Compliance Intelligence API
692 frameworks, 13,700+ controls, and 819,000+ cross-framework mappings. REST API and MCP server for AI agents.
Add to Claude Desktop, Cursor, or any MCP client:
{ "mcpServers": { "compliance": { "url": "https://api.theartofservice.com/mcp" } } }Popular Framework APIs
ISO 27001:2022 API
95 controls · 4 domains · 612+ mappings
SOC 2 API
54 controls · 5 domains · 547+ mappings
NIST Cybersecurity Framework 2.0 API
103 controls · 6 domains · 584+ mappings
GDPR API
44 controls · 4 domains · 316+ mappings
HIPAA Security Rule API
37 controls · 5 domains · 466+ mappings
CMMC 2.0 API
32 controls · 6 domains · 521+ mappings
NIST SP 800-53 Rev 5 API
172 controls · 18 domains · 597+ mappings
EU AI Act API
25 controls · 5 domains · 544+ mappings
ISO 42001 API
25 controls · 5 domains · 544+ mappings
CIS Controls v8 API
153 controls · 18 domains · 858+ mappings
NIS2 Directive API
24 controls · 5 domains · 480+ mappings
All 693 Framework APIs
CSA CCM v4 · 171 controlsISO 22313:2020 — Guidance on Business Continuity Management Systems · 145 controlsISO 39001:2012 — Road Traffic Safety Management · 145 controlsISO 41001:2018 — Facility Management Systems · 145 controlsISO 50001:2018 — Energy Management Systems · 145 controlsISO 56002 · 138 controlsASD Information Security Manual (ISM) · 136 controlsISO 37002:2021 — Whistleblowing Management Systems · 136 controlsNIST Privacy Framework 1.0 · 100 controlsDefence Security Principles Framework (DSPF) · 92 controlsProtective Security Policy Framework (PSPF) Release 2024 · 91 controlsWCAG 2.2 · 86 controlsUK Telecommunications (Security) Act 2021 · 76 controlsConnecticut Data Privacy Act (CTDPA) · 72 controlsISO/IEC 17025:2017 — General Requirements for Testing and Calibration Laboratories · 65 controlsEAR — Export Administration Regulations · 64 controlsFedRAMP Rev 5 · 64 controlsISO 15189:2022 — Medical Laboratories Requirements for Quality and Competence · 64 controlsPCI DSS v4.0 · 63 controlsRhode Island Data Transparency and Privacy Protection Act (RIDTPPA) · 63 controlsEU Digital Markets Act · 61 controlsBank Secrecy Act / Anti-Money Laundering (BSA/AML) · 60 controlsThe Leadership Challenge (Kouzes & Posner) · 60 controlsColorado Privacy Act (CPA) · 59 controlsWCO Authorised Economic Operator (AEO) Framework · 59 controls21 CFR Part 211 — Current Good Manufacturing Practice · 57 controlsAS9100D — Aerospace Quality Management System · 57 controlsASD Essential Eight Maturity Model · 57 controlsFull Range Leadership Model (Bass & Avolio) · 57 controlsISO/IEC 27003:2017 · 57 controlsHeifetz Adaptive Leadership Framework · 56 controlsNIS2 Directive Implementing Acts · 56 controlsTennessee Information Protection Act (TIPA) · 56 controlsWisconsin Data Privacy Act (SB 670) · 55 controlsAustralia Consumer Data Right — Banking (CDR) · 50 controlsEIOPA Guidelines on ICT Security and Governance (2020) · 50 controlsFTC Health Breach Notification Rule · 50 controlsCFTC System Safeguards (17 CFR 37, 38, 39, 49) · 49 controlsNAIC Insurance Data Security Model Law (MDL-668) · 49 controlsFlorida Digital Bill of Rights (FDBR) · 48 controlsUK Modern Slavery Act 2015 · 48 controlsUS EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements · 48 controlsSSAE 18 — Attestation Standards (SOC Reporting) · 47 controlsTISAX — Trusted Information Security Assessment Exchange · 47 controlsGLI-33 — Gaming Laboratories International Event Wagering Systems · 46 controlsAustralia eSafety Commissioner — Online Safety Expectations for Industry · 45 controlsBotswana Data Protection Act (2024) · 45 controlsFAA Cybersecurity Framework for Aviation · 45 controlsISO 26262:2018 — Functional Safety for Road Vehicles · 45 controlsMontenegro Law on Personal Data Protection (2023) · 45 controlsNorth Macedonia Law on Personal Data Protection (2020) · 45 controlsNotifiable Data Breaches Scheme (Australia) · 45 controlsParaguay Law on Protection of Personal Data (Law No. 6534/2020) · 45 controlsHungary Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act) · 44 controlsPortugal Law No. 58/2019 — Data Protection Implementation Act · 44 controlseIDAS 2.0 — EU Digital Identity Regulation · 44 controlsAPRA CPS 230 Operational Risk Management · 43 controlsEU Machinery Regulation (Regulation (EU) 2023/1230) · 43 controlsNIST AI 600-1 Generative AI Profile · 43 controlsSouth Korea Personal Information Protection Act (PIPA) · 43 controlsCISA ICS-CERT Advisories and Industrial Control Systems Security Guidelines · 42 controlsIceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) · 42 controlsAML/CTF Act 2006 (Australia) · 41 controlsEU Anti-Money Laundering Directive (AMLD6 / Directive 2018/1673) · 41 controlsEU NIS2 Directive — Energy Sector Cybersecurity Requirements (Directive 2022/2555) · 41 