| Australian Information Security Manual | Australia | 1081 | kit |
| FFIEC Cybersecurity Assessment Tool (CAT) | United States (FFIEC member agencies; voluntary self-assessment for financial institutions) | 595 | kit |
| FFIEC IT Examination Handbook | United States (FRB, FDIC, NCUA, OCC and state banking supervisors) | 538 | kit |
| BRCGS Global Standard for Food Safety Issue 9 | International (BRCGS, GFSI-benchmarked; sites in over 130 countries) | 455 | kit |
| FedRAMP High | United States | 410 | kit |
| PCI P2PE | Global (PCI Security Standards Council; P2PE solution providers, component providers, application vendors and merchants operating merchant-managed solutions) | 407 | |
| IEC 62443 | International (IEC TC 65/WG 10 with ISA99); adopted as EN IEC 62443 | 399 | kit |
| PCI PIN Security | Global (PCI Security Standards Council; acquirers and their agents processing PINs, key-injection facilities and certification authorities) | 399 | kit |
| Fair Labor Association (FLA) Workplace Code of Conduct | Global (facilities of FLA-affiliated companies and their suppliers) | 380 | |
| FBI CJIS Security Policy | United States (FBI CJIS Division; every CJIS Systems Agency, criminal and noncriminal justice agency and contractor with CJI access) | 376 | kit |
| COBIT 2019 | Global (ISACA) | 342 | kit |
| FedRAMP Moderate | United States | 323 | |
| NIST SP 800-53 Rev 5 | United States | 320 | kit |
| Automotive SPICE (ASPICE) v4.1 | Global (VDA QMC; automotive OEMs and their suppliers, intacs assessment scheme) | 318 | |
| NIST SP 800-53 Revision 5.1 HIGH | United States | 317 | |
| SSAE 18 | United States (AICPA attestation standards; every CPA attestation engagement, including SOC 1, SOC 2 and SOC 3) | 308 | kit |
| IAIS Insurance Core Principles (ICPs) | International (IAIS members; assessed by the IMF and World Bank under the FSAP) | 280 | kit |
| NIST SP 800-53 Rev 5 MODERATE | United States | 275 | |
| GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6 | International (GLOBALG.A.P. c/o FoodPLUS GmbH, Cologne) | 275 | |
| ISO 19650 | International (ISO/TC 59/SC 13); adopted as EN ISO 19650 with national annexes, BS EN ISO 19650 (UK), AS ISO 19650 and others | 256 | kit |
| PCI DSS 4.0 | International | 249 | kit |
| IATA Operational Safety Audit (IOSA) Standards Manual | International (IATA member and non-member airlines, IOSA Registry) | 223 | |
| NFPA 1600 | United States (ANSI-accredited; used internationally) | 220 | kit |
| ISO 26262:2018 | International (ISO/TC 22/SC 32); adopted as GB/T 34590 (China, MOD), BS ISO 26262 and others | 217 | |
| EN 50126 / EN 50128 / EN 50129 | European Union (CENELEC), applied internationally | 210 | |
| Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 | International | 197 | |
| ISO 15189:2022 | International (ISO/TC 212); adopted as EN ISO 15189:2022, AS ISO 15189:2023, I.S. EN ISO 15189:2022 and others | 195 | |
| GLI-33 | International (adopted by state and national gaming regulators) | 195 | kit |
| NIST SP 800-161 Rev 1 | United States | 191 | kit |
| ISO/SAE 21434 | International (ISO/TC 22/SC 32 with SAE International) | 183 | |
| BSI IT-Grundschutz | Germany (used across the German-speaking countries and by German public bodies under the UP Bund) | 180 | kit |
| MTCS (Singapore) | Singapore | 175 | |
| NIST SP 800-53 Rev 5 LOW | United States | 173 | |
| ISO 22313:2020 | International (ISO/TC 292); adopted as EN ISO 22313:2020 and nationally (BS EN, DIN EN, UNE-EN, SIST EN, I.S. EN, AS ISO, DSTU EN ISO 22313:2021 and others) | 163 | |
| API 1164 | United States (API; referenced by the TSA Pipeline Security Guidelines and used internationally) | 163 | kit |
| IEC 62304:2015 Medical Device Software Lifecycle Processes | International (IEC); harmonised as EN 62304 under the EU MDR; FDA recognised consensus standard; adopted as ANSI/AAMI/IEC 62304 and nationally | 158 | |
| PCI SSF | Global (PCI Security Standards Council; payment software vendors seeking validation and listing) | 156 | |
| IEC 60601-1 | International (IEC); adopted as EN 60601-1, ANSI/AAMI ES60601-1, CSA C22.2 No. 60601-1 and nationally | 156 | kit |
| ISO 26000:2010 | International (ISO/TMB WG SR; adopted as NF, SIST, NEN, BS, AS and other national standards) | 155 | |
| CIS Controls v8 | International | 153 | kit |
| ISO 14064 | International (ISO/TC 207/SC 7); adopted as EN ISO 14064, CSA ISO 14064, JIS Q 14064, AS ISO 14064 and others | 150 | kit |
| GAMP 5 | International (pharmaceutical, biotechnology and medical device industry guidance) | 147 | |
| ISO 27001:2013 | International | 140 | |
| ISO 27701:2019 | International | 139 | kit |
| ISO 37000:2021 | International (ISO/TC 309); adopted as BS ISO 37000:2021, SIST ISO 37000:2021 and others | 139 | |
| DAMA-DMBOK2 | Global (DAMA International; data management profession) | 136 | kit |
| ISO 56002 | International (ISO/TC 279); adopted as EN ISO 56002:2021, AS ISO 56002:2020, I.S. EN ISO 56002:2021 and others | 130 | kit |
| ISO 27799:2025 | International (ISO/TC 215) | 130 | |
| IATF 16949:2016 | Global (IATF member OEM supply chains; organizations manufacturing automotive products for automotive customers) | 130 | |
| ISO/IEC 29115:2013 | International (ISO/IEC JTC 1/SC 27 with ITU-T SG 17) | 130 | |
| ISO 8000 | International (ISO/TC 184/SC 4) | 126 | |
| C5 (Germany) | Germany | 121 | |
| ISO 27001:2022 | International | 121 | kit |
| AS9100D | Global (IAQG member companies' supply chains; organizations designing, developing or providing aviation, space and defense products and services) | 121 | kit |
| ITIL 4 | Global (PeopleCert; IT service management) | 117 | kit |
| ISO/IEC 27701:2025 | International | 117 | |
| BREEAM | International (BRE Global; UK origin; national scheme operators in Sweden, the Netherlands, Norway, Spain, Germany, Austria and the USA) | 115 | |
| ISAE 3402 | International (IAASB); adopted identically in Australia, New Zealand, Singapore, India, Brazil, Thailand, Japan and elsewhere | 114 | |
| ISO 27018:2019 | International | 113 | kit |
| CMMC 2.0 | United States | 110 | |
| ISO/IEC 23894:2023 | International | 110 | kit |
| ISO/IEC 29147:2018 | International (ISO/IEC JTC 1/SC 27); adopted as EN ISO/IEC 29147:2020 and nationally | 110 | |
