{
  "gdpr": {
    "name": "GDPR",
    "fullName": "General Data Protection Regulation",
    "category": "EU Data & AI Acts",
    "governance": "European Union",
    "umbrella": "EU",
    "jurisdiction": "EU",
    "status": "Regulation (EU) 2016/679; applicable since May 2018",
    "standardization": "law",
    "description": [
      "The EU's personal data regime: lawful basis, purpose limitation, data minimisation, data subject rights, records of processing, transfer rules, and breach notification within 72 hours.",
      "For a data platform it is the source of most catalogue metadata obligations you cannot avoid: what personal data you hold, why you hold it, who it goes to, and how long you keep it. ISO/IEC 27701 and the EU Cloud Code of Conduct are the usual ways of evidencing it."
    ],
    "links": [
      {
        "label": "Regulation (EU) 2016/679 (EUR-Lex)",
        "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
      },
      {
        "label": "EDPB guidelines",
        "url": "https://www.edpb.europa.eu/our-work-tools/general-guidance/guidelines-recommendations-best-practices_en"
      }
    ],
    "firstReleased": 2016,
    "logo": "/media/icons/standards-map/logos/eu.svg"
  },
  "eu-ai-act": {
    "name": "EU AI Act",
    "fullName": "Artificial Intelligence Act",
    "category": "EU Data & AI Acts",
    "governance": "European Union",
    "umbrella": "EU",
    "jurisdiction": "EU",
    "status": "Regulation (EU) 2024/1689; prohibitions since February 2025, general-purpose AI rules since August 2025, high-risk obligations from 2027",
    "standardization": "law",
    "description": [
      "A risk-tiered regime for AI systems: prohibited practices, obligations for high-risk systems (risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness), transparency duties, and a separate track for general-purpose AI models.",
      "Its data governance article is the one that lands on data teams: training, validation and test data sets must be relevant, sufficiently representative, and as far as possible free of errors and complete. ISO/IEC 42001 and the forthcoming CEN-CENELEC standards are how conformity gets demonstrated."
    ],
    "links": [
      {
        "label": "Regulation (EU) 2024/1689 (EUR-Lex)",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
      },
      {
        "label": "European Commission: AI Act",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
      }
    ],
    "firstReleased": 2024,
    "logo": "/media/icons/standards-map/logos/eu.svg"
  },
  "eu-data-act": {
    "name": "Data Act",
    "fullName": "EU Data Act",
    "category": "EU Data & AI Acts",
    "governance": "European Union",
    "umbrella": "EU",
    "jurisdiction": "EU",
    "status": "Regulation (EU) 2023/2854; in force January 2024, applicable since 12 September 2025",
    "standardization": "law",
    "description": [
      "Rules on access to and use of data generated by connected products and related services: users get access to the data their devices produce and can direct it to third parties, with contractual fairness rules and safeguards against unlawful international access.",
      "It also mandates cloud switching and interoperability, removing egress charges over time and requiring providers to support portability. That makes open formats and portable contracts a legal argument, not only an architectural preference."
    ],
    "links": [
      {
        "label": "Regulation (EU) 2023/2854 (EUR-Lex)",
        "url": "https://eur-lex.europa.eu/eli/reg/2023/2854/oj"
      }
    ],
    "firstReleased": 2023,
    "logo": "/media/icons/standards-map/logos/eu.svg"
  },
  "eu-dga": {
    "name": "DGA",
    "fullName": "Data Governance Act",
    "category": "EU Data & AI Acts",
    "governance": "European Union",
    "umbrella": "EU",
    "jurisdiction": "EU",
    "status": "Regulation (EU) 2022/868; applicable since September 2023",
    "standardization": "law",
    "description": [
      "The framework for data sharing across the EU: re-use of protected public sector data, a notification regime for data intermediation services, and rules for recognised data altruism organisations.",
      "It is the legal scaffolding under the European data spaces, and the reason the Dataspace Protocol, Gaia-X and the DSSC Blueprint exist as concrete implementations rather than position papers."
    ],
    "links": [
      {
        "label": "Regulation (EU) 2022/868 (EUR-Lex)",
        "url": "https://eur-lex.europa.eu/eli/reg/2022/868/oj"
      }
    ],
    "firstReleased": 2022,
    "logo": "/media/icons/standards-map/logos/eu.svg"
  },
  "nis2": {
    "name": "NIS2",
    "fullName": "Network and Information Security Directive 2",
    "category": "EU Resilience & Security Acts",
    "governance": "European Union",
    "umbrella": "EU",
    "jurisdiction": "EU",
    "status": "Directive (EU) 2022/2555; national transposition was due October 2024, and several member states ran late",
    "standardization": "law",
    "description": [
      "Cybersecurity risk management and incident reporting duties for essential and important entities across energy, transport, health, digital infrastructure, public administration and more, with management bodies personally accountable for compliance.",
      "Being a directive, what binds you is the national transposition, not the text itself, so the detail varies by member state. ISO/IEC 27001 and IT-Grundschutz are the usual routes to demonstrating the required measures."
    ],
    "links": [
      {
        "label": "Directive (EU) 2022/2555 (EUR-Lex)",
        "url": "https://eur-lex.europa.eu/eli/dir/2022/2555/oj"
      },
      {
        "label": "European Commission: NIS2",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/nis2-directive"
      }
    ],
    "firstReleased": 2022,
    "logo": "/media/icons/standards-map/logos/eu.svg"
  },
  "dora": {
    "name": "DORA",
    "fullName": "Digital Operational Resilience Act",
    "category": "EU Resilience & Security Acts",
    "governance": "European Union",
    "umbrella": "EU",
    "jurisdiction": "EU",
    "status": "Regulation (EU) 2022/2554; applies since 17 January 2025",
    "standardization": "law",
    "description": [
      "ICT risk management, incident classification and reporting, resilience testing, and third-party risk oversight for financial entities, plus a supervisory regime for critical ICT providers serving them.",
      "The third-party chapter is what reaches data platforms: a register of information on every ICT contract, mandated contractual terms, exit strategies, and concentration risk analysis. Your data vendors become items in a supervisory filing."
    ],
    "links": [
      {
        "label": "Regulation (EU) 2022/2554 (EUR-Lex)",
        "url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj"
      },
      {
        "label": "ESMA: DORA",
        "url": "https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/digital-operational-resilience-act-dora"
      }
    ],
    "firstReleased": 2022,
    "logo": "/media/icons/standards-map/logos/eu.svg"
  },
  "eu-cra": {
    "name": "CRA",
    "fullName": "Cyber Resilience Act",
    "category": "EU Resilience & Security Acts",
    "governance": "European Union",
    "umbrella": "EU",
    "jurisdiction": "EU",
    "status": "Regulation (EU) 2024/2847; reporting from September 2026, main obligations from December 2027",
    "standardization": "law",
    "description": [
      "Cybersecurity requirements for products with digital elements placed on the EU market: secure-by-design obligations, vulnerability handling for the support period, and reporting of actively exploited vulnerabilities.",
      "It puts an SBOM obligation into EU law for the first time, which is why SPDX and CycloneDX moved from good practice to procurement requirement."
    ],
    "links": [
      {
        "label": "Regulation (EU) 2024/2847 (EUR-Lex)",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj"
      }
    ],
    "firstReleased": 2024,
    "logo": "/media/icons/standards-map/logos/eu.svg"
  },
  "bcbs-239": {
    "name": "BCBS 239",
    "fullName": "Principles for Effective Risk Data Aggregation and Risk Reporting",
    "category": "Global & Sector Regulation",
    "governance": "Basel Committee on Banking Supervision",
    "umbrella": "BCBS",
    "jurisdiction": "Global",
    "status": "Published 2013; supervisory expectations ongoing",
    "standardization": "law",
    "description": [
      "Fourteen principles on governance, data architecture, accuracy, completeness, timeliness and adaptability of risk data, written for global systemically important banks after the financial crisis exposed how few could aggregate their own exposures quickly.",
      "It is the closest thing to a regulation about data architecture itself, and the reason lineage, ownership and data quality metrics are audited artefacts in banking. DCAM is the usual assessment vehicle."
    ],
    "links": [
      {
        "label": "BCBS 239 (BIS)",
        "url": "https://www.bis.org/publ/bcbs239.htm"
      }
    ],
    "firstReleased": 2013,
    "logo": "/media/icons/standards-map/logos/bcbs.svg"
  },
  "sox": {
    "name": "SOX",
    "fullName": "Sarbanes-Oxley Act",
    "category": "Global & Sector Regulation",
    "governance": "US Congress / SEC / PCAOB",
    "umbrella": "US SEC",
    "jurisdiction": "US / Global",
    "status": "Enacted 2002; Sections 302 and 404 drive the controls work",
    "standardization": "law",
    "description": [
      "Requires management and auditors to assess and attest to internal control over financial reporting, with personal certification by the CEO and CFO.",
      "Section 404 is why access controls, change management and audit trails on financial data pipelines are tested annually. Any data product feeding the numbers in a listed company's filings is in scope."
