Log360 Supported Compliances

A one-stop resource center designed to help businesses navigate the complexities of regulatory compliance. See how ManageEngine enables businesses to stay secure and compliant effortlessly.

Filter
  • All country
  • Australia
  • Brazil
  • Ecuador
  • European Union
  • Germany
  • Global
  • India
  • Netherlands
  • Qatar
  • Saudi Arabia
  • Spain
  • UAE
  • UK
  • United States
  • All Industries
  • Automotive
  • Aviation
  • Critical
  • Energy
  • Finance / Banking
  • Government / Defense
  • Healthcare
  • IT / SaaS / Cloud
  • Manufacturing

  HIPAA

The Standards for Privacy of Individually Identifiable Health Information, commonly known as the HIPAA Privacy Rule.

  PCI DSS

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards developed to ensure the protection.

  GDPR

GDPR sets several principles that controllers and processors must follow when handling personal data.

  BACEN

The BACEN cybersecurity regulations guide financial institutions in Brazil on managing cyber risks and protecting digital banking operations.

  PNCiber

PNCiber, Brazil's national cybersecurity policy, establishes strategic guidelines to strengthen cyber resilience across organizations.

  ANAC

ANAC cybersecurity guidance helps aviation organizations in Brazil strengthen information security and maintain regulatory readiness.

  NIS2

The NIS2 Directive expands cybersecurity requirements for essential and important entities across the European Union.

  EU CRA

The EU Cyber Resilience Act introduces cybersecurity requirements for digital products and connected software placed on the EU market.

  SEBI CSCRF

SEBI CSCRF helps financial entities in India align cybersecurity practices with risk management, resilience, and reporting expectations.

  ISO 27001

ISO/IEC 27001 is the leading global standard focused on information security management systems (ISMS). It provides a framework that helps companies efficiently protect their data through the implementation of an ISMS.

  Cyber essentials

Cyber Essentials is a UK cybersecurity certification scheme that helps organizations protect against common online threats.

  SOX

The SOX Act also sets rules for the accounting firms that audit public companies and the analysts who publish research on securities.

  PDPL

The Personal Data Protection Law (PDPL) regulates the collection, processing, and storage of personal data within Saudi Arabia.

  NIST CSF

The NIST CSF provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks.

  NIST SP 800-171

NIST SP 800-171 outlines security requirements for protecting controlled unclassified information (CUI) in non-federal systems and organizations.

  UAE-NESA

The UAE NESA Information Assurance Standards define cybersecurity controls to strengthen the protection of the nation’s critical information infrastructure.

  SAMA CSF

The SAMA cybersecurity framework helps financial institutions manage cyber risks and ensure compliance with Saudi Arabia’s regulatory requirements.

  QCF

The Qatar Cybersecurity Framework (QCF) sets security guidelines to protect national information assets and ensure operational resilience.

  TISAX

The Trusted Information Security Assessment Exchange (TISAX) ensures consistent information security standards within the automotive industry.

  LGPD

The Lei Geral de Proteção de Dados (LGPD) governs how organizations in Brazil collect, process, and protect personal data.

  SOC 2

SOC 2 compliance evaluates how service providers manage customer data across security, availability, integrity, confidentiality, and privacy principles.

  ECC

The Essential Cybersecurity Controls (ECC) framework defines baseline cybersecurity standards for government entities and critical sectors in Saudi Arabia.

  NCA

The National Cybersecurity Authority (NCA) establishes policies and frameworks to enhance cybersecurity governance and safeguard national digital infrastructure.

  GAMP 5

GAMP 5 sets out a risk-based approach to specifying, validating, and maintaining GxP computerized systems so they stay fit for intended use and data integrity is preserved.

  DPDP

The DPDP Act governs the collection, processing, storage, and transfer of digital personal data, setting consent, security safeguard, and breach-notification duties for Data Fiduciaries.

  SUSEP

SUSEP Circular No. 638 establishes cybersecurity requirements for insurance companies, open private pension entities, capitalization companies, and local reinsurers.

  ENS

The ENS is Spain's mandatory information security framework for public sector bodies and the private organisations that provide electronic services on their behalf.

  SEPS

SEPS norms set minimum information security and electronic-channel controls for savings and credit cooperatives, mutual associations, and central funds.

  LOPGDD

The LOPDGDD adapts the EU GDPR into Spanish law and adds a national catalogue of digital rights.

  German NIS2

The NIS2UmsuCG transposes the EU NIS2 Directive into German law by replacing the BSI-Gesetz, imposing registration, risk management, and incident-reporting duties on essential and important entities.

  INCIBE

INCIBE is Spain's national cybersecurity institute and operates INCIBE-CERT, the incident response centre for citizens and private-sector entities.

  21 CFR Part 11

FDA rule setting the conditions under which electronic records and electronic signatures are considered trustworthy and equivalent to paper, requiring system validation, secure audit trails, and access controls.

  DORA

Regulation (EU) 2022/2554 imposing uniform ICT risk management, incident reporting, resilience testing, and third-party provider oversight on financial entities, applicable since 17 January 2025.

  BIO2

The Baseline Informatiebeveiliging Overheid 2.0 is the ISO 27001/27002-based information security baseline for Dutch government bodies, and serves as the route by which the government sector meets its Cyberbeveiligingswet duty of care.

  NEN 7510

Dutch sector standard for information security management in healthcare, building on ISO 27001/27002 with additional controls for patient data; current version is NEN 7510-1:2024.

  Cyberbeveiligingswet (Cbw)

The Cyberbeveiligingswet transposes the EU NIS2 Directive into Dutch law and replaces the Wbni, imposing registration, duty of care, incident reporting, and management accountability on essential and important entities across 18 sectors; in force since 15 August 2026. Rijksoverheid Nctv

  KRITIS-Dachgesetz (KRITISDachG)

Transposes the EU CER Directive (2022/2557) and establishes Germany's first cross-sector federal framework for the physical resilience of critical installations across ten sectors, in force since 17 March 2026.

  IT-Sicherheitskatalog

Bundesnetzagentur catalogues issued under §11(1a) and §11(1b) EnWG, requiring electricity and gas network operators and energy installation operators to run a certified ISO 27001/27019-based ISMS.

  Essential Eight

ASD/ACSC baseline of eight prioritised mitigation strategies scored across Maturity Levels 0–3, mandatory for non-corporate Commonwealth entities and widely adopted as a general Australian security benchmark.

Ready to simplify compliance and stay audit-ready with Log360?

Automate compliance checks, streamline audit reporting, and ensure continuous visibility across your IT environment.