SaaS compliance frameworks Black Cat SSPM maps to
- NIS2 Directive 2022/2555
Directive on measures for a high common level of cybersecurity across the Union — governance, risk-management measures, incident reporting, certification, and information-sharing for essential and important entities (Articles 20, 21, 23, 24, 29)
40 controls
- DORA (SaaS Security) 2022/2554
Digital Operational Resilience Act — ICT risk management and third-party risk for financial entities in SaaS environments (Articles 5-6, 8-14, 17-19, 24-30)
58 controls
- ISO 27001:2022 2022
Information security, cybersecurity and privacy protection - Information security management systems - Requirements
17 controls
- SOC 2 Type II 2017
Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy
28 controls
- CIS Controls v8 8.0
Center for Internet Security Critical Security Controls Version 8 - prioritized set of actions to protect organizations from cyber attacks
46 controls
- NIST CSF 2.0 2.0
NIST Cybersecurity Framework 2.0 - voluntary guidance for managing cybersecurity risk
24 controls
- GDPR (SaaS Security) 2016/679
General Data Protection Regulation — SaaS security posture controls for data protection, access control, encryption, and accountability
25 controls
- HIPAA (SaaS Security) 2003
Health Insurance Portability and Accountability Act — administrative, physical, and technical safeguards for electronic Protected Health Information (ePHI) in SaaS environments (45 CFR Part 164, Subparts A & C)
16 controls
Regulated in the EU or France? See how these frameworks map directly to your SaaS estate: SSPM for NIS2 & ReCyF and SSPM for DORA & the Registre d’Information.