Skip to content

Compliance Intelligence API

718 frameworks, 20,400+ controls (99.7% with auditor evidence), and 330,000+ verified cross-framework mappings. REST API and MCP server for AI agents.

Add to Claude Desktop, Cursor, or any MCP client:

{ "mcpServers": { "compliance": { "url": "https://api.theartofservice.com/mcp" } } }

Popular Framework APIs

All 803 Framework APIs

Australian Information Security Manual · 1081 controlsFedRAMP High · 417 controlsNIST SP 800-53 Revision 5.1 HIGH · 317 controlsNIST SP 800-53 Rev 5 MODERATE · 275 controlsFedRAMP Moderate · 238 controlsCloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 · 197 controlsNIST SP 800-53 Rev 5 LOW · 173 controlsCSA CCM v4 · 171 controlsISO 39001:2012 - Road Traffic Safety Management · 169 controlsISO 41001:2018 - Facility Management Systems · 168 controlsISO 22313:2020 - Guidance on Business Continuity Management Systems · 167 controlsISO 56002 · 164 controlsISO 37002:2021 - Whistleblowing Management Systems · 159 controlsASD Information Security Manual (ISM) · 136 controlsISO 27701:2019 · 136 controlsC5 (Germany) · 121 controlsNIST SP 800-171 Rev 3 · 97 controlsISO 27002:2022 · 94 controlsNIST SP 800-171 · 93 controlsISO/IEC 17025:2017 - General Requirements for Testing and Calibration Laboratories · 90 controlsAWS Well-Architected Security Pillar · 89 controlsISO/IEC 23894:2023 · 85 controlsISO 27018:2019 · 84 controlsISO 13485:2016 · 83 controlsIEC 62443 · 81 controlsISO/IEC 42001:2023 · 80 controls21 CFR Part 211 - Current Good Manufacturing Practice · 78 controlsFFIEC IT Examination Handbook · 78 controlsISO 15189:2022 - Medical Laboratories Requirements for Quality and Competence · 77 controlsISO/IEC 27003:2017 · 72 controlsISO 9001:2015 · 71 controlsISO 22000:2018 · 70 controlsISO 26262:2018 - Functional Safety for Road Vehicles · 69 controlsCOBIT 2019 · 68 controlsSSAE 18 - Attestation Standards (SOC Reporting) · 67 controlsISO/IEC 38500:2024 · 66 controlsNIST SP 800-66 Rev 2 · 65 controlsPCI DSS v4.0 · 63 controlsAS9100D - Aerospace Quality Management System · 61 controlsISO 26000:2010 · 60 controlsColorado Privacy Act (CPA) · 59 controlsISO 37000:2021 · 59 controlsASD Essential Eight Maturity Model · 57 controlsISO 31000:2018 · 57 controlsISO 30414:2018 - Human Resource Management: Guidelines for Internal and External Human Capital Reporting · 56 controlsISO 45001:2018 · 56 controlsBSI IT-Grundschutz · 55 controlsISO 19011:2018 · 55 controlseIDAS 2.0 - EU Digital Identity Regulation · 55 controlsAzure Security Benchmark · 54 controlsISO/IEC TR 24028:2020 · 54 controlsISO 50001:2018 - Energy Management Systems · 53 controlsITIL 4 · 53 controlsChina Personal Information Protection Law (PIPL) · 52 controlsISO 27043 · 52 controlsISO/IEC 27006:2024 · 52 controlsNIST AI Risk Management Framework (AI RMF 1.0) · 52 controlsNIST SP 800-207 · 51 controlsISO/SAE 21434 · 50 controlsEgypt Personal Data Protection Law (Law No. 151 of 2020) · 49 controlsFFIEC Cybersecurity Assessment Tool (CAT) · 49 controlsNIST SP 800-160 · 49 controlsPCI SSF · 49 controlsAdministrative Measures for the Security Assessment of Generative AI Services (2023) and Algorithmic Recommendation Management Provisions (2022) · 48 controlsCOSO Internal Control - Integrated Framework (2013) · 48 controlsISO 14004:2016 · 48 controlsISO 9001 · 48 controlsNIST SP 800-53A Rev. 5 · 48 controlsNIST SP 800-82 Rev 3 · 48 controlsAPRA CPS 230 Operational Risk Management · 47 controlsBREEAM - Building Research Establishment Environmental Assessment Method · 47 controlsIAIS Insurance Core Principles (ICPs) · 47 controlsISO 14001:2015 · 47 controlsISO 37301:2021 · 47 controlsCISA Zero Trust Maturity Model · 46 controlsDAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition) · 46 controlsISO 27019 · 46 controlsISO 27799 · 46 controlsDoD Zero Trust Reference Architecture · 45 controlsISO 27005:2022 · 45 controlsISO 27018 · 45 controlsNIST SP 800-190 · 45 controlsNorth Macedonia Law on Personal Data Protection (2020) · 45 controlsAct on the Implementation of the General Data Protection Regulation (OG 42/2018) · 44 controlsBank Secrecy Act / Anti-Money Laundering (BSA/AML) · 44 controlsBelgium CyberFundamentals · 44 controlsISO 19650 - Organisation and Digitisation of Information about Buildings and Civil Engineering Works (BIM) · 44 controlsISO 22301:2019 · 44 controlsISO/IEC 27011:2024 · 44 controlsNIST SP 1800-32 · 44 controlsPCI P2PE · 44 controls3GPP 5G Security Architecture (TS 33.501) · 43 controlsISO 31000 · 43 controlsISO 37301 · 43 controlsISO/IEC 29134:2023 · 43 controlsPCI PIN Security · 43 controlsSouth Korea Personal Information Protection Act (PIPA) · 43 controlsAS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence · 42 controlsASIS SPC.1-2009 - Organizational Resilience Standard · 42 controlsAged Care Quality Standards (Australia) · 42 controlsCISA ICS-CERT Advisories and Industrial Control Systems Security Guidelines · 42 controlsEN 301 549 - Accessibility requirements for ICT products and services · 42 controlsISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3) · 42 controlsISO 27017:2015 · 42 controlsISO 30401 · 42 controlsISO 37001 · 42 controlsISO/IEC 23837 - Security Requirements for Quantum Key Distribution · 42 