Skip to main content
Course

Introduction to Compliance Frameworks

Free starter course: recognize the frameworks every GRC job ad mentions.

Beginner

Level

5

Modules

15

Lessons

5

Graded quizzes

8 hours

Estimated time

What you will be able to do

  • Define governance, risk and compliance with confident plain-English answers
  • Recognize the nine frameworks that dominate GRC job descriptions
  • Distinguish a certification from an attestation from a law
  • Explain CMMC, FedRAMP and NIST RMF and who they apply to
  • Explain GDPR, Cyber Essentials, NIS 2 and DORA and who they apply to

What is inside

5 modules, 15 lessons. Each module ends in a graded quiz.

  1. 01

    What Is GRC, Really?

    Cybersecurity is not what the movies show, and GRC is the side of it most companies actually hire for. This module decodes cybersecurity in plain English, unpacks Governance, Risk, and Compliance with a bank-vault analogy, and walks you through a real Monday in the job. By the end, you will be able to explain GRC to your mum, your best friend, and a hiring manager, and they will all get it.

    3 lessons · 13 quiz questions

  2. 02

    The Framework Landscape

    Meet the 9 compliance frameworks every GRC Analyst sees on job adverts: what each one is for, who demands it, and why companies bother. You will not memorise control numbers this week. You will learn to recognise the names, match them to business scenarios, and explain the comparisons interviewers love.

    3 lessons · 13 quiz questions

  3. 03

    Certifications, Attestations & Laws

    ISO 27001 gives you a certificate. SOC 2 gives you a report. GDPR and HIPAA give you legal obligations. This module pulls those three things apart with the passport and report card analogy, drills the side-by-side comparison interviewers love, and hands you the exact sentences to say when they ask.

    3 lessons · 14 quiz questions

  4. 04

    US Federal Frameworks: RMF, FedRAMP & CMMC

    The US federal family in one module: the NIST Risk Management Framework and its seven steps to an ATO, FedRAMP as RMF applied to cloud services, and CMMC 2.0 as the DoD's enforcement of NIST 800-171. You will finish able to explain all three in plain English, connect them to each other, and name the jobs they create.

    3 lessons · 14 quiz questions

  5. 05

    UK & EU: GDPR, Cyber Essentials, NIS 2 & DORA

    The UK and EU rulebook in one module: how UK GDPR and EU GDPR differ in the ways interviewers actually probe, why Cyber Essentials is the MOT of cybersecurity, and how NIS 2 and DORA turned resilience into law. You will finish able to name the regulator, the fine, and the paperwork for each, and to say the two words that make you sound hired: Register of Information.

    3 lessons · 13 quiz questions