Every framework. Every region. Pre-mapped.
Safeguard ships pre-mapped control narratives and automated evidence pipelines for 219 jurisdictions and 373 frameworks — including the AI-specific regulations now landing across the EU, the US, Singapore, Korea, and India. This page is the encyclopedic map: every framework we cover, organised by region, country, and sector.
Seven regions. One ledger.
Each card lists the frameworks we cover in that jurisdiction, the scope of each, and a direct link to the evidence packet shape we ship for it.
North America
Federal cloud authorisation, DoD maturity, and state-level privacy.
- FedRAMP HIGH— federal cloud authorisation (US)Open framework detail
- CMMC Level 2 / Level 3— DoD contractor cyber maturity (US)Open framework detail
- NIST SP 800-53— federal information system controlsOpen framework detail
- NIST SP 800-161 (Rev 2)— supply-chain risk managementOpen framework detail
- NIST SP 800-218 (SSDF)— secure software development frameworkOpen framework detail
- EO 14028— improving the nation's cybersecurityOpen framework detail
- HIPAA / HITECH— health information privacy (US)Open framework detail
- FISMA— federal information security managementOpen framework detail
- PCI-DSS v4.0— payment card industryOpen framework detail
- SOC 2 Type II— service organisation controlsOpen framework detail
- CCPA / CPRA— California consumer privacyOpen framework detail
- PIPEDA— Canada personal information protectionOpen framework detail
- US Privacy Shield (where applicable)— cross-border data transferEvidence packet
European Union
Privacy, operational resilience, AI obligations, and product cyber security.
- GDPR— general data protection regulationOpen framework detail
- NIS2 Directive— network and information securityOpen framework detail
- DORA— digital operational resilience actOpen framework detail
- EU AI Act— AI risk categorisation and obligationsOpen framework detail
- EU CER Directive— critical entities resilienceOpen framework detail
- EU Cyber Resilience Act (CRA)— product cyber securityEvidence packet
- EU MDR / IVDR— medical device + in vitro diagnosticOpen framework detail
- EU Solvency II + IDD— insurance regulationOpen framework detail
- ENISA Threat Landscape alignment— EU agency threat baselineOpen framework detail
United Kingdom
Post-GDPR privacy plus national cyber assessment baselines.
- UK GDPR— United Kingdom general data protection regulationOpen framework detail
- NCSC Cyber Assessment Framework (CAF)— national cyber baseline for essential servicesOpen framework detail
- PRA SS1/21— operational resilience (banking)Open framework detail
- FCA fintech / SYSC cyber rules— conduct rules for regulated firmsEvidence packet
- MOD JSP-440— Ministry of Defence security policyOpen framework detail
India
DPDP, sector regulators, and sovereign deployment readiness.
- DPDP Act, 2023— digital personal data protectionOpen framework detail
- RBI Cybersecurity Framework— bankingOpen framework detail
- SEBI CSCRF— securities cyber resilienceOpen framework detail
- IFSCA Framework— international financial servicesOpen framework detail
- CERT-In Directions— incident reporting (2022)Open framework detail
- STQC certification readiness— for sovereign deploymentsOpen framework detail
- DoT cybersecurity guidelines— telecomEvidence packet
- DGCA / DGS guidelines— aviation + maritimeEvidence packet
Middle East
GCC national cyber controls plus emerging privacy laws.
- Saudi NCA OTCC— operational technology cybersecurity controlsOpen framework detail
- Saudi NCA ECC— essential cybersecurity controlsOpen framework detail
- UAE NESA / SIA standards— national information assuranceEvidence packet
- UAE Federal Decree-Law No. 45 / 46— data protectionEvidence packet
- Bahrain Personal Data Protection Law— personal data protectionEvidence packet
- Kuwait DCC cyber rules— data classification and protectionEvidence packet
- Oman ITA cyber framework— information technology authority baselineEvidence packet
- Qatar NIA— National Information AssuranceEvidence packet
- Jordan NCSC framework— national cybersecurity baselineEvidence packet
- Egypt NTRA cyber rules— telecom regulator cyber baselineEvidence packet
APAC
Privacy laws, banking technology risk, and AI assurance.
- Japan APPI— personal information protectionOpen framework detail
- Japan METI cyber for industrial— industrial cyber guidanceEvidence packet
- Singapore PDPA— personal data protectionOpen framework detail
- Singapore MAS TRM— banking technology risk managementOpen framework detail
- Singapore AI Verify— AI governance testing frameworkOpen framework detail
- Australia Privacy Act— national privacy baselineEvidence packet
- Australia ACSC Essential Eight— national cyber mitigation strategiesOpen framework detail
- Korea PIPA— personal information protectionOpen framework detail
- Korea KISA cyber framework— national information security guidanceEvidence packet
- China GenAI / DSL / PIPL— deployment requires sovereign tierEvidence packet
Latin America & Africa
Privacy frameworks across Brazil, Mexico, and African data laws.