controlsISO/IEC 38500:2024 - Governance of IT · 42 controlsNIST SP 800-161 Rev 1 · 42 controlsNIST SP 800-218 · 42 controlsUK Cyber Essentials · 42 controlsEU NIS2 Directive — Energy Sector Cybersecurity Requirements (Directive 2022/2555) · 41 controlsISO 37001:2016 · 41 controlsISO/IEC 17025:2017 - General Requirements for Testing and Calibration · 41 controlsISO/IEC 27557:2022 - Organisational Privacy Risk Management · 41 controlsISO/IEC 29115:2023 - Entity Authentication Assurance Framework · 41 controlsISO 20400:2017 - Sustainable Procurement · 40 controlsISO 55001 · 40 controlsISO/IEC 29100:2024 · 40 controlsISO/IEC 29147:2018 · 40 controlsSANS Incident Handler's Handbook and PICERL Methodology · 40 controlsSpace ISAC (Information Sharing and Analysis Center) - Threat Framework · 40 controlsAML/CTF Act 2006 (Australia) · 39 controlsBRCGS Global Standard for Food Safety Issue 9 · 39 controlsCook Islands Electronic Transactions Act & Privacy Provisions (2003) · 39 controlsISO 22000 · 39 controlsISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary · 39 controlsISO 45001 · 39 controlsISO/IEC 27014:2020 · 39 controlsNIST SP 800-128 · 39 controlsIEC 60601-1 - Medical Electrical Equipment Safety · 38 controlsISO/IEC 27701:2019 · 38 controlsNIST SP 800-181 · 38 controlsASD Strategies to Mitigate Cyber Security Incidents · 37 controlsASEAN Guide on AI Governance and Ethics · 37 controlsAWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) · 37 controlsEU Taxonomy Regulation (Regulation 2020/852) · 37 controlsISO 22320:2018 · 37 controlsISO 27017 · 37 controlsAuthorised Economic Operator (AEO) Programmes - Global Standards · 36 controlsBSIMM · 36 controlsDigital Services Act (DSA) - Regulation (EU) 2022/2065 · 36 controlsISO 22317 · 36 controlsISO 22318 · 36 controlsISO 28001:2007 Supply Chain Security Management · 36 controlsISO/IEC 25012:2008 - Data Quality Model · 36 controlsNIST SP 800-172 · 36 controlsAPRA CPS 234 · 35 controlsCISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 · 35 controlsDigital Economy Partnership Agreement (DEPA) · 35 controlsEU Markets in Crypto-Assets Regulation (MiCA, Regulation 2023/1114) · 35 controlsNFPA 1600 - Standard on Continuity, Emergency, and Crisis Management · 35 controlsNIST SP 800-150 · 35 controlsNIST SP 800-171A Rev 3 - Assessing CUI Security Requirements · 35 controlsNYDFS Cybersecurity Regulation (23 NYCRR Part 500) · 35 controlsArgentina Law 25.326 (Personal Data Protection Law) · 34 controlsBrunei Personal Data Protection Order 2024 (PDPO) · 34 controlsEASA Part-IS - Information Security in Aviation · 34 controlsIEC 62351 - Power Systems Communication Security · 34 controlsISAE 3402 - Assurance Reports on Controls at a Service Organisation · 34 controlsISO 19011 · 34 controlsISO/IEC 30111:2019 · 34 controlsIllinois Biometric Information Privacy Act (BIPA) · 34 controlsNIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices · 34 controlsNIST SP 800-161 · 34 controlsConsumer Data Right (CDR) Framework (Australia) · 33 controlsEU Pay Transparency Directive (Directive 2023/970) · 33 controlsFBI CJIS Security Policy · 33 controlsIEC 62304:2015 Medical Device Software Lifecycle Processes · 33 controlsISO 22316 · 33 controlsAustralian Energy Sector Cyber Security Framework (AESCSF) · 32 controlsBotswana Data Protection Act (2024) · 32 controlsFTC Safeguards Rule (16 CFR Part 314) · 32 controlsISO/IEC 27018:2019 · 32 controlsISO/IEC 27400:2022 · 32 controlsNIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) · 32 controlsNIST SP 800-171A — Assessing CUI Security Requirements · 32 controlsNIST SP 800-187 · 32 controlsNIST SP 800-53A · 32 controlsSOC 1 (SSAE 18 / ISAE 3402) · 32 controls21 CFR Part 58 - Good Laboratory Practice (GLP) · 31 controls3GPP Security · 31 controlsAutomotive SPICE (ASPICE) v4.0 - Process Assessment Model · 31 controlsBrazil Open Finance (Resolução Conjunta No. 1/2020) · 31 controlsBrunei Personal Data Protection Order 2022 (PDPO) · 31 controlsCCPA/CPRA · 31 controlsCanadian PIPEDA · 31 controlsCosta Rica Personal Data Protection Law (Law No. 8968) · 31 controlsCôte d'Ivoire Law on Personal Data Protection (Law No. 2013-450) · 31 controlsEU Platform Work Directive (Directive 2024/2831) · 31 controlsNIST SP 800-115 · 31 controlsNIST SP 800-63 · 31 controlsChile Personal Data Protection Law (Law No. 21.719) · 30 controlsEU Audiovisual Media Services Directive (AVMSD, Directive 2010/13/EU as amended by Directive 2018/1808 and Directive (EU) 2023/2586) · 30 controlsEU Clinical Trials Regulation (CTR 536/2014) · 30 controlsISO/IEC 27004:2016 · 30 controlsNIST SP 800-183 · 30 controlsASIC Cyber Resilience Good Practices · 29 controlsArgentina PDPA · 29 controlsBahrain PDPL · 29 controlsBrazil AI Framework · 29 controlsChile DPL · 29 controlsChina PIPL · 29 controlsColombia Habeas Data Law · 29 controlsConnecticut DPA · 29 controlsFERPA · 29 controlsISO 13485 · 29 controlsISO 27701 · 29 controlsISO 8000 - Data Quality · 29 controlsISO/IEC 27050 - Electronic Discovery (Parts 1-4) · 29 controlsIceland DPA · 29 controlsJamaica DPA · 29 controlsKenya DPA · 29 controlsMaryland Online Data Privacy Act · 29 controlsNIST SP 800-88 Rev 1 · 29 controlsNSA Guidance for Transition to Quantum-Resistant Cryptography · 29 controlsNew