Safeguard
Solutions · Compliance & Regulations

Every framework. Every region. Pre-mapped.

Safeguard ships pre-mapped control narratives and automated evidence pipelines for 219 jurisdictions and 373 frameworks — including the AI-specific regulations now landing across the EU, the US, Singapore, Korea, and India. This page is the encyclopedic map: every framework we cover, organised by region, country, and sector.

◈ the meridian sweep — one pass down the rail stamps every region
190+
Jurisdictions covered
60+
Frameworks pre-mapped
AI-Specific
Regs included
Continuous
Evidence, not annual snapshots
Regional Coverage

Seven regions. One ledger.

Each card lists the frameworks we cover in that jurisdiction, the scope of each, and a direct link to the evidence packet shape we ship for it.

AI-Specific Regulations

AI regs overlap regions. We map them anyway.

Eight AI-specific regimes that we surface as standalone control sets in addition to their parent region — because most AI-touching products are now subject to two or three of them at once.

01

EU AI Act

high-risk AI obligations across the EU single market

02

US AI EO 14110

federal AI safety, transparency, and reporting

03

Singapore AI Verify

AI governance testing toolkit and attestations

04

UK AI Safety Institute alignment

frontier model evaluation baseline

05

Japan AI Governance Guidelines (METI)

voluntary corporate AI governance baseline

06

Korea AI Framework Act

AI system risk classification and obligations

07

China Generative AI Measures

model registration, content labelling, training data

08

India DPDP + draft AI Advisory framework

data fiduciary plus AI advisory layer

Sectoral Overlays

The regions are the map. Sectors are the overlays.

Four overlays where a single product is typically subject to two or three frameworks from different regions at the same time.

Finance

  • DORA + EU CRA
    operational resilience plus product cyber
  • MAS TRM + PRA SS1/21
    banking technology risk on both sides of Asia and the UK
  • RBI + SEBI CSCRF + IFSCA
    Indian banking, securities, and international financial services

Healthcare

  • HIPAA / HITECH
    protected health information across covered entities
  • EU MDR / IVDR
    medical device and in vitro diagnostic security obligations
  • Regional privacy overlays
    GDPR, DPDP, LGPD, POPIA where patient data crosses borders

Defence / Government

  • FedRAMP HIGH + CMMC L2/L3
    US federal cloud and DoD supplier maturity
  • MOD JSP-440
    UK Ministry of Defence security policy baseline
  • STQC + Saudi NCA OTCC
    sovereign certification and OT-grade national controls

Critical Infrastructure

  • NIS2 + EU CER Directive
    essential and critical entities across the EU
  • NIST SP 800-53 + 800-161
    federal information systems and supply-chain risk
  • Saudi NCA OTCC + UAE NESA
    OT and national assurance for operators of national importance
What “Covered” Means

Three things. Not just a list.

Most vendors put a logo grid on a marketing page and call it “coverage.” Coverage here means three concrete things. Where a control requires human judgement — policy authoring, organisational scope, attestation of governance — we surface it as an open checklist gap, not a fake green check.

Pre-mapped control narratives

Every control in the framework is read, interpreted, and given a narrative that explains what Safeguard does for it, what the customer must still attest to, and where the gaps live.

Automated evidence collection

Scans, SBOMs, signed attestations, access logs, policy gate verdicts — all bound to controls and collected continuously, not in screenshot sprints before an audit.

Signed export per framework

One-click export in the format the regulator or auditor expects. Each artifact is signed; the auditor can verify without trusting Safeguard.

Coverage Pipeline

How a new region gets added.

Any framework not on this page is a 4–8 week add given the existing evidence pipeline. Here is what those weeks look like.

  1. 01

    Customer Signal

    A regulated buyer, a partner, or an internal review surfaces a framework that isn't yet on the map. We log the regulator, the jurisdiction, and the deadline.

  2. 02

    Legal + Regulator Alignment

    Counsel and the framework authors read the source text. Where the regulator publishes a control catalogue, we map clause-by-clause. Where it doesn't, we infer from guidance and precedent and flag the inference.

