Resources

Compliance Framework Reference

TrustDyne maps every finding against the frameworks below. This is a plain-language reference for what each one actually covers, not a substitute for the framework text itself or legal advice on which ones apply to your product.

EU AI Act

EU regulation setting risk-based obligations for AI systems, including transparency, risk management, and conformity assessment for high-risk AI.

ISO 42001

International standard specifying requirements for an AI management system (AIMS): governance, risk, and lifecycle controls for organizations that develop or use AI.

NIST AI RMF

NIST's voluntary framework for managing risk in AI systems across the govern, map, measure, and manage functions.

SOC 2

AICPA auditing standard evaluating a service organization's controls across security, availability, confidentiality, processing integrity, and privacy.

OWASP ASVS

Application Security Verification Standard: a checklist of security requirements for designing, testing, and verifying web application security.

OWASP LLM Top 10

OWASP's list of the most critical security risks specific to large language model applications, such as prompt injection and insecure output handling.

NIST SSDF

Secure Software Development Framework (NIST SP 800-218): guidance for building secure practices into the software development lifecycle.

MITRE CWE

Common Weakness Enumeration: a community-maintained taxonomy of software and hardware weakness types used to classify vulnerabilities.

UK PSTI Act

UK Product Security and Telecommunications Infrastructure Act: baseline security requirements, including a ban on default passwords, for consumer connectable products sold in the UK.

EU CRA

EU Cyber Resilience Act: cybersecurity requirements for hardware and software products with digital elements placed on the EU market.

IEC 62443

International standard series for the security of industrial automation and control systems (IACS/OT).

FDA Premarket

FDA's premarket cybersecurity guidance for medical devices, requiring documented security risk management before market clearance.

UNECE R155

UN regulation requiring vehicle manufacturers to implement a Cyber Security Management System (CSMS) across the vehicle lifecycle.

OWASP MASVS

Mobile Application Security Verification Standard: baseline security requirements for mobile apps covering storage, cryptography, authentication, and network communication.

DORA

EU Digital Operational Resilience Act: operational resilience, incident reporting, and third-party risk requirements for financial entities and their ICT providers.

PCI-DSS

Payment Card Industry Data Security Standard: security requirements for organizations that store, process, or transmit cardholder data.

FCA SYSC

UK Financial Conduct Authority's Systems and Controls sourcebook, setting operational resilience and risk management expectations for regulated firms.

PSD2

EU Revised Payment Services Directive: mandates strong customer authentication and secure communication for payment service providers.

HIPAA

US Health Insurance Portability and Accountability Act: security and privacy requirements for protected health information.

NHS DTAC

NHS Digital Technology Assessment Criteria: UK baseline standard covering clinical safety, data protection, technical security, and interoperability for digital health products.

FDA Medical Device

FDA cybersecurity requirements for connected medical devices across their lifecycle, including postmarket vulnerability management.

EU MDR

EU Medical Device Regulation: safety, performance, and cybersecurity requirements for medical devices sold in the EU.

ISO 27001

International standard for information security management systems (ISMS), covering risk assessment and a broad set of security controls.