    ],
    "links": [
      {
        "label": "Public Law 107-204 (govinfo)",
        "url": "https://www.govinfo.gov/content/pkg/PLAW-107publ204/pdf/PLAW-107publ204.pdf"
      }
    ],
    "firstReleased": 2002,
    "logo": "/media/icons/standards-map/logos/us-sec.svg"
  },
  "hipaa": {
    "name": "HIPAA",
    "fullName": "Health Insurance Portability and Accountability Act",
    "category": "Global & Sector Regulation",
    "governance": "US HHS / OCR",
    "umbrella": "US HHS",
    "jurisdiction": "US",
    "status": "Enacted 1996; Privacy, Security and Breach Notification Rules",
    "standardization": "law",
    "description": [
      "The US regime for protected health information: the Privacy Rule on permitted use and disclosure, the Security Rule on administrative, physical and technical safeguards, and mandatory breach notification.",
      "Its business associate agreements pull every downstream processor into scope, which is why de-identification and minimum-necessary access are design constraints on any health data platform touching the US."
    ],
    "links": [
      {
        "label": "HHS: HIPAA",
        "url": "https://www.hhs.gov/hipaa/index.html"
      },
      {
        "label": "45 CFR Part 164 (eCFR)",
        "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164"
      }
    ],
    "firstReleased": 1996,
    "logo": "/media/icons/standards-map/logos/us-hhs.svg"
  },
  "ccpa-cpra": {
    "name": "CCPA / CPRA",
    "fullName": "California Consumer Privacy Act, as amended",
    "category": "Global & Sector Regulation",
    "governance": "California Privacy Protection Agency",
    "umbrella": "CPPA",
    "jurisdiction": "US",
    "status": "CCPA 2018, amended by CPRA; enforced by the CPPA",
    "standardization": "law",
    "description": [
      "California's consumer privacy regime: rights to know, delete, correct and opt out of the sale or sharing of personal information, plus limits on the use of sensitive personal information.",
      "It is the template most other US state privacy laws copied, so building for CCPA generally buys you the rest of the patchwork: an opt-out signal and a deletion path that actually reaches every downstream copy."
    ],
    "links": [
      {
        "label": "California AG: CCPA",
        "url": "https://oag.ca.gov/privacy/ccpa"
      },
      {
        "label": "California Privacy Protection Agency",
        "url": "https://cppa.ca.gov/"
      }
    ],
    "firstReleased": 2018,
    "logo": "/media/icons/standards-map/logos/cppa.svg"
  },
  "dama-dmbok": {
    "name": "DAMA-DMBOK2",
    "fullName": "Data Management Body of Knowledge, 2nd Edition",
    "category": "Data Management Frameworks",
    "governance": "DAMA International",
    "umbrella": "DAMA",
    "jurisdiction": "Global",
    "status": "2nd edition (2017), revised 2024; a DMBOK 3.0 project started in 2025",
    "standardization": "community",
    "description": [
      "The reference body of knowledge for enterprise data management, organised around eleven knowledge areas: governance, architecture, modelling, storage, security, integration, reference and master data, warehousing, metadata, quality, and document management.",
      "It is not a certifiable standard and prescribes no controls. Its value under regulatory pressure is the shared vocabulary: when an auditor asks who owns a data set and how its quality is measured, DMBOK gives you the roles and processes to point at."
    ],
    "links": [
      {
        "label": "Official site",
        "url": "https://www.dama.org/cpages/body-of-knowledge"
      },
      {
        "label": "DAMA International",
        "url": "https://www.dama.org/"
      }
    ],
    "firstReleased": 2009,
    "logo": "/media/icons/standards-map/logos/dama.svg"
  },
  "dcam": {
    "name": "DCAM",
    "fullName": "Data Management Capability Assessment Model",
    "category": "Data Management Frameworks",
    "governance": "EDM Council",
    "umbrella": "EDM Council",
    "jurisdiction": "Global",
    "status": "v3: eight components, 34 capabilities and 101 sub-capabilities",
    "standardization": "community",
    "description": [
      "A capability assessment model that scores an organisation's data management maturity across eight components, from data governance and architecture to data quality and technology architecture, broken down into 34 capabilities and 101 sub-capabilities.",
      "Widely used in banking and insurance as the structured evidence base behind BCBS 239 and comparable supervisory expectations. The assessment output is what turns \"we manage our data well\" into a defensible score with a remediation roadmap, run in-house or through an authorised partner."
    ],
    "links": [
      {
        "label": "Official site",
        "url": "https://edmcouncil.org/frameworks/dcam/"
      },
      {
        "label": "EDM Council",
        "url": "https://edmcouncil.org/"
      }
    ],
    "firstReleased": 2014,
    "logo": "/media/icons/standards-map/logos/edmcouncil.svg"
  },
  "cdmc": {
    "name": "CDMC",
    "fullName": "Cloud Data Management Capabilities",
    "category": "Data Management Frameworks",
    "governance": "EDM Council",
    "umbrella": "EDM Council",
    "jurisdiction": "Global",
    "status": "v1.1 (2021); 14 key controls and automations",
    "standardization": "community",
    "description": [
      "A framework for managing and protecting sensitive data in cloud, multi-cloud and hybrid environments, built around fourteen key controls covering classification, ownership, cataloguing, entitlements, and data sovereignty.",
      "It is the cloud-native complement to DCAM rather than a replacement: the key controls are written to be automatable, which makes CDMC the more practical fit when your evidence has to come out of a lakehouse rather than a policy document."
    ],
    "links": [
      {
        "label": "Official site",
        "url": "https://edmcouncil.org/frameworks/cdmc/"
      }
    ],
    "firstReleased": 2021,
    "logo": "/media/icons/standards-map/logos/edmcouncil.svg"
  },
  "iso-38505": {
    "name": "ISO/IEC 38505",
    "fullName": "Governance of Data",
    "category": "Data Management Frameworks",
    "governance": "ISO/IEC JTC 1/SC 40",
    "umbrella": "ISO/IEC",
    "jurisdiction": "Global",
    "status": "Part 1 published 2017; Part 2 (data analytics) 2018",
    "standardization": "formal-standard",
    "description": [
      "Applies the ISO/IEC 38500 IT governance principles specifically to data, giving boards and executives a model for the accountability, strategy and conformance of data use.",
      "Deliberately high level: it tells a governing body what questions to ask, not how to implement controls. Pair it with a control framework if you need something auditable."
    ],
    "links": [
      {
        "label": "ISO/IEC 38505-1:2017",
        "url": "https://www.iso.org/standard/56639.html"
      }
    ],
    "firstReleased": 2017,
    "logo": "/media/icons/standards-map/logos/iso.png"
  },
  "iso-8000": {
    "name": "ISO 8000",
    "fullName": "Data Quality",
    "category": "Metadata & Quality",
    "governance": "ISO TC 184/SC 4",
    "umbrella": "ISO",
    "umbrellaSearch": "ISO ISO/IEC",
    "jurisdiction": "Global",
    "status": "Multi-part series; parts published from 2009 onwards",
    "standardization": "formal-standard",
    "description": [
      "A multi-part standard for data quality, best known for its master data parts: syntax, semantic encoding, provenance and the requirements a data set must meet to be exchanged between organisations without loss of meaning.",
      "It is the standard cited when quality has to be a contractual property of the data itself rather than a property of the pipeline that produced it, which is exactly the framing supply chain and product data regulation tends to use."
    ],
    "links": [
      {
        "label": "ISO 8000-1:2022",
        "url": "https://www.iso.org/standard/81745.html"
      },
      {
        "label": "ISO TC 184/SC 4",
        "url": "https://www.iso.org/committee/54158.html"
      }
    ],
    "firstReleased": 2009,
    "logo": "/media/icons/standards-map/logos/iso.png"
  },
  "iso-11179": {
    "name": "ISO/IEC 11179",
    "fullName": "Metadata Registries",
    "category": "Metadata & Quality",
    "governance": "ISO/IEC JTC 1/SC 32",
    "umbrella": "ISO/IEC",
    "jurisdiction": "Global",
    "status": "Multi-part series; Part 1 first published 1999",
    "standardization": "formal-standard",
    "description": [
      "Specifies how data elements are named, defined, classified and registered so that meaning survives movement between systems and organisations. It is the metadata registry model underneath national statistics offices, health data authorities and public sector registries.",
      "Heavyweight for a product team, but if you file data to a regulator that runs an 11179 registry, its concepts (data element concept, value domain, conceptual domain) are the shape your submissions have to take."
    ],
    "links": [
      {
        "label": "ISO/IEC 11179-1:2023",
        "url": "https://www.iso.org/standard/78914.html"
      },
      {
        "label": "ISO/IEC JTC 1/SC 32",
        "url": "https://www.iso.org/committee/45342.html"
      }
    ],
    "firstReleased": 1999,
    "logo": "/media/icons/standards-map/logos/iso.png"
  },
  "iso-25012": {
    "name": "ISO/IEC 25012",
    "fullName": "Data Quality Model",
    "category": "Metadata & Quality",
    "governance": "ISO/IEC JTC 1/SC 7",
    "umbrella": "ISO/IEC",
    "jurisdiction": "Global",
    "status": "Published 2008; part of the SQuaRE series",
    "standardization": "formal-standard",
    "description": [
      "Defines a general data quality model with fifteen characteristics (accuracy, completeness, consistency, credibility, currentness, accessibility, compliance, confidentiality, and others), split into inherent and system-dependent views.",
      "Useful as the dictionary behind your data quality checks: when a contract or regulation says data must be \"accurate and complete\", 25012 is where those words have an agreed definition."
