← All articles
GRC10 min read

The Complete Compliance Framework Guide: ISO 27001, SOC 2, GDPR, DORA and Every Standard That Matters

The compliance landscape looks more complicated than it is.

From the outside it appears to be a long list of unrelated acronyms. ISO 27001, SOC 2, GDPR, DORA, PCI DSS, HIPAA, NIS2. Each with its own certification body, its own requirements, and its own enforcement authority. No obvious relationship between them. No clear starting point.

The reality is simpler. Every framework, regulation, and standard in the world belongs to one of six domains. The domains do not overlap. They each answer a different question about how an organization operates responsibly. Once you see the structure the individual frameworks stop feeling like a random list and start making sense as a system.

This article maps that structure.

Domain 1: Information Security and Cyber

Information security compliance covers every framework concerned with protecting systems, data, and digital infrastructure from threats, unauthorized access, and operational failure.

It applies to any organization that handles sensitive data or operates digital infrastructure. That definition covers almost every company operating today. A SaaS startup, a hospital, a bank, a government agency, a logistics firm. If your systems hold data that matters to someone else, you are in scope for at least one framework in this domain.

The trigger is almost always commercial before it is regulatory. An enterprise client sends a vendor security questionnaire. A contract goes on hold pending evidence of controls. That moment forces the conversation in most organizations well before any regulator gets involved.

ISO 27001

International standard for Information Security Management Systems. The global baseline for enterprise vendor requirements across every industry and geography.

SOC 2

US-focused audit framework for service organizations. Produces an attestation report rather than a certificate. The default requirement for selling to US enterprise clients.

DORA

EU regulation for financial entities. Legally binding ICT risk management requirements. In force since January 2025.

NIS2

EU directive covering 18 critical sectors. Extends cybersecurity obligations beyond financial services. In force since October 2024.

CMMC and FedRAMP

US government contractor requirements. Mandatory for any company supplying the federal government or Department of Defense.

Domain 2: Data Privacy

Data privacy compliance covers every framework concerned with the legal rights of individuals over their personal data and the obligations of organizations that collect, store, and process it.

It applies to any organization that handles personal data of individuals in regulated jurisdictions. Unlike Domain 1 which is triggered commercially, data privacy compliance is almost always legally mandatory from the moment you collect your first user's email address. There is no threshold of size or revenue that exempts you.

The most important thing to understand about this domain is its extraterritorial reach. A company based anywhere in the world that processes personal data of EU residents is subject to GDPR regardless of where it operates. The law follows the data subject, not the company.

GDPR

Europe. The mother of all privacy laws. Global reach by design. Every privacy law written after 2018 is either inspired by it or reacts to it.

UK GDPR

UK post-Brexit. Separate legal obligation from EU GDPR but substantially identical in requirements.

CCPA

California. The de facto US privacy standard. Relevant the moment you have American users above the revenue threshold.

PIPEDA

Canada. The most established privacy law in North America outside the US.

PDPA

Singapore and Thailand. The most significant privacy framework in Southeast Asia.

Domain 3: Financial and Corporate Governance

Financial and corporate governance compliance covers frameworks concerned with the integrity of financial reporting and the accountability of corporate decision making. This domain primarily affects public companies listed on stock exchanges and regulated financial institutions. For most technology companies it only becomes directly relevant at the moment of a public listing or when operating within regulated financial markets.

SOX

The Sarbanes-Oxley Act. Mandatory for all US-listed public companies. Requires management and auditors to formally report on the integrity of internal financial controls.

Basel IV

The international framework for banks governing capital adequacy and liquidity requirements globally.

MiFID II

The EU directive governing investment firms and trading platforms focused on investor protection and market transparency.

Domain 4: Industry Specific Regulatory

Industry specific compliance covers the rules that apply to particular sectors where general frameworks are not granular enough to address the risks involved. Unlike the other domains, this one is not triggered by company size, geography, or ambition. It is triggered purely by what your business does.

If you process card payments you are in scope for PCI DSS regardless of how small you are. If you supply the US Department of Defense you are in scope for CMMC regardless of where you are based. The business model is the compliance trigger. There is no opting out.

PCI DSS

The Payment Card Industry Data Security Standard. Mandatory for any organization that stores, processes, or transmits cardholder data. Non-compliance results in fines and loss of the ability to process card payments.

