Compliance Frameworks

Every compliance attestation FluffyStack tracks across 947 cloud services and 44 providers. Each card lists the issuing body, the jurisdiction it applies to, a plain-English summary, an official docs link, and how many catalogue services currently hold it.

Catalogue claims reflect each vendor's published “services in scope” pages where we have them, otherwise the provider's default attestation set. Always verify against the vendor's current scope document before procurement decisions.

Global / multi-jurisdiction

EU General Data Protection Regulation

European Data Protection Board (EDPB) · European Union

EU-wide data-protection law governing how personal data of EU residents may be processed, transferred, and stored. Applies to any service handling EU personal data regardless of where it's hosted.

Official documentation

ISO/IEC 27001 Information Security Management

International Organization for Standardization (ISO) · Global

International standard for Information Security Management Systems (ISMS). Defines risk-assessment, control selection, and continual-improvement requirements. The global baseline for vendor risk assessments.

Official documentation

AICPA Service Organization Control Type 2

American Institute of Certified Public Accountants (AICPA) · Global

Audited attestation that a service organisation has effective security, availability, processing integrity, confidentiality, and privacy controls. Type 2 = controls observed over 6–12 months.

Official documentation

Payment Card Industry Data Security Standard

PCI Security Standards Council · Global

Mandatory standard for any system storing, processing, or transmitting cardholder data. Required by Visa, Mastercard, Amex, Discover, JCB. v4.0 introduces customised-implementation pathways.

Official documentation

Cloud Security Alliance Security Trust Assurance and Risk

Cloud Security Alliance (CSA) · Global

Public registry of cloud-provider self-assessments and third-party audits against the CSA Cloud Controls Matrix. Three levels: Self-Assessment, Attestation/Certification, Continuous Monitoring.

Official documentation

United States — civilian

US Health Insurance Portability and Accountability Act

US Department of Health & Human Services · United States

US federal law setting the privacy and security baseline for Protected Health Information (PHI). A cloud service claiming HIPAA must sign a Business Associate Agreement (BAA) with the customer.

Official documentation

US Federal Risk and Authorization Management Program

US General Services Administration (GSA) · United States

Standardised cloud-security assessment for US federal agencies. Three impact levels — Low, Moderate, High. Required for any cloud service hosting federal data. Authorisation is service- and region-specific.

Official documentation
FedRAMP High0 services

US FedRAMP High Impact Baseline

US General Services Administration (GSA) · United States

Highest of the three FedRAMP impact levels. Required for federal data whose loss of confidentiality, integrity, or availability would have severe or catastrophic effect — i.e. anything classified High under FIPS 199. Held by services in AWS GovCloud (US) and Azure Government, plus a subset of commercial-region services.

Official documentation

United States — government / defence

US DoD Cloud Computing SRG Impact Level 4

US Defense Information Systems Agency (DISA) · United States

DoD Cloud Computing Security Requirements Guide level for Controlled Unclassified Information (CUI), non-critical mission information, and non-national-security systems. Builds on FedRAMP Moderate with DoD-specific overlays. Required for DoD components handling CUI.

Official documentation

US DoD Cloud Computing SRG Impact Level 5

US Defense Information Systems Agency (DISA) · United States

DoD CC SRG level for CUI requiring elevated protection (e.g. National-Security Systems, Mission-Critical workloads). Requires physical isolation from non-federal tenants. Held by AWS GovCloud (US) and Azure Government for specific authorised services.

Official documentation

US DoD Cloud Computing SRG Impact Level 6

US Defense Information Systems Agency (DISA) · United States

DoD CC SRG level for classified Secret information. Air-gapped from public internet, connected to SIPRNet, US-citizen-only operators. Held by Azure Government Secret regions (us-dod-east, us-dod-central) and the equivalent AWS Secret Region.

Official documentation

International Traffic in Arms Regulations (US)

US Department of State, Directorate of Defense Trade Controls · United States

US export-control regime for defence-related articles and technical data. Cloud regions storing ITAR-controlled data must guarantee US-citizen-only operator access and US-territorial physical hosting. Met by AWS GovCloud (US) and Azure Government.

Official documentation

Criminal Justice Information Services Security Policy (US)

US Federal Bureau of Investigation (FBI) · United States

Security policy for systems storing or processing FBI Criminal Justice Information (CJI). Mandatory for US state, local, and federal law-enforcement agencies. Covers fingerprint data, criminal histories, and related records. Met by AWS GovCloud (US) and Azure Government.

