Index › 3 › 3GPP SCAS
Click on title for full page
3GPP Security Assurance Specifications define the security requirements and test cases for mobile network functions, forming the technical evaluation basis used by the GSMA NESAS scheme for network equipment product security.
Index › A › ANSSI SecNumCloud
Click on title for full page
SecNumCloud is France's highest-level security qualification for cloud service providers, issued by ANSSI, requiring strict technical controls and digital sovereignty guarantees including immunity from non-European extraterritorial legislation.
Index › B › BSI C5
Click on title for full page
The BSI Cloud Computing Compliance Criteria Catalogue (C5) is Germany's security standard for cloud service providers, defining audit requirements across 17 domains and increasingly mandated for KRITIS operators and the healthcare sector.
Index › B › BSI IT-Grundschutz
Click on title for full page
BSI IT-Grundschutz is Germany's comprehensive, prescriptive methodology for implementing an Information Security Management System, providing detailed building blocks and enabling ISO 27001 certification on the basis of IT-Grundschutz.
Index › C › CIS Benchmarks
Click on title for full page
CIS Benchmarks are consensus-based, prescriptive security configuration guidelines published by the Center for Internet Security for operating systems, cloud platforms, containers, and network devices, widely used as hardening baselines.
Index › D › DISA STIG
Click on title for full page
Defense Information Systems Agency Security Technical Implementation Guides are prescriptive configuration standards mandated for US Department of Defense information systems, defining exact security settings for operating systems, applications, and network devices.
Index › E › E-ITS / ISKE (Estonian Information Security Standard)
Click on title for full page
E-ITS is Estonia's national information security standard, replacing the former ISKE, providing a baseline protection methodology based on BSI IT-Grundschutz and aligned with ISO/IEC 27001 for all organizations performing public duties.
Index › E › ENS (Esquema Nacional de Seguridad)
Click on title for full page
The Esquema Nacional de Seguridad is Spain's mandatory national security framework establishing minimum cybersecurity requirements for public sector information systems and their private-sector service providers, governed by Royal Decree 311/2022.
Index › E › EU Cloud Services Scheme (EUCS)
Click on title for full page
The European Cybersecurity Certification Scheme for Cloud Services is a voluntary EU-wide framework under the Cybersecurity Act, defining assurance levels for cloud service providers operating in the European market.
Index › E › EU Cyber Resilience Act (CRA)
Click on title for full page
The EU Cyber Resilience Act is a mandatory European regulation imposing cybersecurity requirements on all products with digital elements placed on the EU market, covering their entire lifecycle from design to end-of-support.
Index › E › EU Cybersecurity Act (CSA)
Click on title for full page
The EU Cybersecurity Act is the foundational European regulation that established ENISA as a permanent agency and created the EU-wide cybersecurity certification framework for ICT products, services, and processes.
Index › E › EU5G Certification Scheme
Click on title for full page
The EU5G cybersecurity certification scheme is an ENISA-led framework under development to provide EU-wide security assurance for 5G network equipment and components, complementing the EU Toolbox for 5G Security.
Index › E › EUCC (EU Common Criteria)
Click on title for full page
The European Common Criteria-based cybersecurity certification scheme is the first adopted EU-wide certification framework under the Cybersecurity Act, providing a harmonized evaluation methodology for ICT products across all Member States.
Index › F › FedRAMP
Click on title for full page
The Federal Risk and Authorization Management Program is the US government's standardized approach to security assessment and authorization for cloud services, based on NIST 800-53 and mandatory for any cloud product handling federal data.
Index › F › FIPS 140-2 / FIPS 140-3
Click on title for full page
FIPS 140 is the US federal standard for cryptographic module validation, jointly administered by NIST and the Canadian CCCS, mandatory for any cryptographic protection of sensitive government information in the United States and Canada.
Index › G › GSMA NESAS
Click on title for full page
The GSMA Network Equipment Security Assurance Scheme is a voluntary, global industry framework that evaluates telecom vendors' development processes and network products against security baselines defined by 3GPP SCAS specifications.
Index › H › HIPAA
Click on title for full page
The Health Insurance Portability and Accountability Act is a US federal law mandating the protection of individuals' health information, imposing security, privacy, and breach notification requirements on covered entities and their business associates.
Index › I › ISO/IEC 27001
Click on title for full page
ISO/IEC 27001 is the international standard for Information Security Management Systems, specifying requirements for establishing, implementing, maintaining, and continually improving an ISMS, with formal certification through accredited bodies.
Index › K › KRITIS (German Critical Infrastructure)
Click on title for full page
KRITIS is Germany's regulatory framework for the protection of critical infrastructure, combining the NIS2-implementing BSI-Gesetz for cybersecurity with the KRITIS-Dachgesetz for physical resilience, enforced by the BSI and BBK.
Index › N › NIS2 Directive
Click on title for full page
The NIS2 Directive is the EU's revised Network and Information Security legislation mandating cybersecurity risk management, incident reporting, and supply chain security for essential and important entities across 18 critical sectors.
Index › N › NIST 800-53
Click on title for full page
NIST Special Publication 800-53 is the US federal catalog of security and privacy controls for information systems, providing the authoritative control baseline referenced by FedRAMP, FISMA, and numerous international frameworks.
Index › P › PCI-DSS
Click on title for full page
The Payment Card Industry Data Security Standard is a global, mandatory security standard for any organization that stores, processes, or transmits cardholder data, governed by the PCI Security Standards Council and enforced by payment card brands.
Index › S › SOC 2
Click on title for full page
SOC 2 is an auditing framework developed by the AICPA for service organizations, evaluating the design and operational effectiveness of controls across five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Index › V › VSA / VS-NfD (German Classified Information)
Click on title for full page
The Verschlusssachenanweisung (VSA) and VS-NfD-Merkblatt govern the handling of German classified information at the lowest classification level, requiring BSI-approved IT security products, IT-Grundschutz implementation, and mandatory self-accreditation for private-sector contractors.
