Skip to content

Compliance Intelligence API

686 frameworks, 21,696 controls and 311K+ verified cross-framework mappings. REST API and MCP server for AI agents.

Add to Claude Desktop, Cursor, or any MCP client:

{ "mcpServers": { "compliance": { "url": "https://api.theartofservice.com/mcp" } } }

Popular Framework APIs

All 803 Framework APIs

Australian Information Security Manual · 1081 controlsFedRAMP High · 410 controlsFedRAMP Moderate · 323 controlsNIST SP 800-53 Revision 5.1 HIGH · 317 controlsNIST SP 800-53 Rev 5 MODERATE · 275 controlsCloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 · 197 controlsNIST SP 800-161 Rev 1 · 191 controlsNIST SP 800-53 Rev 5 LOW · 173 controlsCSA CCM v4 · 171 controlsISO 39001:2012 - Road Traffic Safety Management · 169 controlsISO 41001:2018 - Facility Management Systems · 168 controlsISO 22313:2020 - Guidance on Business Continuity Management Systems · 167 controlsISO 37002:2021 - Whistleblowing Management Systems · 159 controlsASD Information Security Manual (ISM) · 136 controlsISO 27701:2019 · 136 controlsC5 (Germany) · 121 controlsNIST SP 800-171 Rev 3 · 97 controlsNIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) · 97 controlsISO 27002:2022 · 94 controlsNIST SP 800-171 · 93 controlsISO/IEC 17025:2017 - General Requirements for Testing and Calibration Laboratories · 90 controlsAzure Security Benchmark · 85 controlsISO/IEC 23894:2023 · 85 controlsISO 27018:2019 · 84 controlsISO 13485:2016 · 83 controlsIEC 62443 · 81 controlsISO/IEC 42001:2023 · 80 controls21 CFR Part 211 - Current Good Manufacturing Practice · 78 controlsFFIEC IT Examination Handbook · 78 controlsISO 15189:2022 - Medical Laboratories Requirements for Quality and Competence · 77 controlsISO/IEC 27003:2017 · 72 controlsISO 9001:2015 · 71 controlsISO 22000:2018 · 70 controlsISO 26262:2018 - Functional Safety for Road Vehicles · 69 controlsCOBIT 2019 · 68 controlsSSAE 18 - Attestation Standards (SOC Reporting) · 67 controlsAged Care Quality Standards (Australia) · 66 controlsISO/IEC 38500:2024 · 66 controlsNIST SP 800-66 Rev 2 · 65 controlsAWS Well-Architected Security Pillar · 63 controlsPCI DSS v4.0 · 63 controlsISO 26000:2010 · 60 controlsAPEC Cross-Border Privacy Rules (CBPR) System · 59 controlsColorado Privacy Act (CPA) · 59 controlsISO 37000:2021 · 59 controlsASD Essential Eight Maturity Model · 57 controlsISO 22301:2019 · 57 controlsISO 31000:2018 · 57 controlsISO 30414:2018 - Human Resource Management: Guidelines for Internal and External Human Capital Reporting · 56 controlsISO 45001:2018 · 56 controlsBSI IT-Grundschutz · 55 controlsISO 19011:2018 · 55 controlseIDAS 2.0 - EU Digital Identity Regulation · 55 controlsISO/IEC TR 24028:2020 · 54 controlsITIL 4 · 53 controlsChina Personal Information Protection Law (PIPL) · 52 controlsISO 27043 · 52 controlsISO/IEC 27006:2024 · 52 controlsNIST AI Risk Management Framework (AI RMF 1.0) · 52 controlsNIST SP 800-181 · 52 controlsAASB S2 Climate-related Disclosures · 51 controlsNIST SP 800-207 · 51 controlsISO/SAE 21434 · 50 controlsEgypt Personal Data Protection Law (Law No. 151 of 2020) · 49 controlsFFIEC Cybersecurity Assessment Tool (CAT) · 49 controlsNIST SP 800-160 · 49 controlsPCI SSF · 49 controlsAdministrative Measures for the Security Assessment of Generative AI Services (2023) and Algorithmic Recommendation Management Provisions (2022) · 48 controlsISO 14004:2016 · 48 controlsISO 9001 · 48 controlsNIST SP 800-82 Rev 3 · 48 controlsBREEAM - Building Research Establishment Environmental Assessment Method · 47 controlsIAIS Insurance Core Principles (ICPs) · 47 controlsISO 14001:2015 · 47 controlsISO 37301:2021 · 47 controlsCISA Zero Trust Maturity Model · 46 controlsDAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition) · 46 controlsISO 27019 · 46 controlsISO 27799 · 46 controlsDoD Zero Trust Reference Architecture · 45 controlsISO 27005:2022 · 45 controlsISO 27018 · 45 controlsNIST SP 800-190 · 45 controlsNorth Macedonia Law on Personal Data Protection (2020) · 45 controlsAct on the Implementation of the General Data Protection Regulation (OG 42/2018) · 44 controlsBank Secrecy Act / Anti-Money Laundering (BSA/AML) · 44 controlsBelgium CyberFundamentals · 44 controlsISO 19650 - Organisation and Digitisation of Information about Buildings and Civil Engineering Works (BIM) · 44 controlsISO/IEC 27011:2024 · 44 controlsNIST SP 1800-32 · 44 controlsPCI P2PE · 44 controls3GPP 5G Security Architecture (TS 33.501) · 43 controlsAPRA CPS 230 Operational Risk Management · 43 controlsISO 31000 · 43 controlsISO 37301 · 43 controlsISO/IEC 29134:2023 · 43 controlsPCI PIN Security · 43 controlsSouth Korea Personal Information Protection Act (PIPA) · 43 controlsAS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence · 42 controlsASIS SPC.1-2009 - Organizational Resilience Standard · 42 controlsAuthorised Economic Operator (AEO) Programmes - Global Standards · 42 controlsCISA ICS-CERT Advisories and Industrial Control Systems Security Guidelines · 42 controlsEN 301 549 - Accessibility requirements for ICT products and services · 42 controlsISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3) · 42 controlsISO 27017:2015 · 42 controlsISO 30401 · 42 controlsISO 37001 · 42 controlsISO/IEC 23837 - Security Requirements for Quantum Key Distribution · 42 controlsISO/IEC 38500:2024 - Governance of IT · 42 controlsNIST SP 800-218 · 42 controlsEU NIS2 Directive — Energy Sector Cybersecurity Requirements (Directive 2022/2555) · 41 controlsISO 37001:2016 · 41 controlsISO/IEC 27557:2022 - Organisational Privacy Risk Management · 41 controlsISO/IEC 29115:2023 - Entity Authentication Assurance Framework · 41 controlsAPRA CPS 220 Risk Management · 40 controlsAustralia My Health Records Act 2012 · 40 controlsISO 20400:2017 - Sustainable Procurement · 40 controlsISO 55001 · 40 controlsISO/IEC 29100:2024 · 40 controlsISO/IEC 29147:2018 · 40 controlsSANS Incident Handler's Handbook and PICERL Methodology · 40 controlsSpace ISAC (Information Sharing and Analysis Center) - Threat Framework · 40 controlsAML/CTF Act 2006 (Australia) · 39 controlsBRCGS Global Standard for Food Safety Issue 9 · 39 controlsCFTC System Safeguards (17 CFR 37, 38, 39, 49) · 39 controlsCook Islands Electronic Transactions Act & Privacy Provisions (2003) · 39 controlsISO 22000 · 39 controlsISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary · 39 controlsISO 45001 · 39 controlsISO/IEC 27014:2020 · 39 controlsNIST SP 800-128 · 39 controlsIEC 60601-1 - Medical Electrical Equipment Safety · 38 controlsISO/IEC 27701:2019 · 38 controlsASD Strategies to Mitigate Cyber Security Incidents · 37 controlsASEAN Guide on AI Governance and Ethics · 37 controlsAWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) · 37 controlsEU Taxonomy Regulation (Regulation 2020/852) · 37 controlsISO 22320:2018 · 37 controlsISO 27017 · 37 controlsBSIMM · 36 controlsDigital Services Act (DSA) - Regulation (EU) 2022/2065 · 36 controlsISO 22317 · 36 controlsISO 22318 · 36 controlsISO 28001:2007 Supply Chain Security Management · 36 controlsISO/IEC 25012:2008 - Data Quality Model · 36 controlsUK Cyber Essentials · 36 controlsCISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 · 35 controlsDigital Economy Partnership Agreement (DEPA) · 35 controlsEU Markets in Crypto-Assets Regulation (MiCA, Regulation 2023/1114) · 35 controlsNFPA 1600 - Standard on Continuity, Emergency, and Crisis Management · 35 controlsNIST SP 800-150 · 35 controlsNIST SP 800-171A Rev 3 - Assessing CUI Security Requirements · 35 controlsNIST SP 800-172 · 35 controlsNYDFS Cybersecurity Regulation (23 NYCRR Part 500) · 35 controlsArgentina Law 25.326 (Personal Data Protection Law) · 34 controlsBrunei Personal Data Protection Order 2024 (PDPO) · 34 controlsEASA Part-IS - Information Security in Aviation · 34 controlsIEC 62351 - Power Systems Communication Security · 34 controlsISAE 3402 - Assurance Reports on Controls at a Service Organisation · 34 controlsISO 19011 · 34 controlsISO/IEC 30111:2019 · 34 controlsIllinois Biometric Information Privacy Act (BIPA) · 34 controlsNIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices · 34 controlsNIST SP 800-161 · 34 controlsConsumer Data Right (CDR) Framework (Australia) · 33 controlsEU Pay Transparency Directive (Directive 2023/970) · 33 controlsFBI CJIS Security Policy · 33 controlsIEC 62304:2015 Medical Device Software Lifecycle Processes · 33 controlsISO 22316 · 33 controlsAustralian Energy Sector Cyber Security Framework (AESCSF) · 32 controlsBotswana Data Protection Act (2024) · 32 controlsFTC Safeguards Rule (16 CFR Part 314) · 32 controlsISO/IEC 27018:2019 · 32 controlsISO/IEC 27400:2022 · 32 controlsNIST SP 800-171A — Assessing CUI Security Requirements · 32 controlsNIST SP 800-187 · 32 controlsNIST SP 800-53A · 32 controlsSOC 1 (SSAE 18 / ISAE 3402) · 32 controls21 CFR Part 58 - Good Laboratory Practice (GLP) · 31 controls3GPP Security · 31 controlsAutomotive SPICE (ASPICE) v4.0 - Process Assessment Model · 31 controlsBrazil Open Finance (Resolução Conjunta No. 1/2020) · 31 controlsBrunei Personal Data Protection Order 2022 (PDPO) · 31 controlsCCPA/CPRA · 31 controlsCanadian PIPEDA · 31 controlsCosta Rica Personal Data Protection Law (Law No. 8968) · 31 controlsCôte d'Ivoire Law on Personal Data Protection (Law No. 2013-450) · 31 controlsEU Platform Work Directive (Directive 2024/2831) · 31 controlsNIST SP 800-115 · 31 controlsAPPI · 30 controlsChile Personal Data Protection Law (Law No. 21.719) · 30 controlsEU Audiovisual Media Services Directive (AVMSD, Directive 2010/13/EU as amended by Directive 2018/1808 and Directive (EU) 2023/2586) · 30 controlsEU Clinical Trials Regulation (CTR 536/2014) · 30 controlsISO/IEC 27004:2016 · 30 controlsNIST SP 800-183 · 30 controlsNIST SP 800-53A Rev. 5 · 30 controlsASIC Cyber Resilience Good Practices · 29 controlsArgentina PDPA · 29 controlsBahrain PDPL · 29 controlsBrazil AI Framework · 29 controlsChile DPL · 29 controlsChina PIPL · 29 controlsColombia Habeas Data Law · 29 controlsConnecticut DPA · 29 controlsISO 13485 · 29 controlsISO 27701 · 29 controlsISO 8000 - Data Quality · 29 controlsISO/IEC 27050 - Electronic Discovery (Parts 1-4) · 29 controlsIceland