Regulation to controls
Compliance matrices.
Regulated buyers rarely need another feature list; they need to know which obligations map to which identity controls. Each matrix translates a regulation into concrete CIAM requirements, the evidence an auditor expects, and the exact questions to put to a vendor.
- SOC 2
SOC 2 (AICPA Trust Services Criteria)
SOC 2 is an attestation, not a law: an independent auditor tests your controls against the Trust Services Criteria (security, availability, confidentiality, processing integrity, privacy). For CIAM, the Security criterion is where most identity controls live, logical access, MFA, and audit logging. A Type II report covers a period (usually 6-12 months); a Type I is a point in time.
United States (globally recognized) · 3 mapped requirements
- GDPR
General Data Protection Regulation
GDPR governs how you collect, store, and process personal data, and customer identity sits at the center of it: consent, data subject rights, and security of processing are all identity-adjacent. The heaviest CIAM obligations are lawful-basis and consent capture (Art. 6-7), data subject rights including erasure and portability (Art. 15-20), and security of processing (Art. 32).
European Union / EEA (extraterritorial) · 4 mapped requirements
- CCPA / CPRA
California Consumer Privacy Act, as amended by the CPRA
CCPA (amended by the CPRA) gives California consumers rights to know, delete, correct, and opt out of the sale or sharing of their personal information. For CIAM the core work is verifying the identity of the person making a request, honoring opt-out signals, and giving consumers self-service control over their data.
California, United States · 3 mapped requirements
- HIPAA
Health Insurance Portability and Accountability Act (Security Rule)
The HIPAA Security Rule sets technical safeguards for electronic protected health information, and several land squarely on CIAM: access control, audit controls, and person/entity authentication (45 CFR §164.312). Any vendor touching ePHI must also sign a Business Associate Agreement (BAA).
United States · 4 mapped requirements
- PCI DSS 4.0
Payment Card Industry Data Security Standard 4.0
PCI DSS 4.0 governs the cardholder data environment (CDE). CIAM is identity-adjacent rather than in scope by default, but the identity requirements are strict: Requirement 7 (need-to-know access), Requirement 8 (identify and authenticate users, including MFA into the CDE), and Requirement 10 (log and monitor access). MFA requirements tightened materially in 4.0.
Global (card brand mandate) · 4 mapped requirements
- ISO 27001
ISO/IEC 27001 (Information Security Management)
ISO/IEC 27001 certifies an information security management system, and its Annex A controls include several that land on CIAM: identity management, access control, authentication information, and secure authentication. Unlike SOC 2, it is an internationally recognized certification with a defined control set (updated in the 2022 revision).
International · 3 mapped requirements
- FedRAMP
Federal Risk and Authorization Management Program
FedRAMP standardizes security authorization for cloud services used by US federal agencies, layered on NIST SP 800-53. For CIAM the heaviest families are Access Control (AC) and Identification and Authentication (IA), where phishing-resistant MFA and FIPS-validated cryptography are effectively required. Most CIAM vendors offer FedRAMP only through a dedicated government cloud, at a specific impact level (Low / Moderate / High).
United States (federal government) · 3 mapped requirements
- NIST 800-63
NIST SP 800-63 Digital Identity Guidelines
NIST SP 800-63 is the reference framework for digital identity assurance. It splits assurance into three axes: Identity Assurance Level (IAL, how well you proofed the person), Authenticator Assurance Level (AAL, how strong the authentication is), and Federation Assurance Level (FAL). It is a guideline, not a certification, but it is the vocabulary most CIAM authentication decisions are graded against.
United States (guideline, widely referenced globally) · 3 mapped requirements
- PSD2 / SCA
PSD2 Strong Customer Authentication
PSD2's Strong Customer Authentication (SCA) requires most electronic payments and account access to use at least two independent factors from knowledge, possession, and inherence, with dynamic linking that binds the authentication to the specific payment amount and payee. CIAM supplies the authentication and risk engine; exemptions (low value, transaction risk analysis) rely on adaptive, risk-based auth.
European Union / EEA · 3 mapped requirements
- COPPA
Children's Online Privacy Protection Act
COPPA governs the online collection of personal information from children under 13. For CIAM the core obligations are age determination, verifiable parental consent before collection, and strict data minimization for children's accounts. Games, education, and kids' media are the most affected.
United States · 3 mapped requirements
- FERPA
Family Educational Rights and Privacy Act
FERPA protects the privacy of student education records and gives parents and eligible students rights over them. For CIAM the work is role-based access separating students, parents, and staff, consent for disclosures, directory-information opt-out, and logging who accessed records.
United States · 3 mapped requirements
- DORA
Digital Operational Resilience Act
DORA sets operational-resilience requirements for EU financial entities, and identity is a core ICT risk control. The CIAM-relevant pieces are strong access control and authentication for critical systems, ICT incident detection and reporting, and managing third-party (including identity-provider) risk.
European Union · 3 mapped requirements
- HITRUST
HITRUST CSF (Common Security Framework)
HITRUST CSF is a certifiable framework that harmonizes HIPAA, ISO 27001, NIST, and others into one control set, widely required of healthcare vendors. Its access-control and authentication controls map directly to CIAM: unique identities, MFA, least privilege, and audit logging, assessed and certified rather than self-attested.
United States (healthcare, globally used) · 3 mapped requirements
These matrices are practitioner guidance, not legal advice. Confirm your obligations with qualified counsel. See our disclaimer and methodology.