Cyber, critical infrastructure & AI standards — all in one place.
The latest standards, laws and regulations, with curated metadata, mapped controls and expert guidance from 6clicks. Built for GRC, compliance and security teams.
Browse by industry
Browse by sector. Each page shows relevant standards, laws, regulations, and frameworks.
Explore all industriesContent Library
Showing 20 of 50
Netherlands WBP — Netherlands Personal Data Protection Act
The Personal Data Protection Act (WBP) was the Netherlands' data protection law that governed the processing of personal data and established privacy rights, data protection obligations, and regulatory oversight for organizations handling personal information.
Government of Netherlands • Netherlands
Mauritius DPA — Mauritius Data Protection Act 2017
The Data Protection Act 2017 establishes legal protections for privacy rights in Mauritius, regulating the collection, processing, storage, and use of personal information. It aims to safeguard privacy amid technical advancements while balancing the needs of government, businesses, and individuals.
Government of Mauritius • Mauritius
BDSG — Germany Federal Data Protection Act
The Federal Data Protection Act (BDSG) is Germany's national data protection law that complements the GDPR by establishing rules for personal data processing, privacy protection, regulatory oversight, and compliance obligations for public and private sector organizations.
v23 June 2021
Switzerland FADP — Switzerland Federal Act on Data Protection
The Federal Act on Data Protection (FADP) is Switzerland's data protection law that regulates the processing of personal data and protects the privacy rights of individuals by establishing requirements for lawful, transparent, and secure data handling.
The Federal Assembly of the Swiss Confederation • Switzerland • v3 January 2019
Estonia PDPA — Estonia - Personal Data Protection Act
The Estonia Personal Data Protection Act (IKS) is Estonia's data protection law that implements and supplements the GDPR, establishing requirements for personal data processing, privacy protection, and regulatory oversight.
Government of Estonia • Estonia • v15 January 2019
Dubai HDPR — Dubai Health Data Protection Regulation - DHCC Regulation No. 7 of 2013
The Dubai Health Data Protection Regulation is a healthcare privacy regulation that governs the protection, use, disclosure, and management of patient health information within Dubai Healthcare City, ensuring the confidentiality and security of health data.
Dubai Healthcare City Authority (DHCA) • Dubai • v21 October 2013
Finland Data Protection Act — Data Protection Act (1050/2018) - Finland
The Data Protection Act (1050/2018) provides national specifications and supplements the EU GDPR in Finland. It governs the roles and powers of the data protection authority, sets age limits for services to children, and includes rules for special categories of personal data and data processing in public interest contexts.
Government of Finland • Finland • v1050/2018
CR code v2.1 — Privacy (Credit Reporting) Code 2014 (Version 2.1)
The Privacy (Credit Reporting) Code 2014 (Version 2.1) provides a framework for credit reporting practices under Australia's Privacy Act. It outlines obligations for Credit Reporting Bodies (CRBs), Credit Providers (CPs), and other affected entities to ensure compliance with privacy regulations.
Australian Government • Australia • v2.1
POPIA — Protection of Personal Information Act
The Protection of Personal Information Act (POPIA) is South African legislation that governs the lawful processing of personal information. It establishes principles and rights for data subjects, conditions for processing, obligations for responsible parties, and enforcement mechanisms.
Government of South Africa • South Africa
Royal Decree 69/2008 — Electronic Transactions Law in Oman
The Electronic Transactions Law in Oman, enacted in 2008 through Royal Decree 69/2008, aims to streamline electronic transactions and ensure their security. It establishes provisions for authentication service providers, e-signature confidentiality, and data integrity.
Government of Oman • Oman
EU Data Act — Regulation (EU) 2023/2854 - EU Data Act
The EU Data Act (Regulation (EU) 2023/2854) establishes harmonized rules to make data generated by connected products and related digital services more accessible and usable across the European Union. It gives users of connected devices, such as IoT products, the right to access and share the data they generate with third parties, while requiring data holders to provide that data under fair, reasonable, and non-discriminatory conditions. The regulation aims to reduce barriers to data sharing, promote innovation and competition, enable easier switching between cloud and data-processing services, and support public-sector access to data in situations of exceptional need, while preserving data protection, privacy, intellectual property rights, and trade secret safeguards. Overall, the Data Act is designed to create a fairer and more competitive European data economy by empowering users and improving access to valuable data resources.
European Union • EU
ASD Essential 8 Maturity Model - 2023 — Australian Signals Directorate (ASD) Essential Eight Maturity Model 2023
The ASD Essential 8 Maturity Model is a framework developed by the Australian Signals Directorate (ASD) to guide organizations in implementing prioritized cyber security mitigation strategies. It provides structured maturity levels to help organizations progressively strengthen their defenses against common cyber threats. The model ensures consistency, accountability, and resilience by aligning practices across all eight strategies.
Australian Signals Directorate (ASD) • Australia • vNovember 2023
ISM CCM — Information Security Manual Cloud Controls Matrix Template
The Cloud Controls Matrix (CCM) Template is a comprehensive framework for mapping cloud security controls to industry standards and compliance requirements. It helps organizations assess, implement, and demonstrate effective cloud security practices across diverse environments.
Australian Government • Australia • vJune 2026
ISM SSP — Information Security Manual System Security Plan Annex Template
The System Security Plan (SSP) Annex Template is a structured document used to capture detailed information about an organization’s cyber security controls and implementation. It supports accreditation processes by providing evidence of compliance, risk management, and system-specific security measures.
Australian Government • Australia • vJune 2026
RFFR ISM SoA — Right Fit for Risk Information Security Manual Statement of Applicability
The Right Fit for Risk (RFFR) Statement of Applicability (SoA) is a structured template used to document how organizations meet cyber security accreditation requirements. It outlines applicable controls, their implementation status, and provides assurance of compliance with the RFFR framework.
Australian Government • Australia • vJune 2026
ISM — Information Security Manual
The Australian ISM is the nationally recognized cybersecurity framework developed by the Australian Signals Directorate. It provides organizations with structured guidance to safeguard information and operational technology systems against evolving cyber threats.
Australian Government • Australia • vJune 2026
India - DPDP Rules — India - Digital Personal Data Protection (DPDP) Rules
The Digital Personal Data Protection Rules, 2025 operationalize India’s Digital Personal Data Protection Act, 2023 by establishing detailed requirements for the collection, processing, storage, and protection of digital personal data. The Rules define obligations for organizations handling personal data, including consent management, breach notifications, data retention, and protections for children and vulnerable individuals. They also establish governance mechanisms such as the Data Protection Board and provide a phased implementation timeline for compliance.
Government of India • India • v2025
India - DPDP Act — India - Digital Personal Data Protection (DPDP) Act (Act No. 22 of 2023)
The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) establishes India’s legal framework for processing digital personal data while balancing individuals’ privacy rights with lawful data use. The Act defines obligations for organizations handling personal data, grants rights and duties to individuals, and introduces requirements for consent, data protection, and breach accountability. It also establishes the Data Protection Board of India to oversee compliance, adjudication, and enforcement of penalties for violations.
Government of India • India • v2023
Safe & Trusted Internet — Guidelines on Information Security Practices for Government Entities
The Safe & Trusted Internet Guidelines on Information Security Practices for Government Entities, issued by the Indian Computer Emergency Response Team (CERT-In), establish baseline cyber security controls and best practices to help government entities protect ICT infrastructure, systems, networks, and data against evolving cyber threats and strengthen India’s digital security posture.
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India • India
DCC-1:2022 — Data Cybersecurity Controls
The Data Cybersecurity Controls (DCC-1:2022) establish minimum cybersecurity requirements to protect data throughout its lifecycle. Issued by the Saudi National Cybersecurity Authority, the controls build on existing cybersecurity frameworks to enhance the Kingdom's overall cybersecurity maturity.
National Cybersecurity Authority (NCA) • Kingdom of Saudi Arabia • v1:2022
Partner directory
Certified resellers, integrators and advisors to help you implement and manage your GRC program.