DPA · 29 controlsJamaica DPA · 29 controlsMaryland Online Data Privacy Act · 29 controlsNIST SP 800-88 Rev 1 · 29 controlsNSA Guidance for Transition to Quantum-Resistant Cryptography · 29 controlsNew Hampshire Privacy Act · 29 controlsNew Zealand Privacy Act · 29 controlsNigeria NDPR · 29 controlsNorway PDPA · 29 controlsPIPEDA · 29 controlsUAE PDPL · 29 controlsAPRA SPS 220 Risk Management (Superannuation) · 28 controlsAfrican Union Malabo Convention · 28 controlsBasel III International Banking Framework · 28 controlsColombia Data Protection Law (Law 1581 of 2012) · 28 controlsCustoms-Trade Partnership Against Terrorism (C-TPAT) · 28 controlsEBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07) · 28 controlsENISA Data Protection Engineering - From Theory to Practice · 28 controlsISO/IEC 27007:2020 · 28 controlsISO/IEC 27010:2015 · 28 controlsASEAN Data Management Framework · 27 controlsArgyris Double-Loop Learning · 27 controlsAustralia NHMRC National Statement on Ethical Conduct in Human Research · 27 controlsBermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct · 27 controlsConnecticut Data Privacy Act (CTDPA) · 27 controlsEDM Council DCAM - Data Management Capability Assessment Model · 27 controlsEU Data Act · 27 controlsEU PSD3 and Payment Services Regulation (Proposed) · 27 controlsISO 10005:2005 · 27 controlsISO 20000-1 · 27 controlsISO/IEC 27031:2011 · 27 controlsSSAE 18 SOC 1 — Report on Controls at a Service Organisation (ICFR) · 27 controlsAICPA Privacy Management Framework (PMF) · 26 controlsBIMCO Cyber Security · 26 controlsBS 65000:2014 - Guidance on Organizational Resilience · 26 controlsCanada ITSG-33 - IT Security Risk Management · 26 controlsDORA · 26 controlsEU Chips Act (Regulation (EU) 2023/1781) · 26 controlsEU Digital Markets Act · 26 controlsEU In Vitro Diagnostic Medical Devices Regulation (IVDR) · 26 controlsEU Medical Devices Regulation (MDR 2017/745) · 26 controlsISO 27005 · 26 controlsISO 37000:2021 - Governance of Organizations · 26 controlsMauritius Data Protection Act 2017 · 26 controlsAICPA SOC 1 · 25 controlsCAIQ (CSA) · 25 controlsCDP Corporate Questionnaire · 25 controlsCWE Top 25 Most Dangerous Software Weaknesses (2024) · 25 controlsChina AI Regulations · 25 controlsEIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) · 25 controlsEstonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019) · 25 controlsACSC Essential Eight · 24 controlsAPI 1164 · 24 controlsAPRA CPS 234 · 24 controlsAustralia Consumer Data Right - Banking (CDR) · 24 controlsBermuda Personal Information Protection Act 2016 (PIPA) · 24 controlsBosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011) · 24 controlsCNCF Security Technical Advisory Group (TAG) · 24 controlsCSA STAR (Security, Trust, Assurance, and Risk) · 24 controlsCosta Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP · 24 controlsCzech Republic Act on Personal Data Processing (Act No. 110/2019 Sb.) · 24 controlsEAR - Export Administration Regulations · 24 controlsEU Carbon Border Adjustment Mechanism (CBAM) · 24 controlsEU Cyber Resilience Act · 24 controlsEthiopia Personal Data Protection Proclamation (No. 1321/2024) · 24 controlsKenya Data Protection Act 2019 · 24 controlsNY DFS 23 NYCRR 500 · 24 controlsANSSI Cybersecurity Framework · 23 controlsAngola Personal Data Protection Law (Law No. 22/11) · 23 controlsBarbados Data Protection Act 2019 · 23 controlsMorocco Data Protection Law (09-08) · 23 controls3GPP Security Architecture (TS 33.501 — 5G Security) · 22 controlsAICPA SOC 3 · 22 controlsC2M2 · 22 controlsCIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) · 22 controlsCSRD · 22 controlsCanada's Anti-Spam Legislation (CASL) · 22 controlsCayman Islands Data Protection Act 2017 (DPA) · 22 controlsChina Cybersecurity Law (CSL) · 22 controlsColorado Privacy Act · 22 controlsCritical Raw Materials Act (Proposed Regulation COM(2023) 192) · 22 controlsDISA Security Technical Implementation Guides (STIGs) · 22 controlsDanish Data Protection Act (Databeskyttelsesloven) · 22 controlsData Protection Act 2017 · 22 controlsDirective (EU) 2019/1937 on the protection of persons who report breaches of Union law · 22 controlsDirective (EU) 2023/970 on pay transparency · 22 controlsEMV 3‑D Secure (3DS) - Payment Authentication Protocol · 22 controlsEU General Product Safety Regulation (GPSR, Regulation 2023/988) · 22 controlsEU Markets in Crypto-Assets Regulation (MiCA) · 22 controlsFIDO2 and W3C WebAuthn Standard · 22 controlsICH E6(R2) Good Clinical Practice — Data Integrity and Electronic Systems · 22 controlsBelgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018) · 21 controlsCISA Secure by Design Principles · 21 controlsCOPPA · 21 controlsChina Data Security Law (DSL) · 21 controlsColombia Data Protection Law (Law 1581 of 2012 — SIC Oversight) · 21 controlsCzech Republic Act on the Protection of Personal Data (Act No. 110/2019 Coll.) · 21 controlsDefence Security Principles Framework (DSPF) · 21 controlsEU Energy Performance of Buildings Directive (EPBD Recast) - Directive (EU) 2024/1275 · 21 controlsEU European Media