Cybersecurity Standards
Cybersecurity Standards captures the public, machine-readable, and reference frameworks that establish best practices for protecting information systems, networks, software, and data from cyber threats. The landscape is anchored by U.S. National Institute of Standards and Technology (NIST) publications such as the Cybersecurity Framework (CSF) 2.0, SP 800-53 controls, SP 800-171 controls for controlled unclassified information, the Risk Management Framework (RMF), and the Secure Software Development Framework (SSDF SP 800-218); the international ISO/IEC 27001 / 27002 information security management standard family; the Center for Internet Security (CIS) Critical Security Controls and Benchmarks; the OWASP Top 10 and ASVS for application security; PCI DSS for payment data; HITRUST CSF for healthcare; SOC 2 trust services criteria; and FedRAMP / StateRAMP for cloud authorization. This index aggregates authoritative URLs, machine-readable artifacts (e.g., OSCAL), and cross-references for organizations building or auditing cybersecurity programs.
Resources
-
NIST Cybersecurity Framework (CSF) 2.0
The NIST Cybersecurity Framework 2.0 is a voluntary risk-based framework organizing cybersecurity activities into six core functions (Govern, Identify, Protect, Detect, Respond, Recover) with categories and subcategories. NIST publishes in…
-
NIST SP 800-53 Security and Privacy Controls
NIST Special Publication 800-53 Revision 5 catalogs security and privacy controls for information systems and organizations. Used as the basis of FedRAMP authorizations and Risk Management Framework implementations. Available in machine-re…
-
NIST SP 800-171 Protecting CUI
NIST SP 800-171 specifies requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems. Forms the basis of CMMC (Cybersecurity Maturity Model Certification) for the U.S. defense industrial base.
-
NIST SP 800-218 Secure Software Development Framework (SSDF)
NIST SP 800-218 defines the Secure Software Development Framework (SSDF), a set of high-level secure-development practices referenced by U.S. Executive Order 14028 and procurement attestations.
-
ISO/IEC 27001 Information Security Management
ISO/IEC 27001 is the international standard for information security management systems (ISMS). The 2022 revision aligns Annex A controls with the ISO/IEC 27002:2022 catalog. Certification is performed by accredited bodies.
-
CIS Critical Security Controls and Benchmarks
The Center for Internet Security publishes the Critical Security Controls (currently v8.1) and a library of CIS Benchmarks providing prescriptive secure configuration guidance for OSes, cloud platforms, and applications.
-
OWASP Top 10 and ASVS
OWASP publishes the Top 10 web application risks, the API Security Top 10, and the Application Security Verification Standard (ASVS) used as a baseline for application security reviews.
-
PCI DSS Payment Card Industry Data Security Standard
PCI DSS, maintained by the PCI Security Standards Council, defines requirements for organizations that store, process, or transmit cardholder data. Version 4.0.1 is the current edition.
-
SOC 2 Trust Services Criteria
SOC 2 (System and Organization Controls 2) reports are issued by AICPA-licensed auditors against the Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy). Widely adopted by SaaS vendors.
-
FedRAMP Federal Cloud Authorization
The Federal Risk and Authorization Management Program provides a standardized approach for U.S. federal agencies to authorize cloud services, anchored on NIST SP 800-53 baselines.
Links
Providers working in Cybersecurity Standards
Providers whose own tags share at least two of this topic's tags, most shared first — the top 30 of 195.
| Provider | About | Rating | APIs |
|---|---|---|---|
| Secureframe | Secureframe automates security and privacy compliance for SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, FedRAMP, NIST 800-171 and more. Its Public API is a 112-operation, JSON:API-shaped REST contract over the compliance record of truth —… | strong | 1 |
| Drata | Drata is a continuous security and compliance automation platform supporting SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and more, with policies, evidence, and trust center. Drata exposes a public REST API plus the SafeBase Trust API (acquired… | exemplar | 3 |
| RegScale | RegScale is a Continuous Controls Monitoring (CCM) and compliance-automation company whose cloud-native, OSCAL-native GRC platform keeps organizations continuously audit-ready by turning compliance documentation into living, machine-readab… | developing | 3 |
| Carbide | Carbide (carbidesecure.com) is a compliance-automation and risk-management platform that pairs software with credentialed security advisors to help fast-growing organizations achieve and maintain security certifications and regulatory comp… | emerging | 0 |
| Cleardata | ClearDATA is healthcare's dedicated cloud security, compliance, and operations partner, helping providers, payers, health-tech software companies, medical device makers, and life sciences organizations build and run on AWS, Microsoft Azure… | emerging | 0 |
| Scytale | Scytale is an AI-powered Governance, Risk, and Compliance (GRC) platform that automates security compliance for cloud and SaaS companies. It combines AI agents with in-house compliance experts to automate evidence collection, continuous co… | emerging | 0 |
| Sprinto | Sprinto is a security and compliance automation platform supporting SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, and more. Sprinto offers an API for building custom compliance and risk workflows; specific public reference docs are limited and r… | emerging | 1 |
| Svix | Svix is an enterprise webhooks-as-a-service platform on the sending side of the webhook market. It provides a single API for delivering reliable, secure, low-latency webhooks at scale, with hosted UIs (Consumer App Portal), a polyglot SDK… | exemplar | 1 |