    ],
    "links": [
      {
        "label": "ISO/IEC 25012:2008",
        "url": "https://www.iso.org/standard/35736.html"
      }
    ],
    "firstReleased": 2008,
    "logo": "/media/icons/standards-map/logos/iso.png"
  },
  "odrl": {
    "name": "ODRL",
    "fullName": "Open Digital Rights Language",
    "category": "Usage Policy & Rights",
    "governance": "W3C",
    "umbrella": "W3C",
    "jurisdiction": "Global",
    "status": "ODRL 2.2 W3C Recommendation (2018)",
    "standardization": "formal-standard",
    "description": [
      "A policy expression language for permissions, prohibitions and obligations over any asset: who may use this data, for what purpose, under which constraint, and with what duty attached.",
      "It is the vocabulary European data space initiatives use to make terms of use machine-enforceable rather than PDF-shaped. If you need to carry a purpose limitation alongside the data itself, this is the standard to reach for."
    ],
    "links": [
      {
        "label": "ODRL Information Model 2.2",
        "url": "https://www.w3.org/TR/odrl-model/"
      },
      {
        "label": "ODRL Vocabulary & Expression",
        "url": "https://www.w3.org/TR/odrl-vocab/"
      }
    ],
    "firstReleased": 2018,
    "logo": "/media/icons/standards-map/logos/w3c.svg"
  },
  "dpv": {
    "name": "DPV",
    "fullName": "Data Privacy Vocabulary",
    "category": "Usage Policy & Rights",
    "governance": "W3C Data Privacy Vocabularies and Controls CG",
    "umbrella": "W3C",
    "jurisdiction": "EU",
    "status": "DPV 2.3 (2026); DPVCG report with GDPR, DGA, EHDS and AI Act extensions",
    "standardization": "community",
    "description": [
      "A vocabulary for expressing personal data handling in machine-readable form: personal data categories, purposes, legal bases, processing operations, recipients, and the technical and organisational measures applied.",
      "Ships with jurisdiction extensions (EU GDPR, EU AI Act, and others), which makes it the practical bridge between a records-of-processing obligation and metadata your catalogue can actually hold."
    ],
    "links": [
      {
        "label": "Data Privacy Vocabulary",
        "url": "https://w3c-cg.github.io/dpv/"
      },
      {
        "label": "W3C DPVCG",
        "url": "https://www.w3.org/community/dpvcg/"
      }
    ],
    "firstReleased": 2022,
    "logo": "/media/icons/standards-map/logos/w3c.svg"
  },
  "opa": {
    "name": "OPA",
    "fullName": "Open Policy Agent",
    "category": "Usage Policy & Rights",
    "governance": "CNCF (graduated)",
    "umbrella": "CNCF",
    "jurisdiction": "Global",
    "status": "CNCF graduated project since 2021; Rego policy language",
    "standardization": "foundation",
    "description": [
      "A general-purpose policy engine with its own declarative language, Rego. Policies are decoupled from the services that enforce them: the service asks OPA for a decision, OPA answers from policy and data.",
      "The compliance value is evidence. Policy is code, decisions are logged, and \"access was denied because of clause X\" becomes a query rather than an interview."
    ],
    "links": [
      {
        "label": "Official site",
        "url": "https://www.openpolicyagent.org/"
      },
      {
        "label": "GitHub: open-policy-agent/opa",
        "url": "https://github.com/open-policy-agent/opa"
      }
    ],
    "firstReleased": 2016,
    "logo": "/media/icons/standards-map/logos/opa.png"
  },
  "xacml": {
    "name": "XACML",
    "fullName": "eXtensible Access Control Markup Language",
    "category": "Identity & Access",
    "governance": "OASIS",
    "umbrella": "OASIS",
    "jurisdiction": "Global",
    "status": "XACML 3.0 OASIS Standard (2013)",
    "standardization": "formal-standard",
    "description": [
      "The XML policy language and reference architecture that gave attribute-based access control its vocabulary: policy decision point, policy enforcement point, policy information point.",
      "The architecture outlived the syntax. New systems adopt the PDP/PEP split but express the policy in Rego or Cedar; you will still meet XACML in identity and healthcare platforms that standardised on it a decade ago."
    ],
    "links": [
      {
        "label": "XACML 3.0 specification",
        "url": "https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html"
      },
      {
        "label": "OASIS XACML TC",
        "url": "https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=xacml"
      }
    ],
    "firstReleased": 2003,
    "logo": "/media/icons/standards-map/logos/oasis.png"
  },
  "iso-27001": {
    "name": "ISO/IEC 27001",
    "fullName": "Information Security Management Systems",
    "category": "Management Systems",
    "governance": "ISO/IEC JTC 1/SC 27",
    "umbrella": "ISO/IEC",
    "jurisdiction": "Global",
    "status": "ISO/IEC 27001:2022 current; certifiable",
    "standardization": "formal-standard",
    "description": [
      "The requirements standard for an information security management system: scope, risk assessment, risk treatment, the Annex A control set, and the management processes that keep it alive.",
      "It is the anchor certification of the compliance world. NIS2, DORA and sectoral supervisors do not mandate it by name, but an accredited 27001 certificate is the artefact most readily accepted as evidence that a management system exists."
    ],
    "links": [
      {
        "label": "ISO/IEC 27001 overview",
        "url": "https://www.iso.org/standard/27001"
      },
      {
        "label": "ISO/IEC JTC 1/SC 27",
        "url": "https://www.iso.org/committee/45306.html"
      }
    ],
    "firstReleased": 2005,
    "logo": "/media/icons/standards-map/logos/iso.png"
  },
  "nist-csf": {
    "name": "NIST CSF",
    "fullName": "Cybersecurity Framework 2.0",
    "category": "Management Systems",
    "governance": "NIST",
    "umbrella": "NIST",
    "jurisdiction": "US / Global",
    "status": "CSF 2.0 (2024); six functions including Govern",
    "standardization": "formal-standard",
    "description": [
      "An outcome-based framework organised into six functions (Govern, Identify, Protect, Detect, Respond, Recover), each broken into categories and subcategories that describe what good looks like without prescribing how to get there.",
      "Version 2.0 added the Govern function and dropped the critical-infrastructure framing, which is what made it usable as a general risk-communication layer above whatever control catalogue you actually implement."
    ],
    "links": [
      {
        "label": "NIST Cybersecurity Framework",
        "url": "https://www.nist.gov/cyberframework"
      },
      {
        "label": "CSF 2.0 (NIST CSWP 29)",
        "url": "https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf"
      }
    ],
    "firstReleased": 2014,
    "logo": "/media/icons/standards-map/logos/nist.svg"
  },
  "nist-rmf": {
    "name": "NIST RMF",
    "fullName": "Risk Management Framework (SP 800-37)",
    "category": "Management Systems",
    "governance": "NIST",
    "umbrella": "NIST",
    "jurisdiction": "US",
    "status": "Revision 2 (2018)",
    "standardization": "formal-standard",
    "description": [
      "The seven-step process (prepare, categorise, select, implement, assess, authorise, monitor) that US federal systems follow to select and authorise security controls from SP 800-53.",
      "It is a process standard, not a control catalogue. Outside the US federal supply chain, the categorise-select-assess loop is worth borrowing even if the authorisation ceremony is not."
    ],
    "links": [
      {
        "label": "NIST SP 800-37 Rev. 2",
        "url": "https://csrc.nist.gov/pubs/sp/800/37/r2/final"
      },
      {
        "label": "RMF resource centre",
        "url": "https://csrc.nist.gov/projects/risk-management"
      }
    ],
    "firstReleased": 2010,
    "logo": "/media/icons/standards-map/logos/nist.svg"
  },
  "bsi-grundschutz": {
    "name": "Grundschutz",
    "fullName": "BSI IT-Grundschutz",
    "category": "Management Systems",
    "governance": "BSI (Germany)",
    "umbrella": "BSI",
    "jurisdiction": "EU / Germany",
    "status": "BSI Standards 200-1, 200-2 and 200-3, with 200-4 for business continuity; Kompendium revised regularly",
    "standardization": "formal-standard",
    "description": [
      "The German federal information security methodology: a modular catalogue of building blocks, each with concrete threats and required safeguards, plus the BSI Standards that describe the management system around them.",
      "Its distinguishing feature is prescriptiveness: where ISO/IEC 27001 says \"assess your risk\", IT-Grundschutz hands you a baseline of measures per component. Certification is available as ISO/IEC 27001 on the basis of IT-Grundschutz."