| ISO/IEC 27006-1:2024 | International | 110 | |
| ISO 37002:2021 | International (ISO/TC 309); adopted as BS ISO 37002:2021 and others | 109 | |
| IEC 62351 | International (IEC TC 57 WG15); adopted as EN IEC 62351 | 109 | kit |
| ISO/IEC 27007:2020 | International | 107 | |
| NIST Cybersecurity Framework 2.0 | United States | 106 | kit |
| ISO 20400:2017 | International (ISO/PC 277); adopted as AS ISO 20400:2018, BS ISO 20400:2017 and others | 106 | |
| Egypt Personal Data Protection Law (Law No. 151 of 2020) | Egypt (with extraterritorial reach to processing of Egyptians' and Egyptian residents' data) | 105 | kit |
| ISO/IEC 20000-1:2018 | International (ISO/IEC JTC 1/SC 40); adopted nationally (JIS Q 20000-1, EN ISO/IEC 20000-1 and others) | 101 | |
| ISO/IEC 27043:2015 | International (ISO/IEC JTC 1/SC 27) | 100 | |
| ISO/IEC 27010:2015 | International | 99 | |
| China Personal Information Protection Law (PIPL) | People's Republic of China (with extraterritorial reach under Article 3(2)) | 98 | kit |
| HKMA SPM | Hong Kong SAR | 98 | |
| NIST SP 800-171 Rev 3 | United States | 97 | kit |
| NIST SP 800-171A | United States | 97 | |
| ISO 27002:2022 | International | 96 | kit |
| ISO/IEC 27011:2024 | International | 96 | |
| EU Batteries Regulation (Regulation (EU) 2023/1542) | European Union | 96 | |
| ISO/IEC 27004:2016 | International | 94 | |
| ISO 37003:2025 | International | 94 | |
| ISO 22320:2018 | International (ISO/TC 292); adopted as BS ISO, DIN ISO, SS ISO (Singapore, 2022), SSB ISO, GTC ISO (Panama) and GB/T (China) | 91 | |
| NIST SP 800-171 | United States | 88 | kit |
| ISO 41001:2018 | International (ISO/TC 267); adopted as EN ISO 41001:2018 (BS, DIN, SIST, I.S.) and others | 86 | |
| ISO 27017:2015 | International | 86 | kit |
| Azure Security Benchmark | International | 85 | |
| ISO 39001:2012 | International (ISO/TC 241); adopted as IRAM-ISO 39001:2015, BS ISO 39001:2012, UNE-ISO 39001 and others | 83 | |
| ISO/IEC 29134:2023 | International (ISO/IEC JTC 1/SC 27); adopted as CSA ISO/IEC 29134:24 and nationally | 83 | |
| ISO 28001:2007 Supply Chain Security Management | International (ISO/TC 8, now ISO/TC 292); adopted as BS ISO 28001:2007, SIST ISO 28001:2008 and others | 82 | |
| ISO/IEC 42001:2023 | International | 79 | kit |
| ISO 10006:2003 | International | 79 | |
| ISO 30401 | International (ISO/TC 260); adopted as DIN ISO 30401:2021, BS ISO 30401:2018 and others | 78 | kit |
| 21 CFR Part 211 | United States | 78 | kit |
| ASIS SPC.1-2009 | United States (ANSI-accredited standard, used internationally; adopted under DHS PS-Prep in 2010) | 77 | |
| ISO 10006:2017 | International | 77 | |
| ISO/IEC 42006:2025 | International | 77 | |
| ISO/TS 22318:2021 | International (ISO/TC 292); adopted as PD ISO/TS 22318 (UK) and by other national bodies | 76 | |
| SOC 1 (SSAE 18 / ISAE 3402) | United States (AICPA) and international (IAASB); used worldwide by service organisations serving audited user entities | 76 | |
| DO-178C / ED-12C | International (civil aviation; FAA, EASA and other authorities) | 76 | |
| ISO 27018 | International | 75 | kit |
| EASA Part-IS | European Union (EASA Member States) | 74 | kit |
| ISO/IEC 27557:2022 | International (ISO/IEC JTC 1/SC 27) | 74 | |
| ISO 13485:2016 | International | 73 | kit |
| ISO/IEC 17025:2017 | International | 73 | kit |
| NIST AI Risk Management Framework (AI RMF 1.0) | United States (NIST) | 72 | |
| COSO Internal Control | Global (COSO; used for SOX 404 ICFR assessments in the United States and for internal control generally) | 72 | kit |
| ISO/TS 22317:2021 | International (ISO/TC 292); adopted as PD ISO/TS 22317 (UK) and by other national bodies | 72 | |
| DISA Security Technical Implementation Guides (STIGs) | United States (Department of Defense; used by other federal agencies and adopters) | 72 | |
| SASB Standards | International | 69 | |
| NAIC Insurance Data Security Model Law (MDL-668) | United States (NAIC model, enacted by states) | 68 | kit |
| HIPAA Security Rule | United States | 67 | kit |
| ISO/IEC 38500:2024 | International | 67 | kit |
| ISO/IEC 27019:2024 | International (ISO/IEC JTC 1/SC 27) | 67 | |
| EU ESPR (Regulation (EU) 2024/1781) | European Union | 67 | |
| ISO/IEC 30111:2019 | International (ISO/IEC JTC 1/SC 27); adopted as EN ISO/IEC 30111:2020 and nationally (DIN EN ISO/IEC 30111:2020 held) | 66 | |
| Aged Care Quality Standards (Australia) | Australia | 66 | kit |
| NIST SP 800-66 Rev 2 | United States | 65 | kit |
| ISO/IEC TR 24028:2020 | International | 65 | kit |
| FedRAMP Rev 5 | United States federal government | 65 | |
| FISMA | United States federal government | 65 | kit |
| EU AI Act | European Union | 64 | kit |
| NIS2 Directive | European Union | 64 | kit |
| EU Better Internet for Kids (BIK+) Strategy | European Union | 64 | kit |
| ISO/IEC 29100:2024 | International (ISO/IEC JTC 1/SC 27) | 64 | |
| FATF 40 Recommendations | Global (FATF members, FATF-style regional body members; more than 200 jurisdictions committed) | 64 | kit |
| ISO/IEC 27040:2024 | International | 64 | |
| AWS Well-Architected Security Pillar | International | 63 | kit |
| IFRS 17 | International (IFRS Foundation) | 63 | kit |
| SOC 2 | United States | 61 | kit |
| ISO 50001:2018 | International | 61 | kit |
| EMV 3-D Secure (3DS) | Global (payment systems participating in EMVCo) | 61 | |
| Cyber Security Act 2024 (Australia) | Australia (Commonwealth) | 61 | kit |
| ISO 37500:2014 | International | 61 | |
| EDPB Guidelines 1/2026 on processing of personal data for scientific research purposes | European Union and EEA | 60 | |
| ISO/IEC 27014:2020 | International | 60 | |
| APEC Cross-Border Privacy Rules (CBPR) System | Asia-Pacific (APEC) | 59 | kit |
| ISO/IEC 27031:2025 | International | 59 | |
| ISO 9001:2015 | International | 58 | kit |
| ISO/IEC 25012:2008 | International (ISO/IEC JTC 1/SC 7); adopted as JIS X 25012:2013 and as national standards | 58 | |
| ISO 22316 | International (ISO/TC 292); adopted as BS ISO 22316:2017 (UK), UNE-ISO 22316:2020 (Spain) and by other national bodies | 58 | |
| Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) | Switzerland | 56 | |