controlsEuropean Accessibility Act (Directive (EU) 2019/882) · 41 controlsOntario Accessibility for Ontarians with Disabilities Act (AODA) — IASR Web Standard · 41 controlsPhilippines Cybercrime Prevention Act (RA 10175) · 41 controlsUS Gramm-Leach-Bliley Act (GLBA) — Higher Education Safeguards Rule · 41 controlsUS ITAR and EAR — Export Control and Data Security · 41 controlsUS SEC Digital Assets and Crypto Regulatory Framework · 41 controlsWashington My Health My Data Act (MHMD) · 41 controlsCISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 · 40 controlsCOBIT 2019 · 40 controlsEU Taxonomy Regulation · 40 controlsFATF 40 Recommendations · 40 controlsJordan Draft Personal Data Protection Law (2022) · 40 controlsTNFD Recommendations · 40 controlsAASB S2 Climate-related Disclosures · 39 controlsASEAN Data Management Framework · 39 controlsAustralian Energy Sector Cyber Security Framework (AESCSF) · 39 controlsC-TPAT — Customs-Trade Partnership Against Terrorism · 39 controlsCook Islands Electronic Transactions Act & Privacy Provisions (2003) · 39 controlsEU General Product Safety Regulation (GPSR, Regulation 2023/988) · 39 controlsEU Maritime Single Window Environment Regulation (EU 2019/1239) and EMSA Cybersecurity · 39 controlsEU Markets in Crypto-Assets Regulation (MiCA) · 39 controlsModern Slavery Act 2018 (Australia) · 39 controlsNRF Cybersecurity and Data Privacy Framework (National Retail Federation) · 39 controlsTelecommunications Sector Security Reforms (TSSR) · 39 controlsAS9100D:2016 — Quality Management Systems for Aviation, Space, and Defence · 38 controlsCIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) · 38 controlsEU Deforestation-Free Products Regulation (EUDR) · 38 controlsEU Seveso III Directive (Directive 2012/18/EU) · 38 controlsISO/IEC 27006:2024 · 38 controlsLatvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018) · 38 controlsMiFID II / MiFIR · 38 controlsRwanda Law No. 058/2021 Relating to the Protection of Personal Data · 38 controlsUK Product Security and Telecommunications Infrastructure Act (PSTI) · 38 controlsUruguay Personal Data Protection Act (Law No. 18.331) · 38 controlsASD Strategies to Mitigate Cyber Security Incidents · 37 controlsEU Network Code on Cybersecurity for the Electricity Sector · 37 controlsEU Taxonomy Regulation (Regulation 2020/852) · 37 controlsISO 30414:2018 — Human Resource Management: Guidelines for Internal and External Human Capital Reporting · 37 controlsNHS Healthcare Leadership Model · 37 controlsOWASP DevSecOps Maturity Model (DSOMM) · 37 controlsDO-178C / ED-12C — Software Considerations in Airborne Systems · 36 controlsEU European Media Freedom Act (EMFA) · 36 controlsEU NIS2 Directive — Transport Sector Requirements · 36 controlsFTC GLBA Safeguards Rule (16 CFR Part 314) · 36 controlsUK Data Protection Act 2018 · 36 controlsVietnam Law on Cybersecurity (No. 24/2018/QH14) · 36 controlsDigital Economy Partnership Agreement (DEPA) · 35 controlsEU Markets in Crypto-Assets Regulation (MiCA, Regulation 2023/1114) · 35 controlsFinland Data Protection Act (Tietosuojalaki, 1050/2018) · 35 controlsISO 26000:2010 · 35 controlsNIST SP 800-171A Rev 3 — Assessing CUI Security Requirements · 35 controlsNYDFS Cybersecurity Regulation (23 NYCRR Part 500) · 35 controlsPoland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018) · 35 controlsSouth Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics · 35 controlsUS Americans with Disabilities Act (ADA) — Title III Digital Accessibility · 35 controlsUS OFAC Sanctions Compliance Framework · 35 controlsBrunei Personal Data Protection Order 2024 (PDPO) · 34 controlsEU Digital Services Act — Minors Protection Provisions (Regulation 2022/2065) · 34 controlsEstonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) · 34 controlsFDA Quality Management System Regulation (QMSR) · 34 controlsGAMP 5 — Good Automated Manufacturing Practice · 34 controlsLuxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) · 34 controlsCambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134) · 33 controlsECSS Software Engineering Standards (ESA) · 33 controlsEU Pay Transparency Directive (Directive 2023/970) · 33 controlsEthiopia Personal Data Protection Proclamation (No. 1321/2024) · 33 controlsFBI CJIS Security Policy · 33 controlsISO/IEC 23894:2023 · 33 controlsJapan Act on Specified Commercial Transactions (ASCT) — Digital Services · 33 controlsLaos Law on Prevention and Combating Cybercrime (2015) · 33 controlsLebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018) · 33 controlsMalta Data Protection Act (Cap. 586, 2018) · 33 controlsNetherlands GDPR Implementation Act (UAVG — Uitvoeringswet AVG, 2018) · 33 controlsSingapore Government Instruction Manual on ICT&SS Management (IM8) · 33 controlsANSSI