Every framework you're audited against.
Safeguard maps continuous evidence to the frameworks your auditors actually ask about — US, international, and sector-specific. Major frameworks plus 150+ regional variants and regimes mapped across 6 regions — 25 highlighted below.
US frameworks.
The audits, attestations, and federal baselines that US-based teams ship against — mapped to continuous evidence, not annual screenshots.
SOC 2 Type II
Continuous trust services evidence packs, CC controls auto-mapped.
See coverageNIST SSDF (SP 800-218)
Practice-level evidence for every release.
See coverageNIST CSF 2.0
Govern/Identify/Protect/Detect/Respond/Recover mapped to your stack.
See coverageFedRAMP
Moderate & High baseline coverage, sovereign deployment for federal.
See coverageHIPAA
PHI-aware controls for healthcare.
See coveragePCI-DSS 4.0
Software inventory + reachability evidence for cardholder data envs.
See coverageCMMC 2.0
DIB-ready, with controlled-unclassified-information coverage.
See coverageStateRAMP
State and local gov baseline.
See coverageInternational frameworks.
European, UK, APAC, and LATAM regulations — Safeguard ships the SBOMs, VEX, and AI-BOM evidence regulators actually ask for.
ISO 27001
Annex A controls linked to live evidence.
See coverageISO 27017
Cloud-specific controls.
See coverageISO 27018
PII processing in the cloud.
See coverageISO 42001
AI management system.
See coverageEU CRA
Continuous SBOMs + VEX + vulnerability handling per the Cyber Resilience Act.
See coverageEU AI Act
AI-BOM + provenance + eval evidence.
See coverageNIS2
Essential & important entities supply chain reporting.
See coverageDORA
Financial sector operational resilience.
See coverageUK Cyber Essentials Plus
UK government baseline.
See coverageDPDP (India)
Personal data protection.
See coverageLGPD (Brazil)
Brazilian privacy law.
See coverageSector & industry.
Industry-specific regimes — medical, industrial, transport, energy, finance — where the regulator names the artifacts they want.
FDA Premarket Cybersecurity
Medical device SBOM + VEX for premarket submissions.
See coverageEU MDR / IVDR
Medical device EU coverage.
See coverageISA/IEC 62443
Industrial automation & control systems.
See coverageTSA Security Directives
Pipeline + rail + aviation OT.
See coverageNERC CIP
Bulk electric system.
See coverageNYDFS Cybersecurity Reg
New York financial sector.
See coverageA framework not listed?
If your auditor is asking for it, we'll map it. Book a 30-minute call and we'll walk through your control set with the Safeguard evidence engine live.
Read the detail guide.
66 regimes have a dedicated guide — what it requires, what Safeguard maps to, and the evidence it produces.
Sovereign & national
12Country-level cyber and resilience regimes.
Banking & financial
12Regulators of financial market infrastructure.
Privacy & data protection
11Personal-data regimes and their breach duties.
Critical infrastructure
10Operators of essential services and OT.
AI governance
05Regimes governing AI systems and model supply chains.
ISO / IEC
05International management-system standards.
Health & life sciences
03Patient data and medical software safety.
Payments
03Cardholder-data and payment-network rules.
Defence
02Defence-industrial-base supply chain requirements.
Product & device
02Regulations attaching to a shipped product.
Every framework we support.
All 373 regimes in the registry, grouped by region.
Americas
107Europe
76Asia-Pacific
62Middle East & Africa
76International
41Internal
11Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.