A pack adds three or four modules written by people who work in that sector, cites the provision it supports on screen and in the record, and exports in the form that framework's reviewer expects. Core first, pack on top, one record.
Available now · design-partner pilot
Clinical & GxP
Clinical sites, CROs, sponsors, and the recruitment and data vendors around them.
- E.1Clinical trial and regulated data protection
- E.2Electronic records, audit trails and data integrity
- E.3Security incident identification, escalation and reporting
21 CFR § 11.10(i) · ICH E6(R3) · ALCOA+
The clinical research page →
Roadmap · built with a design partner
Healthcare & HIPAA
Covered entities and business associates: providers, health plans, and the vendors that touch their data.
- Protected health information and the minimum-necessary standard
- Recognizing a breach and who to tell, in what order
- Security reminders, malware, log-in monitoring and passwords as the rule lists them
45 CFR § 164.308(a)(5) · § 164.530(b)(1)
Become the design partner →
Roadmap · built with a design partner
Financial services
Lenders, brokers, advisers, insurers and fintech under the FTC Safeguards Rule.
- Customer financial information and who may see it
- Payment fraud, invoice redirection and executive impersonation
- Training that tracks the risk assessment, as the rule requires
16 CFR § 314.4(e)(1) · NY DFS 23 NYCRR Part 500
Become the design partner →
Roadmap · built with a design partner
Payment card
Merchants and service providers with a cardholder data environment.
- What cardholder data is and where it is allowed to exist
- Skimming, tampering and social engineering at the point of sale
- Handling card data on the phone and in support tools
PCI DSS v4.0 · Requirement 12.6
Become the design partner →
Roadmap · built with a design partner
Defense & government contractors
Suppliers handling controlled unclassified information under CMMC and DFARS.
- CUI and FCI: recognizing, marking and handling it
- Insider threat awareness
- Reporting a cyber incident up the contract chain
NIST SP 800-171 · Awareness and training family (3.2) · CMMC 2.0
Become the design partner →
Roadmap · built with a design partner
SaaS & technology vendors
Companies proving SOC 2 or ISO 27001 to their customers.
- Customer data handling and tenant isolation, for non-engineers too
- Secrets, tokens and access hygiene
- What the auditor will ask about your training, and the evidence they accept
ISO/IEC 27001:2022 · Annex A 6.3 · SOC 2 Trust Services Criteria
Become the design partner →
Roadmap · built with a design partner
Privacy & data protection
Organizations processing EU, UK or state-privacy-law personal data.
- Lawful handling, purpose limitation and data minimization in daily work
- Data subject requests and what not to say in the reply
- Breach notification duties and the internal escalation that makes them meetable
GDPR Art. 32 · Art. 39(1)(b)
Become the design partner →
Roadmap · built with a design partner
Energy & critical infrastructure
Utilities and operators with personnel who touch bulk electric system cyber systems.
- Operational technology is not IT: the differences that matter to the person at the console
- Physical and electronic access to protected systems
- Awareness and role-based training as the standard separates them
NERC CIP-004 · Personnel & Training
Become the design partner →
Roadmap packs are built with a design partner in that sector. If yours is on the list, that partner could be you.