| ISO 22361:2022 | International | 56 | |
| ISO 30414:2018 | International (ISO) | 56 | |
| ISO 22000:2018 | International | 55 | kit |
| ISO 19011:2026 | International | 55 | |
| Rwanda DPL | Rwanda | 55 | |
| eIDAS 2.0 | European Union | 53 | |
| ISO/IEC 27400:2022 | International (ISO/IEC JTC 1/SC 27) | 53 | |
| IEEE 7000 | International | 53 | kit |
| FATF Recommendation 16 | Global (FATF members and FSRB members; transposed by national law) | 53 | |
| ISO 28000:2022 | International | 53 | |
| NIST SP 800-181 | United States | 52 | kit |
| NIST SP 800-207 | United States | 51 | kit |
| AASB S2 Climate-related Disclosures | Australia | 51 | kit |
| Philippines Data Privacy Act | Philippines | 51 | |
| ESRB Privacy Certified | United States (COPPA safe harbor; participants worldwide) | 50 | kit |
| Nigeria Data Protection Act 2023 (NDPA) | Nigeria | 50 | |
| ISO 37101:2016 | International | 50 | |
| ISO 22301:2019 | International | 49 | kit |
| ISO 19011:2018 | International | 49 | kit |
| ISO 37301:2021 | International | 49 | kit |
| ISO/IEC 27003:2017 | International | 49 | |
| NIST SP 800-160 | United States | 49 | kit |
| Senge Fifth Discipline | International | 49 | |
| Heifetz Adaptive Leadership Framework | International | 49 | |
| ISO 37001:2025 | International | 49 | |
| ISO 37009:2025 | International | 49 | |
| ISO 9001 | International | 48 | kit |
| Administrative Measures for the Security Assessment of Generative AI Services (2023) and Algorithmic Recommendation Management Provisions (2022) | China | 48 | |
| NIST SP 800-82 Rev 3 | United States | 48 | kit |
| COSO Enterprise Risk Management (ERM) Framework (2017) | Global (COSO; entities of every type and size) | 48 | |
| China Cybersecurity Law (CSL) | People's Republic of China (with overseas liability under Article 77 as amended) | 47 | kit |
| FTC GLBA Safeguards Rule (16 CFR Part 314) | United States (FTC-jurisdiction financial institutions) | 47 | |
| ISO/IEC 27017:2026 | International | 47 | |
| ISO/IEC 27050-1:2019 | International | 47 | |
| ISO 14004:2016 | International | 46 | kit |
| CISA Zero Trust Maturity Model | United States | 46 | kit |
| ISO/IEC 27018:2025 | International | 46 | |
| DoD Zero Trust Reference Architecture | United States | 45 | kit |
| NIST SP 800-190 | United States | 45 | kit |
| SQF Code Edition 9 | International (GFSI-benchmarked) | 45 | |
| South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics | South Korea (KISO — self-regulatory) | 45 | |
| Belgium CyberFundamentals | Belgium | 44 | kit |
| Bank Secrecy Act / Anti-Money Laundering (BSA/AML) | United States | 44 | |
| NIST SP 1800-32 | United States | 44 | kit |
| Act on the Implementation of the General Data Protection Regulation (OG 42/2018) | Croatia | 44 | |
| Singapore Government Instruction Manual on ICT&SS Management (IM8) | Singapore (GovTech) | 44 | |
| Automotive SPICE for Cybersecurity PAM v2.0 | International (VDA QMC, Germany; automotive supply chain) | 44 | |
| 3GPP 5G Security Architecture (TS 33.501) | International (3GPP) | 43 | kit |
| APRA CPS 230 Operational Risk Management | Australia | 43 | kit |
| ISO 45001:2018 | International | 43 | kit |
| ISO 37301 | International | 43 | kit |
| ISO 31000 | International | 43 | kit |
| EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) | European Union (EBA) | 43 | |
| POPIA | South Africa | 43 | |
| ANSSI Guide d'hygiene informatique (42 mesures, v2.0) | France | 42 | |
| NIST SP 800-218 | United States | 42 | kit |
| EN 301 549 | European Union | 42 | kit |
| ISO 37001 | International | 42 | kit |
| Authorised Economic Operator (AEO) Programmes | International (97+ countries) | 42 | |
| ISO 27005:2022 | International | 42 | kit |
| WHO Global Competency Model | International | 42 | |
| WHO Global Strategy on Digital Health 2020-2025 | International (WHO) | 42 | |
| ISO 37004:2023 | International | 42 | |
| ISO/IEC 42005:2025 | International | 42 | |
| ISO 37001:2016 | International | 41 | kit |
| China Data Security Law (DSL) | People's Republic of China (with extraterritorial liability under Article 2) | 41 | kit |
| Critical Infrastructure Risk Management Program (CIRMP) Rules 2023 | Australia (Commonwealth) | 41 | |
| HITECH Act | United States (federal) | 41 | kit |
| Illinois Biometric Information Privacy Act (BIPA) | United States (Illinois) | 41 | kit |
| ISO 30414:2025 | International | 41 | |
| ISO 37303:2025 | International | 41 | |
| GDPR | European Union | 40 | kit |
| APRA CPS 220 Risk Management | Australia | 40 | kit |
| Australia My Health Records Act 2012 | Australia | 40 | kit |
| ISO 55001:2024 | International | 40 | |
| ISO 55001 | International | 40 | kit |
| SANS Incident Handler's Handbook and PICERL Methodology | International (SANS Institute) | 40 | |
| PDPA Singapore | Singapore | 40 | kit |
| Space ISAC (Information Sharing and Analysis Center) | International (Space Industry) | 40 | |
| Goleman Emotional Intelligence Leadership Framework | International | 40 | |
| ISO 14001:2026 | International | 40 | |
| CFTC System Safeguards (17 CFR 37, 38, 39, 49) | United States (CFTC) | 39 | |
| AML/CTF Act 2006 (Australia) | Australia | 39 | kit |
| ISO 22000 | International | 39 | kit |
| ISO 45001 | International | 39 | kit |
| NIST SP 800-128 | United States | 39 | kit |
| ISO 22739:2024 | International (ISO/TC 307) | 39 | |
| Uruguay DPL | Uruguay | 39 | |
| Texas Data Privacy Act | United States - Texas | 39 | kit |
| Turkey KVKK | Turkey | 39 | kit |
| ETSI Industry Specification Group (ISG) on Quantum Key Distribution (QKD) | Global (ETSI deliverables) | 39 | |
| ISO 10005:2018 | International | 39 | |
| ISO 22398:2013 | International | 39 | |
| ISO 37302:2025 | International | 39 | |
| ISO 10005:2005 | International | 38 | |
| UNESCO Recommendation on the Ethics of AI | International | 38 | |
| ISO/IEC 38500:2024 | International (ISO/IEC) | 38 | kit |
| Commercial National Security Algorithm Suite (CNSA) 2.0 | United States (National Security Systems) | 38 | |
| PDPA Thailand | Thailand | 38 | kit |
| ISO 46001:2019 | International | 38 | |
| ASD Strategies to Mitigate Cyber Security Incidents | Australia | 37 | kit |
