Frameworks

Coverage across compliance programs, certification journeys, and continuous monitoring.

Rhodigital Limited ships advisory and continuous-monitoring engagements against the compliance programs, certification journeys, and continuous monitoring scopes that matter to regulated SMBs and mission-driven non-profits. Each row below links to the dedicated product page for the framework, with the Advisor-Led module attached where one exists.

Nine frameworks. Continuous and Advisor-Led coverage where the program warrants it.

NIST CSF 2.0Coming soon

The cross-sector cybersecurity framework. Six functions — Govern, Identify, Protect, Detect, Respond, Recover — mapped to recurring continuous monitoring on RhodigitalOS.

NIST SP 800-171Coming soon

The 110-control set DoD contractors protect CUI against — and the certification target for CMMC Level 2 assessments.

CMMC 2.0Coming soon

The DoD cybersecurity certification model. CMMC 2.0 simplified the original 5-level model to three levels; Level 2 maps directly to NIST SP 800-171.

PCI-DSSComing soon

12 requirements across 6 goal areas — required for any business that stores, processes, or transmits cardholder data.

FedRAMPComing soon

The federal cloud authorization program. Required for any cloud service provider selling into U.S. federal agencies.

ISO 27001Coming soon

The international information security management system standard — Annex A controls, Statement of Applicability, and certification pathway.

GDPRComing soon

The EU data protection regulation. Lawfulness of processing, data subject rights, breach notification, and cross-border transfer controls.

CCPAComing soon

The California Consumer Privacy Act — consumer rights, business obligations, opt-out mechanics, and the privacy notice requirement.

HIPAAComing soon

The U.S. healthcare privacy and security rule. Administrative, physical, and technical safeguards for protected health information.

Three scopes, one catalog.

Compliance programs — recurring cycles that maintain posture against an external authority (CISA KEV, NIST CSF 2.0, NIST SP 800-171). RhodigitalOS delivers these as subscriptions so certification evidence is built continuously, not assembled before an audit.

Certification journeys — bounded engagements that prepare an organization for an external assessment (CMMC L1/L2, FedRAMP authorization, SOC 2). The catalog above flags Advisor-Led coverage on these so the same named advisor runs the cycle end-to-end.

Continuous monitoring — the universal frame we apply across the catalog. Posture review, KEV escalation, and recurring policy refreshes run on the same RhodigitalOS surface regardless of the framework the page is keyed to.