HIPAA

The US Health Insurance Portability and Accountability Act. Mandatory for healthcare providers, health insurers, and any vendor handling protected health information in the United States.

TISAX

The Trusted Information Security Assessment Exchange. Required for any supplier to major European automotive manufacturers.

CMMC

The Cybersecurity Maturity Model Certification. Mandatory for any company in the US Defense Industrial Base.

Domain 5: Quality and Operational

Quality and operational compliance covers every framework concerned with whether an organization's processes consistently deliver what they claim to deliver. This domain is less about protecting data or reporting finances and more about proving that what you build, manufacture, or deliver meets a defined and repeatable standard.

It primarily affects manufacturing companies, medical device producers, and professional services firms where process consistency directly impacts product safety or service reliability. For software companies it becomes relevant when building products for regulated industries — a healthtech company building medical software, an automotive supplier building safety-critical systems.

The trigger is usually a client requirement or a regulatory approval process. A hospital will not purchase software that does not meet specific quality standards. A car manufacturer will not accept components from a supplier without quality certification.

ISO 9001

The most widely certified standard in the world. Defines the requirements for a quality management system applicable to any organization regardless of size or industry. Over one million companies hold ISO 9001 certification globally.

ISO 13485

ISO 9001 specifically adapted for medical device manufacturers. Required for CE marking of medical devices in the EU and recognized by regulators in over 100 countries.

ISO 45001

Covers occupational health and safety management. Relevant for any organization with significant workplace safety obligations.

Domain 6: ESG and Sustainability

ESG and sustainability compliance covers every framework concerned with how an organization operates in relation to its environmental impact, social responsibility, and governance transparency. This is the newest of the six domains and the fastest growing. Five years ago most of these obligations did not exist. Today large EU companies face legally binding reporting requirements and the scope is expanding rapidly.

The trigger for this domain is shifting from voluntary to mandatory. What began as investor pressure and reputational motivation has become regulatory obligation for large organizations operating in the EU.

CSRD

The Corporate Sustainability Reporting Directive. EU regulation requiring large companies to report in detail on their environmental impact, social factors, and governance practices. Mandatory for large EU companies from 2024 with scope expanding through 2028.

TCFD

The Task Force on Climate-related Financial Disclosures. Originally voluntary but now mandatory in the UK and increasingly required by stock exchanges and institutional investors globally.

EU Taxonomy

Defines which economic activities qualify as environmentally sustainable under EU law. Relevant for any company making green claims or seeking access to sustainable finance in Europe.

SFDR

The Sustainable Finance Disclosure Regulation. Applies to EU financial product providers. Requires disclosure of sustainability risks in investment products.

No organization lives in a single domain

No organization operates in a single domain. The moment a company crosses a certain size, enters a regulated market, or starts handling sensitive data, multiple domains apply simultaneously. The compliance landscape is not a menu where you pick one item. It is a set of overlapping obligations determined by what you do, who your customers are, and where you operate.

Domains 1, 2, 3, and 4

A European fintech processing card payments

ISO 27001 and DORA for ICT risk. GDPR for personal data. PCI DSS because it processes card payments. Four domains. Four sets of obligations. One company.

Domains 1, 2, and 4

A US healthtech SaaS company

SOC 2 as the commercial security baseline. CCPA for California users. HIPAA the moment a covered healthcare entity uses the product.

Domains 1, 2, 5, and 6

A large EU manufacturer

ISO 27001 for information security. GDPR for employee and customer data. ISO 9001 for product quality. CSRD for sustainability reporting from 2025.

Now you have the map

The compliance landscape is not a random collection of acronyms. It is six domains, each answering a different question about how an organization operates responsibly. Information security, data privacy, financial governance, industry specific regulation, quality and operations, ESG and sustainability. Every framework in the world sits inside one of them.

Most organizations discover this landscape one emergency at a time. A questionnaire that blocks a contract. A regulator that sets a deadline. An investor who flags a gap. The companies that navigate compliance well are the ones who saw the full picture before the emergency arrived.

You now have that picture. The domains are clear. The frameworks make sense as a system. The question is no longer what exists. It is which part of it applies to you and in what order you address it.

That is where the real work begins.

Seifeddine LamrimedLinkedIn →