Cybersecurity Frameworks & Compliance Standards We Work To
Eleven UK, US, and international certification and compliance frameworks, four testing methodologies — the standards that actually govern how Mutex Systems designs, tests, and certifies security programmes, broken down individually so you know exactly what each one requires before you commit to it, and exactly how grComply automates the ongoing evidence work behind it.
Governance, Certification & Attestation
What each framework requires, who asks for it, and how long it typically takes.
ISO/IEC 27001:2022
Information security management system (ISMS) certification
Read the guideSOC 2 Type I & Type II
AICPA Trust Services Criteria attestation for SaaS and service providers
Read the guideSOC 3
The public-facing, general-use version of a SOC 2 report
Read the guideNIST Cybersecurity Framework
Govern, Identify, Protect, Detect, Respond, Recover — risk-based baseline
Read the guideUK GDPR & Data Protection Act 2018
Data protection law enforced by the ICO for any UK-facing business
Read the guidePCI DSS v4.0
Mandatory standard for anyone storing, processing, or transmitting card data
Read the guideCyber Essentials & Cyber Essentials Plus
NCSC-backed UK certification, often mandatory for government contracts
Read the guideISO/IEC 42001:2023
The first certifiable AI management system (AIMS) standard
Read the guideHIPAA
US federal law protecting the privacy and security of patient health data
Read the guideCMMC 2.0
Mandatory cybersecurity certification for the US Defense Industrial Base
Read the guideFedRAMP
Authorization standard for cloud services selling to US federal agencies
Read the guideHow Security Testing Actually Gets Structured
The methodologies behind every penetration test, red team engagement, and AI application assessment we run.
OWASP Testing Framework
Top 10, ASVS, MASVS, and API Security Top 10 for application testing
Read the guidePTES
The Penetration Testing Execution Standard — 7-phase engagement methodology
Read the guideMITRE ATT&CK
Adversary tactics and techniques knowledge base for red teaming
Read the guideLLM Penetration Testing
OWASP LLM Top 10 and NIST AI RMF-aligned testing for AI applications
Read the guideCommon Questions About Choosing a Framework
What is the difference between a compliance framework and a testing methodology?
A compliance framework — ISO 27001, SOC 2, NIST CSF, GDPR, PCI DSS, Cyber Essentials, ISO 42001 — defines the governance, controls, and evidence an organisation must maintain, often verified through certification or an attestation report. A testing methodology — OWASP's standards, PTES, MITRE ATT&CK, LLM penetration testing — defines how security testing is actually structured and executed to prove those controls hold up in practice. Most serious security programmes need both: a framework to govern against, and a methodology to test whether the governance actually works.
Which framework should we start with?
It depends on who is asking. If enterprise or US-facing SaaS buyers are asking, SOC 2 is usually the fastest path to a shareable report. If UK or EU procurement or regulators are asking, ISO 27001 carries more weight. If you are bidding for UK government contracts, Cyber Essentials may be a mandatory minimum. If you handle card payments, PCI DSS is not optional. Most organisations end up holding two or three of these frameworks over time as different buyers and markets ask for different proof.
Do these pages cover Pakistan-specific regulation as well?
No — this page covers international and UK standards. Pakistan-specific regulatory frameworks such as PTA CTDISR, the State Bank of Pakistan's cybersecurity guidelines, NEPRA's IT/OT regulations, and the Pakistan Information Security Framework are covered separately on our Pakistan regulatory compliance hub.
Can Mutex Systems help with more than one framework at once?
Yes, and it is usually more efficient to. Control evidence overlaps heavily between frameworks — the same access-control policy, encryption standard, or incident-response plan can satisfy requirements across ISO 27001, SOC 2, and NIST CSF simultaneously. Programmes are scoped to build the underlying control set once and map it to whichever frameworks actually apply to your business.
Not Sure Which Framework You Actually Need?
Tell us who is asking — a customer, a regulator, an insurer, a tender — and we'll tell you honestly which framework actually matters first.