Hampshire Privacy Act · 29 controlsNew Zealand Privacy Act · 29 controlsNigeria NDPR · 29 controlsNorway PDPA · 29 controlsPIPEDA · 29 controlsUAE PDPL · 29 controlsAPRA SPS 220 Risk Management (Superannuation) · 28 controlsAfrican Union Malabo Convention · 28 controlsAustralia Consumer Data Right - Banking (CDR) · 28 controlsBasel III International Banking Framework · 28 controlsColombia Data Protection Law (Law 1581 of 2012) · 28 controlsCustoms-Trade Partnership Against Terrorism (C-TPAT) · 28 controlsEBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) · 28 controlsENISA Data Protection Engineering - From Theory to Practice · 28 controlsISO/IEC 27007:2020 · 28 controlsISO/IEC 27010:2015 · 28 controlsASEAN Data Management Framework · 27 controlsArgyris Double-Loop Learning · 27 controlsAustralia NHMRC National Statement on Ethical Conduct in Human Research · 27 controlsBermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct · 27 controlsConnecticut Data Privacy Act (CTDPA) · 27 controlsEDM Council DCAM - Data Management Capability Assessment Model · 27 controlsEU Data Act · 27 controlsEU PSD3 and Payment Services Regulation (Proposed) · 27 controlsISO 10005:2005 · 27 controlsISO 20000-1 · 27 controlsISO/IEC 27031:2011 · 27 controlsSSAE 18 SOC 1 — Report on Controls at a Service Organisation (ICFR) · 27 controlsAICPA Privacy Management Framework (PMF) · 26 controlsBIMCO Cyber Security · 26 controlsBS 65000:2014 - Guidance on Organizational Resilience · 26 controlsCanada ITSG-33 - IT Security Risk Management · 26 controlsDORA · 26 controlsEU Chips Act (Regulation (EU) 2023/1781) · 26 controlsEU Digital Markets Act · 26 controlsEU In Vitro Diagnostic Medical Devices Regulation (IVDR) · 26 controlsEU Medical Devices Regulation (MDR 2017/745) · 26 controlsISO 27005 · 26 controlsISO 37000:2021 - Governance of Organizations · 26 controlsMauritius Data Protection Act 2017 · 26 controlsAICPA SOC 1 · 25 controlsCAIQ (CSA) · 25 controlsCDP Corporate Questionnaire · 25 controlsCWE Top 25 Most Dangerous Software Weaknesses (2024) · 25 controlsChina AI Regulations · 25 controlsEIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) · 25 controlsEstonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) · 25 controlsMAS TRM · 25 controlsACSC Essential Eight · 24 controlsAPI 1164 · 24 controlsBermuda Personal Information Protection Act 2016 (PIPA) · 24 controlsBosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011) · 24 controlsCNCF Security Technical Advisory Group (TAG) · 24 controlsCSA STAR (Security, Trust, Assurance, and Risk) · 24 controlsCosta Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP · 24 controlsCzech Republic Act on Personal Data Processing (Act No. 110/2019 Sb.) · 24 controlsEAR - Export Administration Regulations · 24 controlsEU Carbon Border Adjustment Mechanism (CBAM) · 24 controlsEU Cyber Resilience Act · 24 controlsEthiopia Personal Data Protection Proclamation (No. 1321/2024) · 24 controlsKenya Data Protection Act 2019 · 24 controlsNY DFS 23 NYCRR 500 · 24 controlsANSSI Cybersecurity Framework · 23 controlsAPRA CPS 220 Risk Management · 23 controlsAngola Personal Data Protection Law (Law No. 22/11) · 23 controlsBarbados Data Protection Act 2019 · 23 controlsMorocco Data Protection Law (09-08) · 23 controls3GPP Security Architecture (TS 33.501 — 5G Security) · 22 controlsAICPA SOC 3 · 22 controlsAlbania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) · 22 controlsAustralia My Health Records Act 2012 · 22 controlsC2M2 · 22 controlsCIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) · 22 controlsCSRD · 22 controlsCanada's Anti-Spam Legislation (CASL) · 22 controlsCayman Islands Data Protection Act 2017 (DPA) · 22 controlsChina Cybersecurity Law (CSL) · 22 controlsColorado Privacy Act · 22 controlsCritical Raw Materials Act (Proposed Regulation COM(2023) 192) · 22 controlsDISA Security Technical Implementation Guides (STIGs) · 22 controlsDanish Data Protection Act (Databeskyttelsesloven) · 22 controlsData Protection Act 2017 · 22 controlsDirective (EU) 2019/1937 on the protection of persons who report breaches of Union law · 22 controlsDirective (EU) 2023/970 on pay transparency · 22 controlsEMV 3‑D Secure (3DS) - Payment Authentication Protocol · 22 controlsEU General Product Safety Regulation (GPSR, Regulation 2023/988) · 22 controlsEU Markets in Crypto-Assets Regulation (MiCA) · 22 controlsFIDO2 and W3C WebAuthn Standard · 22 controlsICH E6(R2) Good Clinical Practice — Data Integrity and Electronic Systems · 22 controlsAASB S2 Climate-related Disclosures · 21 controlsAPPI · 21 controlsBelgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018) · 21 controlsCFTC System Safeguards (17 CFR 37, 38, 39, 49) · 21 controlsCISA Secure by Design Principles · 21 controlsCOPPA · 21 controlsChina Data Security Law (DSL) · 21 controlsColombia Data Protection Law (Law 1581 of 2012 — SIC Oversight) · 21 controlsCzech Republic Act on the Protection of Personal Data (Act No. 110/2019 Coll.) · 21 controlsDefence Security Principles Framework (DSPF) · 21 controlsEU Energy Performance of Buildings Directive (EPBD Recast) - Directive (EU) 2024/1275 · 21 controlsEU European Media Freedom Act (EMFA) · 21 controlsISO 55001:2014 · 21 controlsNIST SP 800-82 Rev 3 — Guide to OT Security · 21 controlsOnline Safety Act 2021 (Australia) · 21 controls6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673) - superseded by AMLD7 · 20 controlsAPEC Cross-Border Privacy Rules (CBPR) System · 20 controlsAustralian Privacy Principles (APPs) · 20 controlsCNCF Cloud Native Security (Cloud Native Computing Foundation) · 20 controlsCOSO ERM · 20 controlsCOSO Enterprise Risk Management (ERM) Framework (2017) · 20 controlsCambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134) · 20 controlsCanada Artificial Intelligence and Data Act (AIDA) · 20 controlsCode of Conduct on Data Protection for Research (GDPR Article 40) · 20 controlsColorado AI Act (SB 24-205) · 20 controlsCyber Essentials Plus · 20 controlsECB TIBER-EU Framework · 20 controlsESRB Privacy Certified · 20 controlsEU Better Internet for Kids (BIK+) Strategy · 20 controlsEU Machinery Regulation (Regulation (EU) 2023/1230) · 20 controlsEU Taxonomy for Sustainable Activities (Regulation 2020/852) · 20 controlsEU Union Customs Code (UCC) — Data Protection and Security Provisions (Regulation 952/2013) · 20 controlsFlorida Digital Bill of Rights (SB 262) · 20 controlsISO 22301 · 20 controlsAPRA Prudential Standard CPS 234 — Information Security (Australia) · 19 controlsColorado Artificial Intelligence Act (proposed SB 24-205) · 19 controlsCroatia Act on Implementation of the GDPR (Official Gazette 42/2018) · 19 controlsEU Data Governance Act (DGA) · 19 controlsEU Payment Services Directive (PSD2) · 19 controlsIACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems · 19 controlsArmenia Law on Protection of Personal Data (2015) · 18 controlsAustralia eSafety Commissioner - Online Safety Expectations for Industry · 18 controlsData (Use and Access) Act 2025 · 18 controlsDefence Industry Security Program (DISP) · 18 controlsEU AI Liability Directive · 18 controlsEU Cyber Solidarity Act (Regulation (EU) 2025/38) · 18 controlsEU Product Liability Directive (Directive (EU) 2024/2853) · 18 controlsEU SFDR (Sustainable Finance Disclosure Regulation) · 18 controlsISO 10006:2003 · 18 controlsAnnex 11 to EU GMP - Computerised Systems · 17 controlsCCSDS 350.0-G-3 - Space Communications Security (Consultative Committee for Space Data Systems) · 17 controlsCMMC 2.0 Level 1 · 17 controlsCook Islands Electronic Transactions Act 2003 · 17 controlsCyber Security Act 2024 (Australia) · 17 controlsEU Network Code on Cybersecurity for the Electricity Sector · 17 controlsEU Seveso III Directive (Directive 2012/18/EU) · 17 controlsISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems · 17 controlsJamaica Data Protection Act 2020 · 17 controlsMaslach Burnout Prevention Model · 17 controlsNIST SP 800-34 Rev 1 — Contingency Planning Guide · 17 controlsAustralia IRAP - Information Security Registered Assessors Program · 16 controlsCISA Industrial Control Systems (ICS) Security Guidance · 16 controlsEU Taxonomy Regulation · 16 controlsEU Whistleblower Protection Directive (2019/1937) · 16 controlsEuropean Accessibility Act (Directive (EU) 2019/882) · 16 controlsFATF 40 Recommendations · 16 controlsFIDO2 / WebAuthn · 16 controlsAustralia Online Safety Act 2021 · 15 controlsAzerbaijan Law on Personal Data (2010) · 15 controlsETSI EN 303 645 · 15 controlsEU ePrivacy Directive (2002/58/EC) · 15 controlsExtractive Industries Transparency Initiative (EITI) Standard (2023) · 15 controlsFAA Cybersecurity Framework for Aviation · 15 controlsFamily Educational Rights and Privacy Act (FERPA) · 15 controlsISO 14001 · 15 controlsNIST SP 800-124 Rev 2 — Mobile Device Security · 15 controlsAustria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) · 14 controlsBCBS 239 · 14 controlsCommercial National Security Algorithm Suite (CNSA) 2.0 · 14 controlsEDM Council CDMC - Cloud Data Management Capability Framework · 14 controlsEU Web Accessibility Directive (Directive 2016/2102) · 14 controlsFrench Sapin II Law (Law No. 2016-1691) · 14 controlsOECD AI Principles (2024 Update) · 14 controlsOWASP ASVS · 14 controlsCDP (formerly Carbon Disclosure Project) · 13 controlsFATF Recommendation 16 - Virtual Asset Travel Rule · 13 controlsFCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) · 13 controlsFDA 21 CFR Part 11 · 13 controlsFDA Quality Management System Regulation (QMSR) · 13 controlsFair Labor Association (FLA) Workplace Code of Conduct · 13 controlsGS1 Global Standards - Supply Chain Traceability and Data Security · 13 controlsHong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) · 13 controlsITU-T X.805 - Security Architecture for End-to-End Communications · 13 controlsJapan AI Guidelines · 13 controlsNATO Cyber Defence Standards and NCIRC (NATO Computer Incident Response Capability) · 13 controlsO-RAN Alliance Security Specifications (O-RAN.WG11) · 13 controlsC-TPAT - Customs-Trade Partnership Against Terrorism · 12 controlsDFARS 252.204-7012 - Safeguarding Covered Defense Information · 12 controlsFIRST CSIRT Services Framework and Standards · 12 controlsFISMA · 12 controlsFedRAMP Rev 5 · 12 controlsFederal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) · 12 controlsFlorida Digital Bill of Rights (FDBR) · 12 controlsGHG Protocol · 12 controlsGLBA · 12 controlsGLI-33 - Gaming Laboratories International Event