    ],
    "links": [
      {
        "label": "BSI IT-Grundschutz",
        "url": "https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/IT-Grundschutz/it-grundschutz_node.html"
      }
    ],
    "firstReleased": 1994,
    "logo": "/media/icons/standards-map/logos/bsi.svg"
  },
  "iso-27002": {
    "name": "ISO/IEC 27002",
    "fullName": "Information Security Controls",
    "category": "Security Controls",
    "governance": "ISO/IEC JTC 1/SC 27",
    "umbrella": "ISO/IEC",
    "jurisdiction": "Global",
    "status": "ISO/IEC 27002:2022; 93 controls in four themes",
    "standardization": "formal-standard",
    "description": [
      "The companion control catalogue to ISO/IEC 27001: for each control, what it is for, how to implement it, and what other guidance applies. The 2022 revision restructured 114 controls into 93 across organisational, people, physical and technological themes.",
      "It introduced attributes (control type, security property, operational capability) so controls can be mapped to other frameworks mechanically instead of by hand."
    ],
    "links": [
      {
        "label": "ISO/IEC 27002:2022",
        "url": "https://www.iso.org/standard/75652.html"
      }
    ],
    "firstReleased": 2005,
    "logo": "/media/icons/standards-map/logos/iso.png"
  },
  "nist-800-53": {
    "name": "NIST SP 800-53",
    "fullName": "Security and Privacy Controls for Information Systems",
    "category": "Security Controls",
    "governance": "NIST",
    "umbrella": "NIST",
    "jurisdiction": "US / Global",
    "status": "Revision 5 (2020); patch release 5.2.0 in 2025",
    "standardization": "formal-standard",
    "description": [
      "A catalogue of over a thousand security and privacy controls across twenty families, with baselines for low, moderate and high impact systems, published free of charge and machine-readable via OSCAL.",
      "Even outside US federal scope it is the reference people map to when two frameworks disagree: 800-53 usually has the finer-grained control that both can point at."
    ],
    "links": [
      {
        "label": "NIST SP 800-53 Rev. 5",
        "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final"
      },
      {
        "label": "OSCAL",
        "url": "https://pages.nist.gov/OSCAL/"
      }
    ],
    "firstReleased": 2005,
    "logo": "/media/icons/standards-map/logos/nist.svg"
  },
  "cis-controls": {
    "name": "CIS Controls",
    "fullName": "CIS Critical Security Controls",
    "category": "Security Controls",
    "governance": "Center for Internet Security",
    "umbrella": "CIS",
    "jurisdiction": "Global",
    "status": "v8.1 (June 2024): 18 controls, 153 safeguards, three implementation groups",
    "standardization": "community",
    "description": [
      "Eighteen prioritised controls with 153 safeguards, split into three implementation groups so a small organisation can implement the first group and honestly claim a baseline.",
      "Paired with the CIS Benchmarks, the hardening configurations for operating systems, cloud services and databases that most CIS-aligned tooling actually checks against."
    ],
    "links": [
      {
        "label": "CIS Critical Security Controls",
        "url": "https://www.cisecurity.org/controls"
      },
      {
        "label": "CIS Benchmarks",
        "url": "https://www.cisecurity.org/cis-benchmarks"
      }
    ],
    "firstReleased": 2008,
    "logo": "/media/icons/standards-map/logos/cis.svg"
  },
  "iso-27701": {
    "name": "ISO/IEC 27701",
    "fullName": "Privacy Information Management System",
    "category": "Privacy",
    "governance": "ISO/IEC JTC 1/SC 27",
    "umbrella": "ISO/IEC",
    "jurisdiction": "Global",
    "status": "27701:2019 as a 27001 extension; 2025 revision makes it standalone",
    "standardization": "formal-standard",
    "description": [
      "Extends an information security management system into a privacy information management system, with separate requirements for controllers and processors and a mapping annex to GDPR articles.",
      "The GDPR mapping is the reason it matters: it turns \"we comply with GDPR\" into a set of auditable management-system requirements a certification body can actually test."
    ],
    "links": [
      {
        "label": "ISO/IEC 27701",
        "url": "https://www.iso.org/standard/85819.html"
      }
    ],
    "firstReleased": 2019,
    "logo": "/media/icons/standards-map/logos/iso.png"
  },
  "iso-27018": {
    "name": "ISO/IEC 27018",
    "fullName": "Protection of PII in Public Clouds",
    "category": "Privacy",
    "governance": "ISO/IEC JTC 1/SC 27",
    "umbrella": "ISO/IEC",
    "jurisdiction": "Global",
    "status": "ISO/IEC 27018:2019",
    "standardization": "formal-standard",
    "description": [
      "A code of practice for public cloud providers acting as processors of personally identifiable information: consent and choice, purpose limitation, disclosure to third parties, return and deletion, and transparency about sub-processors.",
      "Every major cloud provider certifies against it, so it is more often something you inherit from a vendor than something you implement, but it is the right question to ask of any processor in the chain."
    ],
    "links": [
      {
        "label": "ISO/IEC 27018:2019",
        "url": "https://www.iso.org/standard/76559.html"
      }
    ],
    "firstReleased": 2014,
    "logo": "/media/icons/standards-map/logos/iso.png"
  },
  "nist-privacy": {
    "name": "NIST Privacy Framework",
    "fullName": "NIST Privacy Framework",
    "category": "Privacy",
    "governance": "NIST",
    "umbrella": "NIST",
    "jurisdiction": "US / Global",
    "status": "Version 1.0 (2020); 1.1 in development alongside CSF 2.0",
    "standardization": "formal-standard",
    "description": [
      "A voluntary framework structured like the Cybersecurity Framework (Identify, Govern, Control, Communicate, Protect) for managing privacy risk arising from data processing, not only from breaches.",
      "Its useful contribution is separating privacy risk from security risk: problematic data actions can be entirely secure and still harm people. That distinction is what data minimisation and purpose limitation arguments hang on."
    ],
    "links": [
      {
        "label": "NIST Privacy Framework",
        "url": "https://www.nist.gov/privacy-framework"
      }
    ],
    "firstReleased": 2020,
    "logo": "/media/icons/standards-map/logos/nist.svg"
  },
  "iso-29100": {
    "name": "ISO/IEC 29100",
    "fullName": "Privacy Framework",
    "category": "Privacy",
    "governance": "ISO/IEC JTC 1/SC 27",
    "umbrella": "ISO/IEC",
    "jurisdiction": "Global",
    "status": "Published 2011, amended 2018",
    "standardization": "formal-standard",
    "description": [
      "The privacy terminology and principles standard: PII, PII principal, PII controller, PII processor, and eleven privacy principles that later ISO privacy standards build on.",
      "Still the normative source of those definitions, but as an implementation target it has been overtaken by ISO/IEC 27701 and the 27018/27550 family."
    ],
    "links": [
      {
        "label": "ISO/IEC 29100:2011",
        "url": "https://www.iso.org/standard/45123.html"
      }
    ],
    "firstReleased": 2011,
    "logo": "/media/icons/standards-map/logos/iso.png"
  },
  "mitre-attack": {
    "name": "MITRE ATT&CK",
    "fullName": "Adversarial Tactics, Techniques and Common Knowledge",
    "category": "Threat Intelligence",
    "governance": "MITRE",
    "umbrella": "MITRE",
    "jurisdiction": "Global",
    "status": "Enterprise, Mobile and ICS matrices; annual releases (v19, April 2026)",
    "standardization": "community",
    "description": [
      "A curated knowledge base of adversary tactics and techniques observed in the wild, organised as matrices and identified by stable technique IDs.",
      "Those IDs are the point. Detections, threat reports, purple-team exercises and supervisory incident reports can all reference the same technique, which is how you answer \"are we covered?\" with a map rather than an opinion."
    ],
    "links": [
      {
        "label": "MITRE ATT&CK",
        "url": "https://attack.mitre.org/"
      }
    ],
    "firstReleased": 2013,
    "logo": "/media/icons/standards-map/logos/mitre.svg"
  },
  "mitre-d3fend": {
    "name": "MITRE D3FEND",
    "fullName": "Defensive Countermeasures Knowledge Graph",
    "category": "Threat Intelligence",
    "governance": "MITRE",
    "umbrella": "MITRE",
    "jurisdiction": "Global",
    "status": "1.0 released January 2025; matrix at version 1.4",
    "standardization": "community",
    "description": [
      "A knowledge graph of defensive techniques across seven tactics (model, harden, detect, isolate, deceive, evict, restore) with explicit digital artefact relationships linking each countermeasure to the offensive techniques it addresses.",
      "Where ATT&CK tells you what attackers do, D3FEND gives you a vocabulary for what your controls actually do about it. Adoption in commercial tooling is growing but not yet the default."
    ],
    "links": [
      {
        "label": "MITRE D3FEND",
        "url": "https://d3fend.mitre.org/"
      }
    ],
    "firstReleased": 2021,
    "logo": "/media/icons/standards-map/logos/mitre.svg"
  },
  "cwe": {
    "name": "CWE",
    "fullName": "Common Weakness Enumeration",
    "category": "Threat Intelligence",
    "governance": "MITRE / CISA",
    "umbrella": "MITRE",
    "jurisdiction": "Global",
    "status": "Actively maintained; CWE Top 25 published annually",
    "standardization": "community",
    "description": [
      "A hierarchical catalogue of software and hardware weakness types: the class of flaw (CWE) as distinct from the individual vulnerability instance (CVE).",
      "Static analysis findings, penetration test reports and secure development requirements all reference CWE IDs, which makes it the join key between your scanner output and the control you claim satisfies it."
