecting CUI in nonfederal systems. Essential reading for any organization handling controlled unclassified information.

Learn more

NIST 800-53

NIST SP 800-53: Security and Privacy Controls Guide

$50,000–$500,000

NIST SP 800-53 Rev 5 defines over 1,000 security and privacy controls for federal systems and organizations. Learn how to navigate control baselines and implement effectively.

Learn more

SOC 1

SOC 1: Guide to Financial Reporting Controls

$30,000–$200,000

SOC 1 (SSAE 18) examines controls at service organizations relevant to financial reporting. Learn when you need a SOC 1 report versus SOC 2 and what the audit involves.

Learn more

SOC 3

SOC 3: Public Trust Services Report Guide

$20,000–$100,000

SOC 3 is the publicly shareable version of SOC 2, providing a general-use trust services report. Learn when SOC 3 adds value and how it differs from SOC 2.

Learn more

Not sure which to pick? Get a personalised recommendation.

By submitting, you agree to our privacy policy.