Scale compliance across Más de 200 marcos, seamlessly with Sprinto AI
Sprinto helps fast-growing teams get certified faster and stay continuously compliant without rebuilding controls as they grow.
Construye una vez. Reutiliza en todas partes.
Framework directory
Sprinto supports standard and custom frameworks. New frameworks plug into what’s already set up — showing only what’s new, not what you’ve already done.
Categorías
-
SOC 2 Compliance Platform | Evidence, Audit Prep & Autonomous Monitoring | Sprinto
SOC 2 helps SaaS and cloud companies prove their security, availability, and confidentiality to customers—often becoming a requirement for mid-market and enterprise deals.
-
ISO 27001 para startups y pymes | Certificación automatizada, sin trabajo manual | Sprinto
ISO 27001 provides a structured, risk-based ISMS that helps organizations standardize security practices and demonstrate compliance across regions and industries.
-
Secure cardholder data and meet payment security standards.
PCI DSS ensures organizations that store, process, or transmit payment card data follow strict controls to reduce fraud and protect sensitive financial information.
-
GDPR – Meet EU data protection requirements with ongoing privacy controls.
GDPR helps organizations protect personal data, manage consent, and demonstrate accountability when handling data of EU residents—reducing regulatory risk and building customer trust.
-
Protect healthcare data and meet U.S. regulatory requirements.
HIPAA sets standards for safeguarding protected health information (PHI) and is essential for healthcare providers, health tech companies, and partners handling sensitive patient data.
-
NIST – A flexible framework for managing cybersecurity risk.
The NIST Cybersecurity Framework helps organizations identify, protect, detect, respond to, and recover from security risks
-
ISO 42001 – A standard for responsible AI management systems.
ISO 42001 helps organizations govern AI systems responsibly by defining controls for risk management, transparency, accountability, and continuous improvement.
-
TISAX – An information security assessment framework for the automotive industry.
TISAX standardizes how automotive companies and suppliers assess and demonstrate information security across complex supply chains.
-
CIS – A prioritized set of cybersecurity best practices.
The CIS Controls help organizations strengthen security hygiene by focusing on the most effective actions to prevent, detect, and respond to common cyber threats.
-
Demonstrate cloud security maturity and transparency.
CSA STAR helps cloud service providers assess, document, and communicate their security posture using the Cloud Controls Matrix and recognized assurance practices.
-
A U.S. regulation governing consumer credit information.
FCRA defines requirements for collecting, using, and protecting consumer credit data, commonly impacting financial services and background screening organizations.
-
A data security standard for regulated environments.
OFDSS focuses on safeguarding sensitive operational and financial data, typically required in region-specific or sector-specific regulatory contexts.
-
Protect consumer privacy rights under California law.
CCPA gives California residents rights over their personal information and requires businesses to manage data collection, sharing, and disclosure practices responsibly.


Obtenga orientación estructurada, herramientas, plantillas y flujos de trabajo prácticos para formalizar, automatizar y hacer crecer su práctica de GRC (Gobierno, Riesgo y Cumplimiento).

Una guía especializada sobre el marco, los requisitos, la preparación para la auditoría y los recursos fundamentales para ayudarle a lograr y gestionar la certificación ISO 27001.

Guías y recursos que abarcan desde controles y criterios hasta seguimiento y preparación para auditorías, diseñados para simplificar el proceso de certificación SOC 2.

La guía definitiva para principiantes sobre los fundamentos de la norma ISO 42001, las mejores prácticas del sector y recursos seleccionados, todo en un mismo lugar.

Una guía práctica para comprender la HIPAA, determinar qué se aplica a su caso y establecer un cumplimiento normativo que resista auditorías reales.
Start with what you need. Scale without friction.
