Cybersecurity Framework · 32 controlsBSI IT-Grundschutz · 32 controlsBelgium CyberFundamentals · 32 controlsCDP (formerly Carbon Disclosure Project) · 32 controlsCISA Zero Trust Maturity Model · 32 controlsCyber Essentials Plus · 32 controlsDFARS 252.204-7012 — Safeguarding Covered Defense Information · 32 controlsDISA Security Technical Implementation Guides (STIGs) · 32 controlsDoD Zero Trust Reference Architecture · 32 controlsEU Product Liability Directive (Directive (EU) 2024/2853) · 32 controlsFISMA · 32 controlsFTC Safeguards Rule (16 CFR Part 314) · 32 controlsGhana Cybersecurity Act · 32 controlsISO/IEC 29147:2018 · 32 controlsNIST SP 800-171 · 32 controlsNIST SP 800-171A — Assessing CUI Security Requirements · 32 controlsNIST SP 800-172 · 32 controlsNIST SP 800-53A · 32 controlsSaudi NCA ECC · 32 controlsSouth Korea Credit Information Act · 32 controlsSpain ENS · 32 controlsSpain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) · 32 controlsZambia Data Protection Act (2021) · 32 controls21 CFR Part 58 — Good Laboratory Practice (GLP) · 31 controls3GPP Security · 31 controlsAICPA Privacy Management Framework (PMF) · 31 controlsAngola Personal Data Protection Law (Law No. 22/11) · 31 controlsBREEAM — Building Research Establishment Environmental Assessment Method · 31 controlsBSIMM · 31 controlsCOSO Internal Control — Integrated Framework (2013) · 31 controlsCalifornia IoT Security Law · 31 controlsCosta Rica Personal Data Protection Law (Law No. 8968) · 31 controlsCôte d'Ivoire Law on Personal Data Protection (Law No. 2013-450) · 31 controlsETSI EN 303 645 · 31 controlsEU Cyber Resilience Act · 31 controlsEU Platform Work Directive (Directive 2024/2831) · 31 controlsILO Nursing Personnel Convention C149 (1977) · 31 controlsISO 27002:2022 · 31 controlsISO 27043 · 31 controlsISO/SAE 21434 · 31 controlsMITRE ATT&CK · 31 controlsMITRE D3FEND · 31 controlsNIST AI Risk Management Framework (AI RMF 1.0) · 31 controlsNIST SP 800-115 · 31 controlsNIST SP 800-123 · 31 controlsNIST SP 800-128 · 31 controlsNIST SP 800-137 · 31 controlsNIST SP 800-150 · 31 controlsNIST SP 800-160 · 31 controlsNIST SP 800-161 · 31 controlsNIST SP 800-181 · 31 controlsNIST SP 800-183 · 31 controlsNIST SP 800-187 · 31 controlsNIST SP 800-207 · 31 controlsNIST SP 800-218 · 31 controlsNIST SP 800-61 · 31 controlsNIST SP 800-63 · 31 controlsNIST SP 800-88 · 31 controlsNIST SP 800-92 · 31 controlsOWASP ASVS · 31 controlsOWASP MASVS · 31 controlsOWASP SAMM · 31 controlsOpenSSF Scorecard · 31 controlsPTES · 31 controlsSIG (Shared Assessments) · 31 controlsSLSA · 31 controlsSSDF (NIST) · 31 controlsSingapore Payment Services Act 2019 (PSA) — Digital Payment Token Provisions · 31 controlsUK PSTI Act · 31 controlsUNECE WP.29 R155 · 31 controlsUNECE WP.29 R156 · 31 controlsVoluntary Principles on Security and Human Rights (VPs) · 31 controlsAfrican Union Malabo Convention · 30 controlsCanada's Anti-Spam Legislation (CASL) · 30 controlsChina Personal Information Protection Law (PIPL) · 30 controlsEN 301 549 — ICT Accessibility Requirements · 30 controlsEU Digital Services Act · 30 controlsIEC 62304:2015 Medical Device Software Lifecycle Processes · 30 controlsKuwait Data Privacy Protection Regulation (KDPPR, 2021 — CMA Directive) · 30 controlsPakistan Personal Data Protection Bill 2023 · 30 controlsRussia Federal Law on Personal Data (152-FZ) · 30 controlsSQF Code Edition 9 — Safe Quality Food · 30 controlsSecurity of Critical Infrastructure Act 2018 (SOCI) · 30 controlsUK Online Safety Act 2023 · 30 controlsAPPI · 29 controlsArgentina PDPA · 29 controlsBahrain PDPL · 29 controlsBosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011) · 29 controlsCCPA/CPRA · 29 controlsCOPPA · 29 controlsChile DPL · 29 controlsChile Personal Data Protection Law (Law No. 21.719) · 29 controlsChina PIPL · 29 controlsColombia Habeas Data Law · 29 controlsColorado Privacy Act · 29 controlsConnecticut DPA · 29 controlsDelaware Personal Data Privacy Act · 29 controlsDominican Republic DPL · 29 controlsEN 301 549 v3.2.1 — Accessibility Requirements for ICT Products and Services · 29 controlsEcuador LOPDP · 29 controlsFERPA · 29 controlsICN Leadership for Change Programme · 29 controlsISO 27701 · 29 controlsIceland DPA · 29 controlsIndia DPDP Act · 29 controlsIndiana Consumer Data Protection Act · 29 controlsIndonesia PDP Law · 29 controlsIowa Consumer Data Protection Act · 29 controlsJamaica DPA · 29 controlsKentucky Consumer Data Protection Act · 29 controlsKenya DPA · 29 controlsLGPD · 29 controlsLiechtenstein DPA · 29 controlsMalaysia PDPA 2010 · 29 controlsMaryland Online Data Privacy Act · 29 controlsMauritius DPA · 29 controlsMexico LFPDPPP · 29 controlsMinnesota Consumer Data Privacy Act · 29 controlsMontana Consumer Data Privacy Act · 29 controlsNIST