Compliance Framework Selector
Identify which compliance framework(s) actually apply to your organization based on industry, data type, and customer requirements. No account access required.
Framework Selector
Work through each section at your own pace. Results are shown immediately — no email required.
Compliance & Governance Tool
Compliance Framework Selector
Work through your industry, data type, customer requirements, and cyber insurance obligations to identify which compliance framework(s) actually apply to your organization.
What The Recommendation Considers
Four Applicability Factors
Industry
Certain industries (healthcare, defense, financial services) carry framework obligations by default.
Data Type
The kind of sensitive data you handle — PHI, cardholder data, CUI — often determines which framework applies.
Customer Requirements
Contractual or procurement requirements from customers frequently mandate a specific framework.
Cyber Insurance
Insurance applications increasingly reference specific control baselines as a condition of coverage.
Understanding Your Recommendation
A Starting Point, Not a Crosswalk
This tool identifies which framework(s) are likely relevant to your organization — it does not currently compare or map overlapping controls between the frameworks it surfaces. Once you know which framework(s) apply, use the matching framework-specific assessment for directional readiness on that framework individually.
FAQ
Common Questions
How does this tool determine which framework applies to us?
It works through your industry, the type of data you handle, customer or contractual requirements, and cyber insurance obligations — the factors that typically determine which framework(s) are relevant or mandatory for your organization.
Can more than one framework apply to us at the same time?
Yes. It is common for an organization to have overlapping obligations — for example, a healthcare SaaS vendor may need to address both HIPAA and SOC 2. This tool will surface each relevant framework based on your answers.
Does this tool compare or map overlapping controls between the frameworks it identifies?
Not currently. It identifies which framework(s) likely apply to you — it does not yet cross-reference or map overlapping controls between them (for example, showing where a single control satisfies both HIPAA and SOC 2 at once). Once your applicable frameworks are identified, move to each framework-specific assessment for directional readiness on that framework individually.
Related Compliance Guidance
The full guide behind this tool.
Evaluate your broader governance maturity once your applicable frameworks are identified.
A framework-specific directional readiness check, once you know HIPAA applies.
Get hands-on help building toward your identified framework(s).
Operational Support
Need help building toward your applicable framework(s)?
IT KORR can help you scope, document, and operationalize the specific compliance framework(s) your organization needs to satisfy.
No commitment required — we respond within one business day.