| ASEAN Guide on AI Governance and Ethics | ASEAN | 37 | kit |
| ISO 27017 | International | 37 | kit |
| AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) | United States (AWWA) | 37 | |
| Saudi Arabia PDPL | Saudi Arabia | 37 | kit |
| Peru DPL | Peru | 37 | |
| BSIMM | International | 36 | |
| ISO 14001:2015 | International | 36 | kit |
| UK Cyber Essentials | United Kingdom | 36 | kit |
| Digital Services Act (DSA) | European Union | 36 | |
| VUCA Leadership Framework | International | 36 | |
| Qatar DPL | Qatar | 36 | kit |
| ISO/IEC 23837 | International (ISO/IEC) | 36 | |
| Vietnam PDPD | Vietnam | 36 | |
| Hersey & Blanchard Situational Leadership Model | International | 36 | |
| NIST SP 800-172 | United States | 35 | kit |
| Virginia CDPA | United States - Virginia | 35 | |
| CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 | United States | 35 | kit |
| FSSC 22000 | International (FSSC Foundation) | 35 | kit |
| NIST SP 800-150 | United States | 35 | kit |
| Security of Critical Infrastructure Act 2018 (SOCI) | Australia | 35 | |
| Israel Protection of Privacy Law (5741-1981) | Israel | 35 | |
| DO-326A / ED-202A | International (civil aviation; EASA, FAA, UK MAA and other authorities) | 35 | |
| UK Product Security and Telecommunications Infrastructure Act (PSTI) | United Kingdom | 35 | |
| ISO 31000:2018 | International | 34 | kit |
| NIST SP 800-124 Revision 2 | United States | 34 | |
| Argentina Law 25.326 (Personal Data Protection Law) | Argentina | 34 | |
| US Foreign Corrupt Practices Act (FCPA) | United States (Federal — DOJ/SEC) | 34 | |
| NIST SP 800-161 | United States | 34 | kit |
| Solvency II | European Union | 34 | |
| SWIFT CSCF | International | 34 | kit |
| Digital Economy Partnership Agreement (DEPA) | International - Parties: New Zealand, Singapore, Chile (signatories); South Korea (acceded 2023). Applicants: China, Canada (accession process ongoing). | 34 | kit |
| NRC 10 CFR 73.54 | United States | 33 | |
| US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements | United States (USCG) | 33 | |
| Consumer Data Right (CDR) Framework (Australia) | Australia | 33 | kit |
| ISO 37005:2024 | International | 33 | |
| NIST SP 800-187 | United States | 32 | kit |
| CCPA/CPRA | United States - California | 32 | |
| Australian Energy Sector Cyber Security Framework (AESCSF) | Australia | 32 | kit |
| Botswana Data Protection Act (2024) | Botswana | 32 | kit |
| BS 65000:2014 | United Kingdom (BSI; used internationally) | 32 | |
| FAA Aircraft Systems Information Security Protection (ASISP) | United States (FAA design approvals and operators) | 32 | |
| W3C Verifiable Credentials (VC) Data Model 2.0 | International (W3C) | 32 | |
| Canadian PIPEDA | Canada | 31 | |
| Brunei Personal Data Protection Order 2022 (PDPO) | Brunei Darussalam | 31 | kit |
| SIG (Shared Assessments) | International | 31 | |
| Full Range Leadership Model (Bass & Avolio) | International (academic and practitioner leadership theory) | 31 | |
| APPI | Japan | 30 | |
| Chile Personal Data Protection Law (Law No. 21.719) | Chile | 30 | kit |
| EU Clinical Trials Regulation (CTR 536/2014) | European Union | 30 | kit |
| ISO 19011 | International | 30 | kit |
| 21 CFR Part 58 | United States | 30 | kit |
| SEC Cybersecurity Disclosure Rule | United States | 30 | |
| NIST SP 800-53A Rev. 5 | United States | 30 | kit |
| NIST SP 800-183 | United States | 30 | kit |
| Section 508 | United States | 30 | |
| Brazil Open Finance (Resolução Conjunta No. 1/2020) | Brazil | 30 | |
| EU Audiovisual Media Services Directive (AVMSD, Directive 2010/13/EU as amended by Directive 2018/1808 and Directive (EU) 2023/2586) | European Union | 30 | |
| UAE Virtual Asset Regulatory Authority (VARA) Regulations | United Arab Emirates — Dubai | 30 | |
| UK Defence Standard 05-138 | United Kingdom (MOD) | 30 | |
| EU CSDDD (Directive (EU) 2024/1760) | European Union | 30 | |
| ISO 31022:2020 | International | 30 | |
| ASIC Cyber Resilience Good Practices | Australia | 29 | kit |
| ISO/IEC 17025:2017 | International (ISO/IEC) | 29 | |
| Bahrain PDPL | Bahrain | 29 | |
| NSA Guidance for Transition to Quantum-Resistant Cryptography | United States (National Security Agency) | 29 | |
| PTES | International | 29 | |
| TEFCA | United States (ONC) | 29 | |
| NIST SP 800-88 Rev 1 | United States | 29 | kit |
| APRA SPS 220 Risk Management (Superannuation) | Australia | 28 | kit |
| ISO 55001:2014 | International | 28 | kit |
| ENISA Data Protection Engineering | European Union (ENISA) | 28 | |
| WELL Building Standard v2 (International WELL Building Institute) | International (IWBI — 104 countries) | 28 | |
| US Gramm-Leach-Bliley Act (GLBA) | United States (Federal / FTC) | 28 | |
| African Union Malabo Convention | Africa (AU) | 28 | kit |
| Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) | Romania | 28 | |
| TNFD Recommendations | International | 28 | |
| TISAX | International (Automotive) | 28 | |
| Brazil AI Framework | Brazil | 28 | kit |
| PSD2 SCA | European Union | 28 | |
| Basel III International Banking Framework | International | 28 | kit |
| ISO/IEC 27050 | International (ISO/IEC) | 28 | kit |
| Protective Security Policy Framework (PSPF) Release 2024 | Australia | 28 | |
| Russia Federal Law on Personal Data (152-FZ) | Russia | 28 | kit |
| Samoa Telecommunications Act (2005) | Samoa | 28 | |
| Cyber Essentials Plus | United Kingdom | 28 | kit |
| ASEAN Data Management Framework | ASEAN | 27 | kit |
| Colombia Data Protection Law (Law 1581 of 2012) | Colombia | 27 | kit |
| Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct | Bermuda (BMA) | 27 | kit |
| AS9100D:2016 | International (IAQG/SAE) | 27 | |
| Connecticut Data Privacy Act (CTDPA) | United States — Connecticut | 27 | kit |
| Australia NHMRC National Statement on Ethical Conduct in Human Research | Australia (NHMRC) | 27 | |
| ISO/IEC 27031:2011 | International | 27 | |
| ISO/IEC 27701:2019 | International | 27 | kit |
| EU Data Act | European Union | 27 | kit |
| Argyris Double-Loop Learning | International | 27 | |
| EDM Council DCAM | International (EDM Council) | 27 | |
| GLBA | United States (federal) | 27 | |
