Research date: September 14–15, 2026. Framework versions change frequently — 2024–26 produced an unusual cluster of revisions. Every entry below carries a version and status. Educational material, not legal advice.
1. Quick comparison
| Framework | Type | Primary audience | Certification model | Document cost | Current version (Sept 2026) |
|---|---|---|---|---|---|
| NIST CSF 2.0 | Voluntary risk framework | All organizations | None (self-assessed profiles) | Free | 2.0 (Feb 26, 2024) |
| NIST SP 800-53 | Control catalog | US federal + contractors | Via FISMA/FedRAMP assessment | Free | Rev. 5; Release 5.2.0 (Aug 27, 2025) |
| NIST SP 800-171 | CUI requirements | Federal contractors | CMMC third-party assessment | Free | Rev. 3 (May 14, 2024); CMMC still assesses Rev. 2 |
| CIS Controls | Prioritized safeguards | SMB → enterprise | None (self-assessment) | Free | v8.1 (June 2024) |
| ISO/IEC 27001 | Certifiable ISMS | Any size, esp. global B2B | Accredited 3-year cycle | ~CHF 200 | 2022 + Amd 1:2024 |
| SOC 2 | Attestation (AICPA) | Service organizations, SaaS | CPA report (Type I/II) | Audits $20K–$100K+ | TSC 2017, points of focus revised 2022 |
| PCI DSS | Contractual mandate | Anyone touching card data | SAQ or QSA Report on Compliance | Free | v4.0.1; all requirements mandatory since Mar 31, 2025 |
| HIPAA Security Rule | US federal regulation | Covered entities, BAs | None (OCR enforcement) | Free | 2003/2013 rule in force; 2025 NPRM delayed to ≥2027 |
| GDPR Art. 32 | EU regulation | Controllers/processors | None (optional Art. 42) | Free | In force since May 2018 |
| CCPA/CPRA | California law | Businesses over thresholds | CPPA audits phasing in | Free | Cyber-audit/risk/ADMT regs effective Jan 1, 2026 |
| COBIT | IT governance | Boards, CIOs, auditors | Personal certs only | Paid (ISACA) | COBIT 2019 |
| MITRE ATT&CK | Adversary knowledge base | SOCs, CTI, red/blue teams | None | Free | v18 (Oct 2025) |
| OWASP Top 10 | Awareness document | Developers, AppSec | None | Free | 2025 edition |
| OWASP ASVS | Verification standard | AppSec testers | None | Free | 5.0.0 (May 30, 2025) |
| OWASP LLM Top 10 | Awareness document | AI engineering | None | Free | 2025 and 2026 editions |
| CSA CCM / STAR | Cloud controls + assurance | CSPs and customers | STAR L1 self / L2 third-party | Free (CCM) | CCM v4 |
| NIST 800-207 / CISA ZTMM | Zero-trust guidance | Agencies, enterprises | None | Free | 800-207 (2020); ZTMM v2.0 (Apr 2023) |
| IEC 62443 | Industrial/OT | ICS operators, vendors, integrators | ISASecure / IECEE | Paid | Multi-part; 62443-2-1 updated 2024 |
2. The general-purpose frameworks
NIST Cybersecurity Framework 2.0
Released February 26, 2024 — the first major revision since 2014. A voluntary, outcome-based risk-management framework whose scope CSF 2.0 explicitly expanded from critical infrastructure to all organizations of any size and sector.
Six functions: Govern (new), Identify, Protect, Detect, Respond, Recover, decomposed into categories and subcategories, plus Organizational Profiles (current versus target) and Tiers 1–4 characterizing risk-governance maturity. The Govern function is the substantive change — it elevates strategy, roles, policy, and cybersecurity supply-chain risk management to board level, which is why so much 2024–26 regulatory language now echoes it.
No certification; self-assessment through profiles, with free quick-start guides and community profiles. The document is free and effort scales with the organization: a small business can build a lightweight profile in weeks, while enterprises typically map CSF onto SP 800-53, ISO 27001, or the CIS Controls. It is best understood as the universal common-language layer that sits above a control catalog. It is not law, but regulators including NYDFS and the FTC reference it as evidence of reasonable security.