Wagering Systems · 12 controlsGLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6 · 12 controlsGRI Standards · 12 controlsGhana Cybersecurity Act · 12 controlsGhana Data Protection Act 2012 (Act 843) · 12 controlsGlobal Cross-Border Privacy Rules (Global CBPR) Forum · 12 controlsGoleman Emotional Intelligence Leadership Framework · 12 controlsGreece Law 4624/2019 - Hellenic Data Protection Authority (HDPA) Implementation Act · 12 controlsHeifetz Adaptive Leadership Framework · 12 controlsICN Leadership for Change Programme · 12 controlsIRS Publication 1075 — Tax Information Security Guidelines · 12 controlsCritical Infrastructure Risk Management Program (CIRMP) Rules 2023 · 11 controlsEU NIS2 Directive - Transport Sector Requirements · 11 controlsFIDO2 / WebAuthn — Passwordless Authentication Standard · 11 controlsFSSC 22000 - Food Safety System Certification · 11 controlsFTC GLBA Safeguards Rule (16 CFR Part 314) · 11 controlsFTC Health Breach Notification Rule · 11 controlsFinland Data Protection Act (Tietosuojalaki, 1050/2018) · 11 controlsGAMP 5 - Good Automated Manufacturing Practice · 11 controlsGeorgia Law on Personal Data Protection (2012) · 11 controlsGerman Supply Chain Due Diligence Act (LkSG) · 11 controlsHITECH Act · 11 controlsHKMA Cyber Resilience Assessment Framework (C-RAF) · 11 controlsHKMA SPM · 11 controlsHersey & Blanchard Situational Leadership Model · 11 controlsIAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) · 11 controlsISO 10007:2017 · 11 controlsJapan FSA Cybersecurity Guidelines for Financial Institutions · 11 controlsNATO STANAG 4774/4778 — Confidentiality Metadata Labels · 11 controlsNSA CNSA Suite 2.0 — Commercial National Security Algorithm Suite · 11 controlsECSS-E-ST-40C: Space Engineering - Software · 10 controlsEquator Principles (EP4, 2020) · 10 controlsFull Range Leadership Model (Bass & Avolio) · 10 controlsHungary Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act) · 10 controlsIATF 16949:2016 - Quality Management System for Automotive Production · 10 controlsICAO Annex 17 - Aviation Security (AVSEC) · 10 controlsIndonesia PDP Law · 10 controlsOWASP Top 10:2025 · 10 controlsEthical Trading Initiative (ETI) Base Code · 9 controlsIATA Operational Safety Audit (IOSA) Standards Manual · 9 controlsICH E6(R3) - Good Clinical Practice · 9 controlsIEEE 7000 · 9 controlsISSB Standards · 9 controlsIsrael Protection of Privacy Law (5741-1981) · 9 controlsNSA Quantum-Resistant (QR) Cryptography Migration Guidance · 9 controlsPIC/S Guide to Good Manufacturing Practice for Medicinal Products · 9 controlsAustralia AI Ethics Framework · 8 controlsBSI C5 — Cloud Computing Compliance Criteria Catalogue · 8 controlsDelaware Online Privacy and Protection Act (proposed) · 8 controlsHKMA TM-G-1 · 8 controlsICC Incoterms 2020 - International Commercial Terms · 8 controlsICMM Mining Principles (2024 Update) · 8 controlsIFRS 17 - Insurance Contracts · 8 controlsILO Declaration on Fundamental Principles and Rights at Work (Core Conventions) · 8 controlsILO Nursing Personnel Convention C149 (1977) · 8 controlsILO Tripartite Declaration of Principles concerning Multinational Enterprises (MNE Declaration) · 8 controlsIMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2) · 8 controlsIRS Publication 1075 · 8 controlsISMAP (Japan) · 8 controlsITAR - International Traffic in Arms Regulations · 8 controlsITU Radio Regulations and Space Security Standards · 8 controlsIceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) · 8 controlsIndia Account Aggregator Framework (RBI) · 8 controlsIndia CERT-In Cyber Security Directions 2022 · 8 controlsIndia DPDP Act · 8 controlsIndiana Consumer Data Protection Act · 8 controlsIowa Consumer Data Protection Act · 8 controlsItaly Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) · 8 controlsJapan Act on Specified Commercial Transactions (ASCT) - Digital Services · 8 controlsJordan Draft Personal Data Protection Law (2022) · 8 controlsKazakhstan Law on Personal Data and Their Protection (No. 94-V) · 8 controlsKentucky Consumer Data Protection Act · 8 controlsKenya Data Protection Act · 8 controlsKids Online Safety Act (KOSA) · 8 controlsKolb Experiential Learning Cycle · 8 controlsKotter 8-Step Change Model · 8 controlsKuwait Data Privacy Protection Regulation (KDPPR, 2021 - CMA Directive) · 8 controlsKuwait National Cybersecurity Framework · 8 controlsLEED v4.1 - Green Building Rating System (US Green Building Council) · 8 controlsLGPD · 8 controlsLaos Law on Prevention and Combating Cybercrime (2015) · 8 controlsLatvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018) · 8 controlsLaw No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data · 8 controlsLaw No. 172-13 on the Protection of Personal Data · 8 controlsLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data · 8 controlsLaw on Personal Data Protection (Official Gazette No. 42/2020) · 8 controlsLebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018) · 8 controlsLey Orgánica de Protección de Datos Personales (LOPDP) · 8 controlsLiechtenstein DPA · 8 controlsLithuania Law on Legal Protection of Personal Data (2018) · 8 controlsLloyd's Minimum Standards - Cyber Security · 8 controlsLloyd's of London Cyber Insurance Requirements and Underwriting