Frameworks
The framework catalog with ids, display names, and category.
Noru ships 31 frameworks. Each is either regulatory (a law whose requirements you track) or auditable (a standard you can be assessed against); the distinction changes how controls are verified.
Catalog
| Id | Display name | Category | Notes |
|---|---|---|---|
soc_2 | SOC 2 | auditable | |
iso_27001 | ISO 27001 | auditable | Enabled together with iso_27002; the pair is displayed as ISO 27001 and billed as one framework |
iso_27002 | ISO 27002 | auditable | Hidden in Settings; follows iso_27001 |
iso_27017 | ISO 27017 | auditable | Cloud services controls |
iso_27018 | ISO 27018 | auditable | PII in public clouds |
iso_22301 | ISO 22301 | auditable | Business continuity |
iso_42001 | ISO 42001 | auditable | AI management systems |
gdpr | GDPR | regulatory | Included for every organization |
ccpa | CCPA | regulatory | |
eu_ai_act | EU AI Act | regulatory | |
eu_cyber_resilience_act | EU Cyber Resilience Act | auditable | |
nis2 | NIS2 | auditable | |
dora | DORA (Financial Entities) | auditable | 103 controls |
dora_tpp | DORA (ICT TPP) | auditable | 56 controls; for ICT third-party providers |
dora_ctpp | DORA (Critical ICT TPP) | auditable | 92 controls; for critical ICT third-party providers |
psd2 | PSD2 | auditable | |
nist_cybersecurity | NIST Cybersecurity | auditable | |
cis_v8 | CIS V8 | auditable | Skips the verification phase |
bsi_c5 | BSI C5 | auditable | |
cyber_essentials_uk | Cyber Essentials UK | auditable | |
ens | ENS | auditable | Spain |
mlps | MLPS | auditable | China |
tx_ramp_l1 | TX_RAMP L1 | auditable | Texas |
fedramp_tailored | FedRAMP Tailored | auditable | |
fedramp_moderate | FedRAMP Moderate | auditable | |
hipaa_security | HIPAA Security | auditable | |
irap | IRAP | auditable | Australia |
ismap | ISMAP | auditable | Japan |
mas | MAS | auditable | Singapore |
kfsi | KFSI | auditable | Korea |
pci_dss_4_0 | PCI-DSS 4.0 | auditable | |
svensk_eleg | Svensk e-legitimation | auditable | Sweden |
Categories
| Category | Frameworks | What changes |
|---|---|---|
| regulatory | gdpr, ccpa, eu_ai_act | Requirements are tracked but controls skip the verification phase |
| auditable | Everything else | Controls go through verification; cis_v8 is the exception and also skips it |
Related
Last updated on