60+ countries. 80+ frameworks. Pre-mapped.
Comprehensive coverage across six continents and the European Union. Every framework Safeguard supports, listed jurisdiction by jurisdiction — from federal mandates to sector regulators to data-protection authorities.
Every country. Every framework.
Scroll through every jurisdiction Safeguard ships pre-mapped framework packs for. Each card lists the specific obligations Safeguard scanners, policies, and evidence collectors implement.
North America
Federal, state, and provincial frameworks across the US, Canada, and Mexico.
United States
Canada
Mexico
European Union
Pan-EU regulation plus member-state-specific frameworks.
Pan-EU
Germany
France
Netherlands
Italy
Spain
Poland
Ireland
Belgium
Sweden
Denmark
Finland
Norway
Austria
Portugal
Greece
United Kingdom
Post-Brexit UK frameworks across data protection, finance, and defence.
United Kingdom
India
Data protection, sector regulators, and critical-infrastructure rules.
India
Middle East
GCC and Levant frameworks — heavy emphasis on critical national infrastructure.
Saudi Arabia
United Arab Emirates
Qatar
Bahrain
Kuwait
Oman
Jordan
Egypt
Asia-Pacific
Data protection, financial supervision, and AI rules across the world's fastest-moving region.
Japan
Singapore
Australia
New Zealand
South Korea
China
Hong Kong
Taiwan
Indonesia
Vietnam
Thailand
Malaysia
Philippines
Latin America
Data protection across LATAM with sector overlays for finance.
Brazil
Argentina
Chile
Colombia
Peru
Africa
Pan-African data-protection laws and central-bank cyber rules.
South Africa
Nigeria
Kenya
Morocco
Standards that travel everywhere.
Some frameworks span jurisdictions. Safeguard ships these as horizontal packs that satisfy multiple regulators at once.
ISO / IEC family
27001, 27002, 27017, 27017, 27018, 27019, 27034, 27036, 42001 — control mappings, evidence templates, and exception workflows for every certifiable surface.
NIST CSF / 800 family
CSF 2.0, SP 800-53, SP 800-161 (supply chain), SP 800-218 (SSDF), SP 800-190 (containers) — mapped to Safeguard findings, policies, and attestations.
SOC 2 / SOC 3
Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, Privacy. Auditor-ready evidence packs out of the box.
CSA STAR
CCM, CAIQ, and STAR Level 1 / 2 alignment for cloud service providers — including continuous monitoring evidence.
Sector-specific frameworks across regions.
Vertical stacks layered on top of national frameworks for regulated industries.
Banking
Healthcare
Industrial
Government
How we add a new country.
Five steps from regulator publication to a shipped framework pack with policies, evidence, and dashboards.
Capture the regulation
Source the authoritative text, the supervisor's guidance, and any associated technical standards.
Decompose into controls
Break each obligation into the smallest enforceable unit — a policy, an evidence requirement, a reporting trigger.
Map to platform signals
Tie each control to Safeguard scanners, policy gates, SBOM artefacts, attestations, and runtime telemetry.
Ship the framework pack
Publish the framework as a turnkey module — policies enabled, evidence wired, dashboards pre-built.
Watch the change feed
Track regulator updates and amendments; when a control changes, the pack updates automatically and customers get a diff.