Compliance Framework
A structured set of requirements and guidance used to design and assess a compliance program.
A compliance framework provides a structured way to think about requirements, controls, and evidence. It defines what “good” looks like for a given area such as security, privacy, or financial reporting.
Examples include SOC 2, ISO 27001, PCI DSS, HIPAA, and NIST 800-53. Organizations often adopt multiple frameworks and map controls across them to avoid duplicate work.
Using a framework gives teams common language, clear targets, and a baseline for audits and external assessments.