OptimaGRC

Regulatory content

Global standards and local regulations. Mapped once.

OptimaGRC is not limited to information-security GRC. Cross-map ISO, NIST, SOC 2, Privacy, financial resilience, Quality, HSE, healthcare, and UAE/GCC sovereign libraries from one control set.

Showing 32 of 32 featured libraries — OptimaGRC maps 140+ in product.

ISO/IEC 27001:2022

High search

Information Security Management System

The international standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).

Global

SOC 2 Type II

High search

AICPA Trust Services Criteria

Independent examination of controls relevant to security, availability, processing integrity, confidentiality, and privacy over a period of time.

Global / North America

NIST CSF 2.0

High search

Cybersecurity Framework

Govern, Identify, Protect, Detect, Respond, Recover — a widely used language for cyber risk that now emphasizes organizational governance.

US / Global

PCI DSS v4.0

High search

Payment Card Industry Data Security Standard

Technical and operational requirements for entities that store, process, or transmit cardholder data.

Global

FedRAMP

Federal Risk and Authorization Management Program

Standardized security assessment, authorization, and continuous monitoring for cloud services used by US federal agencies.

United States

CIS Controls v8

Critical Security Controls

A prioritized set of safeguards for cyber defense, often used as a practical implementation layer under ISO or NIST.

Global

EU GDPR

High search

General Data Protection Regulation

EU law governing personal data processing, lawful bases, data-subject rights, DPIAs, and breach notification.

European Union / Global

UAE PDPL

High search

UAE Personal Data Protection Law

Federal personal-data protection law of the UAE, including controller/processor duties, cross-border transfers, and data-subject rights.

United Arab Emirates

ISO/IEC 27701

Privacy Information Management System

Extension to ISO 27001 for privacy information management covering PII controllers and processors.

Global

CCPA / CPRA

California Consumer Privacy Act

Consumer privacy rights, sale/share of personal information, and transparency duties for businesses in scope.

California, United States

EU DORA

High search

Digital Operational Resilience Act

EU regulation for ICT risk management, incident reporting, resilience testing, and critical third-party oversight in financial entities.

European Union

SOX 404

Sarbanes-Oxley Internal Control over Financial Reporting

Management assessment and auditor attestation of internal control over financial reporting for public companies.

United States

ISO 22301:2019

High search

Business Continuity Management System

Requirements for a business continuity management system covering BIA, strategies, plans, exercises, and continual improvement.

Global

ISO 9001:2015

High search

Quality Management System

The world’s most used quality management standard — context, leadership, planning, support, operation, performance, and improvement.

Global

ISO 13485

Medical Devices Quality Management

QMS requirements for medical device organizations, emphasizing risk, traceability, and regulatory documentation.

Global

ISO 45001:2018

High search

Occupational Health & Safety Management

International standard for occupational health and safety management systems, including hazard identification, participation, and continual improvement.

Global

ISO 14001:2015

High search

Environmental Management System

Requirements for an environmental management system covering aspects, compliance obligations, and environmental performance.

Global

ISO 50001

Energy Management System

Energy management system requirements for energy performance, efficiency, and continual improvement.

Global

ISO 31000

High search

Risk Management Guidelines

Principles, framework, and process for managing risk of any type — the backbone of enterprise risk management beyond cyber.

Global

ISO 37301

Compliance Management Systems

Requirements and guidance for establishing a compliance management system covering culture, obligations, and performance.

Global

COSO ERM / IC

Committee of Sponsoring Organizations Frameworks

Widely used internal control and enterprise risk management frameworks for boards and internal audit.

Global

COBIT

Control Objectives for Information Technologies

ISACA framework for governance and management of enterprise information and technology.

Global

ITIL

IT Infrastructure Library / IT Service Management

Practices for IT service management including incident, change, and service continuity that overlap GRC processes.

Global

HIPAA

High search

Health Insurance Portability and Accountability Act

US rules protecting ePHI privacy and security for covered entities and business associates.

United States

ADHICS

High search

Abu Dhabi Healthcare Information and Cyber Security Standard

Healthcare information and cybersecurity standard applicable to healthcare entities in Abu Dhabi.

Abu Dhabi, UAE

UAE NESA / IAS

High search

UAE Information Assurance Standard

UAE information assurance and critical-infrastructure cybersecurity baseline used across government and CII entities.

United Arab Emirates

Saudi NCA ECC

High search

Essential Cybersecurity Controls

National Cybersecurity Authority essential cybersecurity controls for organizations in the Kingdom of Saudi Arabia.

Saudi Arabia

SAMA CSF

SAMA Cyber Security Framework

Cybersecurity framework issued by the Saudi Central Bank for financial institutions.

Saudi Arabia

EU NIS 2

High search

Network and Information Security Directive 2

EU directive raising cybersecurity risk-management and reporting duties for essential and important entities across many sectors.

European Union

EU CSRD / ESRS

Corporate Sustainability Reporting Directive

EU sustainability reporting regime covering environmental, social, and governance disclosures.

European Union / Global

ISO 19011

Guidelines for Auditing Management Systems

Guidance for auditing management systems — the method behind integrated ISO 9001/14001/45001/27001 audit programs.

Global

ISO 55000

Asset Management

Overview of asset management principles for value from assets — relevant to infrastructure, utilities, and industrial operators.

Global

Govern smarter. Operate stronger. Grow confidently.

See OptimaGRC map your frameworks in one working session.

Bring your ISO, NESA, PDPL, Quality, or HSE scope. We will show control inheritance, live KPIs, and an auditor-ready trail.