Compliance
Regulatory compliance frameworks and data protection
Standards
PCI-DSS 4.0
The Payment Card Industry Data Security Standard (PCI DSS) is crucial for teams planning software migrations that involve payment processing. Compliance ensures the protection of sensitive cardholder data, mitigates risks of data breaches, and fosters customer trust. By following outlined requirements and best practices, organizations can securely transition their systems while maintaining compliance.
by PCI Security Standards Council
pci-dss-4-0HIPAA Security Rule
The HHS standard is essential for ensuring compliance during software migrations involving health-related data. By adhering to these regulations, teams can protect sensitive information, avoid legal complications, and maintain stakeholder trust, all while facilitating effective data transfer between systems.
by U.S. Department of Health and Human Services
hipaa-security-ruleGDPR (EU 2016/679)
Adhering to established standards during software migrations is crucial for ensuring data security, integrity, and stakeholder trust. This guide provides practical insights on compliance requirements, implementation strategies, and tools to help teams navigate the complexities of migration projects with confidence.
by European Union
gdpr-eu-2016-679UK GDPR 2021
Adhering to compliance standards during software migrations is crucial for protecting sensitive data, maintaining stakeholder confidence, and ensuring seamless transitions. This guide outlines the key requirements, practical steps for adherence, and tools to help teams navigate compliance challenges effectively.
by European Union
uk-gdpr-2021CCPA (AB 375)
Understanding compliance standards is essential for successful software migrations. By adhering to legal and regulatory requirements, teams can protect sensitive data, uphold privacy rights, and ensure operational continuity. This guide outlines key requirements, practical strategies, and tools to help organizations navigate compliance challenges during their migration processes.
by State of California
ccpaFedRAMP Moderate Rev 5
Understanding and adhering to GSA standards is crucial for successful migration projects, ensuring compliance, security, and interoperability. By following structured guidelines and leveraging the right tools, organizations can navigate the complexities of migration while minimizing risks and enhancing efficiency.
by U.S. General Services Administration
fedramp-moderateISO/IEC 29134:2017 (PIA)
Adhering to ISO/IEC standards during software migrations is critical for ensuring quality, minimizing risks, and gaining stakeholder trust. By following established requirements and utilizing appropriate tools and processes, teams can navigate common challenges and execute successful migrations that align with international best practices.
by ISO/IEC Joint Technical Committee
iso-29134-2017ISO/IEC 38505-1:2017 (Data Governance)
Adhering to ISO/IEC standards is essential for effective migration projects, ensuring quality, security, and efficiency. By following structured compliance measures and leveraging the right tools, teams can mitigate risks, enhance trust, and streamline their migration processes.
by ISO/IEC Joint Technical Committee
iso-38505-1-2017ISO/IEC 27001:2022
Information security management systems (ISMS) requirements. The anchor certification for enterprise information security.
by ISO/IEC
iso-iec-27001-2022ISO/IEC 27002:2022
Information security controls — the implementation guidance companion to ISO/IEC 27001 Annex A.
by ISO/IEC
iso-iec-27002-2022AICPA SOC 2 (Trust Services Criteria 2017, rev. 2022)
Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy) underpinning SOC 2 Type I/II attestations.
by AICPA
aicpa-soc-2-tscPCI-DSS 4.0.1
Security requirements for every organisation that stores, processes, or transmits cardholder data. 4.0.1 is a limited revision of 4.0 that corrects and clarifies its text; the future-dated 4.0 requirements became mandatory on 31 March 2025.
by PCI Security Standards Council
pci-dss-4-0-1Best Practices
ISO/IEC 27001:2022 Annex A Controls
Industry baseline for information-security policies and management controls.
by ISO/IEC JTC 1/SC 27EU AI Act (Political Agreement)
First comprehensive regulatory framework for trustworthy AI in the European Union.
by European Parliament & CouncilPrivacy by Design 7 Principles
Framework embedding privacy into systems engineering from the outset.
by International Assembly for Privacy CommissionersNIST Cybersecurity Framework 2.0
A voluntary framework of cybersecurity outcomes organized into six functions, govern, identify, protect, detect, respond, and recover, for managing organizational cyber risk.
