Choosing a Framework
Seven primers is a wall, not a doorway. This page is a router for the analyst standing in front of it: a side-by-side comparison of every primer the platform ships, plus a goal-led routing block that points you at the one to open first. Read the matrix to scan the shape of each framework; read the routing block to be told where to start.
Last updated: 2026-08-06
Comparison
Every primer, side by side
Each row is one shipped primer. Difficulty, best-for, typical role, employer signal, and the family-vs-cert split come from the same source-of-truth the index page reads, so a primer added to the SSOT appears here without re-authoring this page.
Framework · Beginner
- Best for
- Building a shared cybersecurity vocabulary first — the six functions map to almost any other standard.
- Typical role
- GRC analyst on day one, anyone reading a vendor security questionnaire for the first time.
- Employer signal
- Universal translator: the framework every other controls list speaks.
- Control family vs. cert
- Voluntary taxonomy of cyber outcomes — no cert, no audit window, no ATO.
Regulation · Intermediate
- Best for
- Any controller or processor handling personal data of people in the EU — territorial and extra-territorial scope.
- Typical role
- Data-protection analyst, DPA drafter, DPIA operator on a high-risk processing scenario.
- Employer signal
- EU data-protection regulation enforced by each Member State DPA — orders are public.
- Control family vs. cert
- Regulation enforced by national DPAs; no cert, but the Art. 28 DPA and the Art. 35 DPIA are the gating artifacts.
Regulation · Intermediate
- Best for
- Any US entity that creates, receives, maintains, or transmits Protected Health Information.
- Typical role
- Privacy official, security officer, BAA-reviewer on the vendor due-diligence team.
- Employer signal
- OCR-enforced federal law — the resolution-agreement cycle and the Wall of Shame are public.
- Control family vs. cert
- Federal regulation enforced by HHS OCR; no cert, no ATO, but the §164.308 risk analysis is the most-cited artifact.
Standard · Intermediate
- Best for
- Any flow that touches the PAN — twelve requirements, with hard technical mandates and a tiered SAQ.
- Typical role
- Merchant compliance owner, QSA-side assessor, processor AOC reviewer.
- Employer signal
- The only framework with hard technical mandates — Reqs 3, 4, 10, 11 are the gating controls.
- Control family vs. cert
- Standard with ROC (QSA-attested for Level 1) or SAQ + AOC (self-attested); the AOC is what procurement asks for.
Audit · Intermediate
- Best for
- SaaS trust reports — clearing enterprise procurement with a Type II the auditor can sign.
- Typical role
- Evidence-collection analyst, control mapper, audit-support lead on an active SOC 2 run.
- Employer signal
- The default SaaS trust report in the US — Type II is what enterprise procurement demands.
- Control family vs. cert
- Attestation by a CPA firm (Type I design or Type II operating effectiveness); no cert.
Standard · Advanced
- Best for
- Standing up an ISMS and winning the global enterprise customer who asks for the gold-stamp cert.
- Typical role
- ISMS owner, internal auditor, SoA steward, surveillance-audit coordinator.
- Employer signal
- The international ISMS standard — the certification every global enterprise asks for.
- Control family vs. cert
- Management system + Annex A controls; cert issued by an accredited Certification Body on a three-year cycle.
Framework · Advanced
- Best for
- Federal or fed-adjacent systems that need an ATO and a paper trail the AO can sign.
- Typical role
- Federal GRC analyst, FedRAMP-aligned SaaS compliance owner, CISO at a defense-adjacent shop.
- Employer signal
- The lifecycle federal work actually runs on — SP 800-53, ATO, POA&M.
- Control family vs. cert
- Process + lifecycle; cert replaces with the ATO issued by the Authorizing Official.
Router
If your goal is X, start with Y
Pick the row that matches the brief on your desk. Each card links to a primer that is already live on the platform — no dead ends, no "coming soon".
Open the NIST CSF 2.0 primer — the six functions (Govern, Identify, Protect, Detect, Respond, Recover) are the language every other framework inherits from.
Open NIST CSF 2.0 Quick-Start →Open the SOC 2 primer — Trust Services Criteria selection, Type I vs Type II, and the evidence binder the auditor walks first.
Open SOC 2 Quick-Start →Open the PCI DSS primer — the twelve requirements, the four SAQ families, and the redirect-to-tokenized-checkout path that walks SAQ-D down to SAQ-A.
Open PCI DSS Quick-Start →Open the ISO 27001 primer — the mandatory management-system clauses, Annex A controls, the Plan-Do-Check-Act cycle, and the SoA that ties them together.
Open ISO 27001 Quick-Start →Open the HIPAA primer — Privacy, Security, and Breach Notification Rules paired with the §164.308 Risk Analysis and the §164.308(b)(1) BAA gate.
Open HIPAA Quick-Start →Open the GDPR primer — the seven principles, the Art. 6 lawful-basis gate, the Art. 28 DPA, and the Art. 35 DPIA.
Open GDPR Quick-Start →Open the NIST RMF primer — the seven lifecycle steps, SP 800-53 baselines, the SAR + POA&M, and the ATO the Authorizing Official signs.
Open NIST RMF Quick-Start →Every hands-on lab the platform ships — DPIA, Gap Analysis, Risk Register, Policy Drafter, Compliance Checklist — on one page, with the framework selector and the free sub-form marked. Pick the primer that matches the goal-led card above, then run the lab against a real environment to read the gap scoring.
Question banks, scenario walk-throughs, and laminated answers for the GRC interview — keyed to the same primer-specific prep groups the SOC 2, ISO 27001, PCI DSS, and GDPR primers steer toward. Read it as preparation for the framework-specific hire conversation you opened the matching primer to rehearse.