| Singapore Cybersecurity Act 2018 | Singapore | 27 | kit |
| AICPA Privacy Management Framework (PMF) | United States (AICPA) | 26 | kit |
| BIMCO Cyber Security | International | 26 | kit |
| DORA | European Union | 26 | kit |
| Canada ITSG-33 | Canada (Canadian Centre for Cyber Security) | 26 | kit |
| Utah Consumer Privacy Act | United States - Utah | 26 | |
| TSA Pipeline Cybersecurity Directives | United States | 26 | |
| ISO 27005 | International | 26 | kit |
| EU In Vitro Diagnostic Medical Devices Regulation (IVDR) | European Union | 26 | kit |
| EU Medical Devices Regulation (MDR 2017/745) | European Union | 26 | kit |
| ISO 37000:2021 | International (ISO) | 26 | kit |
| UN Guiding Principles on Business and Human Rights (UNGPs) | International (United Nations) | 26 | |
| Secure by Design: A Guide for Manufacturers (CISA) | United States (Federal) | 26 | |
| IEEE 1686 | International (power sector) | 26 | kit |
| UK Building Safety Act 2022 | United Kingdom (England) | 26 | |
| UK Construction (Design and Management) Regulations 2015 (CDM 2015) | United Kingdom (HSE) | 26 | |
| EU Digital Markets Act | European Union | 26 | kit |
| EU Chips Act (Regulation (EU) 2023/1781) | European Union | 26 | |
| Vermont Artificial Intelligence and Consumer Data Act (AICDA) | United States — Vermont | 26 | |
| ICC Incoterms 2020 | International (ICC) | 26 | kit |
| Senegal Law on Personal Data Protection (Law No. 2008-12) | Senegal | 26 | |
| Serbia Law on Personal Data Protection (2018) | Serbia | 26 | kit |
| South Korea Credit Information Act | South Korea | 25 | |
| Zimbabwe Data Protection Act (2021) | Zimbabwe | 25 | |
| CWE Top 25 Most Dangerous Software Weaknesses (2024) | International | 25 | kit |
| EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) | European Union (EIOPA) | 25 | kit |
| South Korea ISMS-P | South Korea | 25 | |
| Union Customs Code (UCC) | European Union | 25 | |
| UK Open Banking Standard | United Kingdom | 25 | |
| Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) | Estonia | 25 | kit |
| Science Based Targets Initiative (SBTi) | International (SBTi) | 25 | |
| Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) | United States — Rhode Island | 25 | |
| SEC Climate Disclosure Rule | United States | 25 | |
| ACSC Essential Eight | Australia | 24 | kit |
| APRA CPS 234 | Australia | 24 | kit |
| Australia Consumer Data Right | Australia | 24 | kit |
| CNCF Security Technical Advisory Group (TAG) | International (CNCF/Linux Foundation) | 24 | |
| Uzbekistan Law on Personal Data (No. ZRU-547) | Uzbekistan | 24 | |
| CSA STAR (Security, Trust, Assurance, and Risk) | International | 24 | |
| ISO 13485 | International | 24 | kit |
| Ethiopia Personal Data Protection Proclamation (No. 1321/2024) | Ethiopia | 24 | kit |
| Bermuda Personal Information Protection Act 2016 (PIPA) | Bermuda | 24 | |
| Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP | Costa Rica | 24 | |
| EU Carbon Border Adjustment Mechanism (CBAM) | European Union | 24 | kit |
| EU Cyber Resilience Act | European Union | 24 | kit |
| US OFAC Sanctions Compliance Framework | United States (Treasury/OFAC) | 24 | kit |
| USMCA Chapter 19 | United States, Mexico, Canada | 24 | |
| EAR | United States (Commerce/BIS) | 24 | kit |
| SA8000:2014 | International (SAI) | 24 | kit |
| SLSA | International | 24 | |
| Voluntary Principles on Security and Human Rights (VPs) | International (VP Initiative) | 24 | |
| Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) | Spain | 24 | |
| Ukraine Law on Personal Data Protection (Law No. 2297-VI) | Ukraine | 24 | |
| WCO SAFE Framework of Standards to Secure and Facilitate Global Trade (2021) | International (WCO — 184 members) | 24 | |
| Wisconsin Data Privacy Act (SB 670) | United States — Wisconsin | 24 | |
| NY DFS 23 NYCRR 500 | United States | 23 | kit |
| Angola Personal Data Protection Law (Law No. 22/11) | Angola | 23 | kit |
| Barbados Data Protection Act 2019 | Barbados | 23 | kit |
| US Automated Commercial Environment (ACE) | United States (CBP) | 23 | |
| US Consumer Product Safety Commission (CPSC) | United States (CPSC) | 23 | |
| Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011) | Bosnia and Herzegovina | 23 | |
| Tanzania Personal Data Protection Act (Draft) | Tanzania | 23 | |
| South Africa Promotion of Access to Information Act (PAIA) | South Africa | 23 | |
| South Korea Cloud Security Assurance Program (CSAP) | South Korea | 23 | |
| ISO/IEC 27035-1:2023 | International | 23 | |
| Tunisia Organic Law on Personal Data Protection (Law No. 2004-63) | Tunisia | 23 | |
| UK Concordat on Open Research Data (UKRI) | United Kingdom (UKRI) | 23 | |
| C2M2 | United States | 22 | |
| Cayman Islands Data Protection Act 2017 (DPA) | Cayman Islands | 22 | kit |
| AICPA SOC 3 | United States | 22 | kit |
| CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) | United States | 22 | |
| Data Protection Act 2017 | Mauritius | 22 | kit |
| SOC for Cybersecurity | United States (AICPA) | 22 | |
| Canada's Anti-Spam Legislation (CASL) | Canada | 22 | |
| CSRD | European Union | 22 | |
| Danish Data Protection Act (Databeskyttelsesloven) | Denmark | 22 | |
| Directive (EU) 2023/970 on pay transparency | European Union | 22 | |
| EU General Product Safety Regulation (GPSR, Regulation 2023/988) | European Union | 22 | kit |
| UNICEF Policy Guidance on AI for Children (2021) | International (UNICEF) | 22 | |
| EU Markets in Crypto-Assets Regulation (MiCA) | European Union | 22 | |
| Critical Raw Materials Act (Proposed Regulation COM(2023) 192) | European Union | 22 | |
| Colorado Privacy Act | United States - Colorado | 21 | kit |
| Singapore AI Governance Framework | Singapore | 21 | kit |
| COPPA | United States | 21 | |
| Czech Republic Act on the Protection of Personal Data (Act No. 110/2019 Coll.) | Czech Republic | 21 | |
| Defence Security Principles Framework (DSPF) | Australia | 21 | kit |
| Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law | European Union | 21 | |
| EU European Media Freedom Act (EMFA) | European Union | 21 | kit |
| EU Energy Performance of Buildings Directive (EPBD Recast) | European Union | 21 | |