CIS Critical Security Controls v8.1
Released June 2024, an incremental update aligning the 18 Controls with CSF 2.0's Govern function. Structure: 18 Controls, 153 Safeguards, tiered into Implementation Groups — IG1 with 56 safeguards defined as "essential cyber hygiene," then IG2 and IG3. Companion CIS Benchmarks provide hardened configuration baselines per product.
No certification; free self-assessment via CIS CSAT. This is the best available answer to "what do we actually do first," and it appears constantly in cyber-insurance questionnaires. For small and mid-size organizations it is the most practical starting point of any framework in this document.
ISO/IEC 27001:2022
The certifiable international information-security management system standard. The transition window from the 2013 edition closed October 31, 2025 — all valid certificates are now on the 2022 edition. Amendment 1:2024 added climate-action considerations to ISMS context.
Structure: management-system clauses 4–10 plus Annex A's 93 controls in four themes (organizational, people, physical, technological), detailed in ISO/IEC 27002:2022. The 2022 additions include threat intelligence, cloud security, data leakage prevention, and secure coding.
Certification runs on a three-year cycle — Stage 1 and Stage 2 audits, annual surveillance, then recertification — and is the strongest certification signal among general frameworks, frequently demanded in international B2B contracts. Standards documents cost roughly CHF 200 each; implementation typically takes six to eighteen months; certification audits run roughly $10K–$50K plus internal effort.
SOC 2
An attestation, not a certification, under AICPA standards: a CPA firm reports on controls against the Trust Services Criteria — Security is mandatory, with Availability, Processing Integrity, Confidentiality, and Privacy optional. Type I covers design at a point in time; Type II covers operating effectiveness over three to twelve months. The output is a restricted-use report shared under NDA, with no public certificate or logo scheme.
Audits commonly run $20K–$100K or more; compliance-automation platforms have compressed timelines substantially. Because the TSC are criteria rather than prescribed controls, scope and rigor vary meaningfully by auditor — a point the site should make, because buyers routinely treat "SOC 2" as a binary.
No law mandates SOC 2. It is purely market-driven, and in North America it is the de facto ticket to enterprise procurement.
COBIT 2019
ISACA's enterprise governance framework: 40 governance and management objectives across five domains, design factors, and a CMMI-based capability model. Aimed at boards, CIOs, and IT auditors in large or regulated enterprises, with strong ties to SOX IT general controls. Individual certifications exist; there is no organizational certification. It sits above security frameworks as a governance and audit layer rather than competing with them.
3. The US federal stack
SP 800-53 Rev. 5 is the master control catalog — roughly 1,190 controls in 20 families — required for federal systems under FISMA and the basis of FedRAMP baselines. NIST began issuing patch releases in 2025; Release 5.2.0 (August 27, 2025) added controls for secure software updates, patching, and logging integrity, partly in response to lessons from the 2024 CrowdStrike outage. A legal requirement for agencies; best practice elsewhere.
SP 800-171 Rev. 3, final May 14, 2024, restructured CUI protection to align with 800-53 Rev. 5, with organization-defined parameters set by federal agencies. The practical wrinkle worth flagging on any page about it: the DoD's CMMC program currently assesses against Rev. 2. The CMMC 32 CFR program rule took effect December 16, 2024, and the 48 CFR acquisition rule became effective November 10, 2025, starting Phase 1 of CMMC clauses in DoD contracts. This is a contractual and legal requirement for defense and many civilian-agency contractors.
SP 800-61 Rev. 3, final April 2025, is a full overhaul that recast incident response as a CSF 2.0 community profile rather than the old four-phase lifecycle, integrating IR into enterprise risk management and deliberately dropping step-by-step technical procedures in favor of outcomes.
SP 800-115, published 2008 and never revised, remains the canonical free reference for planning security assessments and penetration tests — old, but still the compliance backbone for US federal-aligned testing.
SP 800-207 (Zero Trust Architecture), August 2020, defines the tenets and the policy engine / administrator / enforcement point model. Companion practice guide SP 1800-35, finalized 2025, documents 19 commercial example builds.
4. Sector and contractual regimes
PCI DSS 4.0.1
Version 4.0.1 was released June 11, 2024; v4.0 retired December 31, 2024. The critical date: the roughly 51 "future-dated" requirements became mandatory March 31, 2025 — authenticated internal vulnerability scans, payment-page script integrity management (6.4.3), change and tamper detection for payment pages (11.6.1), 12-plus-character passwords, and expanded phishing controls. As of 2026, every v4.0.1 requirement is fully in effect.
