Compliance
Compliance monitoring across 28 frameworks — real control references, evidence exports, breach notification
ManySignal continuously maps security monitoring to the frameworks that matter to your auditors, regulators, and customers — from GDPR Article 25 to NIST SP 800-171 practice 3.14.6 to SAMA CSF Domain 3. Every alert becomes compliance evidence.
Privacy & Data Protection
GDPR
EU General Data Protection Regulation — 72-hour breach notification, Art. 25–49 controls
CCPA / CPRA
California Consumer Privacy Act — reasonable security evidence, SPI monitoring
FERPA
US student record privacy — SIS and LMS access baselining for educational institutions
GLBA
Gramm-Leach-Bliley Act — Safeguards Rule §314.4 for US financial institutions
Healthcare & Life Sciences
Financial Services
SOX
Sarbanes-Oxley — Section 302/404 ITGC monitoring for US public companies
PCI DSS
Payment Card Industry DSS v4.0 — cardholder data environment monitoring
GLBA
FTC Safeguards Rule compliance for banks, brokers, and insurers
SWIFT CSCF
SWIFT Customer Security Controls Framework — operator session and transaction monitoring
Security Frameworks
NIST CSF 2.0
NIST Cybersecurity Framework 2.0 — all 6 functions including new Govern function
NIST SP 800-53
Rev 5 — AU/SI/IR/CA control families for federal agencies and contractors
ISO 27001:2022
International information security management — 11 new 2022 Annex A controls
SOC 2
Trust Services Criteria — Type II evidence for CC6.1 through CC9.1
CIS Controls v8
Center for Internet Security Controls — IG1/2/3 implementation group coverage
ISO 42001
AI Management System Standard — model security for AI companies
US Government & Defense
European Regulatory
Asia-Pacific
CERT-In
India CERT-In Directions 2022 — 6-hour reporting, 20 incident categories
RBI Cybersecurity
Reserve Bank of India CSF — Adaptive maturity, 24x7 SOC for Indian banks
SEBI CSCRF
SEBI Cybersecurity and Cyber Resilience Framework — 6-hour reporting for MIIs
Essential Eight
ACSC Essential Eight — ML0–ML3 for Australian government and enterprise
Middle East
NCA ECC
Saudi National Cybersecurity Authority Essential Cybersecurity Controls
SAMA CSF
Saudi Arabian Monetary Authority Cyber Security Framework — Domain 3 and 4
UAE IA Standards
UAE NESA Information Assurance Standards — government and CII operators
ADGM & DIFC
UAE financial free zone data protection — concurrent 72-hour notifications
Industry-Specific
How ManySignal approaches compliance evidence
Control-level evidence, not just dashboards
Every detection event ManySignal generates is tagged to the specific control clauses it satisfies — HIPAA §164.312(b), PCI DSS Requirement 10.7.1, GDPR Article 32(1)(d). Auditors and assessors receive control-mapped evidence packages, not raw log exports.
Breach notification timelines, tracked automatically
From the moment a breach is confirmed, ManySignal tracks the applicable notification deadlines — 72 hours for GDPR, 6 hours for CERT-In, 4 hours for DORA critical incidents, 24 hours for SAMA CSOC. Each deadline appears in the case management interface with pre-populated regulator notification templates.
Shared responsibility, documented clearly
ManySignal produces shared-responsibility matrices for each framework — showing which controls ManySignal addresses operationally, which require customer configuration, and which are outside ManySignal's scope. This is the starting point for every compliance assessment conversation.
Map your compliance requirements to ManySignal
Tell us which frameworks you're assessed against and we'll walk through the control mapping, evidence export path, and breach notification workflows relevant to your auditors.