Freedom Act (EMFA) · 21 controlsISO 55001:2014 · 21 controlsNIST SP 800-82 Rev 3 — Guide to OT Security · 21 controlsOnline Safety Act 2021 (Australia) · 21 controls6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673) - superseded by AMLD7 · 20 controlsAlbania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) · 20 controlsCNCF Cloud Native Security (Cloud Native Computing Foundation) · 20 controlsCOSO ERM · 20 controlsCOSO Enterprise Risk Management (ERM) Framework (2017) · 20 controlsCambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134) · 20 controlsCanada Artificial Intelligence and Data Act (AIDA) · 20 controlsCode of Conduct on Data Protection for Research (GDPR Article 40) · 20 controlsColorado AI Act (SB 24-205) · 20 controlsECB TIBER-EU Framework · 20 controlsESRB Privacy Certified · 20 controlsEU Better Internet for Kids (BIK+) Strategy · 20 controlsEU Machinery Regulation (Regulation (EU) 2023/1230) · 20 controlsEU Taxonomy for Sustainable Activities (Regulation 2020/852) · 20 controlsEU Union Customs Code (UCC) — Data Protection and Security Provisions (Regulation 952/2013) · 20 controlsFlorida Digital Bill of Rights (SB 262) · 20 controlsISO 22301 · 20 controlsAPRA Prudential Standard CPS 234 — Information Security (Australia) · 19 controlsColorado Artificial Intelligence Act (proposed SB 24-205) · 19 controlsCroatia Act on Implementation of the GDPR (Official Gazette 42/2018) · 19 controlsEU Data Governance Act (DGA) · 19 controlsEU Payment Services Directive (PSD2) · 19 controlsIACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems · 19 controlsArmenia Law on Protection of Personal Data (2015) · 18 controlsAustralia eSafety Commissioner - Online Safety Expectations for Industry · 18 controlsData (Use and Access) Act 2025 · 18 controlsDefence Industry Security Program (DISP) · 18 controlsEU AI Liability Directive · 18 controlsEU Cyber Solidarity Act (Regulation (EU) 2025/38) · 18 controlsEU Product Liability Directive (Directive (EU) 2024/2853) · 18 controlsEU SFDR (Sustainable Finance Disclosure Regulation) · 18 controlsISO 10006:2003 · 18 controlsAnnex 11 to EU GMP - Computerised Systems · 17 controlsCCSDS 350.0-G-3 - Space Communications Security (Consultative Committee for Space Data Systems) · 17 controlsCMMC 2.0 Level 1 · 17 controlsCook Islands Electronic Transactions Act 2003 · 17 controlsCyber Security Act 2024 (Australia) · 17 controlsEU Network Code on Cybersecurity for the Electricity Sector · 17 controlsEU Seveso III Directive (Directive 2012/18/EU) · 17 controlsISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems · 17 controlsJamaica Data Protection Act 2020 · 17 controlsMaslach Burnout Prevention Model · 17 controlsNIST SP 800-34 Rev 1 — Contingency Planning Guide · 17 controlsAustralia IRAP - Information Security Registered Assessors Program · 16 controlsCISA Industrial Control Systems (ICS) Security Guidance · 16 controlsEU Taxonomy Regulation · 16 controlsEU Whistleblower Protection Directive (2019/1937) · 16 controlsEuropean Accessibility Act (Directive (EU) 2019/882) · 16 controlsFATF 40 Recommendations · 16 controlsFIDO2 / WebAuthn · 16 controlsAustralia Online Safety Act 2021 · 15 controlsAzerbaijan Law on Personal Data (2010) · 15 controlsETSI EN 303 645 · 15 controlsEU ePrivacy Directive (2002/58/EC) · 15 controlsExtractive Industries Transparency Initiative (EITI) Standard (2023) · 15 controlsFAA Cybersecurity Framework for Aviation · 15 controlsFamily Educational Rights and Privacy Act (FERPA) · 15 controlsISO 14001 · 15 controlsNIST SP 800-124 Rev 2 — Mobile Device Security · 15 controlsAustria Data Protection Act (Datenschutzgesetz, DSG, amended 2018) · 14 controlsBCBS 239 · 14 controlsCommercial National Security Algorithm Suite (CNSA) 2.0 · 14 controlsEDM Council CDMC - Cloud Data Management Capability Framework · 14 controlsEU Web Accessibility Directive (Directive 2016/2102) · 14 controlsFrench Sapin II Law (Law No. 2016-1691) · 14 controlsOECD AI Principles (2024 Update) · 14 controlsOWASP ASVS · 14 controlsAustralian Privacy Principles (APPs) · 13 controlsCDP (formerly Carbon Disclosure Project) · 13 controlsFATF Recommendation 16 - Virtual Asset Travel Rule · 13 controlsFCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) · 13 controlsFDA 21 CFR Part 11 · 13 controlsFDA Quality Management System Regulation (QMSR) · 13 controlsFair Labor Association (FLA) Workplace Code of Conduct · 13 controlsGS1 Global Standards - Supply Chain Traceability and Data Security · 13 controlsHong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) · 13 controlsITU-T X.805 - Security Architecture for End-to-End Communications · 13 controlsJapan AI Guidelines · 13 controlsNATO Cyber Defence Standards and NCIRC (NATO Computer Incident Response Capability) · 13 controlsO-RAN Alliance Security Specifications (O-RAN.WG11) · 13 controlsC-TPAT - Customs-Trade Partnership Against Terrorism · 12 controlsDFARS 252.204-7012 - Safeguarding Covered Defense Information · 12 controlsFIRST CSIRT Services Framework and Standards · 12 controlsFISMA · 12 controlsFedRAMP Rev 5 · 12 controlsFederal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) · 12 controlsGHG Protocol · 12 controlsGLBA · 12 controlsGLI-33 - Gaming Laboratories International Event Wagering Systems · 12 controlsGLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6 · 12 controlsGRI Standards · 12 controlsGhana Cybersecurity Act · 12 controlsGhana Data Protection Act 2012 (Act 843) · 12 controlsGlobal Cross-Border Privacy Rules (Global CBPR) Forum · 12 controlsGoleman Emotional Intelligence Leadership Framework · 12 controlsGreece Law 4624/2019 - Hellenic Data Protection Authority (HDPA) Implementation Act · 12 controlsHeifetz Adaptive Leadership Framework · 12 controlsICN Leadership for Change Programme · 12 controlsIRS Publication 1075 — Tax Information Security Guidelines · 12 controlsCritical Infrastructure Risk Management Program (CIRMP) Rules 2023 · 11 controlsEU NIS2 Directive - Transport Sector Requirements · 11 controlsFSSC 22000 - Food Safety System Certification · 11 controlsFTC GLBA Safeguards Rule (16 CFR Part 314) · 11 controlsFTC Health Breach Notification Rule · 11 controlsFinland Data Protection Act (Tietosuojalaki, 1050/2018) · 11 controlsGAMP 5 - Good Automated Manufacturing Practice · 11 controlsGeorgia Law on Personal Data Protection (2012) · 11 controlsGerman Supply Chain Due Diligence Act (LkSG) · 11 controlsHITECH Act · 11 controlsHKMA Cyber Resilience Assessment Framework (C-RAF) · 11 controlsHKMA SPM · 11 controlsHersey & Blanchard Situational Leadership Model · 11 controlsIAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) · 11 controlsISO 10007:2017 · 11 controlsJapan FSA Cybersecurity Guidelines for Financial Institutions · 11 controlsNATO STANAG 4774/4778 Confidentiality Metadata Labels · 11 controlsNSA CNSA Suite 2.0 — Commercial National Security Algorithm Suite · 11 controlsECSS-E-ST-40C: Space Engineering - Software · 10 controlsEquator Principles (EP4, 2020) · 10 controlsFull Range Leadership Model (Bass & Avolio) · 10 controlsHungary Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act) · 10 controlsIATF 16949:2016 - Quality Management System for Automotive Production · 10 controlsICAO Annex 17 - Aviation Security (AVSEC) · 10 controlsIndonesia PDP Law · 10 controlsOWASP Top 10:2025 · 10 controlsEthical Trading Initiative (ETI) Base Code · 9 controlsIATA Operational Safety Audit (IOSA) Standards Manual · 9 controlsICH E6(R3) - Good Clinical Practice · 9 controlsIEEE 7000 · 9 controlsISSB Standards · 9 controlsNSA Quantum-Resistant (QR) Cryptography Migration Guidance · 9 controlsPIC/S Guide to Good Manufacturing Practice for Medicinal Products · 9 controlsAustralia AI Ethics Framework · 8 controlsBSI C5 — Cloud Computing Compliance Criteria Catalogue · 8 controlsDelaware Online Privacy and Protection Act (proposed) · 8 controlsHKMA TM-G-1 · 8 controlsICC Incoterms 2020 - International Commercial Terms · 8 controlsICMM Mining Principles (2024 Update) · 8 controlsIFRS 17 - Insurance Contracts · 8 controlsILO Declaration on Fundamental Principles and Rights at Work (Core Conventions) · 8 controlsILO Nursing Personnel Convention C149 (1977) · 8 controlsILO Tripartite Declaration of Principles concerning Multinational Enterprises (MNE Declaration) · 8 controlsIMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2) · 8 controlsIRS Publication 1075 · 8 controlsISMAP (Japan) · 8 controlsITAR - International Traffic in Arms Regulations · 8 controlsITU Radio Regulations and Space Security Standards · 8 controlsIceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) · 8 controlsIndia Account Aggregator Framework (RBI) · 8 controlsIndia CERT-In Cyber Security Directions 2022 · 8 controlsIndia DPDP Act · 8 controlsIndiana Consumer Data Protection Act · 8 controlsIowa Consumer Data Protection Act · 8 controlsItaly Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) · 8 controlsJapan Act on Specified Commercial Transactions (ASCT) - Digital Services · 8 controlsJordan Draft Personal Data Protection Law (2022) · 8 controlsKazakhstan Law on Personal Data and Their Protection (No. 94-V) · 8 controlsKentucky Consumer Data Protection Act · 8 controlsKenya Data Protection Act · 8 controlsKids Online Safety Act (KOSA) · 8 controlsKolb Experiential Learning Cycle · 8 controlsKotter 8-Step Change Model · 8 controlsKuwait Data Privacy Protection Regulation (KDPPR, 2021 - CMA Directive) · 8 controlsLEED v4.1 - Green Building Rating System (US Green Building Council) · 8 controlsLGPD · 8 controlsLaos Law on Prevention and Combating Cybercrime (2015) · 8 controlsLatvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018) · 8 controlsLaw No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data · 8 controlsLaw No. 172-13 on the Protection of Personal Data · 8 controlsLaw No. 2013-450 of 19 June 2013 on the Protection of Personal Data · 8 controlsLaw on Personal Data Protection (Official Gazette No. 42/2020) · 8 controlsLebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018) · 8 controlsLey Orgánica de Protección de Datos Personales (LOPDP) · 8 controlsLiechtenstein DPA · 8 controlsLithuania