SP 800-122 · 29 controlsNebraska Data Privacy Act · 29 controlsNew Hampshire Privacy Act · 29 controlsNew Jersey Data Privacy Act · 29 controlsNew Zealand Privacy Act · 29 controlsNigeria NDPR · 29 controlsNorway PDPA · 29 controlsOregon Consumer Privacy Act · 29 controlsPDPA Singapore · 29 controlsPDPA Thailand · 29 controlsPIPEDA · 29 controlsPOPIA · 29 controlsPanama Law on Personal Data Protection (Law No. 81 of 2019) · 29 controlsPeru DPL · 29 controlsPhilippines DPA · 29 controlsPrivacy Act 1988 (Australia) · 29 controlsQatar DPL · 29 controlsRomania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) · 29 controlsRwanda DPL · 29 controlsSaudi Arabia PDPL · 29 controlsSerbia Law on Personal Data Protection (2018) · 29 controlsSouth Korea PIPA · 29 controlsSwitzerland FADP · 29 controlsTaiwan PDPA · 29 controlsTennessee IPA · 29 controlsTexas Data Privacy Act · 29 controlsTurkey KVKK · 29 controlsUAE PDPL · 29 controlsUK Construction (Design and Management) Regulations 2015 (CDM 2015) · 29 controlsUK Gambling Commission — Cyber Resilience Requirements · 29 controlsUruguay DPL · 29 controlsUtah Consumer Privacy Act · 29 controlsVietnam PDPD · 29 controlsVirginia CDPA · 29 controls3GPP 5G Security Architecture (TS 33.501) · 28 controlsAlbania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) · 28 controlsAutomotive SPICE (ASPICE) v4.0 — Process Assessment Model · 28 controlsBRCGS Global Standard for Food Safety Issue 9 · 28 controlsCayman Islands Data Protection Act 2017 (DPA) · 28 controlsCustoms-Trade Partnership Against Terrorism (C-TPAT) · 28 controlsEU Chips Act (Regulation (EU) 2023/1781) · 28 controlsEU Critical Raw Materials Act (Regulation (EU) 2024/1252) · 28 controlsFiji Data Protection Bill (2020) · 28 controlsGHG Protocol · 28 controlsGeorgia Law on Personal Data Protection (2012) · 28 controlsOECD/G20 Principles of Corporate Governance · 28 controlsOman Personal Data Protection Law (Royal Decree 6/2022) · 28 controlsSingapore Payment Services Act (PSA) — Digital Payment Token Regulation · 28 controlsSouth Korea Cloud Security Assurance Program (CSAP) · 28 controlsWCO SAFE Framework of Standards to Secure and Facilitate Global Trade (2021) · 28 controlsZimbabwe Data Protection Act (2021) · 28 controlsEU Digital Services Act — Online Gaming Platform Requirements · 27 controlsEU PSD3 and Payment Services Regulation (Proposed) · 27 controlsEgypt Personal Data Protection Law (Law No. 151 of 2020) · 27 controlsFFIEC Cybersecurity Assessment Tool (CAT) · 27 controlsGoleman Emotional Intelligence Leadership Framework · 27 controlsILO Tripartite Declaration of Principles concerning Multinational Enterprises (MNE Declaration) · 27 controlsISO/IEC 27011:2024 · 27 controlsITAR — International Traffic in Arms Regulations · 27 controlsPeru Personal Data Protection Law (Law No. 29733) · 27 controlsSSAE 18 SOC 1 — Report on Controls at a Service Organisation (ICFR) · 27 controlsUAE Virtual Asset Regulatory Authority (VARA) Regulations · 27 controlsUzbekistan Law on Personal Data (No. ZRU-547) · 27 controlsAustralia Online Safety Act 2021 · 26 controlsBasel III International Banking Framework · 26 controlsDenmark Data Protection Act (Databeskyttelsesloven, 2018) · 26 controlsEBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04) · 26 controlsEU SFDR (Sustainable Finance Disclosure Regulation) · 26 controlsExtractive Industries Transparency Initiative (EITI) Standard (2023) · 26 controlsIATA Operational Safety Audit (IOSA) Standards Manual · 26 controlsISO 37000:2021 — Governance of Organizations · 26 controlsISO/IEC 27014:2020 · 26 controlsJamaica Data Protection Act 2020 · 26 controlsMauritius Data Protection Act 2017 · 26 controlsOCC Heightened Standards (12 CFR Part 30, Appendix D) · 26 controlsQatar Personal Data Privacy Protection Law (Law No. 13 of 2016) · 26 controlsUK Security and Emergency Measures Direction (SEMD) — Water Industry · 26 controlsUganda Data Protection and Privacy Act (2019) · 26 controlsVermont Artificial Intelligence and Consumer Data Act (AICDA) · 26 controlsWELL Building Standard v2 (International WELL Building Institute) · 26 controlsAICPA SOC 1 · 25 controlsAICPA SOC 3 · 25 controlsAPRA CPS 234 · 25 controlsAWS Well-Architected Security Pillar · 25 controlsAWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) · 25 controlsAustralia AI Ethics Framework · 25 controlsAustralia NHMRC National Statement on Ethical Conduct in Human Research · 25 controlsAzure Security Benchmark · 25 controlsBCBS 239 · 25 controlsBrazil AI Framework · 25 controlsC5 (Germany) · 25 controlsCAIQ (CSA) · 25 controlsCDP Corporate Questionnaire · 25 controlsCWE Top 25 Most Dangerous Software Weaknesses (2024) · 25 controlsChina AI Regulations · 25 controlsConsumer Data Right (CDR) Framework (Australia) · 25 controlsDORA · 25 controlsECB TIBER-EU · 25 controlsESA ECSS-E-ST-40C — Space Software Engineering Standard · 25 controlsESRB Privacy Certified Programme · 25 controlsEU European Health Data Space (EHDS) · 25 controlsFFIEC IT Examination Handbook · 25 controlsGLBA · 25 controlsHKMA SPM · 25 controlsIATF 16949:2016 — Quality Management System for Automotive Production · 25 controlsIEEE 7000 · 25 controlsISMAP (Japan) · 25 controlsISO 27017 · 25 controlsISO 27018 · 25 controlsISO 8000 — Data Quality · 25 controlsISO/IEC 27010:2015 · 25 controlsItaly Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) · 25 controlsJapan AI Guidelines · 25 controlsMAS TRM · 25 controlsMTCS (Singapore) · 25 controlsNIST SP 800-144 · 25 controlsNIST SP 800-145 · 25 controlsNIST SP 800-146 · 25 controlsNIST SP 800-190 · 25 controlsNRC 10 CFR 73.54 — Nuclear Facility Cybersecurity · 25 controlsOECD AI Principles · 25 controlsOSFI B-13 · 25 controlsOpen Banking Security · 25 controlsPCI P2PE · 25 controlsPCI SSF · 25 controlsPSD2 SCA · 25 controlsSASB Standards (ISSB Integrated) · 25 controlsSWIFT CSCF · 25 controlsSWIFT CSP · 25 controlsSingapore AI Governance Framework · 25 controlsSingapore Protection from Online Falsehoods and Manipulation Act (POFMA, 2019) · 25 controlsTanzania Personal Data Protection Act (Draft) · 25 controlsUK AI Regulation Framework · 25 controlsUK Bribery Act 2010 · 25 controlsUNESCO Recommendation on the Ethics of AI · 25 controlsAPEC Cross-Border Privacy Rules (CBPR) System · 24 controlsAPI 1164 · 24 controlsBIMCO Cyber Security · 24 controlsBrazil Open Finance (Resolução Conjunta No. 1/2020) · 24 controlsC2M2 · 24 controlsCanada Artificial Intelligence and Data Act (AIDA) · 24 controlsCanada ITSG-33 — IT Security Risk Management · 24 controlsCzech Republic Act on Personal Data Processing (Act No. 110/2019 Sb.) · 24 controlsDO-326A · 24 controlsEDM Council DCAM — Data Management Capability Assessment Model · 24 controlsFCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) · 24 controlsFDA 21 CFR Part 11 · 24 controlsHKMA Cyber Resilience Assessment Framework (C-RAF) · 24 controlsIAIS Insurance Core Principles (ICPs) · 24 controlsIEC 62443 · 24 controlsIEEE 1686 · 24 controlsISO 13485 · 24 controlsISO 27019 · 24 controlsISO 27799 · 24 controlsISO/IEC 27004:2016 · 24 controlsISO/IEC 27400:2022 · 24 controlsISO/IEC 38500:2024 — Governance of IT · 24 controlsIllinois Biometric Information Privacy Act (BIPA) · 24 controlsKenya Data Protection Act 2019 · 24 controlsMARS-E · 24 controlsMDS2 (Medical Device) · 24 controlsNIST SP 1800-32 · 24 controlsNIST SP 800-66 · 24 controlsNevada Gaming Control Board Cybersecurity Requirements · 24 controlsNew Zealand Information Security Manual (NZISM) · 24 controlsPAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments · 24 controlsSenegal Law on Personal Data Protection (Law No. 2008-12) · 24 controlsSenge Fifth Discipline — Learning Organization · 24 controlsTSA Pipeline Security · 24 controlsTunisia Organic Law on Personal Data Protection (Law No. 2004-63) · 24 controlsTurkey Personal Data Protection Law (KVKK — Law No. 6698) · 24 controlsUK Building Safety Act 2022 · 24 controlsUK GDPR (UK General Data Protection Regulation) · 24 controlsUS Executive Order 14028 — Improving the Nation's Cybersecurity · 24 controlsWHO Global Competency Model · 24 controlsArmenia Law on Protection of Personal Data (2015) · 23 controlsBarbados Data Protection Act 2019 · 23 controlsChina Cybersecurity Law (CSL) · 23 controlsEU Better Internet for Kids (BIK+) Strategy · 23 controlsEU GMP Annex 11 — Computerised Systems · 23 controlsEU In Vitro Diagnostic Medical Devices Regulation (IVDR) · 23 controlsGreece Law 4624/2019 — Hellenic Data Protection Authority (HDPA) Implementation Act · 23 controlsICAO Annex 17 — Aviation Security (AVSEC) · 23 controlsISO 9001 · 23 controlsISO/IEC 29134:2023 · 23 controlsLithuania Law on Legal Protection of Personal Data (2018) · 23 controlsMorocco Data Protection Law (09-08) · 23 controlsNIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) · 23 controlsSASB Standards · 23 controlsSolvency II · 23 controlsTEFCA — Trusted Exchange Framework and Common Agreement · 23 controlsTrinidad and Tobago Data Protection Act 2011 · 23 controlsUK ONR Cyber Security and Information Assurance (CSIA) for Nuclear Facilities · 23 controlsUNICEF Policy Guidance on AI for Children (2021) · 23 controlsWHO Global Strategy on Digital Health 2020-2025 · 23 controls3GPP Security Architecture (TS 33.501 — 5G Security) · 22 controlsASIC Cyber Resilience Good Practices · 22 controlsASIS SPC.1-2009 — Organizational Resilience Standard · 22 controlsAged Care Quality Standards (Australia) · 22 controlsAustralia My Health Records Act 2012 · 22 controlsEU AI Liability