Standards · 8 controlsLuxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) · 8 controlsMARS-E · 8 controlsMDS2 (Medical Device) · 8 controlsMITRE ATT&CK · 8 controlsMITRE D3FEND · 8 controlsMTCS (Singapore) · 8 controlsMalaysia PDPA 2010 · 8 controlsMalta Data Protection Act (Cap. 586, 2018) · 8 controlsMaryland Online Data Privacy Act of 2024 · 8 controlsMaslach Burnout Inventory (MBI) and Areas of Worklife Survey (AWS) Model · 8 controlsMauritius DPA · 8 controlsMexico LFPDPPP · 8 controlsMiFID II / MiFIR · 8 controlsMinnesota Consumer Data Privacy Act · 8 controlsModern Slavery Act 2018 (Australia) · 8 controlsMonetary Authority of Singapore Technology Risk Management Guidelines · 8 controlsMontana Consumer Data Privacy Act · 8 controlsMontenegro Law on Personal Data Protection (2023) · 8 controlsMyanmar Cybersecurity Law (2023) · 8 controlsNABERS - National Australian Built Environment Rating System · 8 controlsNAIC Insurance Data Security Model Law (MDL-668) · 8 controlsNATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production · 8 controlsNATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) · 8 controlsNATO STANAG 4774 (Confidentiality Metadata Labels) and STANAG 4778 (Metadata Binding) · 8 controlsNERC CIP · 8 controlsNHS Healthcare Leadership Model · 8 controlsNIS2 Directive Implementing Acts · 8 controlsNIST AI 600-1: Generative AI Profile · 8 controlsNIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) · 8 controlsNIST Privacy Framework · 8 controlsNIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) · 8 controlsNIST SP 800-122 · 8 controlsNIST SP 800-123 · 8 controlsNIST SP 800-137 · 8 controlsNIST SP 800-144 · 8 controlsNIST SP 800-145 · 8 controlsNIST SP 800-146 · 8 controlsNIST SP 800-30 · 8 controlsNIST SP 800-37 · 8 controlsNIST SP 800-39 · 8 controlsNIST SP 800-61 · 8 controlsNIST SP 800-63 Digital Identity Guidelines · 8 controlsNIST SP 800-63-4 · 8 controlsNIST SP 800-66 · 8 controlsNIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security · 8 controlsNIST SP 800-88 · 8 controlsNIST SP 800-92 · 8 controlsNIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems · 8 controlsNRC 10 CFR 73.54 - Nuclear Facility Cybersecurity · 8 controlsNRF Cybersecurity and Data Privacy Framework (National Retail Federation) · 8 controlsNebraska Data Privacy Act · 8 controlsNetherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018) · 8 controlsNevada Gaming Control Board Cybersecurity Requirements · 8 controlsNew Hampshire Data Privacy Act · 8 controlsNew Jersey Data Privacy Act · 8 controlsNew Zealand Information Security Manual (NZISM) · 8 controlsNigeria Data Protection Act 2023 (NDPA) · 8 controlsNigeria Data Protection Regulation (NDPR) · 8 controlsNigeria Open Banking Regulatory Framework (CBN, 2023) · 8 controlsNotifiable Data Breaches Scheme (Australia) · 8 controlsO-RAN WG11 Security Specification · 8 controlsOCC Heightened Standards (12 CFR Part 30, Appendix D) · 8 controlsOECD AI Principles · 8 controlsOECD Guidelines for Multinational Enterprises on Responsible Business Conduct (2023 Update) · 8 controlsOECD Recommendation on Artificial Intelligence (2024 Update) · 8 controlsOECD/G20 Principles of Corporate Governance · 8 controlsOSFI B-13 · 8 controlsOWASP API Security Top 10 - 2023 · 8 controlsOWASP MASVS · 8 controlsOWASP Top 10 for LLM Applications 2025 · 8 controlsOman National Cybersecurity Framework · 8 controlsOman Personal Data Protection Law (Royal Decree 6/2022) · 8 controlsOntario Accessibility for Ontarians with Disabilities Act (AODA) - IASR Web Standard · 8 controlsOpen Banking Security · 8 controlsOpenSSF Scorecard · 8 controlsOregon Consumer Privacy Act · 8 controlsPCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR) · 8 controlsPDPA Singapore · 8 controlsPDPA Thailand · 8 controlsPOPIA · 8 controlsPakistan Personal Data Protection Bill 2023 · 8 controlsPanama Law on Personal Data Protection (Law No. 81 of 2019) · 8 controlsParaguay Law on Protection of Personal Data (Law No. 6534/2020) · 8 controlsPersonal Data Act (personopplysningsloven) · 8 controlsPeru DPL · 8 controlsPhilippines Data Privacy Act · 8 controlsPoland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018) · 8 controlsPortugal Law No. 58/2019 - Data Protection Implementation Act · 8 controlsPrivacy Act 1988 (Australia) · 8 controlsPrivacy Act 2020 · 8 controlsPrivacy and Other Legislation Amendment Act 2024 (Australia) · 8 controlsQatar DPL · 8 controlsRBI Cybersecurity Framework for Banks · 8 controlsRomania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) · 8 controlsRussia Federal Law on Personal Data (152-FZ) · 8 controlsRwanda DPL · 8 controlsSIG (Shared Assessments) · 8 controlsSWIFT CSCF · 8 controlsSaudi Arabia PDPL · 8 controlsSouth Korea PIPA · 8 controlsSwitzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) · 8 controlsTaiwan PDPA · 8 controlsETSI Industry Specification Group (ISG) on Quantum Key Distribution (QKD) · 7 controlsFiji Data Protection Bill (2020) · 7 controlsHL7 FHIR Security Framework · 7 controlsIEEE 1686 · 7 controlsIRM Enterprise Risk Management Framework (Institute of Risk Management) · 7 controlsPTES · 7 controlsPrivacy by Design (PbD) - Seven Foundational Principles · 7 controlsRhode Island Data Transparency