by National Institute of Standards and TechnologyNIST SP 800-53 Security and Privacy Controls
A comprehensive catalog of security and privacy controls for information systems, organized into control families with baselines for different risk levels.
by National Institute of Standards and TechnologyCIS Critical Security Controls v8
A prioritized set of 18 safeguards and implementation groups that defend against the most common cyber attacks, mapped to other major frameworks.
by Center for Internet SecurityData Governance Framework
A structured set of roles, policies, and processes that make an organization accountable for the quality, security, and proper use of its data assets.
by DAMA InternationalISO/IEC 42001 AI Management System
ISO/IEC 42001 is the first international standard for an Artificial Intelligence Management System, giving organizations a certifiable framework to govern AI responsibly.
by ISO/IECWCAG 2.2 Accessibility Compliance
The W3C Web Content Accessibility Guidelines 2.2 define testable success criteria across four principles so web content is perceivable, operable, understandable, and robust.
by World Wide Web Consortium (W3C)Test Data Management
Practices for provisioning realistic, isolated, and compliant test data so tests are reliable, repeatable, and free of production data exposure.
by ThoughtworksSOC 2 Compliance
SOC 2 is an AICPA auditing framework that assesses how a service organization protects customer data against five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.
by American Institute of Certified Public Accountants (AICPA)PCI DSS Compliance
PCI DSS is the global security standard for organizations that handle payment card data, defining requirements to protect cardholder data across networks, systems, and processes.
by PCI Security Standards CouncilGDPR Compliance Engineering
GDPR compliance engineering turns the EU General Data Protection Regulation's legal principles into concrete technical controls: lawful processing, data minimization, consent, and data-subject rights.
by European UnionChecklists
Data Governance Review Checklist
A review checklist for assessing data ownership, quality, lineage, access control, and policy compliance across data assets.
PII and Data Classification Audit Checklist
An audit checklist for discovering, classifying, and protecting personally identifiable information across systems and data stores.
SOC 2 & ISO 27001 Evidence Readiness Checklist
Prepare the controls and evidence needed for a SOC 2 or ISO 27001 audit across access, change management, and monitoring.
FAQs
What is SOC 2 compliance?
SOC 2 is an audit framework from the AICPA that evaluates how a service organization manages customer data against five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. A Type I report assesses controls at a single point in time, while a Type II report tests that those controls operated effectively over a period, usually 3 to 12 months. SOC 2 reports are commonly requested by enterprise customers as evidence that a SaaS vendor handles data responsibly.
What is GDPR in a nutshell?
The General Data Protection Regulation (GDPR) is an EU law that governs how organizations collect, process, and store the personal data of people in the EU and EEA, regardless of where the organization is based. It grants individuals rights such as access, correction, deletion ("right to be forgotten"), and portability, and requires a lawful basis for processing, data-protection-by-design, and breach notification within 72 hours. Non-compliance can incur fines of up to 20 million euros or 4% of global annual revenue, whichever is higher.
What is PII (personally identifiable information)?
PII is any data that can identify a specific individual, either on its own or when combined with other information. Direct identifiers include name, email, government ID, and biometric data, while indirect identifiers like IP address, device ID, or location can identify someone in combination. Handling PII triggers obligations under regulations such as GDPR and CCPA, so it should be minimized, encrypted, access-controlled, and retained only as long as necessary.
What is HIPAA compliance?
HIPAA (the Health Insurance Portability and Accountability Act) is a US law that sets standards for protecting sensitive patient health information, known as protected health information (PHI). Its Security Rule requires administrative, physical, and technical safeguards such as access controls, encryption, and audit logging, while the Privacy Rule governs how PHI may be used and disclosed. Software vendors that handle PHI on behalf of healthcare organizations are typically considered business associates and must sign a Business Associate Agreement (BAA).
What is ISO 27001?
ISO/IEC 27001 is an international standard that specifies the requirements for an information security management system (ISMS), a risk-based framework of policies, processes, and controls for protecting information assets. Organizations identify risks, select and implement controls (guided by the Annex A control set), and can pursue independent certification by an accredited auditor. Unlike SOC 2, which produces an audit report, ISO 27001 results in a formal certificate that is recognized globally, especially outside the US.
See a real scan run
A replay of the actual CLI running against our test repositories — live progress, real findings, a genuine DriftScore. Nothing executes in your browser.