  3. 03

    Control Narrative + Evidence Pipeline

    Each control gets a written narrative plus an automated evidence binding to the underlying telemetry — scans, SBOMs, attestations, access logs, policy gates. Where a control needs human attestation, we ship it as a checklist gap rather than a fake check.

  4. 04

    Release

    The framework appears in the console, the export menu, and on this page. Any framework not yet listed is a 4–8 week add given the existing evidence pipeline — most of the work is narrative authoring, not engineering.

Headline Coverage

The shortlist. One row per region.

Region
Frameworks covered
Flagship framework
Evidence packet
North America
13 mapped
FedRAMP HIGH
European Union
9 mapped
EU AI Act
United Kingdom
5 mapped
NCSC CAF
India
8 mapped
DPDP Act, 2023
Middle East
10 mapped
Saudi NCA ECC
APAC
10 mapped
Singapore MAS TRM
Latin America & Africa
6 mapped
Brazil LGPD

Totals on this table refer to frameworks explicitly mapped in the console. Sectoral overlays and AI regimes are counted within their parent region as well as listed in their own sections above.

Country-by-country detail

190+ jurisdictions. Frameworks per country.

Every country and SAR we support, with the specific frameworks we map per jurisdiction. Click any framework name in color to open its dedicated detail page. Sectoral and cross-jurisdiction frameworks (PCI-DSS, FATF, ISO 27001, etc.) apply globally and are included in addition to the country rows below.

North America

3 jurisdictions · 24 frameworks

Canada

PIPEDACCCS baselineBill C-26 (Cyber Security Act)CSE PROTECTED B/CQuebec Law 25OSFI B-13