    ],
    "links": [
      {
        "label": "CWE",
        "url": "https://cwe.mitre.org/"
      },
      {
        "label": "CWE Top 25",
        "url": "https://cwe.mitre.org/top25/"
      }
    ],
    "firstReleased": 2006,
    "logo": "/media/icons/standards-map/logos/mitre.svg"
  },
  "capec": {
    "name": "CAPEC",
    "fullName": "Common Attack Pattern Enumeration and Classification",
    "category": "Threat Intelligence",
    "governance": "MITRE",
    "umbrella": "MITRE",
    "jurisdiction": "Global",
    "status": "Actively maintained; cross-referenced with CWE and ATT&CK",
    "standardization": "community",
    "description": [
      "A catalogue of attack patterns, the method by which a weakness is exploited, cross-referenced to the CWE weaknesses they target and the ATT&CK techniques they realise.",
      "It sits between the two: use it when a threat model needs to explain how a specific weakness becomes a specific technique."
    ],
    "links": [
      {
        "label": "CAPEC",
        "url": "https://capec.mitre.org/"
      }
    ],
    "firstReleased": 2007,
    "logo": "/media/icons/standards-map/logos/mitre.svg"
  },
  "stix": {
    "name": "STIX",
    "fullName": "Structured Threat Information Expression",
    "category": "Threat Intelligence",
    "governance": "OASIS Cyber Threat Intelligence TC",
    "umbrella": "OASIS",
    "jurisdiction": "Global",
    "status": "STIX 2.1 OASIS Standard (2021), with errata published in 2025",
    "standardization": "formal-standard",
    "description": [
      "A JSON data model for cyber threat intelligence: indicators, observed data, threat actors, campaigns, malware, courses of action, and the relationships between them.",
      "Relevant to regulated entities mainly through mandated reporting and sector information-sharing schemes, where the ISAC or supervisor expects machine-readable submissions rather than email."
    ],
    "links": [
      {
        "label": "STIX 2.1 specification",
        "url": "https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html"
      },
      {
        "label": "OASIS CTI TC",
        "url": "https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=cti"
      }
    ],
    "firstReleased": 2012,
    "logo": "/media/icons/standards-map/logos/oasis.png"
  },
  "taxii": {
    "name": "TAXII",
    "fullName": "Trusted Automated Exchange of Intelligence Information",
    "category": "Threat Intelligence",
    "governance": "OASIS Cyber Threat Intelligence TC",
    "umbrella": "OASIS",
    "jurisdiction": "Global",
    "status": "TAXII 2.1 OASIS Standard (2021)",
    "standardization": "formal-standard",
    "description": [
      "The HTTPS application protocol for exchanging STIX content: collections to pull from, channels to subscribe to, and the API endpoints a sharing community agrees on.",
      "Deploy it when you join a sharing community that runs one; there is no reason to adopt it in isolation."
    ],
    "links": [
      {
        "label": "TAXII 2.1 specification",
        "url": "https://docs.oasis-open.org/cti/taxii/v2.1/taxii-v2.1.html"
      }
    ],
    "firstReleased": 2012,
    "logo": "/media/icons/standards-map/logos/oasis.png"
  },
  "iso-42001": {
    "name": "ISO/IEC 42001",
    "fullName": "Artificial Intelligence Management System",
    "category": "AI Governance",
    "governance": "ISO/IEC JTC 1/SC 42",
    "umbrella": "ISO/IEC",
    "jurisdiction": "Global",
    "status": "Published December 2023; certifiable",
    "standardization": "formal-standard",
    "description": [
      "A management system standard for artificial intelligence, built on the same Annex SL structure as ISO/IEC 27001: context, leadership, planning, support, operation, evaluation, improvement, with AI-specific controls covering impact assessment, data for AI systems, and lifecycle documentation.",
      "It does not make you AI Act compliant on its own; the Act's harmonised standards are being written by CEN-CENELEC. But it is the management system regulators, customers and insurers can already audit against, and its documentation obligations line up closely with the Act's technical documentation requirements."
    ],
    "links": [
      {
        "label": "ISO/IEC 42001:2023",
        "url": "https://www.iso.org/standard/42001"
      },
      {
        "label": "ISO/IEC JTC 1/SC 42 (AI)",
        "url": "https://www.iso.org/committee/6794475.html"
      }
    ],
    "firstReleased": 2023,
    "logo": "/media/icons/standards-map/logos/iso.png"
  },
  "iso-23894": {
    "name": "ISO/IEC 23894",
    "fullName": "AI Risk Management Guidance",
    "category": "AI Governance",
    "governance": "ISO/IEC JTC 1/SC 42",
    "umbrella": "ISO/IEC",
    "jurisdiction": "Global",
    "status": "Published 2023",
    "standardization": "formal-standard",
    "description": [
      "Guidance on managing risk specific to AI systems, applying the ISO 31000 risk management process to AI-specific sources of risk: data quality, model behaviour, autonomy, transparency, and human oversight.",
      "Non-certifiable and deliberately procedural. Read it as the implementation companion when 42001 asks for an AI risk assessment and you need to decide what that actually contains."
    ],
    "links": [
      {
        "label": "ISO/IEC 23894:2023",
        "url": "https://www.iso.org/standard/77304.html"
      }
    ],
    "firstReleased": 2023,
    "logo": "/media/icons/standards-map/logos/iso.png"
  },
  "nist-ai-rmf": {
    "name": "NIST AI RMF",
    "fullName": "AI Risk Management Framework",
    "category": "AI Governance",
    "governance": "NIST",
    "umbrella": "NIST",
    "jurisdiction": "US / Global",
    "status": "AI RMF 1.0 (2023) plus the Generative AI Profile (2024)",
    "standardization": "formal-standard",
    "description": [
      "A voluntary framework organised into four functions (Govern, Map, Measure, Manage) for identifying and managing risks across the AI lifecycle, with a companion playbook of concrete actions.",
      "The Generative AI Profile extends it to foundation-model risks: confabulation, data leakage, provenance, and the supply chain of models you did not train yourself."
    ],
    "links": [
      {
        "label": "NIST AI Risk Management Framework",
        "url": "https://www.nist.gov/itl/ai-risk-management-framework"
      },
      {
        "label": "AI RMF 1.0 (NIST AI 100-1)",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf"
      }
    ],
    "firstReleased": 2023,
    "logo": "/media/icons/standards-map/logos/nist.svg"
  },
  "cen-clc-jtc21": {
    "name": "JTC 21",
    "fullName": "CEN-CENELEC JTC 21: Harmonised European Standards for AI",
    "category": "AI Governance",
    "governance": "CEN-CENELEC JTC 21",
    "umbrella": "CEN/CLC",
    "jurisdiction": "EU",
    "status": "Standardisation request under the AI Act; deliverables in progress, none yet cited in the Official Journal",
    "standardization": "formal-standard",
    "description": [
      "The joint technical committee drafting the harmonised European standards for the EU AI Act, covering risk management, data governance and data quality, transparency, human oversight, accuracy and robustness, and conformity assessment for high-risk AI systems.",
      "Once cited in the Official Journal, conformity with these standards gives a presumption of conformity with the corresponding AI Act requirements, which is why anyone building high-risk AI in Europe should be tracking the drafts rather than waiting."
    ],
    "links": [
      {
        "label": "CEN-CENELEC JTC 21",
        "url": "https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/"
      }
    ],
    "firstReleased": 2021,
    "logo": "/media/icons/standards-map/logos/cen-cenelec.svg"
  },
  "iso-5259": {
    "name": "ISO/IEC 5259",
    "fullName": "Data Quality for Analytics and Machine Learning",
    "category": "AI Governance",
    "governance": "ISO/IEC JTC 1/SC 42",
    "umbrella": "ISO/IEC",
    "jurisdiction": "Global",
    "status": "Multi-part series; core parts published from 2024",
    "standardization": "formal-standard",
    "description": [
      "A series covering data quality for analytics and machine learning: vocabulary, quality measures, management requirements, a process framework, and governance of the data used to train and evaluate models.",
      "It is the standards work that most directly addresses what \"relevant, representative, free of errors and complete\" is supposed to mean when a regulator says it about training data."
    ],
    "links": [
      {
        "label": "ISO/IEC 5259-1:2024",
        "url": "https://www.iso.org/standard/81088.html"
      },
      {
        "label": "ISO/IEC JTC 1/SC 42 (AI)",
        "url": "https://www.iso.org/committee/6794475.html"
      }
    ],
    "firstReleased": 2024,
    "logo": "/media/icons/standards-map/logos/iso.png"
  },
  "owasp-llm-top10": {
    "name": "OWASP LLM Top 10",
    "fullName": "OWASP Top 10 for LLM Applications",
    "category": "Application & API Security",
    "governance": "OWASP",
    "umbrella": "OWASP",
    "jurisdiction": "Global",
    "status": "2025 edition (March 2025); part of the OWASP GenAI Security Project",
    "standardization": "community",
    "description": [
      "The consensus risk list for applications built on large language models: prompt injection, sensitive information disclosure, supply chain, data and model poisoning, improper output handling, excessive agency, and more.",
      "Directly relevant wherever an LLM touches governed data: a retrieval pipeline over regulated data inherits every one of these risks, and this is the list auditors have started asking about by name."
