219 countries. 373 frameworks. Pre-mapped.
Comprehensive coverage across six continents and the European Union. Every framework Safeguard supports, listed jurisdiction by jurisdiction — from federal mandates to sector regulators to data-protection authorities.
Every country. Every framework.
Scroll through every jurisdiction Safeguard ships pre-mapped framework packs for. Each card lists the specific obligations Safeguard scanners, policies, and evidence collectors implement.
North America
3 jurisdictionsFederal, state, and provincial frameworks across the US, Canada, and Mexico.
United States
15Canada
05Mexico
02European Union
16 jurisdictionsPan-EU regulation plus member-state-specific frameworks.
Pan-EU
09Germany
05France
03Netherlands
02Italy
02Spain
01Poland
01Ireland
01Belgium
02Sweden
02Denmark
02Finland
02Norway
02Austria
02Portugal
02Greece
02United Kingdom
1 jurisdictionsPost-Brexit UK frameworks across data protection, finance, and defence.
United Kingdom
07India
1 jurisdictionsData protection, sector regulators, and critical-infrastructure rules.
India
12Middle East
8 jurisdictionsGCC and Levant frameworks — heavy emphasis on critical national infrastructure.
Saudi Arabia
06United Arab Emirates
04Qatar
02Bahrain
02Kuwait
01Oman
01Jordan
02Egypt
02Asia-Pacific
13 jurisdictionsData protection, financial supervision, and AI rules across the world's fastest-moving region.
Japan
03Singapore
04Australia
04New Zealand
02South Korea
04China
04Hong Kong
02Taiwan
02Indonesia
02Vietnam
02Thailand
02Malaysia
02Philippines
02Latin America
5 jurisdictionsData protection across LATAM with sector overlays for finance.
Brazil
03Argentina
01Chile
02Colombia
02Peru
01Africa
4 jurisdictionsPan-African data-protection laws and central-bank cyber rules.
South Africa
03Nigeria
02Kenya
02Morocco
02Standards that travel everywhere.
Some frameworks span jurisdictions. Safeguard ships these as horizontal packs that satisfy multiple regulators at once.
ISO / IEC family
27001, 27002, 27017, 27017, 27018, 27019, 27034, 27036, 42001 — control mappings, evidence templates, and exception workflows for every certifiable surface.
NIST CSF / 800 family
CSF 2.0, SP 800-53, SP 800-161 (supply chain), SP 800-218 (SSDF), SP 800-190 (containers) — mapped to Safeguard findings, policies, and attestations.
SOC 2 / SOC 3
Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, Privacy. Auditor-ready evidence packs out of the box.
CSA STAR
CCM, CAIQ, and STAR Level 1 / 2 alignment for cloud service providers — including continuous monitoring evidence.
Sector-specific frameworks across regions.
Vertical stacks layered on top of national frameworks for regulated industries.
Banking
Healthcare
Industrial
Government
How we add a new country.
Five steps from regulator publication to a shipped framework pack with policies, evidence, and dashboards.
- 01
Capture the regulation
Source the authoritative text, the supervisor's guidance, and any associated technical standards.
- 02
Decompose into controls
Break each obligation into the smallest enforceable unit — a policy, an evidence requirement, a reporting trigger.
- 03
Map to platform signals
Tie each control to Safeguard scanners, policy gates, SBOM artefacts, attestations, and runtime telemetry.
- 04
Ship the framework pack
Publish the framework as a turnkey module — policies enabled, evidence wired, dashboards pre-built.
- 05
Watch the change feed
Track regulator updates and amendments; when a control changes, the pack updates automatically and customers get a diff.
Need a framework we have not listed?
Most new framework packs ship inside two weeks of a customer asking. Tell us the jurisdiction and the obligations, and we will scope the mapping with you.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.