Directive · 22 controlsEU Cyber Solidarity Act (Regulation (EU) 2025/38) · 22 controlsEU ePrivacy Directive (2002/58/EC) · 22 controlsFATF Recommendation 16 — Virtual Asset Travel Rule · 22 controlsFIDO2 and W3C WebAuthn Standard · 22 controlsGhana Data Protection Act 2012 (Act 843) · 22 controlsIACS Unified Requirements E26/E27 — Cyber Resilience of Ships and On-Board Systems · 22 controlsIAEA Nuclear Security Series — Computer Security at Nuclear Facilities (NSS-17-T Rev 1) · 22 controlsICH E6(R2) Good Clinical Practice — Data Integrity and Electronic Systems · 22 controlsIFRS 17 — Insurance Contracts · 22 controlsISO 14064 — Greenhouse Gas Accounting and Verification (Parts 1-3) · 22 controlsISO/IEC 23837 — Security Requirements for Quantum Key Distribution · 22 controlsISO/IEC 27031:2011 · 22 controlsISO/IEC 27557:2022 — Organisational Privacy Risk Management · 22 controlsISO/IEC 30111:2019 · 22 controlsIndia CERT-In Cyber Security Directions 2022 · 22 controlsPCI PIN Security · 22 controlsScience Based Targets initiative (SBTi) Corporate Standard · 22 controlsCCSDS 350.0-G-3 — Space Communications Security (Consultative Committee for Space Data Systems) · 21 controlsCISA Secure by Design Principles · 21 controlsColombia Data Protection Law (Law 1581 of 2012 — SIC Oversight) · 21 controlsDAMA-DMBOK2 — Data Management Body of Knowledge (2nd Edition) · 21 controlsEU Audiovisual Media Services Directive (AVMSD, Directive 2018/1808) · 21 controlsEU Carbon Border Adjustment Mechanism (CBAM) · 21 controlsISO 19650 — Organisation and Digitisation of Information about Buildings and Civil Engineering Works (BIM) · 21 controlsISO 28001:2007 Supply Chain Security Management · 21 controlsISO 37000:2021 · 21 controlsISO/IEC 29115:2023 — Entity Authentication Assurance Framework · 21 controlsKazakhstan Law on Personal Data and Their Protection (No. 94-V) · 21 controlsMARS-E — Minimum Acceptable Risk Standards for Exchanges · 21 controlsMyanmar Cybersecurity Law (2023) · 21 controlsNIST SP 800-82 Rev 3 — Guide to OT Security · 21 controlsNigeria Data Protection Act 2023 (NDPA) · 21 controlsOECD Guidelines for Multinational Enterprises on Responsible Business Conduct (2023 Update) · 21 controlsOnline Safety Act 2021 (Australia) · 21 controlsScience Based Targets Initiative (SBTi) — Net-Zero Standard · 21 controlsUK Defence Standard 05-138 — Cyber Security for Defence Suppliers · 21 controlsUK Open Banking Standard · 21 controlsUS Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements · 21 controlsUS NRC 10 CFR 73.54 — Cyber Security for Nuclear Power Plants · 21 controlsUkraine Law on Personal Data Protection (Law No. 2297-VI) · 21 controlsCNCF Cloud Native Security (Cloud Native Computing Foundation) · 20 controlsCOSO ERM · 20 controlsCOSO Enterprise Risk Management (ERM) Framework (2017) · 20 controlsColorado AI Act (SB 24-205) · 20 controlsEU Data Act · 20 controlsEU Medical Devices Regulation (MDR 2017/745) · 20 controlsEU Taxonomy for Sustainable Activities (Regulation 2020/852) · 20 controlsEU Union Customs Code (UCC) — Data Protection and Security Provisions (Regulation 952/2013) · 20 controlsFlorida Digital Bill of Rights (SB 262) · 20 controlsHITECH Act · 20 controlsIEC 60601-1 — Medical Electrical Equipment Safety · 20 controlsISO 22301 · 20 controlsISO 22316 · 20 controlsISO 22317 · 20 controlsISO 22318 · 20 controlsISO 22320:2018 · 20 controlsISO 27005 · 20 controlsISO 31000 · 20 controlsISO/IEC 29100:2024 · 20 controlsLEADS in a Caring Environment · 20 controlsLEED v4.1 — Green Building Rating System (US Green Building Council) · 20 controlsNATO AQAP 2110 — Quality Assurance Requirements for Design, Development, and Production · 20 controlsNIST SP 800-30 · 20 controlsNIST SP 800-37 · 20 controlsNIST SP 800-39 · 20 controlsPCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) · 20 controlsPrivacy and Other Legislation Amendment Act 2024 (Australia) · 20 controlsRBI Cybersecurity Framework for Banks · 20 controlsSouth Korea ISMS-P · 20 controlsSpace ISAC (Information Sharing and Analysis Center) — Threat Framework · 20 controlsTonga Communications Act (2015) — Privacy & Data Protection · 20 controlsUK FCA/PRA Operational Resilience Framework · 20 controlsUN Guiding Principles on Business and Human Rights (UNGPs) · 20 controlsUS Automated Commercial Environment (ACE) — CBP Trade Data Requirements · 20 controlsUS Children's Online Privacy Protection Act (COPPA) and COPPA 2.0 Proposed Updates · 20 controlsUS Consumer Product Safety Commission (CPSC) — Connected Product Safety · 20 controlsUS Foreign Corrupt Practices Act (FCPA) · 20 controlsUS Section 508 — ICT Accessibility Standards (Revised 2017) · 20 controlsAPRA Prudential Standard CPS 234 — Information Security (Australia) · 19 controlsBS 