    ],
    "links": [
      {
        "label": "OWASP Top 10 for LLM Applications",
        "url": "https://genai.owasp.org/llm-top-10/"
      },
      {
        "label": "OWASP GenAI Security Project",
        "url": "https://genai.owasp.org/"
      }
    ],
    "firstReleased": 2023,
    "logo": "/media/icons/standards-map/logos/owasp.svg"
  },
  "owasp-api-top10": {
    "name": "OWASP API Top 10",
    "fullName": "OWASP API Security Top 10",
    "category": "Application & API Security",
    "governance": "OWASP",
    "umbrella": "OWASP",
    "jurisdiction": "Global",
    "status": "2023 edition",
    "standardization": "community",
    "description": [
      "The API-specific risk list: broken object level authorisation, broken authentication, broken object property level authorisation, unrestricted resource consumption, and the rest of the failures that dominate real API breaches.",
      "Authorisation failures top the list because APIs expose object identifiers directly, the same shape of mistake that turns a data product output port into an unintended bulk export."
    ],
    "links": [
      {
        "label": "OWASP API Security Top 10",
        "url": "https://owasp.org/API-Security/editions/2023/en/0x11-t10/"
      }
    ],
    "firstReleased": 2019,
    "logo": "/media/icons/standards-map/logos/owasp.svg"
  },
  "owasp-asvs": {
    "name": "OWASP ASVS",
    "fullName": "Application Security Verification Standard",
    "category": "Application & API Security",
    "governance": "OWASP",
    "umbrella": "OWASP",
    "jurisdiction": "Global",
    "status": "Version 5.0 (2025)",
    "standardization": "community",
    "description": [
      "A catalogue of application security requirements organised into verification levels, written so each requirement can be tested rather than asserted.",
      "Unlike the Top 10 lists, ASVS is a requirements standard: it is what you put in a supplier contract or a definition of done when \"secure\" has to survive contact with an auditor."
    ],
    "links": [
      {
        "label": "OWASP ASVS",
        "url": "https://owasp.org/www-project-application-security-verification-standard/"
      }
    ],
    "firstReleased": 2009,
    "logo": "/media/icons/standards-map/logos/owasp.svg"
  },
  "owasp-samm": {
    "name": "OWASP SAMM",
    "fullName": "Software Assurance Maturity Model",
    "category": "Application & API Security",
    "governance": "OWASP",
    "umbrella": "OWASP",
    "jurisdiction": "Global",
    "status": "Version 2 (2020)",
    "standardization": "community",
    "description": [
      "A maturity model for secure software delivery across five business functions (governance, design, implementation, verification, operations), each with streams scored at three maturity levels.",
      "Its purpose is direction rather than certification: measure where you are, choose the next increment, re-measure. The output is a roadmap, which is what most secure-development clauses in regulation actually expect you to have."
    ],
    "links": [
      {
        "label": "OWASP SAMM",
        "url": "https://owaspsamm.org/"
      }
    ],
    "firstReleased": 2009,
    "logo": "/media/icons/standards-map/logos/owasp.svg"
  },
  "owasp-ml-top10": {
    "name": "OWASP ML Top 10",
    "fullName": "OWASP Machine Learning Security Top 10",
    "category": "Application & API Security",
    "governance": "OWASP",
    "umbrella": "OWASP",
    "jurisdiction": "Global",
    "status": "Draft; superseded in practice by the GenAI project for LLM work",
    "standardization": "community",
    "description": [
      "A risk list for classical machine learning systems: input manipulation, data poisoning, model inversion, membership inference, model theft, and transfer learning attacks.",
      "Still the better reference for a trained-in-house model that is not a language model. Treat it as a checklist rather than a standard: the document has been in draft for years."
    ],
    "links": [
      {
        "label": "OWASP Machine Learning Security Top 10",
        "url": "https://owasp.org/www-project-machine-learning-security-top-10/"
      }
    ],
    "firstReleased": 2023,
    "logo": "/media/icons/standards-map/logos/owasp.svg"
  },
  "csa-ccm": {
    "name": "CSA CCM",
    "fullName": "Cloud Controls Matrix",
    "category": "Cloud & Certification",
    "governance": "Cloud Security Alliance",
    "umbrella": "CSA",
    "jurisdiction": "Global",
    "status": "CCM v4.1: 197 control objectives in 17 domains; CAIQ and the STAR registry",
    "standardization": "community",
    "description": [
      "A cloud-specific control framework of nearly two hundred control objectives across seventeen domains, with a shared responsibility model that says which controls belong to the provider and which to the customer.",
      "The companion CAIQ questionnaire and the public STAR registry are what make it operationally useful: for most major cloud services, the answers already exist and can be diffed rather than requested."
    ],
    "links": [
      {
        "label": "Cloud Controls Matrix",
        "url": "https://cloudsecurityalliance.org/research/cloud-controls-matrix"
      },
      {
        "label": "CSA STAR registry",
        "url": "https://cloudsecurityalliance.org/star/registry"
      }
    ],
    "firstReleased": 2010,
    "logo": "/media/icons/standards-map/logos/csa.svg"
  },
  "iso-27017": {
    "name": "ISO/IEC 27017",
    "fullName": "Cloud Security Controls",
    "category": "Cloud & Certification",
    "governance": "ISO/IEC JTC 1/SC 27",
    "umbrella": "ISO/IEC",
    "jurisdiction": "Global",
    "status": "ISO/IEC 27017:2015",
    "standardization": "formal-standard",
    "description": [
      "A code of practice adding cloud-specific implementation guidance to the ISO/IEC 27002 controls, plus seven controls that exist only in a cloud context: shared roles, virtual machine hardening, administrator operations, monitoring, and segregation in virtual environments.",
      "Certification is normally an extension of a 27001 audit rather than a standalone exercise."
    ],
    "links": [
      {
        "label": "ISO/IEC 27017:2015",
        "url": "https://www.iso.org/standard/43757.html"
      }
    ],
    "firstReleased": 2015,
    "logo": "/media/icons/standards-map/logos/iso.png"
  },
  "bsi-c5": {
    "name": "BSI C5",
    "fullName": "Cloud Computing Compliance Criteria Catalogue",
    "category": "Cloud & Certification",
    "governance": "BSI (Germany)",
    "umbrella": "BSI",
    "jurisdiction": "EU / Germany",
    "status": "C5:2020: 121 criteria in 17 areas; attested under ISAE 3000",
    "standardization": "formal-standard",
    "description": [
      "A criteria catalogue for cloud service security, assessed by an auditor and reported as an attestation rather than a certificate, so the customer receives a full report, including the auditor's findings, not just a pass mark.",
      "The transparency criteria are the distinctive part: providers must disclose jurisdiction, data location, and the legal environment they operate under, which is exactly what a European data sovereignty review needs to see."
    ],
    "links": [
      {
        "label": "BSI C5",
        "url": "https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/Cloud-Computing/Kriterienkatalog-C5/kriterienkatalog-c5_node.html"
      }
    ],
    "firstReleased": 2016,
    "logo": "/media/icons/standards-map/logos/bsi.svg"
  },
  "eu-cloud-coc": {
    "name": "EU Cloud CoC",
    "fullName": "EU Cloud Code of Conduct",
    "category": "Cloud & Certification",
    "governance": "SCOPE Europe",
    "umbrella": "SCOPE Europe",
    "jurisdiction": "EU",
    "status": "Approved under GDPR Article 40 (2021); monitored by SCOPE Europe",
    "standardization": "community",
    "description": [
      "A code of conduct for cloud providers acting as processors, formally approved by the Belgian data protection authority under GDPR Article 40 with an accredited monitoring body.",
      "Adherence is one of the mechanisms GDPR explicitly recognises for demonstrating sufficient guarantees from a processor, which makes it a lighter alternative to bespoke due diligence when it is available."
    ],
    "links": [
      {
        "label": "EU Cloud Code of Conduct",
        "url": "https://eucoc.cloud/en/home"
      }
    ],
    "firstReleased": 2021,
    "logo": "/media/icons/standards-map/logos/scope-europe.svg"
  },
  "soc2": {
    "name": "SOC 2",
    "fullName": "Trust Services Criteria (SOC 2)",
    "category": "Audit & Attestation",
    "governance": "AICPA",
    "umbrella": "AICPA",
    "jurisdiction": "US / Global",
    "status": "Trust Services Criteria (2017, revised points of focus 2022)",
    "standardization": "formal-standard",
    "description": [
      "An attestation report by an independent auditor against five trust services criteria: security, availability, processing integrity, confidentiality and privacy. A Type I report covers design at a point in time; Type II covers operating effectiveness over a period.",
      "Not a certification and not a European instrument, but for SaaS vendors it is the de-facto entry ticket, and the Type II report is the evidence pack most third-party risk teams open first."