and Privacy Protection Act (RIDTPPA) · 7 controlsSA8000:2014 - Social Accountability Standard · 7 controlsTennessee Information Protection Act (TIPA) · 7 controlsTurkey KVKK · 7 controlsCalifornia IoT Security Law · 6 controlsICH Q10 - Pharmaceutical Quality System · 6 controlsOWASP DevSecOps Maturity Model (DSOMM) · 6 controlsPAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments · 6 controlsPSD2 SCA · 6 controlsPapua New Guinea National Cybersecurity Policy & Cybercrime Act (2016) · 6 controlsPhilippines Cybercrime Prevention Act (RA 10175) · 6 controlsProposal for a Directive on improving working conditions in platform work (COM(2023) 491) · 6 controlsRegulation on the European Health Data Space (EHDS) · 6 controlsSASB Standards · 6 controlsSOC for Cybersecurity - Cybersecurity Risk Management Examination · 6 controlsScience Based Targets Initiative (SBTi) - Net-Zero Standard · 6 controlsSenegal Law on Personal Data Protection (Law No. 2008-12) · 6 controlsSingapore MAS TRM Guidelines · 6 controlsTexas Data Privacy Act · 6 controlsUK GDPR (UK General Data Protection Regulation) · 6 controlsUS Children's Online Privacy Protection Act (COPPA) and COPPA 2.0 Proposed Updates · 6 controlsUruguay DPL · 6 controlsVietnam PDPD · 6 controlsVirginia CDPA · 6 controlsWashington My Health My Data Act (MHMD) · 6 controlsLEADS in a Caring Environment · 5 controlsOWASP SAMM · 5 controlsPropTech Security Standards - Smart Building Cybersecurity · 5 controlsProtection of Privacy Law (1981) · 5 controlsProtective Security Policy Framework (PSPF) Release 2024 · 5 controlsSEC Climate Disclosure Rule · 5 controlsSOX 404 / ICFR · 5 controlsSQF Code Edition 9 - Safe Quality Food · 5 controlsSaudi NCA ECC · 5 controlsSecurity of Critical Infrastructure Act 2018 (SOCI) · 5 controlsSenge Fifth Discipline - Learning Organization · 5 controlsSerbia Law on Personal Data Protection (2018) · 5 controlsSingapore AI Governance Framework · 5 controlsSingapore Cybersecurity Act 2018 · 5 controlsSingapore Government Instruction Manual on ICT&SS Management (IM8) · 5 controlsSingapore Payment Services Act (PSA) - Digital Payment Token Regulation · 5 controlsSouth Korea Credit Information Act · 5 controlsSouth Korea ISMS-P · 5 controlsSpain ENS · 5 controlsSri Lanka Personal Data Protection Act (No. 9 of 2022) · 5 controlsTanzania Personal Data Protection Act (Draft) · 5 controlsThe Leadership Challenge (Kouzes & Posner) · 5 controlsTrinidad and Tobago Data Protection Act 2011 · 5 controlsUAE Virtual Asset Regulatory Authority (VARA) Regulations · 5 controlsUK AI Regulation Framework · 5 controlsUK Age Appropriate Design Code (Children's Code) · 5 controlsUK Bribery Act 2010 · 5 controlsUK Building Safety Act 2022 · 5 controlsUK Data Protection Act 2018 · 5 controlsUK Defence Standard 05-138 - Cyber Security for Defence Suppliers · 5 controlsUK FCA/PRA Operational Resilience Framework · 5 controlsUK Gambling Commission - Cyber Resilience Requirements · 5 controlsUK Modern Slavery Act 2015 · 5 controlsUK Online Safety Act 2023 · 5 controlsUS Executive Order 14028 - Improving the Nation's Cybersecurity · 5 controlsUS Foreign Corrupt Practices Act (FCPA) · 5 controlsUS ITAR and EAR - Export Control and Data Security · 5 controlsUS NRC 10 CFR 73.54 - Cyber Security for Nuclear Power Plants · 5 controlsUS OFAC Sanctions Compliance Framework · 5 controlsUS SEC Digital Assets and Crypto Regulatory Framework · 5 controlsUtah Consumer Privacy Act · 5 controlsWCAG 2.2 · 5 controlsWCO Authorised Economic Operator (AEO) Framework · 5 controlsZambia Data Protection Act (2021) · 5 controlsZimbabwe Data Protection Act (2021) · 5 controlsOwn Risk and Solvency Assessment (ORSA) - NAIC Model Act · 4 controlsPEGI - Pan European Game Information Age Rating System · 4 controlsRFC 2350 - Expectations for Computer Security Incident Response (BCP 21) · 4 controlsRICS Professional Standards - Data and Technology in Property · 4 controlsRegional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter · 4 controlsRegulation (EU) 2019/1239 on the Maritime Single Window (MSW) · 4 controlsRegulation (EU) 2023/1115 on deforestation-free supply chains · 4 controlsResponsible Minerals Initiative (RMI) - Responsible Minerals Assurance Process · 4 controlsRight to Disconnect (Australia) · 4 controlsSEC Cybersecurity Disclosure Rule · 4 controlsSLSA · 4 controlsSSDF (NIST) · 4 controlsSamoa Telecommunications Act (2005) - Privacy & Data Protection · 4 controlsSection 508 - ICT Accessibility (Revised) · 4 controlsSigstore - Software Artifact Signing and Verification · 4 controlsSingapore Protection from Online Falsehoods and Manipulation Act (POFMA, 2019) · 4 controlsSolvency II · 4 controlsSouth Africa Promotion of Access to Information Act (PAIA) · 4 controlsSouth Korea Cloud Security Assurance Program (CSAP) · 4 controlsSpain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) · 4 controlsStudent Privacy Pledge 2020 · 4 controlsSweden Data Protection Act (Dataskyddslag, 2018:218) · 4 controlsTCFD Recommendations · 4 controlsTEFCA - Trusted Exchange Framework and Common Agreement · 4 controlsTISAX - Trusted Information Security Assessment Exchange · 4 controlsTNFD Recommendations · 4 controlsTSA Pipeline Cybersecurity Directives · 4 controlsTonga