自社は、どの基準から始めるべきか。
- 3つの質問に答えるだけで、最適なフレームワークが適合度順に分かる
- 対応する6つのフレームワークの立ち位置と特性
- 選んだ基準が、他の規格をどれだけカバーできるか
Not sure which framework to pick?
Three questions, the right framework for you.
Among the security frameworks we support,
we propose the best fits for your purpose, scale, and partner requirements — ranked by suitability.
No expertise required to pick the right axis for your company.
Scale & industry
Select your headcount range and industry.
Assessment purpose
Certification, self-assessment, partner requirements, public procurement, board reporting — pick what fits.
Regulation & situation
Personal data handling, listing status, domestic-scheme alignment, international trade — pick what applies.
Based on your answers, frameworks ranked by suitability
We also show why each is recommended and how well it covers other standards.
CIS Controls
v8.1.2RecommendedIdeal for organizations that want to start with priority-ordered, practical controls. Even with limited resources, you can start with the highest-leverage countermeasures.
Cross-framework coverage: ~80% of the NIST Cybersecurity Framework (CSF) / ~60% of ISO 27001
NIST Cybersecurity Framework (CSF)
2.0For organizations that want to brief leadership and manage risk comprehensively in an internationally accepted framework.
Cross-framework coverage: ~85% of SCS
ISO 27001
2022For organizations seeking certification or that need to satisfy partner / tender requirements.
Suitability is computed from clearly defined criteria; the final choice remains yours.
Actual results depend on your specific answers.
Get ready now, before applications open.
The supply-chain security evaluation scheme (SCS, METI/IPA) is expected to begin accepting applications by end of FY2026. Before it becomes a partner requirement, get a clear current-state read at the ★ level — self-assessment automatically scores ★3.
See the full scheme details and readiness supportSix frameworks —
complementing each other from different angles.
We visualize each framework's position by the specificity of technical controls and the breadth of management coverage.
Pick the right axis for your purpose, scale, and partner requirements.
Supported frameworks as of July 18, 2026 — more are added over time.
- ISO 27001:202293 controlsInternational ISMS standardManagement82Technical22
- NIST Cybersecurity Framework (CSF) 2.0106 sub-categories6 functions covering exec to opsManagement76Technical70
- Supply-chain Security Evaluation Scheme (SCS)153 criteriaJapanese scheme / partner reqsManagement52Technical42
- CIS Controls v8.1.2153 safeguardsAttack-data-driven implementation baselineManagement22Technical80
- OWASP Top 10 for LLM 202555 controlsGenerative-AI-specific cyber riskManagement48Technical88
- AI Governance Maturity Assessment68 questionsAI organizational governance (our own framework referencing NIST AI RMF 1.0 × ISO/IEC 42001:2023)Management64Technical18
Positions are our own, based on each framework's characteristics — not a judgment of standards.