- Brazil LGPD— general data protection lawOpen framework detail
- Mexico LFPDPPP— federal protection of personal dataEvidence packet
- Argentina PDPA— personal data protection actEvidence packet
- South Africa POPIA— protection of personal informationOpen framework detail
- Nigeria NDPR— Nigeria data protection regulationEvidence packet
- Kenya Data Protection Act— national data protection lawEvidence packet
AI regs overlap regions. We map them anyway.
Eight AI-specific regimes that we surface as standalone control sets in addition to their parent region — because most AI-touching products are now subject to two or three of them at once.
EU AI Act
high-risk AI obligations across the EU single market
US AI EO 14110
federal AI safety, transparency, and reporting
Singapore AI Verify
AI governance testing toolkit and attestations
UK AI Safety Institute alignment
frontier model evaluation baseline
Japan AI Governance Guidelines (METI)
voluntary corporate AI governance baseline
Korea AI Framework Act
AI system risk classification and obligations
China Generative AI Measures
model registration, content labelling, training data
India DPDP + draft AI Advisory framework
data fiduciary plus AI advisory layer
The regions are the map. Sectors are the overlays.
Four overlays where a single product is typically subject to two or three frameworks from different regions at the same time.
Finance
- DORA + EU CRAoperational resilience plus product cyber
- MAS TRM + PRA SS1/21banking technology risk on both sides of Asia and the UK
- RBI + SEBI CSCRF + IFSCAIndian banking, securities, and international financial services
Healthcare
- HIPAA / HITECHprotected health information across covered entities
- EU MDR / IVDRmedical device and in vitro diagnostic security obligations
- Regional privacy overlaysGDPR, DPDP, LGPD, POPIA where patient data crosses borders
Defence / Government
- FedRAMP HIGH + CMMC L2/L3US federal cloud and DoD supplier maturity
- MOD JSP-440UK Ministry of Defence security policy baseline
- STQC + Saudi NCA OTCCsovereign certification and OT-grade national controls
Critical Infrastructure
- NIS2 + EU CER Directiveessential and critical entities across the EU
- NIST SP 800-53 + 800-161federal information systems and supply-chain risk
- Saudi NCA OTCC + UAE NESAOT and national assurance for operators of national importance
Three things. Not just a list.
Most vendors put a logo grid on a marketing page and call it “coverage.” Coverage here means three concrete things. Where a control requires human judgement — policy authoring, organisational scope, attestation of governance — we surface it as an open checklist gap, not a fake green check.
Pre-mapped control narratives
Every control in the framework is read, interpreted, and given a narrative that explains what Safeguard does for it, what the customer must still attest to, and where the gaps live.
Automated evidence collection
Scans, SBOMs, signed attestations, access logs, policy gate verdicts — all bound to controls and collected continuously, not in screenshot sprints before an audit.
Signed export per framework
One-click export in the format the regulator or auditor expects. Each artifact is signed; the auditor can verify without trusting Safeguard.
How a new region gets added.
Any framework not on this page is a 4–8 week add given the existing evidence pipeline. Here is what those weeks look like.
- 01
Customer Signal
A regulated buyer, a partner, or an internal review surfaces a framework that isn't yet on the map. We log the regulator, the jurisdiction, and the deadline.
- 02
Legal + Regulator Alignment
Counsel and the framework authors read the source text. Where the regulator publishes a control catalogue, we map clause-by-clause. Where it doesn't, we infer from guidance and precedent and flag the inference.
- 03
Control Narrative + Evidence Pipeline
Each control gets a written narrative plus an automated evidence binding to the underlying telemetry — scans, SBOMs, attestations, access logs, policy gates. Where a control needs human attestation, we ship it as a checklist gap rather than a fake check.
- 04
Release
The framework appears in the console, the export menu, and on this page. Any framework not yet listed is a 4–8 week add given the existing evidence pipeline — most of the work is narrative authoring, not engineering.
The shortlist. One row per region.
Totals on this table refer to frameworks explicitly mapped in the console. Sectoral overlays and AI regimes are counted within their parent region as well as listed in their own sections above.
Where to go next.
Comply with Global Regulations
The use-case page: how compliance actually gets done, step by step, across frameworks.
OpenSupply Chain Compliance
Supplier evidence packets, SBOM exchange, third-party risk attestations.
OpenSecurity
How Safeguard itself is built — controls, trust posture, sub-processors, and architecture.
OpenResources & Downloads
Public framework crosswalks, sample evidence packets, and regulator-ready exports.
Open190+ jurisdictions. Frameworks per country.