| anecdotes | anecdotes is an enterprise Governance, Risk and Compliance (GRC) platform, founded in 2020 and headquartered in Tel Aviv, that pairs a GRC data engine with AI agents to replace point-in-time audit cycles with continuous, evidence-backed co… | strong | 3 |
| FormAssembly | FormAssembly is an enterprise form and data collection platform with a REST API for managing forms, exporting submission data, handling Salesforce integrations, and building compliant data collection workflows. The API supports OAuth2 auth… | developing | 1 |
| VISO Trust | VISO TRUST is an AI-powered third-party risk management (TPRM) platform that helps security teams assess and continuously monitor vendor risk across third, fourth, and nth parties. Its Artifact Intelligence AI engine reads vendor security… | developing | 1 |
| Heidi Health | Heidi Health is a Melbourne, Australia-founded AI care partner for clinicians, founded in 2019 by Dr. Tom Kelly (CEO), Waleed Mussa (CFO), and Yu Liu (CTO). The product began as an ambient AI medical scribe and now spans four capability su… | developing | 1 |
| Vanta | Vanta is a trust management platform that automates security compliance for frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR. The Vanta API enables organizations to programmatically manage their compliance posture, automate… | developing | 2 |
| Google Cloud Assured Workloads | Google Cloud Assured Workloads enables organizations to create and manage compliance-controlled environments on Google Cloud. It provides guardrails for regulatory compliance frameworks such as FedRAMP, HIPAA, CJIS, ITAR, and others by enf… | developing | 1 |
| SecurityScorecard | SecurityScorecard is a cybersecurity ratings and third-party risk management platform that continuously rates the security posture of any company from the outside in, producing an A-F security score across ten risk factors. Its REST API (b… | developing | 1 |
| Nucleus Security | Nucleus Security is a risk-based vulnerability and exposure management platform that unifies findings from across an organization's scanning estate - network, application, cloud, container and penetration-test tooling - into a single norma… | thin | 2 |
| Anitian | Anitian, Inc. is a Portland, Oregon cloud security and compliance automation company that helps SaaS providers reach and maintain U.S. federal compliance. Its FedFlex platform automates the FedRAMP lifecycle — pre-engineered AWS and Azure… | thin | 2 |
| Cynomi | Cynomi is an AI-powered, automated virtual CISO (vCISO) platform built for MSPs, MSSPs, and cybersecurity consultancies to deliver scalable security and compliance services to their clients. The platform automates risk assessments, generat… | emerging | 1 |
| Thoropass | Thoropass is an auditor-led, AI-powered compliance and audit automation platform that combines software with expert auditor services. Its products span continuous compliance monitoring and alerting, automated evidence collection, a global… | emerging | 1 |
| Risk Ledger | Risk Ledger is a London-based third-party and supply chain risk management platform that helps organizations assess, monitor, and continuously manage the security risks across their supplier networks. Through its "Active Supply Chain Secur… | emerging | 0 |
| Hyperproof | Hyperproof is a continuous compliance and risk management platform that automates evidence collection, control management, and audit workflows. It exposes a public REST API covering 20+ resources (Controls, Policies, Programs, Risks, Proof… | emerging | 2 |
| Tugboat Logic | Tugboat Logic is a security assurance and compliance automation platform acquired by OneTrust in 2021. It supports SOC 2, ISO 27001, HIPAA, GDPR, and NIST. As of 2024, the product has been rebranded under OneTrust's Certification Automatio… | emerging | 1 |
| Cowbell | Cowbell is a Pleasanton, California-based adaptive cyber insurance provider serving small and medium-sized businesses (SMBs) and the middle market with standalone cyber liability coverage, technology errors & omissions (Tech E&O), manageme… | minimal | 0 |
| Alyne | Alyne is a cloud-native governance, risk and compliance (GRC) platform, founded in Munich in 2015 and acquired by Mitratech in 2021, where it is now offered as Mitratech's Alyne. The platform pairs a large curated library of controls and r… | minimal | 0 |
| Paubox | Paubox is a HIPAA compliant, HITRUST certified email infrastructure company serving healthcare organizations in the United States. Its products encrypt outbound email without recipient portals, passwords, or plugins, and work alongside Goo… | exemplar | 3 |
| OneTrust | OneTrust is an enterprise trust, privacy, and AI-governance platform. Its developer portal publishes 37 downloadable OpenAPI definitions covering roughly 631 operations across Universal Consent & Preference Management, Cookie Consent / CMP… | exemplar | 37 |
| Microsoft Azure Health Data Services | Microsoft Azure Health Data Services is a cloud-based suite of managed API services built on open healthcare standards (FHIR R4, DICOM, HL7) that enables healthcare organizations to collect, store, analyze, and exchange protected health in… | strong | 2 |
| xCures | xCures operates the Clinical Clarity Engine, an AI platform that retrieves, organizes and structures fragmented patient medical records into decision-ready clinical data. Founded in 2018 and headquartered in Oakland, California, the compan… | strong | 1 |
| Spruce Health | Spruce Health is a HIPAA-compliant healthcare communication platform that unifies phone, SMS, secure messaging, video, e-fax, team chat, mobile payments and VoIP phone lines into one system for medical practices, with AI-enabled voicemail… | strong | 16 |
| Dun & Bradstreet | Dun & Bradstreet is a leading global provider of business decisioning data and analytics, anchored by the D-U-N-S Number — a unique nine-digit identifier assigned to more than 500 million businesses worldwide. Founded in 1841 as The Mercan… | strong | 1 |