1886 Consulting
- Region
- Australia
Tap into our knowledge of wealth.
Governance • Risk Management • Compliance Management • GRC Advisory

19eighty Advisory
- Region
- Australia
Business ownership is the most powerful calling.

3 Lights
- Region
- 4001, Brisbane, Australia
GRC | Information Security | Cyber | Advisory Services | Operations
Risk Management • ISO 27001 • NIST CSF • Essential Eight

3Quotes
- Region
- Canada
Your IT Procurement Partner

A1 Hrvatska d.o.o.
- Region
- Croatia
Croatia's leading telecommunications provider offering mobile, internet, TV, and managed security services.
Managed Security Services • Security Operations • Cloud Security

Accenture
- Region
- Australia
De-risk tomorrow by infusing cybersecurity into strategy, resilience, and protection at global scale.
GRC Advisory • Risk Management • Compliance Management • Security Operations

AfterDark Technology
- Region
- Australia
ISO 27001-certified managed IT services provider keeping Australian businesses secure, reliable, and running.
IT Managed Services • Managed Security Services • Essential Eight • ISO 27001

Archer & Round
- Region
- Australia
Cybersecurity that keeps you one step ahead with 24/7 managed SOC, vCISO, and GRC services.
Managed Security Services • Governance • Risk Management • Incident Response
Ready to manage these frameworks?
6clicks maps regulations to controls, evidence and risks — automatically.