Every country and SAR we support, with the specific frameworks we map per jurisdiction. Click any framework name in color to open its dedicated detail page. Sectoral and cross-jurisdiction frameworks (PCI-DSS, FATF, ISO 27001, etc.) apply globally and are included in addition to the country rows below.
North America
3 jurisdictions · 24 frameworksUnited States
Canada
Mexico
Central America & Caribbean
14 jurisdictions · 25 frameworksGuatemala
Belize
Honduras
El Salvador
Nicaragua
Costa Rica
Panama
Cuba
Dominican Republic
Haiti
Jamaica
Trinidad and Tobago
Bahamas
Barbados · Saint Lucia · St. Vincent · St. Kitts · Grenada · Antigua · Dominica
South America
12 jurisdictions · 26 frameworksBrazil
Argentina
Chile
Colombia
Peru
Venezuela
Ecuador
Bolivia
Paraguay
Uruguay
Guyana
Suriname
European Union
28 jurisdictions · 99 frameworksPan-EU
Austria
Belgium
Bulgaria
Croatia
Cyprus
Czech Republic
Denmark
Estonia
Finland
France
Germany
Greece
Hungary
Ireland
Italy
Latvia
Lithuania
Luxembourg
Malta
Netherlands
Poland
Portugal
Romania
Slovakia
Slovenia
Spain
Sweden
Non-EU Europe
19 jurisdictions · 47 frameworksUnited Kingdom
Switzerland
Norway
Iceland
Liechtenstein
Monaco
San Marino
Andorra
Albania
Bosnia and Herzegovina
Serbia
Montenegro
North Macedonia
Kosovo
Ukraine
Moldova
Belarus (sovereign tier)
Turkey
Vatican City
Middle East
13 jurisdictions · 33 frameworksUnited Arab Emirates
Qatar
Bahrain
Kuwait
Oman
Jordan
Lebanon
Israel
Palestine
Iraq
Iran (sovereign / sanctions-aware)
Syria · Yemen
North Africa
7 jurisdictions · 15 frameworksEgypt
Libya
Tunisia
Algeria
Morocco
Sudan
Mauritania
West Africa
10 jurisdictions · 20 frameworksNigeria
Ghana
Senegal
Côte d'Ivoire
Mali · Burkina Faso · Niger
Sierra Leone
Liberia
Gambia · Guinea · Guinea-Bissau
Togo · Benin
Cape Verde
Central Africa
8 jurisdictions · 10 frameworksCameroon
Chad
Central African Republic
Republic of the Congo
DR Congo
Gabon
Equatorial Guinea · São Tomé and Príncipe
Angola
East Africa
12 jurisdictions · 21 frameworksKenya
Tanzania
Uganda
Rwanda
Burundi
Ethiopia
Eritrea · Djibouti · Somalia
South Sudan
Madagascar
Mauritius
Seychelles
Comoros
Southern Africa
8 jurisdictions · 17 frameworksSouth Africa
Namibia
Botswana
Zimbabwe
Zambia
Mozambique
Malawi
Lesotho · Eswatini
South Asia
8 jurisdictions · 24 frameworksIndia
Pakistan
Bangladesh
Sri Lanka
Nepal
Bhutan
Maldives
Afghanistan
Southeast Asia
11 jurisdictions · 26 frameworksMalaysia
Indonesia
Thailand
Vietnam
Philippines
Myanmar (limited engagement)
Cambodia
Laos
Brunei
Timor-Leste
East Asia
8 jurisdictions · 25 frameworksJapan
South Korea
China
Taiwan
Hong Kong SAR
Macau SAR
Mongolia
North Korea
Central Asia & Caucasus
8 jurisdictions · 14 frameworksKazakhstan
Uzbekistan
Turkmenistan
Tajikistan
Kyrgyzstan
Armenia
Azerbaijan
Georgia
Oceania
7 jurisdictions · 14 frameworksAustralia
New Zealand
Fiji
Papua New Guinea
Solomon Islands · Vanuatu · Samoa · Tonga
Kiribati · Tuvalu · Nauru
Marshall Islands · Micronesia · Palau
Russia & Eurasian Economic Union (sovereign tier)
1 jurisdiction · 3 frameworksRussia (sovereign / sanctions-aware)
Cross-jurisdictional
7 jurisdictions · 37 frameworksISO / IEC family
NIST family
Global financial / payments
AI-specific (cross-jurisdiction)
Healthcare cross-jurisdiction
Industrial / OT
Climate & ESG disclosure
Missing your jurisdiction? New countries are typically added within 4–8 weeks given the existing evidence pipeline. Talk to the compliance team
Talk to compliance.
Bring the frameworks you owe. We'll walk the map with you — region by region, control by control, evidence packet by evidence packet.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.