    ],
    "links": [
      {
        "label": "AICPA SOC 2",
        "url": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2"
      }
    ],
    "firstReleased": 2011,
    "logo": "/media/icons/standards-map/logos/aicpa.svg"
  },
  "isae-3402": {
    "name": "ISAE 3402",
    "fullName": "Assurance Reports on Controls at a Service Organization",
    "category": "Audit & Attestation",
    "governance": "IAASB",
    "umbrella": "IAASB",
    "jurisdiction": "Global",
    "status": "Effective since 2011; the international counterpart to SSAE 18",
    "standardization": "formal-standard",
    "description": [
      "The international assurance standard for reporting on controls at a service organisation that are relevant to its customers' financial reporting: the report an outsourced provider gives its clients' auditors.",
      "Where SOC 2 answers security questions, ISAE 3402 answers the auditor's question about whether your controls can be relied on in someone else's financial statements. ISAE 3000 covers the same mechanics for non-financial subject matter, including BSI C5."
    ],
    "links": [
      {
        "label": "IAASB standards & pronouncements",
        "url": "https://www.iaasb.org/standards-pronouncements"
      }
    ],
    "firstReleased": 2009,
    "logo": "/media/icons/standards-map/logos/iaasb.svg"
  },
  "spdx": {
    "name": "SPDX",
    "fullName": "System Package Data Exchange",
    "category": "Software Supply Chain",
    "governance": "Linux Foundation",
    "umbrella": "LF",
    "jurisdiction": "Global",
    "status": "SPDX 3.0 (2024), 3.1 in review; version 2.2.1 published as ISO/IEC 5962:2021",
    "standardization": "foundation",
    "description": [
      "A bill-of-materials standard for describing software components, licences, copyrights and security references. SPDX 3.0 generalised the model to cover builds, AI models, datasets and services alongside packages.",
      "The dataset and AI profiles matter here: they are the closest thing to a standard way of shipping a machine-readable declaration of what data a model was trained on."
    ],
    "links": [
      {
        "label": "SPDX",
        "url": "https://spdx.dev/"
      },
      {
        "label": "ISO/IEC 5962:2021",
        "url": "https://www.iso.org/standard/81870.html"
      }
    ],
    "firstReleased": 2011,
    "logo": "/media/icons/standards-map/logos/lf.svg"
  },
  "cyclonedx": {
    "name": "CycloneDX",
    "fullName": "CycloneDX Bill of Materials",
    "category": "Software Supply Chain",
    "governance": "OWASP",
    "umbrella": "OWASP",
    "jurisdiction": "Global",
    "status": "CycloneDX v1.7, published as ECMA-424 (2nd edition, 2025); SBOM, SaaSBOM, ML-BOM, CBOM and VEX",
    "standardization": "community",
    "description": [
      "A bill-of-materials standard designed for security use cases, covering software, services, hardware, machine learning models and cryptographic assets, with VEX support for stating whether a vulnerability actually affects you.",
      "The ML-BOM and CBOM profiles are directly regulatory: one documents model and dataset provenance, the other inventories cryptography ahead of post-quantum migration mandates."
    ],
    "links": [
      {
        "label": "CycloneDX",
        "url": "https://cyclonedx.org/"
      },
      {
        "label": "ECMA-424",
        "url": "https://ecma-international.org/publications-and-standards/standards/ecma-424/"
      }
    ],
    "firstReleased": 2017,
    "logo": "/media/icons/standards-map/logos/owasp.svg"
  },
  "slsa": {
    "name": "SLSA",
    "fullName": "Supply-chain Levels for Software Artifacts",
    "category": "Software Supply Chain",
    "governance": "OpenSSF",
    "umbrella": "OpenSSF",
    "jurisdiction": "Global",
    "status": "v1.2 current, adding a source track; v1.0 released 2023",
    "standardization": "foundation",
    "description": [
      "A framework of graduated levels for build integrity and provenance: what a build platform must guarantee at each of build levels L0 to L3, and what the resulting provenance attestation must say about how an artefact was produced. Version 1.2 adds a source track alongside it.",
      "It is the concrete answer to \"prove this binary came from that source\", the requirement underneath most modern software supply chain expectations."
    ],
    "links": [
      {
        "label": "SLSA",
        "url": "https://slsa.dev/"
      }
    ],
    "firstReleased": 2021,
    "logo": "/media/icons/standards-map/logos/openssf.svg"
  },
  "sigstore": {
    "name": "Sigstore",
    "fullName": "Sigstore",
    "category": "Software Supply Chain",
    "governance": "OpenSSF",
    "umbrella": "OpenSSF",
    "jurisdiction": "Global",
    "status": "Production; Fulcio, Rekor and Cosign",
    "standardization": "foundation",
    "description": [
      "Signing infrastructure for software artefacts using short-lived certificates tied to an OIDC identity, with signatures recorded in a public transparency log.",
      "The keyless model is why it gets adopted: no long-lived signing key to protect, and the transparency log gives an auditor something to check independently."
    ],
    "links": [
      {
        "label": "Sigstore",
        "url": "https://www.sigstore.dev/"
      }
    ],
    "firstReleased": 2021,
    "logo": "/media/icons/standards-map/logos/openssf.svg"
  },
  "in-toto": {
    "name": "in-toto",
    "fullName": "in-toto Attestation Framework",
    "category": "Software Supply Chain",
    "governance": "CNCF",
    "umbrella": "CNCF",
    "jurisdiction": "Global",
    "status": "CNCF graduated project (2025); in-toto Attestation Framework v1.0",
    "standardization": "foundation",
    "description": [
      "A framework for cryptographically verifying that every step of a software supply chain was carried out by the intended party, in the intended order, on the intended materials.",
      "Its attestation format is the substrate SLSA provenance is carried in, so adopt it as plumbing rather than as a programme of its own."
    ],
    "links": [
      {
        "label": "in-toto",
        "url": "https://in-toto.io/"
      },
      {
        "label": "GitHub: in-toto/attestation",
        "url": "https://github.com/in-toto/attestation"
      }
    ],
    "firstReleased": 2016,
    "logo": "/media/icons/standards-map/logos/cncf.svg"
  },
  "gaia-x": {
    "name": "Gaia-X",
    "fullName": "Gaia-X Trust Framework",
    "category": "Data Spaces & Sovereignty",
    "governance": "Gaia-X AISBL",
    "umbrella": "Gaia-X",
    "jurisdiction": "EU",
    "status": "Trust Framework with compliance and clearing house services",
    "standardization": "community",
    "description": [
      "A trust framework for European data infrastructure: self-descriptions of participants, services and resources as verifiable credentials, validated against machine-readable compliance rules by clearing houses.",
      "The idea worth borrowing regardless of your view on the initiative is that jurisdiction, data location and applicable law become attributes of a service that a machine can check, not claims in a sales deck."
    ],
    "links": [
      {
        "label": "Gaia-X",
        "url": "https://gaia-x.eu/"
      },
      {
        "label": "Gaia-X technical documentation",
        "url": "https://docs.gaia-x.eu/"
      }
    ],
    "firstReleased": 2021,
    "logo": "/media/icons/standards-map/logos/gaia-x.svg"
  },
  "dataspace-protocol": {
    "name": "Dataspace Protocol",
    "fullName": "Dataspace Protocol",
    "category": "Data Spaces & Sovereignty",
    "governance": "IDSA / Eclipse Dataspace Working Group",
    "umbrella": "IDSA",
    "jurisdiction": "EU",
    "status": "Release 2025-1; maintained by the Eclipse Dataspace Working Group",
    "standardization": "community",
    "description": [
      "A protocol for sovereign data exchange: catalogue discovery, contract negotiation over ODRL usage policies, and a transfer process that hands off to whatever data plane the parties agree on.",
      "It is the machinery that makes \"data stays under the provider's terms\" enforceable across organisational boundaries, and the reference protocol for EU data space implementations such as the Eclipse Dataspace Components."
    ],
    "links": [
      {
        "label": "Dataspace Protocol specification",
        "url": "https://eclipse-dataspace-protocol-base.github.io/DataspaceProtocol/"
      },
      {
        "label": "Eclipse Dataspace Working Group",
        "url": "https://dataspace.eclipse.org/"
      }
    ],
    "firstReleased": 2023,
    "logo": "/media/icons/standards-map/logos/idsa.svg"
  },
  "dssc-blueprint": {
    "name": "DSSC Blueprint",
    "fullName": "Data Spaces Blueprint",
    "category": "Data Spaces & Sovereignty",
    "governance": "Data Spaces Support Centre",
    "umbrella": "DSSC",
    "jurisdiction": "EU",
    "status": "Blueprint 3.0, the concluding version of the DSSC project",
    "standardization": "community",
    "description": [
      "The European Commission-funded reference blueprint for data spaces: the building blocks a data space needs for identity, trust, contracts, vocabularies, and data exchange, with the standards that fill each slot.",
      "Read it as the index to the sector data spaces being built under the Data Governance Act and the Data Act: it tells you which specification each participating initiative expects you to implement."
    ],
    "links": [
      {
        "label": "DSSC Blueprint",
        "url": "https://blueprint.dssc.eu/"
      },
      {
        "label": "Data Spaces Support Centre",
        "url": "https://dssc.eu/"
      }
    ],
    "firstReleased": 2023,
    "logo": "/media/icons/standards-map/logos/dssc.svg"
  },
  "ids-ram": {
    "name": "IDS-RAM",
    "fullName": "International Data Spaces Reference Architecture Model",
    "category": "Data Spaces & Sovereignty",
    "governance": "International Data Spaces Association",
    "umbrella": "IDSA",
    "jurisdiction": "EU",
    "status": "RAM 4 is the stable edition, with 2026-1 in draft; the connector concept lives on in the Dataspace Protocol",
    "standardization": "community",
    "description": [
      "The architecture model that introduced the data space vocabulary in Europe: connectors, identity providers, clearing houses, vocabulary hubs, and the sovereign exchange of data between them.",
      "Its concepts survive; its own protocol layer has effectively been superseded by the Dataspace Protocol, which is where the interoperability work has moved."