Mexico

LFPDPPPINE cybersecurity guidelinesCNBV cyber

Central America & Caribbean

14 jurisdictions · 25 frameworks

Guatemala

Personal data protection (draft)Banco de Guatemala cyber

Belize

Central Bank cyber baseline

Honduras

Personal data protection lawCNBS cyber

El Salvador

Personal data protection lawBCR cyber

Nicaragua

Law 787 (Personal Data Protection)SIBOIF cyber

Costa Rica

Law 8968 (PROTECDATOS)SUGEF cyber

Panama

Law 81 (Data Protection)Superintendencia de Bancos cyber

Cuba

Decree-Law 35 cyber

Dominican Republic

Law 172-13Superintendencia de Bancos cyber

Haiti

BRH cyber baseline

Jamaica

Data Protection Act 2020BOJ cyber

Trinidad and Tobago

Data Protection Act 2011Central Bank cyber

Bahamas

Data Protection ActCentral Bank cyber

Barbados · Saint Lucia · St. Vincent · St. Kitts · Grenada · Antigua · Dominica

CARICOM data protection alignmentECCB cyber

South America

12 jurisdictions · 26 frameworks

Brazil

LGPDBACEN Resolution 4658 (cyber)ANPDCVM cyber rules

Argentina

Law 25.326 (PDPA)BCRA cyber communication A6354

Chile

Law 19.628 (revised 2024)CMF cyberMISP-CL

Colombia

Law 1581SuperFinanciera cyberMinTIC GEL

Peru

Law 29733 (PDPA)SBS cyber

Venezuela

Personal data protection (Constitutional Article 28)BCV cyber

Ecuador

LOPDP 2021Junta de Política Financiera cyber

Bolivia

Constitutional data protectionASFI cyber

Paraguay

Law 6534 (PDPA)BCP cyber

Uruguay

Law 18.331 (PDPA)BCU cyber

Guyana

Bank of Guyana cyber

Suriname

Central Bank cyber baseline

European Union

28 jurisdictions · 99 frameworks

Austria

NIS2 transposition (NISG)DSG (data protection)FMA cyber

Belgium

NIS2 transpositionAPD data protectionNBB cyber

Bulgaria

NIS2 transpositionCPDPBNB cyber

Croatia

NIS2 transpositionAZOPHNB cyber

Cyprus

NIS2 transpositionCommissioner for Personal Data ProtectionCBC cyber

Czech Republic

NIS2 transpositionNÚKIB directivesÚOOÚ data protectionČNB cyber

Denmark

NIS2 transpositionDatatilsynetFinanstilsynet cyber

Estonia

NIS2 transpositionRIAAKI data protectionBaltic eID

Finland

NIS2 transpositionTraficom KybertutFinanssivalvonta cyber

France

ANSSI RGSANSSI SecNumCloudCNILOIV requirementsACPR cyber

Germany

BSI IT-GrundschutzBSI KRITISBAIT (banking)VAIT (insurance)KAITBfDI

Greece

NIS2 transpositionHDPABoG cyber

Hungary

NIS2 transpositionNAIHMNB cyber

Ireland

NIS2 transpositionDPC IrelandCBI cyber

Italy

ACN cyber frameworkMisure Minime AgIDGarante per la protezione dei datiBanca d'Italia cyber

Latvia

NIS2 transpositionCERT.LVDVI data protection

Lithuania

NIS2 transpositionCERT-LTVDAI data protection

Luxembourg

NIS2 transpositionCSSF Circular 22/806CNPD

Malta

NIS2 transpositionIDPCMFSA cyber

Netherlands

NCSC NL BaselineBIO (government)AP data protectionDNB cyber

Poland

KSC cyber frameworkUODO data protectionKNF cyber

Portugal

NIS2 transpositionCNPDBanco de Portugal cyber

Romania

NIS2 transpositionANSPDCPBNR cyber

Slovakia

NIS2 transpositionNBÚ directivesÚOOÚ data protection

Slovenia

NIS2 transpositionIP data protectionBS cyber

Spain

ENS (Esquema Nacional de Seguridad)AEPDBanco de España cyber

Sweden

NIS2 transpositionIMYFinansinspektionen cyber

Non-EU Europe

19 jurisdictions · 47 frameworks

United Kingdom

UK GDPRNCSC CAFPRA SS1/21FCA SYSCMOD JSP-440MOD Cyber Essentials PlusNCSC Active Cyber Defence

Switzerland

FADP (revFADP)FINMA Circular 2023/01FINMA cyber incident reportingNCSC.ch

Norway

PersonopplysningslovenNSM GrunnprinsipperFinanstilsynet cyber

Iceland

Act 90/2018FME national cyber strategyFME finance cyber

Liechtenstein

DSG (EEA aligned)FMA cyber

Monaco

Law 1.165 (data protection)CCAF cyber baseline

San Marino

Law 171/2018 (GDPR aligned)

Andorra

LQPD (data protection)AFA cyber

Albania

Law 9887 (data protection)AKCESK cyber

Bosnia and Herzegovina

Law on Personal Data ProtectionCBBH cyber

Serbia

Law on Personal Data ProtectionNBS cyber

Montenegro

Law on Personal Data ProtectionCBCG cyber

North Macedonia

Law on PDPNBRSM cyber

Kosovo

Law 06/L-082 (data protection)CBK cyber

Ukraine

Law on Personal Data ProtectionSSSCIP cyber baselinesNBU cyber for banks

Moldova

Law 133/2011 (data protection)NBM cyber

Belarus (sovereign tier)

Law on Personal Data Protection (limited engagement)

Turkey

KVKKBTK telecom cyberBDDK banking cyberTCMB cyber

Vatican City

Holy See data protection norms

Middle East

13 jurisdictions · 33 frameworks

Saudi Arabia

NCA OTCCNCA ECCNCA CCCNCA TCCNDMOSAMA cyber framework

United Arab Emirates

NESA / SIAFederal Decree-Law 45/46ADGM Data ProtectionDIFC DP LawCBUAE cyber

Qatar

NIAQFC DPAQCB cyber

Bahrain

Personal Data Protection LawCBB cybersecurity framework

Kuwait

DCC cyber rulesCBK cyber

Oman

ITA cyber frameworkCBO cyber

Jordan

NCSC frameworkJoPDPCBJ cyber

Lebanon

Law 81/2018 (electronic transactions and PDP)BDL cyber

Israel

Privacy Protection Law (amendments 13/14)INCD methodologiesBanking Supervision cyber