Law on Legal Protection of Personal Data (2018) · 8 controlsLloyd's Minimum Standards - Cyber Security · 8 controlsLloyd's of London Cyber Insurance Requirements and Underwriting Standards · 8 controlsLuxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation) · 8 controlsMARS-E · 8 controlsMDS2 (Medical Device) · 8 controlsMITRE ATT&CK · 8 controlsMITRE D3FEND · 8 controlsMTCS (Singapore) · 8 controlsMalaysia PDPA 2010 · 8 controlsMalta Data Protection Act (Cap. 586, 2018) · 8 controlsMaryland Online Data Privacy Act of 2024 · 8 controlsMaslach Burnout Inventory (MBI) and Areas of Worklife Survey (AWS) Model · 8 controlsMauritius DPA · 8 controlsMexico LFPDPPP · 8 controlsMiFID II / MiFIR · 8 controlsMinnesota Consumer Data Privacy Act · 8 controlsModern Slavery Act 2018 (Australia) · 8 controlsMonetary Authority of Singapore Technology Risk Management Guidelines · 8 controlsMontana Consumer Data Privacy Act · 8 controlsMontenegro Law on Personal Data Protection (2023) · 8 controlsMyanmar Cybersecurity Law (2023) · 8 controlsNABERS - National Australian Built Environment Rating System · 8 controlsNAIC Insurance Data Security Model Law (MDL-668) · 8 controlsNATO AQAP 2110 - Quality Assurance Requirements for Design, Development, and Production · 8 controlsNATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) · 8 controlsNATO STANAG 4774 (Confidentiality Metadata Labels) and STANAG 4778 (Metadata Binding) · 8 controlsNERC CIP · 8 controlsNHS Healthcare Leadership Model · 8 controlsNIS2 Directive Implementing Acts · 8 controlsNIST AI 600-1: Generative AI Profile · 8 controlsNIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) · 8 controlsNIST Privacy Framework · 8 controlsNIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) · 8 controlsNIST SP 800-122 · 8 controlsNIST SP 800-123 · 8 controlsNIST SP 800-137 · 8 controlsNIST SP 800-144 · 8 controlsNIST SP 800-145 · 8 controlsNIST SP 800-146 · 8 controlsNIST SP 800-30 · 8 controlsNIST SP 800-37 · 8 controlsNIST SP 800-39 · 8 controlsNIST SP 800-61 · 8 controlsNIST SP 800-63 Digital Identity Guidelines · 8 controlsNIST SP 800-63-4 · 8 controlsNIST SP 800-66 · 8 controlsNIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security · 8 controlsNIST SP 800-88 · 8 controlsNIST SP 800-92 · 8 controlsNIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems · 8 controlsNRC 10 CFR 73.54 - Nuclear Facility Cybersecurity · 8 controlsNRF Cybersecurity and Data Privacy Framework (National Retail Federation) · 8 controlsNebraska Data Privacy Act · 8 controlsNetherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018) · 8 controlsNevada Gaming Control Board Cybersecurity Requirements · 8 controlsNew Hampshire Data Privacy Act · 8 controlsNew Jersey Data Privacy Act · 8 controlsNew Zealand Information Security Manual (NZISM) · 8 controlsNigeria Data Protection Act 2023 (NDPA) · 8 controlsNigeria Data Protection Regulation (NDPR) · 8 controlsNigeria Open Banking Regulatory Framework (CBN, 2023) · 8 controlsNotifiable Data Breaches Scheme (Australia) · 8 controlsO-RAN WG11 Security Specification · 8 controlsOCC Heightened Standards (12 CFR Part 30, Appendix D) · 8 controlsOECD AI Principles · 8 controlsOECD Guidelines for Multinational Enterprises on Responsible Business Conduct (2023 Update) · 8 controlsOECD Recommendation on Artificial Intelligence (2024 Update) · 8 controlsOECD/G20 Principles of Corporate Governance · 8 controlsOSFI B-13 · 8 controlsOWASP API Security Top 10 - 2023 · 8 controlsOWASP MASVS · 8 controlsOWASP Top 10 for LLM Applications 2025 · 8 controlsOman National Cybersecurity Framework · 8 controlsOman Personal Data Protection Law (Royal Decree 6/2022) · 8 controlsOntario Accessibility for Ontarians with Disabilities Act (AODA) - IASR Web Standard · 8 controlsOpen Banking Security · 8 controlsOpenSSF Scorecard · 8 controlsOregon Consumer Privacy Act · 8 controlsPCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR) · 8 controlsPDPA Singapore · 8 controlsPOPIA · 8 controlsPakistan Personal Data Protection Bill 2023 · 8 controlsPanama Law on Personal Data Protection (Law No. 81 of 2019) · 8 controlsParaguay Law on Protection of Personal Data (Law No. 6534/2020) · 8 controlsPersonal Data Act (personopplysningsloven) · 8 controlsPeru DPL · 8 controlsPhilippines Data Privacy Act · 8 controlsPoland Act on Personal Data Protection (Ustawa o ochronie danych osobowych, 2018) · 8 controlsPortugal Law No. 58/2019 - Data Protection Implementation Act · 8 controlsPrivacy Act 1988 (Australia) · 8 controlsPrivacy Act 2020 · 8 controlsPrivacy and Other Legislation Amendment Act 2024 (Australia) · 8 controlsQatar DPL · 8 controlsRBI Cybersecurity Framework for Banks · 8 controlsRomania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) · 8 controlsRwanda DPL · 8 controlsSouth Korea PIPA · 8 controlsSwitzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) · 8 controlsTaiwan PDPA · 8 controlsETSI Industry Specification Group (ISG) on Quantum Key Distribution (QKD) · 7 controlsFiji Data Protection Bill (2020) · 7 controlsHL7 FHIR Security Framework · 7 