| Canada Artificial Intelligence and Data Act (AIDA) | Canada | 20 | kit |
| TCFD Recommendations | International | 20 | |
| Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134) | Cambodia | 20 | kit |
| Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) | Albania | 20 | |
| Belgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018) | Belgium | 20 | |
| UK Age Appropriate Design Code (Children's Code) | United Kingdom | 20 | |
| UK Security and Emergency Measures Direction (SEMD) | United Kingdom | 20 | |
| EU Machinery Regulation (Regulation (EU) 2023/1230) | European Union | 20 | |
| Regional Comprehensive Economic Partnership (RCEP) | Asia-Pacific (15 RCEP members) | 20 | |
| UK Bribery Act 2010 | United Kingdom (SFO) | 20 | kit |
| ECB TIBER-EU Framework | European Union (coordinated by ENISA, adopted by national authorities and the ECB) | 20 | |
| US ITAR and EAR | United States (State Dept/BIS) | 20 | |
| 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673) | European Union | 20 | kit |
| Science Based Targets initiative (SBTi) Corporate Standard | International (SBTi) | 20 | |
| Colorado Artificial Intelligence Act (proposed SB 24-205) | Colorado, United States | 19 | |
| IACS Unified Requirements E26/E27 | International (IACS — 12 classification societies) | 19 | |
| UK Online Safety Act 2023 | United Kingdom (Ofcom) | 19 | kit |
| Florida Digital Bill of Rights (FDBR) | United States | 19 | kit |
| EU Data Governance Act (DGA) | European Union | 19 | kit |
| EU Payment Services Directive (PSD2) | European Union | 19 | |
| Singapore Protection from Online Falsehoods and Manipulation Act (POFMA, 2019) | Singapore (MCI) | 19 | |
| SOX 404 / ICFR | United States | 19 | kit |
| Armenia Law on Protection of Personal Data (2015) | Armenia | 18 | kit |
| TSA Pipeline Security | United States | 18 | |
| EU AI Liability Directive | European Union | 18 | |
| EU Product Liability Directive (Directive (EU) 2024/2853) | European Union | 18 | |
| Responsible Minerals Initiative (RMI) | International (RBA/RMI) | 18 | |
| EU SFDR (Sustainable Finance Disclosure Regulation) | European Union | 18 | kit |
| Australia eSafety Commissioner | Australia (eSafety Commissioner) | 18 | |
| Data (Use and Access) Act 2025 | United Kingdom | 18 | kit |
| Defence Industry Security Program (DISP) | Australia | 18 | |
| EU Cyber Solidarity Act (Regulation (EU) 2025/38) | European Union | 18 | |
| Sweden Data Protection Act (Dataskyddslag, 2018:218) | Sweden | 18 | |
| Tennessee Information Protection Act (TIPA) | United States — Tennessee | 18 | kit |
| Washington My Health My Data Act (MHMD) | United States — Washington | 18 | |
| Annex 11 to EU GMP | European Union (EMA/EC) | 17 | kit |
| CMMC 2.0 Level 1 | United States | 17 | kit |
| CCSDS 350.0-G-3 | International (CCSDS — 11 member agencies) | 17 | |
| Jamaica Data Protection Act 2020 | Jamaica | 17 | kit |
| ISO 10007:2017 | International | 17 | |
| Uganda Data Protection and Privacy Act (2019) | Uganda | 17 | |
| Sigstore | International (OpenSSF) | 17 | |
| EU Network Code on Cybersecurity for the Electricity Sector | European Union | 17 | kit |
| EU Seveso III Directive (Directive 2012/18/EU) | European Union | 17 | kit |
| Cook Islands Electronic Transactions Act 2003 | Cook Islands | 17 | kit |
| UNECE WP.29 R156 | International | 17 | |
| CISA Industrial Control Systems (ICS) Security Guidance | United States (CISA) | 16 | |
| Australia IRAP | Australia (ASD) | 16 | |
| European Accessibility Act (Directive (EU) 2019/882) | European Union | 16 | |
| EU Taxonomy Regulation | European Union | 16 | kit |
| FIDO2 / WebAuthn | International (FIDO Alliance/W3C) | 16 | kit |
| Reserve Bank of Fiji Guideline 4 | Fiji | 16 | |
| NIST SP 800-171A Rev 3 | United States (NIST) | 15 | kit |
| Australia Online Safety Act 2021 | Australia (eSafety Commissioner) | 15 | kit |
| Azerbaijan Law on Personal Data (2010) | Azerbaijan | 15 | kit |
| ETSI EN 303 645 | European Union | 15 | kit |
| Family Educational Rights and Privacy Act (FERPA) | United States | 15 | |
| EU ePrivacy Directive (2002/58/EC) | European Union | 15 | kit |
| Extractive Industries Transparency Initiative (EITI) Standard (2023) | International (EITI) | 15 | kit |
| UNECE WP.29 R155 | International | 15 | |
| ISO/IEC 27036-1:2021 | International | 15 | |
| Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) | Austria | 14 | kit |
| BCBS 239 | International | 14 | kit |
| ISO 14001 | International | 14 | kit |
| EDM Council CDMC | International (EDM Council) | 14 | |
| OWASP ASVS | International | 14 | |
| DFARS 252.204-7012 | United States (DoD) | 14 | kit |
| EU Web Accessibility Directive (Directive 2016/2102) | European Union | 14 | kit |
| French Sapin II Law (Law No. 2016-1691) | France | 14 | |
| Australian Privacy Principles (APPs) | Australia | 13 | kit |
| FDA 21 CFR Part 11 | United States | 13 | kit |
| FDA Quality Management System Regulation (QMSR) | United States | 13 | |
| Japan AI Guidelines | Japan | 13 | kit |
| FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) | United States (FCC) | 13 | |
| GS1 Global Standards | International (GS1 — 116 countries) | 13 | |
| CDP (formerly Carbon Disclosure Project) | International | 13 | |
| ITU-T X.805 | International (ITU-T) | 13 | kit |
| Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) | Hong Kong | 13 | |
| ISO/IEC 17050-1:2004 | International | 13 | |
| US Americans with Disabilities Act (ADA) | United States (Federal — DOJ) | 13 | |
| Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) | United Arab Emirates | 12 | |
| C-TPAT | United States (CBP) | 12 | |
| Ghana Cybersecurity Act | Ghana | 12 | kit |
| ICN Leadership for Change Programme | International | 12 | |
| Telecommunications Sector Security Reforms (TSSR) | Australia | 12 | |
| GHG Protocol | International | 12 | |
| GRI Standards | International | 12 | kit |
| UK Data Protection Act 2018 | United Kingdom | 12 | kit |
| FIRST CSIRT Services Framework and Standards | International (FIRST — 107 countries) | 12 | |
| Global Cross-Border Privacy Rules (Global CBPR) Forum | International (Global CBPR Forum) | 12 | |
| Kuwait National Cybersecurity Framework | Kuwait | 12 | |