Official documentation

United Kingdom

UK Government G-Cloud framework

UK Crown Commercial Service (CCS) · United Kingdom

UK government procurement framework for cloud services. Listing on the G-Cloud Digital Marketplace is required to sell cloud to UK public-sector buyers. Currently iterates as G-Cloud 14.

Official documentation
Cyber Essentials0 services

UK NCSC Cyber Essentials (baseline-security scheme)

UK National Cyber Security Centre (NCSC) · United Kingdom

NCSC's baseline-security scheme. Two tiers — Basic (self-certified) and Plus (independently audited). Required for every UK central-government supplier and most regulated industries.

Official documentation

Europe

Hébergement de Données de Santé (French health-data hosting certification)

Agence du Numérique en Santé (ANS), France · FR

French health-data hosting certification, conceptually France's HIPAA. Mandatory for any provider hosting French patient data — covers technical, organisational, and physical-security requirements specific to medical workloads.

Official documentation
SecNumCloud36 services

ANSSI SecNumCloud — French sovereign-cloud qualification

ANSSI (Agence nationale de la sécurité des systèmes d'information), France · FR

ANSSI's French sovereign-cloud cert. Required for processing data classified Sensitive in the French public sector. Held only by OVHcloud Sovereign Cloud, Outscale's regulated SKU, and the Bleu / S3NS joint ventures.

Official documentation

BSI C5 — Cloud Computing Compliance Controls Catalogue (Germany)

Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany · DE

BSI's Cloud Computing Compliance Controls Catalogue — the German federal baseline for cloud-service procurement. Claimed by every hyperscaler operating in DE plus STACKIT, IONOS, T-Systems-owned providers, Exoscale.

Official documentation

Trusted Information Security Assessment Exchange (German automotive)

Verband der Automobilindustrie (VDA), Germany · DE

VDA-managed industry scheme for the German automotive supply chain. Mandatory if hosting OEM data for VW, BMW, Mercedes-Benz, Audi, Porsche. Assessment levels AL1/AL2/AL3 scale with data sensitivity.

Official documentation

Esquema Nacional de Seguridad — Nivel Alto (Spain)

Centro Criptológico Nacional (CCN-CERT), Spain · ES

Spanish National Security Framework, Alta tier. Mandatory for Spanish public-sector workloads handling classified or sensitive data. Three tiers — Básica, Media, Alta. Recognised by CCN-CERT.

Official documentation

Asia-Pacific & Canada

Australian Signals Directorate Information Security Registered Assessors Program

Australian Signals Directorate (ASD) · AU

Australian Government's accreditation scheme for cloud services handling Commonwealth data. Assessment tiers map to PROTECTED, SECRET, TOP SECRET. Required by Australian federal agencies.

Official documentation

Information system Security Management and Assessment Program (Japan)

IPA + METI, Government of Japan · JP

Japanese government-wide cloud assessment scheme administered jointly by IPA (technical) and METI (policy). Required for Japan-resident public-sector procurement. Registered cloud services listed in a public catalogue.

Official documentation

Multi-Tier Cloud Security Level 3 (Singapore)

Infocomm Media Development Authority (IMDA), Singapore · SG

IMDA's three-tier standard; Level 3 is Singapore's public-sector baseline. Required for whole-of-government cloud (WOG-Cloud) procurement. Held by hyperscaler Singapore regions plus Tencent and Alibaba SG.

Official documentation

Korean Information Security Management System (KISA)

Korea Internet & Security Agency (KISA) · KR

Mandatory for South Korean cloud-service providers serving public sector or regulated industries. The Cloud Security Assurance Program (CSAP) is the cloud-specific extension. Held by Naver Cloud, KT Cloud, Korean hyperscaler regions.

Official documentation
CCCS Medium403 services

Canadian Centre for Cyber Security Cloud IT Security Assessment, Medium

Canadian Centre for Cyber Security (CCCS) · CA

Canadian federal baseline for cloud, comparable to FedRAMP Moderate. Required by Government of Canada departments for hosting Protected B / Medium-impact workloads. Reciprocity with FedRAMP Moderate is partial.

Official documentation

Notes on how FluffyStack records compliance

  • Each provider has a defaultCompliance array applied across all of its services unless a service has an explicit override. AWS C5 and IRAP are explicit per-service overrides drawn from AWS's public services-in-scope pages.
  • Holding a tag means the vendor has self-attested or been certified at the corporate level. Whether a specific instance of the service in a specific region carries the same coverage is a separate question — check the vendor's scope document for region eligibility before committing to procurement.
  • New frameworks are added when at least one provider in the catalogue legitimately claims them. Suggestions welcome via the GitHub issues tracker.