Security compliance frameworks define standards for how organizations protect information. Each has slightly different focus; some overlap heavily.
This page covers the major frameworks and the practical work of compliance.
The most-asked-for framework in B2B SaaS. AICPA-developed. Five Trust Service Criteria:
Most companies start with Security only.
Type 1: controls existed at a point in time. Type 2: controls operated effectively over a period (typically 12 months).
Type 2 is what enterprise customers want. Type 1 is sometimes a starting point.
Process: external auditor; ongoing evidence collection; report.
International equivalent of SOC 2. Required by some non-US enterprises.
Defines an Information Security Management System (ISMS). Annex A controls (114 of them) describe specific safeguards.
Process: external auditor; certification; annual surveillance audits; full re-certification every 3 years.
Compared to SOC 2: more prescriptive about specific controls; documentation-heavy; international recognition.
US-government-developed. Voluntary; widely adopted.
Five functions:
Less prescriptive than ISO 27001; useful as an organizing framework.
Common as an organizational tool even when not seeking certification.
US federal cloud authorization. Required for federal customers.
Levels:
Process: extensive; expensive; takes years for new vendors. Worth it for federal market access; not worth it otherwise.
US healthcare data regulation. See CloudComplianceFrameworks.
Payment card industry. See CloudComplianceFrameworks.
EU privacy regulation. See CloudComplianceFrameworks.
Center for Internet Security. Prioritized controls for common security weaknesses.
20 controls organized into Implementation Groups (IG1, IG2, IG3) by maturity.
Useful as a practical checklist independent of certification.
Significant overlap. SOC 2 + ISO 27001 share most controls. NIST CSF organizes; specific frameworks implement.
Mapping tools (Vanta, Drata, Secureframe) show which controls satisfy which frameworks. One control often satisfies multiple frameworks.
For organizations seeking multiple certifications, the marginal cost of adding frameworks decreases — most controls already in place.
Initial certification: 6-12 months for SOC 2 Type 2; longer for ISO.
Maintenance is the larger workload long-term.
External auditor renews the certification. Process:
Compliance platforms (Vanta, Drata, Secureframe) automate most evidence collection.
The controls that show up everywhere:
If you implement these well, you're 80% toward compliance with most frameworks.
The tools that make modern compliance practical:
These integrate with cloud providers, HR systems, identity providers. Continuously check for compliance; collect evidence automatically.
For B2B SaaS pursuing SOC 2, one of these is essentially required to be efficient.
Enterprise customers ask for SOC 2. If they're large enough to matter, you'll get the certification.
Healthcare → HIPAA. Payments → PCI. Government → FedRAMP. Fixed costs of doing business in regulated industries.
Some companies pursue certifications proactively for trust signals. Less driven by specific customer demands.
For B2B SaaS:
For other industries: pursue what's actually required.