| Ghana Data Protection Act 2012 (Act 843) | Ghana | 12 | kit |
| Greece Law 4624/2019 | Greece | 12 | kit |
| IAEA Nuclear Security Series | International (IAEA) | 11 | kit |
| Regulation on the European Health Data Space (EHDS) | European Union | 11 | |
| Modern Slavery Act 2018 (Australia) | Australia | 11 | |
| German Supply Chain Due Diligence Act (LkSG) | Germany | 11 | kit |
| EU NIS2 Directive | European Union | 11 | |
| HKMA Cyber Resilience Assessment Framework (C-RAF) | Hong Kong | 11 | |
| Japan FSA Cybersecurity Guidelines for Financial Institutions | Japan | 11 | kit |
| Georgia Law on Personal Data Protection (2012) | Georgia | 11 | kit |
| Finland Data Protection Act (Tietosuojalaki, 1050/2018) | Finland | 11 | kit |
| FTC Health Breach Notification Rule | United States | 11 | kit |
| OWASP Top 10:2025 | International | 10 | kit |
| Indonesia PDP Law | Indonesia | 10 | kit |
| Equator Principles (EP4, 2020) | International (Equator Principles Association) | 10 | |
| ICAO Annex 17 | International (ICAO) | 10 | kit |
| UK Telecommunications (Security) Act 2021 | United Kingdom | 10 | |
| RICS Professional Standards | International (RICS — 146 countries) | 10 | |
| Hungary Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act) | Hungary | 10 | |
| Singapore Payment Services Act (PSA) | Singapore (MAS) | 10 | |
| ECSS-E-ST-40C: Space Engineering | Europe (ECSS) | 10 | kit |
| ICH E6(R3) | International (ICH) | 9 | kit |
| PIC/S Guide to Good Manufacturing Practice for Medicinal Products | International (PIC/S — 54 member authorities) | 9 | |
| Ethical Trading Initiative (ETI) Base Code | International (ETI — UK-based alliance) | 9 | |
| ISSB Standards | International | 9 | |
| UK Gambling Commission | United Kingdom (Gambling Commission) | 9 | |
| UK Modern Slavery Act 2015 | United Kingdom | 9 | kit |
| Australia AI Ethics Framework | Australia | 8 | kit |
| Kotter 8-Step Change Model | International | 8 | |
| NATO AQAP 2110 | International (NATO — 31 member nations) | 8 | kit |
| Nebraska Data Privacy Act | United States - Nebraska | 8 | kit |
| NIST Privacy Framework | United States | 8 | kit |
| NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security | United States | 8 | |
| OECD AI Principles | International | 8 | kit |
| OECD Recommendation on Artificial Intelligence (2024 Update) | International (OECD) | 8 | |
| Iowa Consumer Data Protection Act | United States - Iowa | 8 | kit |
| Malaysia PDPA 2010 | Malaysia | 8 | kit |
| MARS-E | United States | 8 | |
| Mauritius DPA | Mauritius | 8 | |
| Montana Consumer Data Privacy Act | United States - Montana | 8 | kit |
| NIST SP 800-144 | United States | 8 | kit |
| NIST SP 800-92 | United States | 8 | kit |
| OpenSSF Scorecard | International | 8 | |
| OWASP MASVS | International | 8 | |
| Privacy Act 1988 (Australia) | Australia | 8 | kit |
| Indiana Consumer Data Protection Act | United States - Indiana | 8 | kit |
| Liechtenstein DPA | Liechtenstein | 8 | |
| Mexico LFPDPPP | Mexico | 8 | |
| Minnesota Consumer Data Privacy Act | United States - Minnesota | 8 | kit |
| MITRE ATT&CK | International | 8 | |
| MITRE D3FEND | International | 8 | |
| Monetary Authority of Singapore Technology Risk Management Guidelines | Singapore | 8 | |
| Nigeria Data Protection Regulation (NDPR) | Nigeria | 8 | |
| NIST SP 800-122 | United States | 8 | kit |
| NIST SP 800-30 | United States | 8 | kit |
| NIST SP 800-63-4 | United States | 8 | kit |
| O-RAN WG11 Security Specification | International (O-RAN Alliance) | 8 | kit |
| Oman National Cybersecurity Framework | Oman | 8 | |
| Oregon Consumer Privacy Act | United States - Oregon | 8 | kit |
| Personal Data Act (personopplysningsloven) | Norway | 8 | |
| Privacy Act 2020 | New Zealand | 8 | kit |
| Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) | Iceland | 8 | |
| ILO Declaration on Fundamental Principles and Rights at Work (Core Conventions) | International (ILO — 187 member states) | 8 | kit |
| IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2) | International (IMO) | 8 | |
| India DPDP Act | India | 8 | kit |
| ISMAP (Japan) | Japan | 8 | |
| Kentucky Consumer Data Protection Act | United States - Kentucky | 8 | kit |
| Kolb Experiential Learning Cycle | International | 8 | |
| Law No. 172-13 on the Protection of Personal Data | Dominican Republic | 8 | |
| Ley Orgánica de Protección de Datos Personales (LOPDP) | Ecuador | 8 | |
| LGPD | Brazil | 8 | |
| Maryland Online Data Privacy Act of 2024 | United States - Maryland | 8 | |
| MDS2 (Medical Device) | United States | 8 | kit |
| Nevada Gaming Control Board Cybersecurity Requirements | United States — Nevada | 8 | |
| New Hampshire Data Privacy Act | United States - New Hampshire | 8 | kit |
| New Jersey Data Privacy Act | United States - New Jersey | 8 | kit |
| NHS Healthcare Leadership Model | United Kingdom | 8 | |
| NIS2 Directive Implementing Acts | European Union | 8 | |
| NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) | United States (NIST) | 8 | |
| NIST SP 800-123 | United States | 8 | kit |
| NIST SP 800-137 | United States | 8 | kit |
| NIST SP 800-145 | United States | 8 | kit |
| NIST SP 800-61 | United States | 8 | kit |
| NIST SP 800-88 | United States | 8 | kit |
| NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems | United States | 8 | |
| OECD Guidelines for Multinational Enterprises on Responsible Business Conduct (2023 Update) | International (OECD — 51 adhering governments) | 8 | |
| OECD/G20 Principles of Corporate Governance | International | 8 | kit |
| Open Banking Security | United Kingdom | 8 | kit |
| OSFI B-13 | Canada | 8 | kit |
| OWASP Top 10 for LLM Applications 2025 | International | 8 | kit |
| Pakistan Personal Data Protection Bill 2023 | Pakistan | 8 | |
| South Korea PIPA | South Korea | 8 | |
| Delaware Online Privacy and Protection Act (proposed) | United States - Delaware | 8 | |
| India CERT-In Cyber Security Directions 2022 | India | 8 | kit |
| Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) | Italy | 8 | |
| ITAR | United States (State Department) | 8 | |
| Maslach Burnout Inventory (MBI) and Areas of Worklife Survey (AWS) Model | United States (origin), International applicability | 8 | |
