Reviewed by: Mansoor Ali, Technical Editor, PenPonder | Last Updated: July 2026
There are over 13 cybersecurity frameworks. Nobody needs all of them. Most businesses need one or two — and the wrong choice wastes months of work building controls that don’t apply to your situation.
This guide cuts through the noise. For each major framework we cover what it is, who actually needs it, what it requires, and whether it is mandatory or optional. Then we give you a clear decision path for picking yours.
What Is a Cybersecurity Framework?
A cybersecurity framework is a structured set of guidelines that tells you what controls to put in place, how to assess your current security posture, and how to prove to regulators or customers that your defenses are working.
Think of it as a blueprint. It does not tell you which firewall to buy or which antivirus software to run. It tells you what categories of controls you need — access management, incident response, data protection, risk assessment — and gives you a standard way to measure whether those controls are working.
Frameworks matter for three reasons in 2026:
- Regulators increasingly require them — GDPR, HIPAA, DORA, and NIS2 all reference specific frameworks
- Enterprise buyers demand them — most large company procurement processes now require SOC 2 or ISO 27001 before signing
- Cyber insurance underwriters use them — insurers check your framework compliance when calculating premiums and coverage limits
The 8 Frameworks That Actually Matter in 2026
Quick selection guide — which framework fits your situation
| Framework | Who Needs It | Mandatory? | Effort to Implement |
|---|---|---|---|
| NIST CSF 2.0 | Any US organisation, any size | Voluntary but widely adopted | Medium — flexible implementation |
| CIS Controls v8 | Small to mid-size businesses starting out | Voluntary | Low — 18 prioritised controls |
| ISO 27001 | International businesses, enterprise vendors | Voluntary — required in many contracts | High — full ISMS required |
| SOC 2 Type II | US SaaS companies, B2B vendors | Voluntary — enterprise buyers demand it | High — requires external audit |
| HIPAA Security Rule | Healthcare organisations, health tech | Legally required in US healthcare | Medium — specific to PHI |
| PCI DSS v4.0 | Any business processing payment cards | Contractually required by card networks | Medium to high — depends on scope |
| DORA | Financial entities operating in the EU | Legally required from January 2025 | High — ICT risk management + testing |
| NIS2 | Essential and important EU entities | Legally required across EU member states | High — incident reporting + governance |
NIST Cybersecurity Framework 2.0 — The Starting Point for Most Organisations
NIST CSF is the most widely adopted cybersecurity framework in the US. Version 2.0 was released in February 2024 and added a sixth core function to the original five.
The six functions now are: Govern, Identify, Protect, Detect, Respond, Recover.
What each function means in plain terms:
- Govern — Set the rules. Define your cybersecurity policy, assign accountability, integrate security into enterprise risk management. New in version 2.0.
- Identify — Know what you have. Asset inventory, risk assessment, supply chain risk. You cannot protect what you do not know exists.
- Protect — Keep threats out. Access controls, data security, training, secure configuration.
- Detect — Spot threats when they happen. Continuous monitoring, anomaly detection, logging.
- Respond — Act when something goes wrong. Incident response plan, communication, analysis, mitigation.
- Recover — Get back to normal. Recovery planning, improvements, communication after an incident.
NIST CSF is flexible. You do not implement all of it at once. You do a profile — a snapshot of your current state — and a target profile of where you need to be. The gap between them is your roadmap.
Who should start here: Any US organisation that does not have a specific regulatory requirement. NIST CSF gives you the language and structure to build everything else on top of. Most other US frameworks map back to NIST CSF controls.
Cost: Free to use. The NIST CSF is a public document. Implementation costs depend on the gaps you find during your profile assessment.
CIS Controls v8 — The Fastest Way to Get Secure
The CIS Controls are 18 prioritised security actions produced by the Center for Internet Security. Unlike NIST CSF, which gives you a framework to build your own program, CIS Controls tells you exactly what to do and in what order.
The controls are split into three implementation groups:
- IG1 — 56 safeguards for small businesses with limited IT resources. Basic cyber hygiene. This alone stops the majority of common attacks.
- IG2 — Additional controls for organisations with dedicated IT staff handling sensitive data.
- IG3 — Full set for large organisations or those facing sophisticated threats.
The top controls by priority:
- Inventory and control of enterprise assets
- Inventory and control of software assets
- Data protection
- Secure configuration of enterprise assets and software
- Account management
Who should start here: Small to mid-size businesses that need a practical, prioritised checklist rather than a conceptual framework. Start with IG1, get those 56 safeguards in place, then expand.
Cost: Free. The CIS Controls document is available at cisecurity.org at no charge.
ISO 27001 — The International Standard
ISO 27001 is the international standard for information security management. Unlike NIST and CIS which are US-centric, ISO 27001 is recognised globally and is often required by enterprise buyers in Europe, Asia, and the Middle East.
It requires building and maintaining an Information Security Management System (ISMS) — a documented system of policies, processes, and controls covering how you manage information security across the organisation.
The 2022 revision reduced the control domains from 14 to 4 and reorganised 93 controls into cleaner categories: Organisational Controls, People Controls, Physical Controls, and Technological Controls.
