Compliance frameworks supported by GRCLens
Cybersecurity, privacy, payment and health frameworks on one shared control model — assess once, satisfy several obligations, and deploy in your own environment.
Assess once, evidence everywhere
Frameworks overlap far more than most compliance programmes assume. GRCLens maps them onto a single control model, so evidence gathered for one obligation is reused wherever the same control applies — instead of being collected two or three times by different teams.
NCA-ECC
National Cybersecurity Authority (NCA) · Saudi Arabia
Assess, evidence and report against the Kingdom's Essential Cybersecurity Controls — in Arabic or English, hosted in your own environment.
Read more →PDPL
SDAIA · Saudi Arabia
Operationalise the Kingdom's Personal Data Protection Law: processing records, data subject rights, transfer controls and breach readiness.
Read more →ISO/IEC 27001
ISO / IEC · International
Annex A controls, Statement of Applicability, risk treatment and evidence — managed in one place, ready for your certification body.
Read more →SOC 2
AICPA · International
Map the Trust Services Criteria, maintain your system description, and evidence control operation across the observation period.
Read more →PCI DSS
PCI Security Standards Council · International
Scope your cardholder data environment, work through SAQ or ROC, and evidence every PCI DSS v4.0.1 requirement.
Read more →HIPAA
U.S. Department of Health & Human Services · United States
Run the required risk analysis, evidence administrative, physical and technical safeguards, and manage business associate obligations.
Read more →PK-CTDISR
Pakistan Telecommunication Authority (PTA) · Pakistan
Assess and evidence Pakistan's Critical Telecom Data and Infrastructure Security Regulations with audit-ready reporting.
Read more →Need a framework that is not listed?
Frameworks are enabled per tenant, so each client sees only what applies to them. If your obligation is not shown here, talk to us about adding it to your programme.
Contact us