    ],
    "links": [
      {
        "label": "IDS Reference Architecture Model",
        "url": "https://kb.internationaldataspaces.org/external/ram/"
      },
      {
        "label": "IDSA",
        "url": "https://internationaldataspaces.org/"
      }
    ],
    "firstReleased": 2019,
    "logo": "/media/icons/standards-map/logos/idsa.svg"
  },
  "saml": {
    "name": "SAML",
    "fullName": "Security Assertion Markup Language",
    "category": "Identity & Access",
    "governance": "OASIS",
    "umbrella": "OASIS",
    "jurisdiction": "Global",
    "status": "SAML 2.0 OASIS Standard (2005)",
    "standardization": "formal-standard",
    "description": [
      "The XML standard for exchanging authentication and authorisation assertions between an identity provider and a service provider. It is what most enterprise single sign-on still runs on.",
      "It matters here because access control evidence starts with authentication: an auditor asking who could reach a data set is really asking which identity provider vouched for them, and what the assertion claimed."
    ],
    "links": [
      {
        "label": "SAML 2.0 specifications",
        "url": "https://docs.oasis-open.org/security/saml/v2.0/"
      }
    ],
    "firstReleased": 2002,
    "logo": "/media/icons/standards-map/logos/oasis.png"
  },
  "oauth2": {
    "name": "OAuth 2.0",
    "fullName": "OAuth 2.0 Authorization Framework",
    "category": "Identity & Access",
    "governance": "IETF",
    "umbrella": "IETF",
    "jurisdiction": "Global",
    "status": "RFC 6749 with a large family of extensions",
    "standardization": "formal-standard",
    "description": [
      "The delegated authorisation framework behind almost every modern API: a client obtains a scoped, time limited token instead of the user's credentials.",
      "Scopes and token lifetimes are the enforcement points a control framework leans on, and token issuance logs are the evidence that least privilege was more than an intention."
    ],
    "links": [
      {
        "label": "RFC 6749",
        "url": "https://www.rfc-editor.org/rfc/rfc6749"
      },
      {
        "label": "RFC 9700: Best Current Practice for OAuth 2.0 Security",
        "url": "https://www.rfc-editor.org/rfc/rfc9700"
      }
    ],
    "firstReleased": 2012,
    "logo": "/media/icons/standards-map/logos/ietf.svg"
  },
  "oidc": {
    "name": "OpenID Connect",
    "fullName": "OpenID Connect Core",
    "category": "Identity & Access",
    "governance": "OpenID Foundation",
    "umbrella": "OpenID",
    "jurisdiction": "Global",
    "status": "OpenID Connect Core 1.0; widely certified",
    "standardization": "community",
    "description": [
      "An identity layer on top of OAuth 2.0: the ID token carries verified claims about who the user is, alongside the access token that says what they may do.",
      "Its certification programme is the practical part. Where a control requires federated identity, pointing at a certified implementation is a shorter conversation than describing your own."
    ],
    "links": [
      {
        "label": "OpenID Connect Core 1.0",
        "url": "https://openid.net/specs/openid-connect-core-1_0.html"
      },
      {
        "label": "OpenID Foundation",
        "url": "https://openid.net/"
      }
    ],
    "firstReleased": 2014,
    "logo": "/media/icons/standards-map/logos/openid.svg"
  },
  "scim": {
    "name": "SCIM",
    "fullName": "System for Cross-domain Identity Management",
    "category": "Identity & Access",
    "governance": "IETF",
    "umbrella": "IETF",
    "jurisdiction": "Global",
    "status": "SCIM 2.0 (RFC 7642, 7643, 7644)",
    "standardization": "formal-standard",
    "description": [
      "A schema and REST protocol for provisioning and deprovisioning user accounts and groups between systems.",
      "Deprovisioning is the audit finding it prevents. Joiner, mover and leaver controls only hold if account removal propagates automatically to every tool holding data, which is precisely what SCIM automates."
    ],
    "links": [
      {
        "label": "RFC 7644 (SCIM protocol)",
        "url": "https://www.rfc-editor.org/rfc/rfc7644"
      },
      {
        "label": "SCIM overview",
        "url": "https://scim.cloud/"
      }
    ],
    "firstReleased": 2015,
    "logo": "/media/icons/standards-map/logos/ietf.svg"
  },
  "did": {
    "name": "DID",
    "fullName": "Decentralized Identifiers",
    "category": "Agent Identity & Trust",
    "governance": "W3C",
    "umbrella": "W3C",
    "jurisdiction": "Global",
    "status": "DID Core 1.0 W3C Recommendation (2022)",
    "standardization": "formal-standard",
    "description": [
      "Globally unique identifiers that resolve to a document describing how to authenticate the subject, without depending on a central registry.",
      "The reason it appears on a compliance map: European data spaces and agent ecosystems both need a party to prove who it is across organisational boundaries, and a DID is the identifier those trust frameworks are built on."
    ],
    "links": [
      {
        "label": "DID Core 1.0",
        "url": "https://www.w3.org/TR/did-core/"
      }
    ],
    "firstReleased": 2022,
    "logo": "/media/icons/standards-map/logos/w3c.svg"
  },
  "verifiable-credentials": {
    "name": "Verifiable Credentials",
    "fullName": "Verifiable Credentials Data Model",
    "category": "Agent Identity & Trust",
    "governance": "W3C",
    "umbrella": "W3C",
    "jurisdiction": "Global",
    "status": "VC Data Model 2.0 W3C Recommendation",
    "standardization": "formal-standard",
    "description": [
      "A data model for tamper evident claims that a holder can present and a verifier can check cryptographically, without contacting the issuer.",
      "Gaia-X self descriptions and the EU digital identity wallet both rest on it. It is how an assertion such as \"this service is certified and hosted in the EU\" becomes machine checkable rather than a claim in a brochure."
    ],
    "links": [
      {
        "label": "Verifiable Credentials Data Model 2.0",
        "url": "https://www.w3.org/TR/vc-data-model-2.0/"
      }
    ],
    "firstReleased": 2019,
    "logo": "/media/icons/standards-map/logos/w3c.svg"
  },
  "acp": {
    "name": "ACP",
    "fullName": "Agent Communication Protocol",
    "category": "Agent Interaction",
    "governance": "Linux Foundation",
    "umbrella": "LF",
    "jurisdiction": "Global",
    "status": "Merged into A2A under the Linux Foundation (2025)",
    "standardization": "foundation",
    "description": [
      "An open protocol for agents to discover each other and exchange tasks, launched by IBM Research in 2025 for the BeeAI platform and donated to the Linux Foundation with it.",
      "Listed for completeness rather than as a target: the effort has been folding into A2A, so new work should look there first."
    ],
    "links": [
      {
        "label": "Agent Communication Protocol",
        "url": "https://agentcommunicationprotocol.dev/"
      }
    ],
    "firstReleased": 2025,
    "logo": "/media/icons/standards-map/logos/lf.svg"
  },
  "ag-ui": {
    "name": "AG-UI",
    "fullName": "Agent User Interaction Protocol",
    "category": "Agent Interaction",
    "governance": "CopilotKit and the AG-UI community",
    "umbrella": "AG-UI",
    "jurisdiction": "Global",
    "status": "Open specification with reference implementations",
    "standardization": "community",
    "description": [
      "An event based protocol between agent backends and user facing applications, covering streaming output, tool calls, state updates and human approval steps.",
      "Its compliance relevance is human oversight. Where the AI Act expects a person to be able to intervene, the interaction protocol is where that intervention is actually implemented and logged."
    ],
    "links": [
      {
        "label": "AG-UI protocol",
        "url": "https://docs.ag-ui.com/"
      }
    ],
    "firstReleased": 2025,
    "logo": "/media/icons/standards-map/logos/ag-ui.svg"
  },
  "ap2": {
    "name": "AP2",
    "fullName": "Agent Payments Protocol",
    "category": "Agent Interaction",
    "governance": "Google; standardisation moving to the FIDO Alliance",
    "umbrella": "Google",
    "jurisdiction": "Global",
    "status": "v0.2 (2025); open specification, early adoption",
    "standardization": "community",
    "description": [
      "A protocol for payments initiated by agents, using signed mandates and verifiable credentials so that intent, authorisation and execution can each be proven after the fact.",
      "Payments are where agent autonomy meets regulated ground: strong customer authentication, audit trails and liability all need an answer before an agent may spend anything. The FIDO Alliance has taken up the standardisation work through its agentic authentication and payments working groups."
    ],
    "links": [
      {
        "label": "Agent Payments Protocol",
        "url": "https://ap2-protocol.org/"
      }
    ],
    "firstReleased": 2025,
    "logo": "/media/icons/standards-map/logos/google.svg"
  }
}