ISO 27001 requires an external audit and certification from an accredited certification body. The audit process typically takes 6 to 18 months and costs between $20,000 and $80,000 depending on organisation size.
Who needs it: Organisations selling to enterprise buyers internationally, or those in regulated industries where ISO 27001 is a contractual requirement. It is also the best choice if you want a single framework that satisfies multiple regulatory requirements through its broad control set.
Mandatory? Not legally required in most jurisdictions, but effectively mandatory if your enterprise customers or procurement processes require it. ISO 27001 certification is increasingly a baseline expectation in B2B SaaS contracts.
SOC 2 Type II — What US SaaS Buyers Require
SOC 2 is an auditing standard produced by the American Institute of Certified Public Accountants (AICPA). It is specifically designed for service organisations — SaaS companies, cloud providers, data processors — that handle customer data.
SOC 2 is built around five Trust Service Criteria:
- Security — the only required criterion. Covers access controls, encryption, incident response.
- Availability — uptime and performance commitments.
- Processing Integrity — data is processed completely, accurately, and in a timely manner.
- Confidentiality — sensitive information is protected.
- Privacy — personal information is collected, used, and retained appropriately.
Type I is a point-in-time assessment. Type II covers a period of at least 6 months and carries significantly more weight with buyers. Enterprise procurement teams almost always require Type II.
Cost: SOC 2 audits typically cost $30,000 to $100,000. Compliance platforms like Vanta, Drata, or Secureframe can reduce this by automating evidence collection — typically $10,000 to $25,000 per year for the platform plus audit fees.
Who needs it: Any US SaaS company selling to enterprise buyers. If a potential customer’s security questionnaire includes “Do you have a SOC 2 report?” — and most do — you need one. It is not legally required but is commercially necessary for B2B SaaS.
HIPAA Security Rule — Required for Healthcare
The HIPAA Security Rule sets standards for protecting electronic Protected Health Information (ePHI). If your organisation creates, receives, maintains, or transmits ePHI — or provides services to an organisation that does — HIPAA applies to you.
The Security Rule has three categories of requirements:
- Administrative safeguards — risk analysis, workforce training, access management policies, contingency planning
- Physical safeguards — facility access controls, workstation security, device controls
- Technical safeguards — access controls, audit controls, transmission security, encryption
Cloud vendors handling ePHI must sign a Business Associate Agreement (BAA) with covered entities before processing any data. AWS, Azure, and GCP all offer BAAs — but you must request them. They are not automatic.
Penalties: HIPAA violations range from $100 to $50,000 per violation, with an annual maximum of $1.9 million per violation category. Willful neglect can result in criminal charges.
For a detailed look at how HIPAA intersects with AI systems and health tech, see our HIPAA Compliance in Health Tech guide.
PCI DSS v4.0 — Required for Payment Processing
The Payment Card Industry Data Security Standard applies to any organisation that stores, processes, or transmits cardholder data. Version 4.0 became the only active version in April 2024.
Key changes in v4.0 include stronger authentication requirements — multi-factor authentication is now required for all access to the cardholder data environment, not just remote access. Targeted risk analysis is also now required for several controls, meaning you must document and justify your specific implementation approach.
PCI DSS compliance is validated through Self-Assessment Questionnaires (SAQs) for smaller merchants or Reports on Compliance (ROC) from a Qualified Security Assessor (QSA) for larger organisations.
Who needs it: Every business that accepts credit or debit card payments. Compliance is contractually required by card brands (Visa, Mastercard, Amex) through your payment processor. Non-compliance can result in fines, increased transaction fees, or termination of your ability to accept card payments.
DORA and NIS2 — The EU’s New Mandatory Requirements
If you operate in the EU financial sector or provide essential services to EU organisations, two relatively new regulations now apply.
DORA (Digital Operational Resilience Act) came into force January 17, 2025. It applies to financial entities including banks, insurance companies, investment firms, payment institutions, and their critical ICT third-party service providers. DORA requires ICT risk management, incident reporting, digital operational resilience testing, and third-party risk management. Fines reach 2% of total annual worldwide turnover for financial entities and 1% for ICT third-party providers.
NIS2 (Network and Information Security Directive 2) replaced NIS1 across EU member states with transposition deadlines in October 2024. It covers essential entities (energy, transport, banking, health, digital infrastructure) and important entities (postal services, waste management, manufacturing, digital providers). NIS2 requires risk management measures, incident reporting within 24 hours for significant incidents, and supply chain security assessments.
For organisations already compliant with ISO 27001 or NIST CSF, NIS2 compliance is mostly a documentation and governance exercise. If you are starting from scratch, both frameworks provide a significant head start. While security frameworks dictate how you protect your infrastructure, your legal obligations change depending on where your customers are located. If you serve EU or California residents, map your controls against our Data Protection and Compliance Laws 2026 guide to ensure you meet the strict reporting deadlines and data subject rights requirements.
For more detail on EU AI compliance requirements that intersect with NIS2 and DORA, see our EU AI Act & GDPR Compliance guide and our 2026 AI Compliance Guide.