controlsIEEE 1686 · 7 controlsIRM Enterprise Risk Management Framework (Institute of Risk Management) · 7 controlsPrivacy by Design (PbD) - Seven Foundational Principles · 7 controlsSA8000:2014 - Social Accountability Standard · 7 controlsCalifornia IoT Security Law · 6 controlsICH Q10 - Pharmaceutical Quality System · 6 controlsOWASP DevSecOps Maturity Model (DSOMM) · 6 controlsPAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments · 6 controlsPapua New Guinea National Cybersecurity Policy & Cybercrime Act (2016) · 6 controlsPhilippines Cybercrime Prevention Act (RA 10175) · 6 controlsProposal for a Directive on improving working conditions in platform work (COM(2023) 491) · 6 controlsSingapore MAS TRM Guidelines · 6 controlsUK GDPR (UK General Data Protection Regulation) · 6 controlsUS Children's Online Privacy Protection Act (COPPA) and COPPA 2.0 Proposed Updates · 6 controlsUruguay DPL · 6 controlsVietnam PDPD · 6 controlsWashington My Health My Data Act (MHMD) · 6 controlsLEADS in a Caring Environment · 5 controlsOWASP SAMM · 5 controlsPropTech Security Standards - Smart Building Cybersecurity · 5 controlsProtection of Privacy Law (1981) · 5 controlsSOX 404 / ICFR · 5 controlsSaudi NCA ECC · 5 controlsSingapore Government Instruction Manual on ICT&SS Management (IM8) · 5 controlsSpain ENS · 5 controlsSri Lanka Personal Data Protection Act (No. 9 of 2022) · 5 controlsThe Leadership Challenge (Kouzes & Posner) · 5 controlsTrinidad and Tobago Data Protection Act 2011 · 5 controlsUK AI Regulation Framework · 5 controlsUK Age Appropriate Design Code (Children's Code) · 5 controlsUK FCA/PRA Operational Resilience Framework · 5 controlsUS Executive Order 14028 - Improving the Nation's Cybersecurity · 5 controlsUS NRC 10 CFR 73.54 - Cyber Security for Nuclear Power Plants · 5 controlsWCAG 2.2 · 5 controlsWCO Authorised Economic Operator (AEO) Framework · 5 controlsZambia Data Protection Act (2021) · 5 controlsOwn Risk and Solvency Assessment (ORSA) - NAIC Model Act · 4 controlsPEGI - Pan European Game Information Age Rating System · 4 controlsRFC 2350 - Expectations for Computer Security Incident Response (BCP 21) · 4 controlsRegulation (EU) 2019/1239 on the Maritime Single Window (MSW) · 4 controlsRegulation (EU) 2023/1115 on deforestation-free supply chains · 4 controlsRight to Disconnect (Australia) · 4 controlsSEC Cybersecurity Disclosure Rule · 4 controlsSSDF (NIST) · 4 controlsSpain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) · 4 controlsStudent Privacy Pledge 2020 · 4 controlsSweden Data Protection Act (Dataskyddslag, 2018:218) · 4 controlsTonga Communications Act (2015) - Privacy & Data Protection · 4 controlsUK NCSC Cyber Assessment Framework · 4 controlsUK ONR Cyber Security and Information Assurance (CSIA) for Nuclear Facilities · 4 controlsUNECE WP.29 R155 · 4 controlsUNECE WP.29 R156 · 4 controlsUnion Customs Code (UCC) - Regulation (EU) No 952/2013 · 4 controlsVietnam Law on Cybersecurity (No. 24/2018/QH14) · 4 controlsW3C Verifiable Credentials (VC) Data Model 2.0 · 4 controlsISO/IEC 17050-2:2004 · 3 controlsMARS-E - Minimum Acceptable Risk Standards for Exchanges · 3 controlsUNCITRAL Model Law on Electronic Commerce (1996, updated 2005) · 3 controlsISO/IEC 17050-1:2004 · 1 controlsAS9100D - Aerospace Quality Management SystemCOSO Internal Control - Integrated Framework (2013)Cyber Essentials PlusDO-178C / ED-12C - Software Considerations in Airborne SystemsDO-326A / ED-202AEN 50126 / EN 50128 / EN 50129 - Railway Applications RAMSFERPAFIDO2 / WebAuthn — Passwordless Authentication StandardFlorida Digital Bill of Rights (FDBR)ISO 50001:2018 - Energy Management SystemsISO 56002ISO/IEC 17025:2017 - General Requirements for Testing and CalibrationIsrael Protection of Privacy Law (5741-1981)Kenya DPAKuwait National Cybersecurity FrameworkMAS TRMMTCS - Multi-Tier Cloud Security (Singapore)NAIC MDL-668NIST Privacy Framework 1.0NIST Privacy Framework Version 1.0NIST SP 800-63Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA)PDPA ThailandPSD2 SCAPTESPeru Personal Data Protection Law (Law No. 29733)Philippines DPAPhilippines Data Privacy Act (RA 10173)Protective Security Policy Framework (PSPF) Release 2024Qatar Personal Data Privacy Protection Law (Law No. 13 of 2016)RICS Professional Standards - Data and Technology in PropertyRegional Comprehensive Economic Partnership (RCEP) - E-Commerce ChapterRegulation on the European Health Data Space (EHDS)Responsible Minerals Initiative (RMI) - Responsible Minerals Assurance ProcessRhode Island Data Transparency and Privacy Protection Act (RIDTPPA)Russia FZ-152Russia Federal Law on Personal Data (152-FZ)Rwanda Law No. 058/2021 Relating to the Protection of Personal DataSASB StandardsSASB Standards (ISSB Integrated)SEC Climate Disclosure RuleSEC Cybersecurity Disclosure RulesSIG (Shared Assessments)SLSASOC for Cybersecurity - Cybersecurity Risk Management ExaminationSQF Code Edition 9 - Safe Quality FoodSWIFT CSCFSWIFT CSCF v2024SWIFT CSPSWIFT Customer Security Programme (CSP)Samoa Telecommunications Act (2005) - Privacy & Data ProtectionSarbanes-Oxley Act (SOX)Saudi Arabia PDPLSaudi PDPLScience Based Targets Initiative (SBTi) - Net-Zero StandardScience Based Targets initiative (SBTi) Corporate StandardSection 508 - ICT Accessibility (Revised)Secure by Design: A Guide for Manufacturers (CISA)Security of Critical Infrastructure Act 2018 (SOCI)Senegal Law on Personal Data Protection (Law No. 2008-12)Senge Fifth Discipline - Learning OrganizationSerbia Law on Personal Data Protection (2018)Sigstore - Software Artifact Signing and VerificationSingapore AI Governance FrameworkSingapore Cybersecurity Act 2018Singapore Model AI Governance Framework (2nd Edition)Singapore PDPASingapore Payment Services Act (PSA) - Digital Payment Token RegulationSingapore Payment Services Act 2019 (PSA) - Digital Payment Token ProvisionsSingapore Protection from Online Falsehoods and Manipulation Act (POFMA, 2019)Solvency IISouth Africa Promotion of Access to Information Act (PAIA)South African POPIASouth Korea Cloud Security Assurance Program (CSAP)South Korea Credit Information ActSouth Korea ISMS-PSouth Korea Korea Internet Self-Governance Organisation (KISO) Code of EthicsSwitzerland FADPTCFD RecommendationsTEFCA - Trusted Exchange Framework and Common AgreementTISAX - Trusted Information Security Assessment ExchangeTNFD RecommendationsTSA Pipeline Cybersecurity DirectivesTSA Pipeline SecurityTanzania Personal Data Protection Act (Draft)Telecommunications Sector Security Reforms (TSSR)Tennessee IPATennessee Information Protection Act (TIPA)Texas Data Privacy ActTexas TDPSAThailand PDPATunisia Organic Law on Personal Data Protection (Law No. 2004-63)Turkey KVKKTurkey Personal Data Protection Law (KVKK - Law No. 6698)UAE Virtual Asset Regulatory Authority (VARA) RegulationsUK Bribery Act 2010UK Building Safety Act 2022UK Concordat on Open Research Data (UKRI)UK Construction (Design and Management) Regulations 2015 (CDM 2015)UK Data Protection Act 2018UK Data Protection Act 2018 + UK GDPRUK Defence Standard 05-138 - Cyber Security for Defence SuppliersUK Gambling Commission - Cyber Resilience RequirementsUK Modern Slavery Act 2015UK Online Safety Act 2023UK Open Banking StandardUK PSTI ActUK Product Security and Telecommunications Infrastructure Act (PSTI)UK Security and Emergency Measures Direction (SEMD) - Water IndustryUK Telecommunications (Security) Act 2021UN Guiding Principles on Business and Human Rights (UNGPs)UNESCO Recommendation on the Ethics of AIUNICEF Policy Guidance on AI for Children (2021)US Americans with Disabilities Act (ADA) - Title III Digital AccessibilityUS Automated Commercial Environment (ACE) - CBP Trade Data RequirementsUS Consumer Product Safety Commission (CPSC) - Connected Product SafetyUS EPA Safe Drinking Water Act (SDWA) - Cybersecurity RequirementsUS Foreign Corrupt Practices Act (FCPA)US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards RuleUS ITAR and EAR - Export Control and Data SecurityUS Maritime Transportation Security Act (MTSA) and USCG Cybersecurity RequirementsUS OFAC Sanctions Compliance FrameworkUS SEC Digital Assets and Crypto Regulatory FrameworkUS Section 508 - ICT Accessibility Standards (Revised 2017)USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)Uganda Data Protection and Privacy Act (2019)Ukraine Law on Personal Data Protection (Law No. 2297-VI)Uruguay Personal Data Protection Act (Law No. 18.331)Utah Consumer Privacy ActUtah Consumer Privacy Act (UCPA)Uzbekistan Law on Personal Data (No. ZRU-547)VUCA Leadership FrameworkVermont Artificial Intelligence and Consumer Data Act (AICDA)Vietnam PDPL (Decree 13)Virginia CDPAVirginia Consumer Data Protection Act (VCDPA)Virginia VCDPAVoluntary Principles on Security and Human Rights (VPs)WCO SAFE Framework of Standards to Secure and Facilitate Global Trade (2021)WELL Building Standard v2 (International WELL Building Institute)WHO Global Competency ModelWHO Global Strategy on Digital Health 2020-2025Wisconsin Data Privacy Act (SB 670)Zimbabwe Data Protection Act (2021)

Frequently Asked Questions

What is the Compliance Intelligence API?
A REST and MCP API providing programmatic access to 686 compliance frameworks, 21,696 controls, and 311K+ verified cross-framework control mappings. Query framework details, map controls between standards, run gap analyses, and get coverage reports.
Is there a free tier?
Yes. Anonymous access gives you 10 API calls per day with no signup required. Free accounts get 100 calls/month with an API key. Professional plans start at $149/month with 10,000 calls included.
Does it work with AI agents?
Yes. The API is available as an MCP (Model Context Protocol) server at api.theartofservice.com/mcp. Add it to Claude Desktop, Cursor, Windsurf, or any MCP client. AI agents can query compliance data directly.
What frameworks are available?
686 frameworks including ISO 27001, SOC 2, NIST CSF, GDPR, HIPAA, PCI DSS, CMMC, NIS2, DORA, EU AI Act, and hundreds more. Each framework includes controls, domains, and cross-framework mappings.

Start building with the Compliance API

No signup required for 10 free API calls per day. Create a free account for 100 calls/month.