The difference

One important distinction: some of these are standards/frameworks, while others are laws/regulations. “Contractual” usually means a requirement imposed through a contract rather than by law.

#Framework / RegulationCategoryWhat makes it that category?
1NIST CSF🏭 Industry FrameworkVoluntary cybersecurity framework used to manage cyber risk
2NIST SP 800-53🏭 Industry / Government FrameworkControl catalogue for security and privacy; widely used in GRC
3ISO/IEC 27001🏭 Industry Standard / FrameworkInternational information-security standard; certification is voluntary
4SOC 2🤝 Contractual / Assurance FrameworkCustomer/business-driven assurance requirement; commonly required through contracts or procurement
5PCI DSS🤝 Contractual / Industry StandardCreated by the payment-card industry and enforced primarily through agreements with payment networks/acquirers
6GDPR⚖️ Regulatory LawEU law that creates legally binding privacy obligations
7UK GDPR + Data Protection Act 2018⚖️ Regulatory LawLegally binding UK data-protection requirements
8DORA⚖️ Regulatory Framework / LawEU regulation creating legally binding ICT-risk and resilience requirements for financial entities
9NIS2 Directive⚖️ Regulatory Framework / LawEU cybersecurity legislation implemented through national laws
10EU AI Act⚖️ Regulatory Law / FrameworkEU legislation establishing legally binding AI requirements

TypeSimple meaningExamples
🏭 Industry Framework/Standard“Here is a recognized way to manage security.”NIST CSF, NIST 800-53, ISO 27001
⚖️ Regulatory Law/Framework“You are legally required to comply.”GDPR, UK GDPR, DORA, NIS2, EU AI Act
🤝 Contractual / Industry Requirement“Your customer/business/payment partner requires you to comply.”SOC 2, PCI DSS