Twelve requirements across six goals, validated by merchant level through Self-Assessment Questionnaires or a QSA Report on Compliance for Level 1. The new "customized approach" permits objective-based alternatives with documented risk analysis.
PCI DSS is a contractual mandate flowing from card brands through acquirers to merchants, not a statute — though a few US states reference it in breach-liability law. For small merchants, outsourced payments (Stripe-style redirects) minimize scope, but the 2025 e-commerce script requirements narrowed even SAQ A obligations.
HIPAA Security Rule
45 CFR Part 164 Subpart C, applying to covered entities and business associates, enforced by HHS OCR with state AG co-enforcement. Current text dates to 2003 as amended in 2013, with safeguards split into "required" and "addressable."
The proposed overhaul published January 6, 2025 would remove the required/addressable distinction and mandate MFA, encryption at rest and in transit, asset inventories, network mapping, segmentation, 72-hour restore objectives, and annual compliance audits. More than 4,000 comments were received. Status as of 2026: moved to HHS's long-term regulatory agenda, with final action not expected before July 2027. The existing rule remains fully enforceable meanwhile, and OCR's Risk Analysis Initiative already penalizes weak risk analyses. Healthcare organizations should treat the NPRM's safeguards as a preview of enforcement expectations rather than a future problem.
GDPR Article 32
Requires "appropriate technical and organisational measures" proportionate to risk, expressly naming pseudonymization and encryption, ongoing confidentiality/integrity/availability/resilience, restoration capability, and regular testing and evaluation of measures. Articles 33 and 34 add 72-hour breach notification to supervisory authorities and notification to individuals for high-risk breaches. Article 28 forces security terms into processor contracts.
No certification required; fines reach €10M or 2% of global turnover for Article 32 breaches and €20M or 4% for broader violations. GDPR is technology-neutral, so regulators interpret "appropriate" through guidance and enforcement — ISO 27001 or CIS implementation is a common way to evidence compliance, but neither immunizes.
CCPA/CPRA
Businesses must use "reasonable security procedures and practices." The security hook that matters most is the private right of action with statutory damages of $100–$750 per consumer per incident for breaches of unencrypted personal information caused by unreasonable security — the main engine of US breach class actions. The California Privacy Protection Agency's regulations on cybersecurity audits, risk assessments, and automated decision-making technology became effective January 1, 2026, with mandatory independent cybersecurity audits phasing in by business size roughly 2028–2030.
IEC 62443
The ISA/IEC 62443 series for industrial automation and control systems, structured in four groups: General, Policies and Procedures (62443-2-1 updated 2024), System (including 3-2 risk assessment with zones and conduits, and 3-3 system requirements), and Component (4-1 secure development lifecycle, 4-2 component requirements). Key concepts: zones and conduits segmentation, Security Levels SL0–SL4, and distinct roles for asset owners, integrators, and product suppliers. Certification runs through ISASecure and IECEE schemes, and the EU Cyber Resilience Act and NIS2 sectoral guidance increasingly reference it as a conformity route.
5. The knowledge bases and testing standards
MITRE ATT&CK
A free, continuously updated knowledge base of adversary tactics, techniques, and procedures across Enterprise, Mobile, and ICS matrices, mapped to real threat groups and software. Updated roughly twice yearly: v17 (April 2025) added the VMware ESXi platform; v18 (October 2025) overhauled detections into detection strategies and analytics.
It is not a compliance framework — no certification, no controls. Its uses are threat-informed defense: detection-coverage mapping, red-team planning, threat-intelligence reporting, and gap analysis. A pragmatic 2026 benchmark for detection coverage is roughly 65% of relevant techniques, with detections at three or more points in a typical attack chain.
OWASP
Top 10 (2025 edition), which superseded the long-serving 2021 list: 1. Broken Access Control, 2. Security Misconfiguration, 3. Software Supply Chain Failures (new), 4. Cryptographic Failures, 5. Injection, 6. Insecure Design, 7. Authentication Failures, 8. Software or Data Integrity Failures, 9. Security Logging and Alerting Failures, 10. Mishandling of Exceptional Conditions (new); SSRF folded into Broken Access Control. It is an awareness document, not a testing standard, though PCI DSS and many contracts reference it.