Palestine

PMA cyber baseline

Iraq

National ICT regulator baselinesCBI cyber

Iran (sovereign / sanctions-aware)

Available only via sovereign tier where lawful

Syria · Yemen

Sovereign tier only where lawful

North Africa

7 jurisdictions · 15 frameworks

Egypt

Data Protection Law 2020NTRA cyber rulesCBE cyber

Libya

Central Bank cyber baseline

Tunisia

INPDP data protectionANCS cyberBCT cyber

Algeria

Law 18-07 data protectionARPCE cyber baselinesBank of Algeria cyber

Morocco

Law 09-08 + CNDPDGSSI cyberBAM cyber

Sudan

Central Bank cyber baseline

Mauritania

Central Bank cyber baseline

West Africa

10 jurisdictions · 20 frameworks

Nigeria

NDPA / NDPRCBN cyber frameworkSEC cyber

Ghana

Data Protection Act 2012Cyber Security Authority directivesBank of Ghana cyber

Senegal

Law 2008-12 (data protection)BCEAO cyber

Côte d'Ivoire

Law 2013-450 (data protection)BCEAO cyber

Mali · Burkina Faso · Niger

BCEAO cyber for banksNational data protection laws

Sierra Leone

Bank of Sierra Leone cyber

Liberia

CBL cyber baseline

Gambia · Guinea · Guinea-Bissau

BCEAO / Central Bank cyberData protection drafts

Togo · Benin

WAEMU cyber alignmentBCEAO cyber

Cape Verde

Data Protection LawBanco de Cabo Verde cyber

Central Africa

8 jurisdictions · 10 frameworks

Cameroon

Law 2010/012 (data protection)BEAC cyber

Chad

BEAC cyber baseline

Central African Republic

BEAC cyber baseline

Republic of the Congo

BEAC cyber baseline

DR Congo

BCC cyber

Gabon

BEAC cyber

Equatorial Guinea · São Tomé and Príncipe

BEAC cyber

Angola

Law 22/11 (PDPA)BNA cyber

East Africa

12 jurisdictions · 21 frameworks

Kenya

Data Protection Act 2019CBK cyber

Tanzania

Personal Data Protection Act 2022BoT cyber

Uganda

Data Protection and Privacy Act 2019BoU cyber

Rwanda

Law 058/2021 (data protection)BNR cyber

Burundi

BRB cyber baseline

Ethiopia

Computer Crime ProclamationINSA baselinesNBE cyber

Eritrea · Djibouti · Somalia

Central Bank cyber baselines

South Sudan

BoSS cyber baseline

Madagascar

Law 2014-038 (data protection)BFM cyber

Mauritius

Data Protection Act 2017Bank of Mauritius cyber

Seychelles

Data Protection ActCBS cyber

Comoros

BCC cyber baseline

Southern Africa

8 jurisdictions · 17 frameworks

South Africa

POPIASARB cyberNCPFFSCA cyber

Namibia

Personal Data Protection (in development)Bank of Namibia cyber

Botswana

Data Protection Act 2018Bank of Botswana cyber

Zimbabwe

Cyber and Data Protection ActRBZ cyber

Zambia

Data Protection Act 2021BoZ cyber

Mozambique

Personal Data Protection LawBM cyber

Malawi

Data Protection BillRBM cyber

Lesotho · Eswatini

Central Bank cyber baselines

South Asia

8 jurisdictions · 24 frameworks

India

DPDP Act 2023RBI Cybersecurity FrameworkSEBI CSCRFIFSCA FrameworkCERT-In Directions (2022)STQCDoT cyberDGCA / DGSMeitYRBI PA-PGNCIIPC

Pakistan

PECASBP cyber frameworkPTA telecom cyber

Bangladesh

Personal Data Protection Act (draft)Bangladesh Bank cyber guidelines

Sri Lanka

Personal Data Protection Act 2022CBSL cyber

Nepal

Privacy Act 2018NRB cyber

Bhutan

RMA cyber baseline

Maldives

MMA banking cyberData protection (draft)

Afghanistan

DAB cyber baseline (constrained engagement)