| New Zealand Information Security Manual (NZISM) | New Zealand (GCSB/NCSC) | 8 | |
| Nigeria Open Banking Regulatory Framework (CBN, 2023) | Nigeria (CBN) | 8 | kit |
| NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) | United States | 8 | kit |
| NIST SP 800-146 | United States | 8 | kit |
| NIST SP 800-37 | United States | 8 | kit |
| NIST SP 800-66 | United States | 8 | kit |
| NRF Cybersecurity and Data Privacy Framework (National Retail Federation) | United States (NRF) | 8 | |
| OWASP API Security Top 10 | International | 8 | kit |
| PCAOB AS 2201 | United States (PCAOB) | 8 | kit |
| Taiwan PDPA | Taiwan | 8 | |
| ILO Nursing Personnel Convention C149 (1977) | International | 8 | kit |
| Kids Online Safety Act (KOSA) | United States | 8 | |
| NABERS | Australia | 8 | |
| NERC CIP | North America | 8 | kit |
| NIST SP 800-39 | United States | 8 | kit |
| NIST SP 800-63 Digital Identity Guidelines | United States | 8 | kit |
| Notifiable Data Breaches Scheme (Australia) | Australia | 8 | kit |
| OCC Heightened Standards (12 CFR Part 30, Appendix D) | United States (OCC) | 8 | |
| US SEC Digital Assets and Crypto Regulatory Framework | United States (SEC) | 8 | |
| ICMM Mining Principles (2024 Update) | International (ICMM) | 8 | |
| India Account Aggregator Framework (RBI) | India (RBI) | 8 | kit |
| ITU Radio Regulations and Space Security Standards | International (ITU — 193 member states) | 8 | |
| Jordan Draft Personal Data Protection Law (2022) | Jordan | 8 | kit |
| Kenya Data Protection Act | Kenya | 8 | |
| Laos Law on Prevention and Combating Cybercrime (2015) | Laos | 8 | |
| LEED v4.1 | International (USGBC — 185 countries) | 8 | kit |
| Lloyd's of London Cyber Insurance Requirements and Underwriting Standards | United Kingdom (Lloyd's of London) | 8 | |
| MiFID II / MiFIR | European Union | 8 | |
| NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) | International (NATO — 32 members) | 8 | |
| NATO STANAG 4774 (Confidentiality Metadata Labels) and STANAG 4778 (Metadata Binding) | International (NATO) | 8 | kit |
| NIST AI 600-1: Generative AI Profile | United States | 8 | kit |
| ILO Tripartite Declaration of Principles concerning Multinational Enterprises (MNE Declaration) | International (ILO) | 8 | |
| Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018) | Latvia | 8 | |
| Law on Personal Data Protection (Official Gazette No. 42/2020) | North Macedonia | 8 | |
| Lebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018) | Lebanon | 8 | |
| Myanmar Cybersecurity Law (2023) | Myanmar | 8 | |
| Ontario Accessibility for Ontarians with Disabilities Act (AODA) | Canada (Ontario) | 8 | |
| Paraguay Law on Protection of Personal Data (Law No. 6534/2020) | Paraguay | 8 | |
| Privacy and Other Legislation Amendment Act 2024 (Australia) | Australia | 8 | kit |
| HKMA TM-G-1 | Hong Kong | 8 | kit |
| IRS Publication 1075 | United States | 8 | kit |
| Japan Act on Specified Commercial Transactions (ASCT) | Japan (CAA) | 8 | |
| Kazakhstan Law on Personal Data and Their Protection (No. 94-V) | Kazakhstan | 8 | |
| Kuwait Data Privacy Protection Regulation (KDPPR, 2021 | Kuwait | 8 | |
| Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data | Morocco | 8 | kit |
| Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data | Côte d'Ivoire | 8 | |
| Lithuania Law on Legal Protection of Personal Data (2018) | Lithuania | 8 | kit |
| Lloyd's Minimum Standards | United Kingdom (Lloyd's) | 8 | |
| Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) | Luxembourg | 8 | kit |
| Malta Data Protection Act (Cap. 586, 2018) | Malta | 8 | |
| Montenegro Law on Personal Data Protection (2023) | Montenegro | 8 | kit |
| Netherlands GDPR Implementation Act (UAVG | Netherlands | 8 | |
| Oman Personal Data Protection Law (Royal Decree 6/2022) | Oman | 8 | |
| Panama Law on Personal Data Protection (Law No. 81 of 2019) | Panama | 8 | kit |
| Poland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018) | Poland | 8 | kit |
| Portugal Law No. 58/2019 | Portugal | 8 | kit |
| RBI Cybersecurity Framework for Banks | India | 8 | |
| HL7 FHIR Security Framework | International (Healthcare) | 7 | kit |
| IRM Enterprise Risk Management Framework (Institute of Risk Management) | International (IRM) | 7 | kit |
| US EPA Safe Drinking Water Act (SDWA) | United States (EPA) | 7 | |
| Fiji Data Protection Bill (2020) | Fiji | 7 | kit |
| Privacy by Design (PbD) | International | 7 | kit |
| OWASP DevSecOps Maturity Model (DSOMM) | International | 6 | kit |
| ICH Q10 | International (ICH) | 6 | |
| PAS 1192-5:2015 | United Kingdom (BSI/CPNI) | 6 | kit |
| ISO/IEC 17050-2:2004 | International | 6 | |
| UK GDPR (UK General Data Protection Regulation) | United Kingdom | 6 | |
| California IoT Security Law | United States - California | 6 | |
| Papua New Guinea National Cybersecurity Policy & Cybercrime Act (2016) | Papua New Guinea | 6 | |
| US Children's Online Privacy Protection Act (COPPA) and COPPA 2.0 Proposed Updates | United States (FTC) | 6 | |
| Philippines Cybercrime Prevention Act (RA 10175) | Philippines | 6 | kit |
| Proposal for a Directive on improving working conditions in platform work (COM(2023) 491) | European Union | 6 | |
| Singapore MAS TRM Guidelines | Singapore | 6 | |
| LEADS in a Caring Environment | International | 5 | |
| Trinidad and Tobago Data Protection Act 2011 | Trinidad and Tobago | 5 | |
| OWASP SAMM | International | 5 | |
| UK AI Regulation Framework | United Kingdom | 5 | |
| UK FCA/PRA Operational Resilience Framework | United Kingdom | 5 | |
| US NRC 10 CFR 73.54 | United States (NRC) | 5 | kit |
| WCAG 2.2 | International | 5 | |
| PropTech Security Standards | International | 5 | |
| Protection of Privacy Law (1981) | Israel | 5 | |
| Saudi NCA ECC | Saudi Arabia | 5 | kit |
| Spain ENS | Spain | 5 | |
| Sri Lanka Personal Data Protection Act (No. 9 of 2022) | Sri Lanka | 5 | |
| The Leadership Challenge (Kouzes & Posner) | International | 5 | |
| US Executive Order 14028 | United States | 5 | |
| WCO Authorised Economic Operator (AEO) Framework | International (WCO) | 5 | |
| Zambia Data Protection Act (2021) | Zambia | 5 | |