Supported frameworks

Compliance frameworks supported by GRCLens

Cybersecurity, privacy, payment and health frameworks on one shared control model — assess once, satisfy several obligations, and deploy in your own environment.

One control model

Assess once, evidence everywhere

Frameworks overlap far more than most compliance programmes assume. GRCLens maps them onto a single control model, so evidence gathered for one obligation is reused wherever the same control applies — instead of being collected two or three times by different teams.

NZ PSR

New Zealand Government (PSR — hosted by NZSIS) · New Zealand

Assess and evidence the Protective Security Requirements across GOVSEC, PERSEC, INFOSEC and PHYSEC — ready for annual PSR assurance reporting.

Read more →

NZ MCSS

National Cyber Security Centre (NCSC, part of GCSB) · New Zealand

Meet the Minimum Cyber Security Standards — evidence each standard on business-critical and externally facing systems, at the required maturity.

Read more →

NZ HISO 10029

Te Whatu Ora — Health New Zealand · New Zealand

Protect health information to New Zealand's national standard — assess HISO 10029:2022 across plan, identify, protect, detect and respond.

Read more →

AU PSPF

Australian Government — Department of Home Affairs · Australia

Assess protective security maturity across the PSPF domains — governance, risk, information, technology, personnel and physical security.

Read more →

IRAP (AU ISM)

Australian Signals Directorate (ASD) · Australia

Manage Australian ISM assessments end to end — engagements, control-by-control evaluation, automated evidence collection and findings.

Read more →

AESCSF / SOCI

AEMO (AESCSF) · Cyber and Infrastructure Security Centre (SOCI) · Australia

Evidence AESCSF maturity and SOCI Act risk-management obligations for Australian critical infrastructure — one assessment, board-ready reporting.

Read more →

AU VPDSF

Office of the Victorian Information Commissioner (OVIC) · Australia (Victoria)

Assess and evidence the Victorian Protective Data Security Standards, from governance through ICT security, ready for OVIC attestation.

Read more →

PCI DSS

PCI Security Standards Council · International

Scope your cardholder data environment, work through SAQ or ROC, and evidence every PCI DSS v4.0.1 requirement.

Read more →

ISA/IEC 62443

ISA / IEC · International

Evidence industrial cybersecurity against ISA/IEC 62443 — from the security programme to the seven foundational requirements for control systems.

Read more →

HIPAA

U.S. Department of Health & Human Services · United States

Run the required risk analysis, evidence administrative, physical and technical safeguards, and manage business associate obligations.

Read more →

GDPR

European Union · European Union

Demonstrate accountability under the GDPR — lawful basis, data subject rights, records of processing and breach readiness, evidenced in one place.

Read more →

NIST SP 800-53

U.S. National Institute of Standards and Technology (NIST) · United States / International

Assess and evidence NIST SP 800-53 Rev. 5 controls — the catalogue behind FISMA, FedRAMP and the Risk Management Framework.

Read more →

SOC 2

AICPA · International

Map the Trust Services Criteria, maintain your system description, and evidence control operation across the observation period.

Read more →

ISO/IEC 27001

ISO / IEC · International

Annex A controls, Statement of Applicability, risk treatment and evidence — managed in one place, ready for your certification body.

Read more →

ISO 9001

International Organization for Standardization (ISO) · International

Run your quality management system as a living assessment — every ISO 9001:2015 requirement with an owner, a status and evidence.

Read more →

ISO 14001

International Organization for Standardization (ISO) · International

Evidence your environmental management system — aspects, obligations, operational controls and improvement — against ISO 14001:2015.

Read more →

ISO 45001

International Organization for Standardization (ISO) · International

Evidence your OH&S management system — hazard identification, worker consultation, operational controls — against ISO 45001:2018.

Read more →

ISO 22301

International Organization for Standardization (ISO) · International

Assess and evidence your business continuity management system — from business impact analysis to exercising — against every ISO 22301 requirement.

Read more →

ISO 22361

International Organization for Standardization (ISO) · International

Measure and strengthen your crisis management capability — leadership, decision-making, communication and learning — against ISO 22361 guidance.

Read more →

ISO/IEC 20000-1

ISO / IEC · International

Evidence your service management system against every ISO/IEC 20000-1:2018 requirement, from planning to continual improvement.

Read more →

ISO/IEC 42001

ISO / IEC · International

Govern AI responsibly: assess and evidence your AI management system against ISO/IEC 42001, including Annex A controls and an AI system register.

Read more →

NCA-ECC

National Cybersecurity Authority (NCA) · Saudi Arabia

Assess, evidence and report against the Kingdom's Essential Cybersecurity Controls — in Arabic or English, hosted in your own environment.

Read more →

PDPL

SDAIA · Saudi Arabia

Operationalise the Kingdom's Personal Data Protection Law: processing records, data subject rights, transfer controls and breach readiness.

Read more →

CST CRF

Communications, Space & Technology Commission (CST), Saudi Arabia · Saudi Arabia

Assess and evidence CST's Cybersecurity Regulatory Framework across 215 controls, six domains and the CL1–CL3 progression, with reporting built for the annual CST self-assessment.

Read more →

UAE IA (NESA/SIA)

Signals Intelligence Agency (SIA) — formerly NESA · United Arab Emirates

Assess and evidence the UAE Information Assurance Standard — management and technical controls, prioritised P1 to P4, in Arabic or English.

Read more →

Dubai DESC ISR

Dubai Electronic Security Center (DESC) · United Arab Emirates (Dubai)

Assess and evidence Dubai's Information Security Regulation v3 — including its cloud, data residency, IoT and supply-chain provisions.

Read more →

PK-CTDISR

Pakistan Telecommunication Authority (PTA) · Pakistan

Assess and evidence Pakistan's Critical Telecom Data and Infrastructure Security Regulations with audit-ready reporting.

Read more →

PISF 2026

Pakistan Computer Emergency Response Team (PKCERT) · Pakistan

Assess and evidence Pakistan's Cabinet-approved Information Security Framework across 238 controls and 13 domains, with audit-ready reporting.

Read more →

NSPM

GRCLens platform module · International

Govern firewalls and network policy operationally — device inventory, rule-base analysis, findings and compliance checks in one workspace.

Read more →

PhishLens

GRCLens platform module · International

Test and evidence security awareness — phishing campaigns, click analytics and executive reporting that feed your compliance frameworks.

Read more →

Need a framework that is not listed?

Frameworks are enabled per tenant, so each client sees only what applies to them. If your obligation is not shown here, talk to us about adding it to your programme.

Contact us