Southeast Asia

11 jurisdictions · 26 frameworks

Singapore

Malaysia

PDPA 2010BNM RMiTSecurities Commission cyber

Indonesia

PDP Law (UU PDP)OJK cyberBI cyber

Thailand

PDPA 2019BoT cyberSEC cyber

Vietnam

Cybersecurity LawDecree 53/2022DTPSBV cyber

Philippines

DPA 2012BSP cyberSEC cyber

Myanmar (limited engagement)

CBM cyber baseline

Cambodia

Cybersecurity Law (in process)NBC banking cyber

Laos

BoL cyber baseline

Brunei

AMBD cyber

Timor-Leste

BCTL cyber baseline

East Asia

8 jurisdictions · 25 frameworks

Japan

APPIMETI cybersecurityFSA cyberCybersecurity Basic Act

South Korea

PIPAKISAK-ISMS-PKorea AI Framework ActFSC cyber

China

GenAI MeasuresDSLPIPLMLPS 2.0 (sovereign tier only)CSL

Taiwan

Cyber Security Management ActNCC rulesFSC cyber

Hong Kong SAR

PDPOHKMA cyber frameworkSFC cyber

Macau SAR

Data Protection Law 8/2005AMCM cyber

Mongolia

Cyber Security Law 2021Mongolbank cyber

North Korea

Not supported

Central Asia & Caucasus

8 jurisdictions · 14 frameworks

Kazakhstan

Law on Personal Data ProtectionNBK cyberAFSA cyber

Uzbekistan

Law on Personal DataCBU cyber

Turkmenistan

CB cyber baseline

Tajikistan

NBT cyber baseline

Kyrgyzstan

NBKR cyber baseline

Armenia

Law on Protection of Personal DataCBA cyber

Azerbaijan

Law on Personal DataCBA-AZ cyber

Georgia

Law of Georgia on Personal Data ProtectionNBG cyber

Oceania

7 jurisdictions · 14 frameworks

Australia

Privacy ActACSC Essential EightSOCI ActAPRA CPS 234ASIC cyber

New Zealand

NZISMPrivacy Act 2020RBNZ cyber

Fiji

RBF cyber baseline

Papua New Guinea

BPNG cyber baseline

Solomon Islands · Vanuatu · Samoa · Tonga

South Pacific Central Bank cyber alignment

Kiribati · Tuvalu · Nauru

Pacific Islands Forum cyber baseline

Marshall Islands · Micronesia · Palau

Compact of Free Association cyber alignmentBanking cyber baselines

Russia & Eurasian Economic Union (sovereign tier)

1 jurisdiction · 3 frameworks

Russia (sovereign / sanctions-aware)

FSTEC Order 17/21FSB cyber rules (sovereign deployments only where lawful)CBR cyber (sanctions-aware)

Cross-jurisdictional

7 jurisdictions · 37 frameworks

ISO / IEC family

ISO/IEC 27001:2022ISO/IEC 27002ISO/IEC 27017ISO/IEC 27018ISO/IEC 27019ISO/IEC 27701ISO/IEC 42001 (AI management)

NIST family

Global financial / payments

PCI-DSS v4.0FATF Travel RuleFFIECSWIFT CSPBasel III operational riskIOSCO cyber

AI-specific (cross-jurisdiction)

EU AI ActUS AI EO 14110Singapore AI VerifyUK AI Safety Institute alignmentJapan AI Governance GuidelinesKorea AI Framework ActChina Generative AI Measures

Healthcare cross-jurisdiction

HITRUST CSFHIPAA / HITECHEU MDR / IVDRPIC/S GMP Annex 11FDA 21 CFR Part 11

Industrial / OT

IEC 62443ISA/IEC 62443-4-1NERC CIPTSA Pipeline Cybersecurity Directives

Climate & ESG disclosure

ISSB IFRS S1/S2CSRD / ESRSSEC Climate Disclosure Rule

Missing your jurisdiction? New countries are typically added within 4–8 weeks given the existing evidence pipeline. Talk to the compliance team

Talk to compliance.

Bring the frameworks you owe. We'll walk the map with you — region by region, control by control, evidence packet by evidence packet.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.