How to Choose the Right Framework for Your Organisation
Follow this decision path:
Step 1 — Check regulatory requirements first. Do you handle patient health data? HIPAA is not optional. Do you process card payments? PCI DSS is not optional. Are you a financial entity in the EU? DORA applies. Do you provide essential services in an EU member state? Check NIS2. Regulatory requirements are the starting point — not a choice.
Step 2 — Check what your customers require. Do enterprise buyers ask for your SOC 2 report? Do international customers require ISO 27001? Sales-driven compliance is the second tier. A deal you cannot close because you lack a certification is a real cost.
Step 3 — Pick a voluntary framework for governance. Once regulatory and commercial requirements are met, NIST CSF 2.0 is the best choice for ongoing security program management in the US. CIS Controls IG1 is the fastest way to establish baseline hygiene if you are starting from zero.
Step 4 — Do not try to do everything at once. The most common mistake is attempting to implement multiple frameworks simultaneously. Start with your highest-priority requirement, get it in place, then expand. NIST CSF maps to most other frameworks so building it first pays dividends when you add SOC 2 or ISO 27001 later.
Cybersecurity Framework Comparison 2026
| Framework | Scope | Certification Available? | Typical Cost |
|---|---|---|---|
| NIST CSF 2.0 | All industries, US-focused | No formal certification | Free framework, implementation varies |
| CIS Controls v8 | All industries, any size | CIS CSAT assessment available | Free framework |
| ISO 27001 | All industries, international | Yes — external audit required | $20,000–$80,000 for certification |
| SOC 2 Type II | Service organisations, SaaS | Yes — CPA firm audit required | $30,000–$100,000 for audit |
| HIPAA | Healthcare, US only | No formal certification | Varies — internal assessment |
| PCI DSS v4.0 | Payment processing, all industries | SAQ or QSA audit | $5,000–$50,000+ depending on level |
| DORA | EU financial sector | No — regulatory compliance | Significant — ICT testing required |
| NIS2 | EU essential/important entities | No — regulatory compliance | Varies by member state implementation |
Final Verdict
Most organisations need one mandatory framework and one voluntary governance framework. That is it.
If you are a US SaaS company with no specific regulatory requirements: start with NIST CSF 2.0 for governance and work toward SOC 2 Type II when enterprise buyers start asking for it.
If you are a healthcare organisation: HIPAA is non-negotiable. Build your security program on top of CIS Controls IG1 for the technical baseline.
If you are a payment processor: PCI DSS first. Everything else comes after you have your cardholder data environment secured.
If you sell to international enterprise buyers: ISO 27001 is the most commercially valuable single certification you can get. It satisfies requirements across more markets than any other framework.
The mistake most organisations make is starting with the most impressive-sounding framework rather than the most relevant one. Start with what is required. Build from there.
For a deeper look at how these frameworks apply specifically to cloud environments, see our Cloud Security Compliance guide.
Frequently Asked Questions
What is a cybersecurity framework?
A cybersecurity framework is a structured set of guidelines that helps organisations identify, protect against, detect, respond to, and recover from cybersecurity threats. It provides a common language for security teams, leadership, and regulators to assess and improve security posture.
Which cybersecurity framework is best?
There is no single best framework — the right one depends on your industry, location, and customer requirements. For most US organisations starting out, NIST CSF 2.0 is the best foundation. For SaaS companies selling to enterprises, add SOC 2. For international businesses, ISO 27001 carries the most global recognition.
Is NIST CSF mandatory?
No. NIST CSF is voluntary for most US organisations. However, it is required for US federal agencies and their contractors, and is widely referenced by other regulations and frameworks. Many organisations adopt it voluntarily because it aligns with common regulatory requirements.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an international standard requiring a documented Information Security Management System (ISMS). SOC 2 is a US audit standard for service organisations focusing on security, availability, and confidentiality controls. ISO 27001 has global recognition. SOC 2 is primarily recognised by US enterprise buyers. Many international SaaS companies pursue both.
What cybersecurity framework do small businesses need?
CIS Controls Implementation Group 1 (IG1) is the fastest path to basic cyber hygiene for small businesses. It covers 56 specific safeguards that stop the majority of common attacks without requiring a dedicated security team. Start there before moving to NIST CSF or SOC 2.
What is DORA in cybersecurity?
DORA is the Digital Operational Resilience Act — an EU regulation that came into force in January 2025 for financial entities. It requires ICT risk management, incident reporting, digital resilience testing, and management of third-party ICT providers. It applies to banks, insurance companies, investment firms, and their critical technology suppliers operating in the EU.
How long does it take to implement a cybersecurity framework?
CIS Controls IG1 can be implemented in 3 to 6 months for a small organisation. NIST CSF typically takes 6 to 12 months for initial implementation. ISO 27001 certification takes 12 to 18 months on average. SOC 2 Type II requires at least 6 months of audit period plus preparation time, so plan for 9 to 15 months from start to report.
Framework information sourced from NIST, CIS, ISO, AICPA, and EU Official Journal publications as of July 2026. Cost estimates based on industry benchmarks and vary significantly by organisation size and complexity. PenPonder does not have commercial relationships with any certification bodies or compliance platforms mentioned in this article.

