Supported Frameworks
Information Security
- ISO/IEC 27001:2022
- NIST CSF
- SOC 2
- FIPS 140-3
Finance & Payments
- PCI-DSS
- SOX
- DORA
- Basel III
Privacy
- GDPR
- HIPAA
- CCPA
- TW-PDPA
Development Security
- OWASP Top 10
- CMMC 2.0
- SLSA
- CIS Controls
Asia-Pacific
- APPI (Japan)
- ISMAP (Japan)
- K-ISMS (Korea)
- PIPA (Korea)
Governance
- COBIT 2019
- ITIL v4
- TOGAF
- ISO/IEC 38500
AI governance
- ISO/IEC 42001
- EU AI Act
- NIST AI RMF
- OWASP LLM Top 10
- OWASP Agentic Top 10
- Korea AI Basic Act
- Taiwan AI Basic Act + FSC guidelines
Every scan maps against all 31 built-in frameworks at once, on every plan.
What ForgeHelm covers — and what it doesn't
Standards like ISO 27001 audit your information security management system, not your code. ForgeHelm provides code-level evidence for the technical controls — secure development, change management, vulnerabilities and dependencies, use of cryptography, access control. Policies, risk assessment, and organizational controls stay with you and your consultants. Whether you pass an audit depends on whether the findings get fixed — the auditor makes that call, not us.
What's in a Compliance Report
Framework coverage matrix — which controls have code-level evidence, which have some, and which have none yet
Every finding points to a specific file and line number
Remediation recommendations ranked by risk
Risk assessment summary using ISO 31000, NIST RMF, or ISO 27005
Export to PDF, Excel, CSV, or Word in six languages
The evidence pack can go straight to an external auditor — they do not need an account on your system
31 frameworks, and the depth varies
"Mapped" means different amounts of work depending on how much a framework can actually be verified in code. ISO 27001, SOC 2, NIST CSF, GDPR, PCI-DSS, CMMC, HIPAA and Taiwan's Personal Data Protection Act carry a large number of technical controls that show up in code and configuration, so they map to the most items. Governance frameworks such as TOGAF, ITIL, COBIT and ISO 38500, and regulations driven by contracts and organisational process such as SOX, Basel III and DORA, have far less that can be verified in code, so the mapping is shallower and the report states plainly which controls found no evidence. If you want to know exactly which controls a given framework maps to, write to us and we'll send the list.
ForgeHelm is not a replacement for a source-code vulnerability scanning (SAST) tool. On the security side we run rule-based checks (weak hashes, hard-coded passwords, SQL string concatenation and similar) and map framework controls; where deep vulnerability scanning is required, ForgeHelm sits alongside that kind of tool.
Seven of them are AI governance frameworks
ISO/IEC 42001, the EU AI Act, the NIST AI RMF, OWASP's two Top 10 lists for LLM and agentic applications, and the AI basic acts of Korea and Taiwan. They look at the places in your code that use AI: whether there is an inventory of AI use, whether AI calls are logged, whether there is a switch to turn AI off, whether keys have leaked, how models are loaded, what AI agents are allowed to do, and whether users are told they are interacting with AI — 23 checks in all. If a project does not use AI, these seven show as "not applicable" and do not affect the scores of the other frameworks.
This maps code-level evidence; it is not a certification and not legal advice. Only part of each framework is checked automatically, and the report states the size of the reference universe and how many clauses are checked — for example, 10 of the EU AI Act's 18 technical obligations; the rest are organizational, process or legal matters. Clauses that apply only to certain categories (high-risk systems in the EU, high-impact AI in Korea) are listed separately as conditional readiness and do not count toward the score; whether your system falls into such a category is for your organization to determine. Clauses and legal status are as verified on 28 September 2026.