Guides
Comparison

Choosing a Framework

Seven primers is a wall, not a doorway. This page is a router for the analyst standing in front of it: a side-by-side comparison of every primer the platform ships, plus a goal-led routing block that points you at the one to open first. Read the matrix to scan the shape of each framework; read the routing block to be told where to start.

Last updated: 2026-08-06

Comparison

Every primer, side by side

Each row is one shipped primer. Difficulty, best-for, typical role, employer signal, and the family-vs-cert split come from the same source-of-truth the index page reads, so a primer added to the SSOT appears here without re-authoring this page.

Framework · Beginner

Best for
Building a shared cybersecurity vocabulary first — the six functions map to almost any other standard.
Typical role
GRC analyst on day one, anyone reading a vendor security questionnaire for the first time.
Employer signal
Universal translator: the framework every other controls list speaks.
Control family vs. cert
Voluntary taxonomy of cyber outcomes — no cert, no audit window, no ATO.

Regulation · Intermediate

Best for
Any controller or processor handling personal data of people in the EU — territorial and extra-territorial scope.
Typical role
Data-protection analyst, DPA drafter, DPIA operator on a high-risk processing scenario.
Employer signal
EU data-protection regulation enforced by each Member State DPA — orders are public.
Control family vs. cert
Regulation enforced by national DPAs; no cert, but the Art. 28 DPA and the Art. 35 DPIA are the gating artifacts.

Regulation · Intermediate

Best for
Any US entity that creates, receives, maintains, or transmits Protected Health Information.
Typical role
Privacy official, security officer, BAA-reviewer on the vendor due-diligence team.
Employer signal
OCR-enforced federal law — the resolution-agreement cycle and the Wall of Shame are public.
Control family vs. cert
Federal regulation enforced by HHS OCR; no cert, no ATO, but the §164.308 risk analysis is the most-cited artifact.

Standard · Intermediate

Best for
Any flow that touches the PAN — twelve requirements, with hard technical mandates and a tiered SAQ.
Typical role
Merchant compliance owner, QSA-side assessor, processor AOC reviewer.
Employer signal
The only framework with hard technical mandates — Reqs 3, 4, 10, 11 are the gating controls.
Control family vs. cert
Standard with ROC (QSA-attested for Level 1) or SAQ + AOC (self-attested); the AOC is what procurement asks for.

Audit · Intermediate

Best for
SaaS trust reports — clearing enterprise procurement with a Type II the auditor can sign.
Typical role
Evidence-collection analyst, control mapper, audit-support lead on an active SOC 2 run.
Employer signal
The default SaaS trust report in the US — Type II is what enterprise procurement demands.
Control family vs. cert
Attestation by a CPA firm (Type I design or Type II operating effectiveness); no cert.

Standard · Advanced

Best for
Standing up an ISMS and winning the global enterprise customer who asks for the gold-stamp cert.
Typical role
ISMS owner, internal auditor, SoA steward, surveillance-audit coordinator.
Employer signal
The international ISMS standard — the certification every global enterprise asks for.
Control family vs. cert
Management system + Annex A controls; cert issued by an accredited Certification Body on a three-year cycle.

Framework · Advanced

Best for
Federal or fed-adjacent systems that need an ATO and a paper trail the AO can sign.
Typical role
Federal GRC analyst, FedRAMP-aligned SaaS compliance owner, CISO at a defense-adjacent shop.
Employer signal
The lifecycle federal work actually runs on — SP 800-53, ATO, POA&M.
Control family vs. cert
Process + lifecycle; cert replaces with the ATO issued by the Authorizing Official.

Router

If your goal is X, start with Y

Pick the row that matches the brief on your desk. Each card links to a primer that is already live on the platform — no dead ends, no "coming soon".

I am new to GRC and want a shared vocabulary first

Open the NIST CSF 2.0 primer — the six functions (Govern, Identify, Protect, Detect, Respond, Recover) are the language every other framework inherits from.

Open NIST CSF 2.0 Quick-Start
I am selling to enterprise customers or running a SaaS trust report

Open the SOC 2 primer — Trust Services Criteria selection, Type I vs Type II, and the evidence binder the auditor walks first.

Open SOC 2 Quick-Start
I touch cardholder data or want to reduce PCI scope

Open the PCI DSS primer — the twelve requirements, the four SAQ families, and the redirect-to-tokenized-checkout path that walks SAQ-D down to SAQ-A.

Open PCI DSS Quick-Start
I am building (or auditing) an ISMS that has to certify

Open the ISO 27001 primer — the mandatory management-system clauses, Annex A controls, the Plan-Do-Check-Act cycle, and the SoA that ties them together.

Open ISO 27001 Quick-Start
I work in US healthcare or review a Business Associate

Open the HIPAA primer — Privacy, Security, and Breach Notification Rules paired with the §164.308 Risk Analysis and the §164.308(b)(1) BAA gate.

Open HIPAA Quick-Start
I handle EU data subjects or run a Chapter V transfer

Open the GDPR primer — the seven principles, the Art. 6 lawful-basis gate, the Art. 28 DPA, and the Art. 35 DPIA.

Open GDPR Quick-Start
I work on a federal or fed-adjacent system

Open the NIST RMF primer — the seven lifecycle steps, SP 800-53 baselines, the SAR + POA&M, and the ATO the Authorizing Official signs.

Open NIST RMF Quick-Start
Browse the Labs index

Every hands-on lab the platform ships — DPIA, Gap Analysis, Risk Register, Policy Drafter, Compliance Checklist — on one page, with the framework selector and the free sub-form marked. Pick the primer that matches the goal-led card above, then run the lab against a real environment to read the gap scoring.

Browse the Labs index →
Browse Interview Prep

Question banks, scenario walk-throughs, and laminated answers for the GRC interview — keyed to the same primer-specific prep groups the SOC 2, ISO 27001, PCI DSS, and GDPR primers steer toward. Read it as preparation for the framework-specific hire conversation you opened the matching primer to rehearse.

Browse Interview Prep →