Communications Act (2015) - Privacy & Data Protection · 4 controlsTunisia Organic Law on Personal Data Protection (Law No. 2004-63) · 4 controlsUK Construction (Design and Management) Regulations 2015 (CDM 2015) · 4 controlsUK NCSC Cyber Assessment Framework · 4 controlsUK ONR Cyber Security and Information Assurance (CSIA) for Nuclear Facilities · 4 controlsUK Open Banking Standard · 4 controlsUK Product Security and Telecommunications Infrastructure Act (PSTI) · 4 controlsUK Telecommunications (Security) Act 2021 · 4 controlsUN Guiding Principles on Business and Human Rights (UNGPs) · 4 controlsUNECE WP.29 R155 · 4 controlsUNECE WP.29 R156 · 4 controlsUNESCO Recommendation on the Ethics of AI · 4 controlsUNICEF Policy Guidance on AI for Children (2021) · 4 controlsUS Americans with Disabilities Act (ADA) - Title III Digital Accessibility · 4 controlsUS Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule · 4 controlsUS Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements · 4 controlsUSMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement) · 4 controlsUganda Data Protection and Privacy Act (2019) · 4 controlsUkraine Law on Personal Data Protection (Law No. 2297-VI) · 4 controlsUnion Customs Code (UCC) - Regulation (EU) No 952/2013 · 4 controlsUzbekistan Law on Personal Data (No. ZRU-547) · 4 controlsVUCA Leadership Framework · 4 controlsVermont Artificial Intelligence and Consumer Data Act (AICDA) · 4 controlsVietnam Law on Cybersecurity (No. 24/2018/QH14) · 4 controlsW3C Verifiable Credentials (VC) Data Model 2.0 · 4 controlsWCO SAFE Framework of Standards to Secure and Facilitate Global Trade (2021) · 4 controlsWELL Building Standard v2 (International WELL Building Institute) · 4 controlsWHO Global Strategy on Digital Health 2020-2025 · 4 controlsWisconsin Data Privacy Act (SB 670) · 4 controlsISO/IEC 17050-2:2004 · 3 controlsMARS-E - Minimum Acceptable Risk Standards for Exchanges · 3 controlsSecure by Design: A Guide for Manufacturers (CISA) · 3 controlsSouth Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics · 3 controlsTelecommunications Sector Security Reforms (TSSR) · 3 controlsUK Concordat on Open Research Data (UKRI) · 3 controlsUK Security and Emergency Measures Direction (SEMD) - Water Industry · 3 controlsUNCITRAL Model Law on Electronic Commerce (1996, updated 2005) · 3 controlsUS Automated Commercial Environment (ACE) - CBP Trade Data Requirements · 3 controlsUS Consumer Product Safety Commission (CPSC) - Connected Product Safety · 3 controlsUS EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements · 3 controlsVoluntary Principles on Security and Human Rights (VPs) · 3 controlsWHO Global Competency Model · 3 controlsISO/IEC 17050-1:2004 · 1 controlsDO-178C / ED-12C - Software Considerations in Airborne SystemsDO-326A / ED-202AEN 50126 / EN 50128 / EN 50129 - Railway Applications RAMSMTCS - Multi-Tier Cloud Security (Singapore)NAIC MDL-668NIST Privacy Framework 1.0NIST Privacy Framework Version 1.0Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA)Peru Personal Data Protection Law (Law No. 29733)Philippines DPAPhilippines Data Privacy Act (RA 10173)Qatar Personal Data Privacy Protection Law (Law No. 13 of 2016)Russia FZ-152Rwanda Law No. 058/2021 Relating to the Protection of Personal DataSASB Standards (ISSB Integrated)SEC Cybersecurity Disclosure RulesSWIFT CSCF v2024SWIFT CSPSWIFT Customer Security Programme (CSP)Sarbanes-Oxley Act (SOX)Saudi PDPLScience Based Targets initiative (SBTi) Corporate StandardSingapore Model AI Governance Framework (2nd Edition)Singapore PDPASingapore Payment Services Act 2019 (PSA) - Digital Payment Token ProvisionsSouth African POPIASwitzerland FADPTSA Pipeline SecurityTennessee IPATexas TDPSAThailand PDPATurkey Personal Data Protection Law (KVKK - Law No. 6698)UK Data Protection Act 2018 + UK GDPRUK PSTI ActUS Section 508 - ICT Accessibility Standards (Revised 2017)Uruguay Personal Data Protection Act (Law No. 18.331)Utah Consumer Privacy Act (UCPA)Vietnam PDPL (Decree 13)Virginia Consumer Data Protection Act (VCDPA)Virginia VCDPA

Frequently Asked Questions

What is the Compliance Intelligence API?
A REST and MCP API providing programmatic access to 718 compliance frameworks, 20,400+ controls (99.7% with auditor evidence), and 330,000+ verified cross-framework control mappings. Query framework details, map controls between standards, run gap analyses, and get coverage reports.
Is there a free tier?
Yes. Anonymous access gives you 10 API calls per day with no signup required. Free accounts get 100 calls/month with an API key. Professional plans start at $149/month with 10,000 calls included.
Does it work with AI agents?
Yes. The API is available as an MCP (Model Context Protocol) server at api.theartofservice.com/mcp. Add it to Claude Desktop, Cursor, Windsurf, or any MCP client. AI agents can query compliance data directly.
What frameworks are available?
718 frameworks (526 source-grounded) including ISO 27001, SOC 2, NIST CSF, GDPR, HIPAA, PCI DSS, CMMC, NIS2, DORA, EU AI Act, and hundreds more. Each framework includes controls, domains, and cross-framework mappings.

Start building with the Compliance API

No signup required for 10 free API calls per day. Create a free account for 100 calls/month.