Safeguard
Compliance · By Country

219 countries. 373 frameworks. Pre-mapped.

Comprehensive coverage across six continents and the European Union. Every framework Safeguard supports, listed jurisdiction by jurisdiction — from federal mandates to sector regulators to data-protection authorities.

◈ the drill — the regulator publishes, the pack updates, you get a diff
219
countries
373
frameworks
All
regions
24/7
continuous evidence
Country-level granularity

Every country. Every framework.

Scroll through every jurisdiction Safeguard ships pre-mapped framework packs for. Each card lists the specific obligations Safeguard scanners, policies, and evidence collectors implement.

North America

3 jurisdictions

Federal, state, and provincial frameworks across the US, Canada, and Mexico.

United States

15
FedRAMP HIGHCMMC L2 / L3NIST SP 800-53 / 161 / 218EO 14028HIPAAHITECHFISMAPCI-DSSSOC 2CCPACPRANYDFSSOXGLBACISA Directives

Canada

05
PIPEDACanadian Centre for Cyber Security baselineBill C-26 (Cyber Security Act)CSE PROTECTED B / CQuebec Law 25

Mexico

02
LFPDPPPINE cybersecurity guidelines

European Union

16 jurisdictions

Pan-EU regulation plus member-state-specific frameworks.

Pan-EU

09
GDPRNIS2DORAEU AI ActEU CEREU CRAEU MDR / IVDREU Solvency IIENISA TL

Germany

05
BSI IT-GrundschutzBSI KRITISBAIT (banking)VAIT (insurance)KAIT

France

03
ANSSI RGSANSSI SecNumCloudOIV

Netherlands

02
NCSC NL BaselineBIO (government)

Italy

02
ACN cyber frameworkMisure Minime AgID

Spain

01
ENS (Esquema Nacional de Seguridad)

Poland

01
KSC (cyber framework)

Ireland

01
NCSC IE NIS2 transposition

Belgium

02
CCB baselineNIS2 transposition

Sweden

02
MSB frameworkNIS2 transposition

Denmark

02
CFCS guidanceNIS2 transposition

Finland

02
Traficom KatakriNIS2 transposition

Norway

02
NSM grunnprinsipperDatatilsynet guidance

Austria

02
NISG transpositionDSG

Portugal

02
CNCS frameworkLei n.o 46/2018

Greece

02
NCSA frameworkHDPA

United Kingdom

1 jurisdictions

Post-Brexit UK frameworks across data protection, finance, and defence.

United Kingdom

07
UK GDPRNCSC CAFPRA SS1/21FCA SYSCMOD JSP-440MOD Cyber EssentialsNCSC Active Cyber Defence

India

1 jurisdictions

Data protection, sector regulators, and critical-infrastructure rules.

India

12
DPDP Act 2023RBI Cybersecurity FrameworkSEBI CSCRFIFSCA FrameworkCERT-In Directions 2022STQC certificationDoT cybersecurity guidelinesDGCADGSMeitY cyber guidelinesRBI PA-PGNCIIPC Critical Information Infrastructure

Middle East

8 jurisdictions

GCC and Levant frameworks — heavy emphasis on critical national infrastructure.

Saudi Arabia

06
NCA OTCCNCA ECCNCA CCCNCA TCCNDMOSAMA cyber framework

United Arab Emirates

04
NESA / SIAUAE Federal Decree-Law No. 45/46ADGM Data ProtectionDIFC DP Law

Qatar

02
NIAQFC DPA

Bahrain

02
Personal Data Protection LawCBB cybersecurity framework

Kuwait

01
DCC cyber rules

Oman

01
ITA cyber framework

Jordan

02
NCSC frameworkJoPDP

Egypt

02
NTRA cyber rulesData Protection Law 2020

Asia-Pacific

13 jurisdictions

Data protection, financial supervision, and AI rules across the world's fastest-moving region.

Japan

03
APPIMETI cybersecurityFSA cyber

Singapore

04
PDPAMAS TRMAI VerifyIM8

Australia

04
Privacy ActACSC Essential EightSOCI ActAPRA CPS 234

New Zealand

02
NZISMPrivacy Act 2020

South Korea

04
PIPAKISAK-ISMS-PKorea AI Framework Act

China

04
GenAI MeasuresDSLPIPLMLPS 2.0 — deployment requires sovereign tier

Hong Kong

02
PDPOHKMA cyber framework

Taiwan

02
Cyber Security Management ActNCC rules

Indonesia

02
PDP Law (UU PDP)OJK cyber

Vietnam

02
Cybersecurity LawDTP

Thailand

02
PDPABoT cyber

Malaysia

02
PDPABNM RMiT

Philippines

02
DPABSP cyber

Latin America

5 jurisdictions

Data protection across LATAM with sector overlays for finance.

Brazil

03
LGPDBACEN Resolution 4658ANPD

Argentina

01
PDPA

Chile

02
Personal Data Protection LawCMF cyber

Colombia

02
Law 1581SuperFinanciera

Peru

01
PDPA

Africa

4 jurisdictions

Pan-African data-protection laws and central-bank cyber rules.

South Africa

03
POPIASARB cyberNCPF

Nigeria

02
NDPRCBN cyber framework

Kenya

02
Data Protection ActCBK cyber

Morocco

02
Law 09-08CNDP
Cross-jurisdictional

Standards that travel everywhere.

Some frameworks span jurisdictions. Safeguard ships these as horizontal packs that satisfy multiple regulators at once.

ISO / IEC family

27001, 27002, 27017, 27017, 27018, 27019, 27034, 27036, 42001 — control mappings, evidence templates, and exception workflows for every certifiable surface.

NIST CSF / 800 family

CSF 2.0, SP 800-53, SP 800-161 (supply chain), SP 800-218 (SSDF), SP 800-190 (containers) — mapped to Safeguard findings, policies, and attestations.

SOC 2 / SOC 3

Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, Privacy. Auditor-ready evidence packs out of the box.

CSA STAR

CCM, CAIQ, and STAR Level 1 / 2 alignment for cloud service providers — including continuous monitoring evidence.

Sector overlays

Sector-specific frameworks across regions.

Vertical stacks layered on top of national frameworks for regulated industries.

Banking

PCI-DSSFFIECMAS TRMBoE Operational Resilience

Healthcare

HIPAAEU MDREU IVDRFDA SaMD

Industrial

IEC 62443NERC CIPISO 27019

Government

FedRAMPNCSC CAFSTQCNESA
Process

How we add a new country.

Five steps from regulator publication to a shipped framework pack with policies, evidence, and dashboards.

  1. 01

    Capture the regulation

    Source the authoritative text, the supervisor's guidance, and any associated technical standards.

  2. 02

    Decompose into controls

    Break each obligation into the smallest enforceable unit — a policy, an evidence requirement, a reporting trigger.

  3. 03

    Map to platform signals

    Tie each control to Safeguard scanners, policy gates, SBOM artefacts, attestations, and runtime telemetry.

  4. 04

    Ship the framework pack

    Publish the framework as a turnkey module — policies enabled, evidence wired, dashboards pre-built.

  5. 05

    Watch the change feed

    Track regulator updates and amendments; when a control changes, the pack updates automatically and customers get a diff.

Need a framework we have not listed?

Most new framework packs ship inside two weeks of a customer asking. Tell us the jurisdiction and the obligations, and we will scope the mapping with you.

Browse by region

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.