Regulatory content
Global standards and local regulations. Mapped once.
OptimaGRC is not limited to information-security GRC. Cross-map ISO, NIST, SOC 2, Privacy, financial resilience, Quality, HSE, healthcare, and UAE/GCC sovereign libraries from one control set.
Showing 32 of 32 featured libraries — OptimaGRC maps 140+ in product.
ISO/IEC 27001:2022
High searchInformation Security Management System
The international standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
Global
SOC 2 Type II
High searchAICPA Trust Services Criteria
Independent examination of controls relevant to security, availability, processing integrity, confidentiality, and privacy over a period of time.
Global / North America
NIST CSF 2.0
High searchCybersecurity Framework
Govern, Identify, Protect, Detect, Respond, Recover — a widely used language for cyber risk that now emphasizes organizational governance.
US / Global
PCI DSS v4.0
High searchPayment Card Industry Data Security Standard
Technical and operational requirements for entities that store, process, or transmit cardholder data.
Global
FedRAMP
Federal Risk and Authorization Management Program
Standardized security assessment, authorization, and continuous monitoring for cloud services used by US federal agencies.
United States
CIS Controls v8
Critical Security Controls
A prioritized set of safeguards for cyber defense, often used as a practical implementation layer under ISO or NIST.
Global
EU GDPR
High searchGeneral Data Protection Regulation
EU law governing personal data processing, lawful bases, data-subject rights, DPIAs, and breach notification.
European Union / Global
UAE PDPL
High searchUAE Personal Data Protection Law
Federal personal-data protection law of the UAE, including controller/processor duties, cross-border transfers, and data-subject rights.
United Arab Emirates
ISO/IEC 27701
Privacy Information Management System
Extension to ISO 27001 for privacy information management covering PII controllers and processors.
Global
CCPA / CPRA
California Consumer Privacy Act
Consumer privacy rights, sale/share of personal information, and transparency duties for businesses in scope.
California, United States
EU DORA
High searchDigital Operational Resilience Act
EU regulation for ICT risk management, incident reporting, resilience testing, and critical third-party oversight in financial entities.
European Union
SOX 404
Sarbanes-Oxley Internal Control over Financial Reporting
Management assessment and auditor attestation of internal control over financial reporting for public companies.
United States
ISO 22301:2019
High searchBusiness Continuity Management System
Requirements for a business continuity management system covering BIA, strategies, plans, exercises, and continual improvement.
Global
ISO 9001:2015
High searchQuality Management System
The world’s most used quality management standard — context, leadership, planning, support, operation, performance, and improvement.
Global
ISO 13485
Medical Devices Quality Management
QMS requirements for medical device organizations, emphasizing risk, traceability, and regulatory documentation.
Global
ISO 45001:2018
High searchOccupational Health & Safety Management
International standard for occupational health and safety management systems, including hazard identification, participation, and continual improvement.
Global
ISO 14001:2015
High searchEnvironmental Management System
Requirements for an environmental management system covering aspects, compliance obligations, and environmental performance.
Global
ISO 50001
Energy Management System
Energy management system requirements for energy performance, efficiency, and continual improvement.
Global
ISO 31000
High searchRisk Management Guidelines
Principles, framework, and process for managing risk of any type — the backbone of enterprise risk management beyond cyber.
Global
ISO 37301
Compliance Management Systems
Requirements and guidance for establishing a compliance management system covering culture, obligations, and performance.
Global
COSO ERM / IC
Committee of Sponsoring Organizations Frameworks
Widely used internal control and enterprise risk management frameworks for boards and internal audit.
Global
COBIT
Control Objectives for Information Technologies
ISACA framework for governance and management of enterprise information and technology.
Global
ITIL
IT Infrastructure Library / IT Service Management
Practices for IT service management including incident, change, and service continuity that overlap GRC processes.
Global
HIPAA
High searchHealth Insurance Portability and Accountability Act
US rules protecting ePHI privacy and security for covered entities and business associates.
United States
ADHICS
High searchAbu Dhabi Healthcare Information and Cyber Security Standard
Healthcare information and cybersecurity standard applicable to healthcare entities in Abu Dhabi.
Abu Dhabi, UAE
UAE NESA / IAS
High searchUAE Information Assurance Standard
UAE information assurance and critical-infrastructure cybersecurity baseline used across government and CII entities.
United Arab Emirates
Saudi NCA ECC
High searchEssential Cybersecurity Controls
National Cybersecurity Authority essential cybersecurity controls for organizations in the Kingdom of Saudi Arabia.
Saudi Arabia
SAMA CSF
SAMA Cyber Security Framework
Cybersecurity framework issued by the Saudi Central Bank for financial institutions.
Saudi Arabia
EU NIS 2
High searchNetwork and Information Security Directive 2
EU directive raising cybersecurity risk-management and reporting duties for essential and important entities across many sectors.
European Union
EU CSRD / ESRS
Corporate Sustainability Reporting Directive
EU sustainability reporting regime covering environmental, social, and governance disclosures.
European Union / Global
ISO 19011
Guidelines for Auditing Management Systems
Guidance for auditing management systems — the method behind integrated ISO 9001/14001/45001/27001 audit programs.
Global
ISO 55000
Asset Management
Overview of asset management principles for value from assets — relevant to infrastructure, utilities, and industrial operators.
Global
Govern smarter. Operate stronger. Grow confidently.
See OptimaGRC map your frameworks in one working session.
Bring your ISO, NESA, PDPL, Quality, or HSE scope. We will show control inheritance, live KPIs, and an auditor-ready trail.