65000:2014 — Guidance on Organizational Resilience · 19 controlsCroatia Act on Implementation of the GDPR (Official Gazette 42/2018) · 19 controlsDefence Industry Security Program (DISP) · 19 controlsEU Energy Performance of Buildings Directive (EPBD Recast, Directive 2024/1275) · 19 controlsISO 20000-1 · 19 controlsISO 20400:2017 — Sustainable Procurement · 19 controlsISO 22739:2024 — Blockchain and Distributed Ledger Technologies Vocabulary · 19 controlsISO 37301 · 19 controlsISO/IEC 27007:2020 · 19 controlsITIL 4 · 19 controlsJapan FSA Cybersecurity Guidelines for Financial Institutions · 19 controlsPrivacy by Design (PbD) — Seven Foundational Principles · 19 controlsSA8000:2014 — Social Accountability Standard · 19 controlsSANS Incident Handler's Handbook and PICERL Methodology · 19 controlsSwitzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) · 19 controlsAuthorised Economic Operator (AEO) Programmes — Global Standards · 18 controlsBermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct · 18 controlsChina Data Security Law (DSL) · 18 controlsEASA Part-IS — Information Security in Aviation · 18 controlsEN 50126/50128/50129 — Railway RAMS and Safety · 18 controlsEU Code of Conduct for Research Data Management (GDPR Article 40) · 18 controlsEU Web Accessibility Directive (Directive 2016/2102) · 18 controlsGlobal Cross-Border Privacy Rules (Global CBPR) Forum · 18 controlsISO 19011 · 18 controlsISO 30401 · 18 controlsISO 37001 · 18 controlsISO 55001 · 18 controlsISO/IEC 25012:2008 — Data Quality Model · 18 controlsNIST Privacy Framework Version 1.0 · 18 controlsRFC 2350 — Expectations for Computer Security Incident Response (BCP 21) · 18 controlsSection 508 — ICT Accessibility (Revised) · 18 controlsSouth Africa Promotion of Access to Information Act (PAIA) · 18 controlsUK Age Appropriate Design Code (Children's Code) · 18 controlsUNCITRAL Model Law on Electronic Commerce (1996, updated 2005) · 18 controlsUSMCA Chapter 19 — Digital Trade (United States-Mexico-Canada Agreement) · 18 controlsW3C Verifiable Credentials (VC) Data Model 2.0 · 18 controlsASEAN Guide on AI Governance and Ethics · 17 controlsECB TIBER-EU Framework · 17 controlsEU Clinical Trials Regulation (CTR 536/2014) · 17 controlsEU Data Governance Act (DGA) · 17 controlsFIRST CSIRT Services Framework and Standards · 17 controlsICH E6(R3) — Good Clinical Practice · 17 controlsISO/IEC 27050 — Electronic Discovery (Parts 1-4) · 17 controlsISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems · 17 controlsMaslach Burnout Prevention Model · 17 controlsNFPA 1600 — Standard on Continuity, Emergency, and Crisis Management · 17 controlsNIST SP 800-34 Rev 1 — Contingency Planning Guide · 17 controlsOman National Cybersecurity Framework · 17 controlsPIC/S Guide to Good Manufacturing Practice for Medicinal Products · 17 controlsTSA Pipeline Cybersecurity Directives · 17 controlsAPRA SPS 220 Risk Management (Superannuation) · 16 controlsEU Whistleblower Protection Directive (2019/1937) · 16 controlsFSSC 22000 — Food Safety System Certification · 16 controlsGLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6 · 16 controlsICC Incoterms 2020 — International Commercial Terms · 16 controlsKids Online Safety Act (KOSA) · 16 controlsKuwait National Cybersecurity Framework · 16 controlsLloyd's Minimum Standards — Cyber Security · 16 controlsOWASP Top 10:2025 · 16 controlsPEGI — Pan European Game Information Age Rating System · 16 controlsPapua New Guinea National Cybersecurity Policy & Cybercrime Act (2016) · 16 controlsSOC for Cybersecurity — Cybersecurity Risk Management Examination · 16 controlsSingapore Model AI Governance Framework (2nd Edition) · 16 controlsSri Lanka Personal Data Protection Act (No. 9 of 2022) · 16 controlsSweden Data Protection Act (Dataskyddslag, 2018:218) · 16 controlsAzerbaijan Law on Personal Data (2010) · 15 controlsCSA STAR (Security, Trust, Assurance, and Risk) · 15 controlsCritical Infrastructure Risk Management Program (CIRMP) Rules 2023 · 15 controlsEMV 3-D Secure (3DS2) — Payment Authentication Protocol · 15 controlsENISA Privacy Enhancing Technologies (PETs) Guidance · 15 controlsICH Q10 — Pharmaceutical Quality System · 15 controlsIRM Enterprise Risk Management Framework (Institute of Risk Management) · 15 controlsISO 22000 · 15 controlsISO 45001 · 15 controlsNABERS — National Australian Built Environment Rating System · 15 controlsNIST SP 800-124 Rev 2 — Mobile Device Security · 15 controlsSWIFT Customer Security Programme (CSP) · 15 controlsSingapore Cybersecurity Act 2018 · 15 controlsUK Concordat on Open Research Data (UKRI) · 15 controlsAustria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) · 14 controlsBelgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018) · 14 controlsCSRD · 14 controlsCyber