ASVS 5.0.0, released May 30, 2025 — roughly 350 requirements across 17 chapters and three levels, reworked for easier first-level adoption. This, not the Top 10, is the correct basis for security requirements and penetration-test depth.
MASVS and MASTG for mobile verification and testing.
Top 10 for LLM Applications, whose 2025 edition (published November 2024) and 2026 edition both keep prompt injection at LLM01, followed by sensitive information disclosure, supply chain, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, misinformation, and unbounded consumption. The project has since expanded into agentic-AI guidance.
All OWASP material is free.
Cloud Security Alliance CCM and STAR
The Cloud Controls Matrix v4 comprises 197 control objectives across 17 domains mapped to ISO 27001/27017/27018, NIST, and PCI, plus the CAIQ questionnaire. The STAR Registry offers Level 1 free self-assessment and Level 2 third-party certification (ISO 27001 + CCM) or attestation (SOC 2 + CCM). An AI controls track was added as CSA's AI Controls Matrix matured in 2025–26. Cloud providers use it to demonstrate trust; customers use CAIQ for vendor due diligence.
Zero Trust frameworks
NIST SP 800-207 is the definitional document; NIST SP 1800-35 demonstrates implementation. CISA's Zero Trust Maturity Model v2.0 (April 2023) is the practical roadmap: five pillars — identity, devices, networks, applications and workloads, data — with three cross-cutting capabilities (visibility and analytics, automation and orchestration, governance) and four maturity stages from Traditional through Initial and Advanced to Optimal. Binding for US federal civilian agencies; best practice elsewhere and heavily used as an enterprise roadmap.
6. Which framework fits whom
| Audience | Sensible starting stack |
|---|---|
| Individuals and students | MITRE ATT&CK and OWASP Top 10/ASVS for skills; CIS IG1 concepts for personal hygiene; no certification needed, since all of it is free |
| Small businesses | CIS Controls IG1 progressing to IG2; NIST CSF 2.0 Small Business quick-start; PCI SAQ if taking cards; state breach-notification awareness |
| Startups (B2B SaaS) | SOC 2 Type II for the US market and/or ISO 27001 for global; CSF 2.0 as internal structure; OWASP ASVS in the SDLC; CSA CAIQ to answer security questionnaires |
| Regulated companies | Whatever the regulator mandates first — HIPAA, PCI DSS, GLBA Safeguards, NYDFS 500, DORA — mapped onto CSF 2.0 or ISO 27001; 800-171 plus CMMC for defense contractors |
| Enterprises | ISO 27001 certification plus an 800-53-derived control catalog; COBIT for governance and audit; ATT&CK-driven detection; CISA ZTMM as roadmap |
| Critical infrastructure / OT | NIST CSF 2.0 plus IEC 62443, plus sector rules (NERC CIP, TSA directives, NIS2/CER in the EU); CISA CPGs as the prioritized floor; CIRCIA reporting readiness |
7. Editorial rules for framework content
- Always date-stamp the version. The 2024–26 cluster of revisions — CSF 2.0, 800-171r3, 800-61r3, 800-53 5.2.0, CIS 8.1, ASVS 5.0, OWASP Top 10:2025, PCI 4.0.1, the completed ISO transition, ATT&CK v18, CPG 2.0 — means undated framework content goes wrong within a year.
- Separate must from should. Statutes and regulations (HIPAA, GDPR, NIS2, DORA, CRA, NYDFS, GLBA, SEC, state laws) versus contractual mandates (PCI DSS, SOC 2, CMMC clauses) versus voluntary frameworks (CSF, CIS, ATT&CK, OWASP, COBIT, CSA).
- Say what certification proves and does not prove. ISO 27001 proves a management system existed and was audited against Annex A; SOC 2 Type II proves controls the organization chose operated over a window; neither proves the organization is secure. Target was PCI-compliant weeks before its 2013 breach; Change Healthcare was HIPAA-covered and lacked MFA on the exploited portal.
- Flag the moving targets for readers. HIPAA's final rule (2027 or later), CIRCIA's final rule, the UK Cyber Security and Resilience Bill's passage, CMMC phase-in, EU AI Act high-risk timing under the digital omnibus, and UN cybercrime convention ratifications all changed during 2025–26 and will change again.