Sign In Try Free
Workflow-specific products Content, decks, briefs, proposals, legal, and sales each have a clearer buying path.
Review before delivery Draft, edit, collaborate, approve, and export in the same workspace.
Security + procurement path Security policy, support, and Azure Marketplace buying are public.
← Free tools and references

Curated reference · Gixo Lex

Compliance and assurance frameworks

Primary framework, control and regulatory sources for security, privacy, payment, cloud, software and AI programmes.

16 named sources Last link check: 2026-08-03 First-party sources preferred

How this list is selected

This directory distinguishes voluntary frameworks, certification standards, attestation criteria and law. Mapping one to another does not make their evidence or scope interchangeable.

Cybersecurity risk outcomes

NIST Cybersecurity Framework 2.0

A flexible outcome taxonomy with Govern added in 2.0. Profiles and informative references make it useful without turning it into a checklist.

Free

Security and privacy controls

NIST SP 800-53 Rev. 5

A deep control catalogue, not a certification by itself. Baselines and tailoring live in related NIST publications.

Free

Prioritised cyber safeguards

CIS Critical Security Controls v8.1

A pragmatic implementation sequence with implementation groups; confirm licensing terms before redistributing control text.

Free access with terms

Information security management systems

ISO/IEC 27001

A certifiable management-system standard. Annex A is only one part; scope, risk treatment and operating evidence decide the system.

Paid standard; public overview

Payment-card data security

PCI DSS Document Library

Use the current PCI SSC documents and applicability guidance; merchant/service-provider validation paths differ.

Free documents; registration may apply

Service-organisation attestation

AICPA SOC 2 resources

SOC 2 is an attestation engagement against Trust Services Criteria, not a certification badge or public control list.

Mixed public/member resources

Cloud control assurance

Cloud Controls Matrix

A cloud-focused meta-framework with mappings and CAIQ companion material; version-lock mappings used in evidence work.

Free download with terms

Software assurance maturity

OWASP SAMM

An open maturity model for evaluating and improving a secure-development programme across governance, design, implementation, verification and operations.

Free and open

Application security verification

OWASP ASVS

A testable requirements baseline for web applications. State the ASVS version and level used in any claim.

Free and open

GDPR and EU privacy law

EU data-protection rules

Use the official regulatory text and supervisory guidance; a control mapping cannot answer jurisdiction, role or lawful-basis questions alone.

Free law and guidance

US health-information safeguards

HHS HIPAA Security Rule

Official HHS guidance for regulated entities and business associates. Privacy, Breach Notification and Security rules have distinct obligations.

Free

Enterprise governance of information and technology

COBIT

A governance system and objectives model, broader than security controls. ISACA licensing affects detailed content reuse.

Public overview; licensed publications

US federal cloud authorisation

FedRAMP Rev. 5 Documents and Templates

Rev. 5 packages are transitioning under FedRAMP's 2026 rules, so confirm the active process and current machine-readable requirements before using a legacy template.

Free

US defence industrial-base cybersecurity

CMMC Model

CMMC connects contract requirements, assessment levels and NIST SP 800-171 practices. Check the rule and contract clause actually applicable.

Free

AI risk governance

NIST AI Risk Management Framework

A voluntary framework organised around Govern, Map, Measure and Manage, with profiles and a playbook rather than certification.

Free

AI management systems

ISO/IEC 42001

A certifiable management-system standard for organisational AI governance; it does not certify that an individual model is safe or accurate.

Paid standard; public overview

Turn the source material into a governed workflow

The directory stays free and outward-linking. Gixo Lex adds saved workspaces, reviews, evidence and clean deliverables.