One important distinction: some of these are standards/frameworks, while others are laws/regulations. “Contractual” usually means a requirement imposed through a contract rather than by law.
#
Framework / Regulation
Category
What makes it that category?
1
NIST CSF
🏭 Industry Framework
Voluntary cybersecurity framework used to manage cyber risk
2
NIST SP 800-53
🏭 Industry / Government Framework
Control catalogue for security and privacy; widely used in GRC
3
ISO/IEC 27001
🏭 Industry Standard / Framework
International information-security standard; certification is voluntary
4
SOC 2
🤝 Contractual / Assurance Framework
Customer/business-driven assurance requirement; commonly required through contracts or procurement
5
PCI DSS
🤝 Contractual / Industry Standard
Created by the payment-card industry and enforced primarily through agreements with payment networks/acquirers
6
GDPR
⚖️ Regulatory Law
EU law that creates legally binding privacy obligations
7
UK GDPR + Data Protection Act 2018
⚖️ Regulatory Law
Legally binding UK data-protection requirements
8
DORA
⚖️ Regulatory Framework / Law
EU regulation creating legally binding ICT-risk and resilience requirements for financial entities
9
NIS2 Directive
⚖️ Regulatory Framework / Law
EU cybersecurity legislation implemented through national laws
10
EU AI Act
⚖️ Regulatory Law / Framework
EU legislation establishing legally binding AI requirements
Type
Simple meaning
Examples
🏭 Industry Framework/Standard
“Here is a recognized way to manage security.”
NIST CSF, NIST 800-53, ISO 27001
⚖️ Regulatory Law/Framework
“You are legally required to comply.”
GDPR, UK GDPR, DORA, NIS2, EU AI Act
🤝 Contractual / Industry Requirement
“Your customer/business/payment partner requires you to comply.”