Security Act 2024 (Australia) · 14 controlsEDM Council CDMC — Cloud Data Management Capabilities Framework · 14 controlsGRI Standards · 14 controlsIEC 62351 — Power Systems Communication Security · 14 controlsISO 14001 · 14 controlsISSB Standards · 14 controlsITU-T X.805 — Security Architecture for End-to-End Communications · 14 controlsIsrael Protection of Privacy Law (5741-1981) · 14 controlsNigeria Open Banking Regulatory Framework (CBN, 2023) · 14 controlsOECD AI Principles (2024 Update) · 14 controlsPropTech Security Standards — Smart Building Cybersecurity · 14 controlsRegional Comprehensive Economic Partnership (RCEP) — E-Commerce Chapter · 14 controlsResponsible Minerals Initiative (RMI) — Responsible Minerals Assurance Process · 14 controlsSEC Cybersecurity Disclosure Rules · 14 controlsTCFD Recommendations · 14 controlsAustralian Privacy Principles (APPs) · 13 controlsBermuda Personal Information Protection Act 2016 (PIPA) · 13 controlsEquator Principles (EP4, 2020) · 13 controlsGerman Supply Chain Due Diligence Act (LkSG) · 13 controlsHL7 FHIR Security Framework · 13 controlsISAE 3402 — Assurance Reports on Controls at a Service Organisation · 13 controlsNATO Cyber Defence Standards and NCIRC (NATO Computer Incident Response Capability) · 13 controlsNERC CIP · 13 controlsO-RAN Alliance Security Specifications (O-RAN.WG11) · 13 controlsPhilippines Data Privacy Act (RA 10173) · 13 controlsSigstore — Software Artifact Signing and Verification · 13 controlsStudent Privacy Pledge 2020 · 13 controlsArgyris Double-Loop Learning · 12 controlsAustralia IRAP — Information Security Registered Assessors Program · 12 controlsGS1 Global Standards — Supply Chain Traceability and Data Security · 12 controlsIMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2) · 12 controlsIRS Publication 1075 — Tax Information Security Guidelines · 12 controlsITU Radio Regulations and Space Security Standards · 12 controlsIndia Account Aggregator Framework (RBI) · 12 controlsRICS Professional Standards — Data and Technology in Property · 12 controlsRight to Disconnect (Australia) · 12 controlsVUCA Leadership Framework · 12 controlsVirginia Consumer Data Protection Act (VCDPA) · 12 controlsETSI QKD Standards — Quantum Key Distribution (ETSI ISG QKD) · 11 controlsFIDO2 / WebAuthn — Passwordless Authentication Standard · 11 controlsFrench Sapin II Law (Law No. 2016-1691) · 11 controlsHersey & Blanchard Situational Leadership Model · 11 controlsNATO STANAG 4774/4778 — Confidentiality Metadata Labels · 11 controlsNSA CNSA Suite 2.0 — Commercial National Security Algorithm Suite · 11 controlsOwn Risk and Solvency Assessment (ORSA) — NAIC Model Act · 11 controlsSEC Climate Disclosure Rule · 11 controlsICMM Mining Principles (2024 Update) · 10 controlsILO Declaration on Fundamental Principles and Rights at Work (Core Conventions) · 10 controlsLloyd's of London Cyber Insurance Requirements and Underwriting Standards · 10 controlsOWASP API Security Top 10:2023 · 10 controlsOWASP Top 10 for LLM Applications 2025 · 10 controlsEthical Trading Initiative (ETI) Base Code · 9 controlsFair Labor Association (FLA) Workplace Code of Conduct · 9 controlsNSA Quantum-Resistant (QR) Cryptography Migration Guidance · 9 controlsAPRA CPS 220 Risk Management · 8 controlsBSI C5 — Cloud Computing Compliance Criteria Catalogue · 8 controlsKolb Experiential Learning Cycle · 8 controlsKotter 8-Step Change Model · 8 controlsMTCS — Multi-Tier Cloud Security (Singapore) · 4 controlsSamoa Telecommunications Act (2005) — Privacy & Data Protection · 4 controlsHong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) · 3 controlsSarbanes-Oxley Act (SOX)
Frequently Asked Questions
What is the Compliance Intelligence API?▾
A REST and MCP API providing programmatic access to 692 compliance frameworks, 13,700+ controls, and 819,000+ cross-framework control mappings. Query framework details, map controls between standards, run gap analyses, and get coverage reports.
Is there a free tier?▾
Yes. Anonymous access gives you 10 API calls per day with no signup required. Free accounts get 100 calls/month with an API key. Professional plans start at $49/month with 10,000 calls included.
Does it work with AI agents?▾
Yes. The API is available as an MCP (Model Context Protocol) server at api.theartofservice.com/mcp. Add it to Claude Desktop, Cursor, Windsurf, or any MCP client. AI agents can query compliance data directly.
What frameworks are available?▾
692 frameworks including ISO 27001, SOC 2, NIST CSF, GDPR, HIPAA, PCI DSS, CMMC, NIS2, DORA, EU AI Act, and hundreds more. Each framework includes controls, domains, and cross-framework mappings.
Start building with the Compliance API
No signup required for 10 free API calls per day. Create a free account for 100 calls/month.