References & Resources

Standards, frameworks, and tools referenced across Structured For Growth - curated for developers, compliance teams, and security professionals.

🌐 Web Standards & Specifications

W3C WCAG 2.2

Web Content Accessibility Guidelines - the international standard for making web content accessible to people with disabilities.

w3.org

W3C WAI-ARIA

Accessible Rich Internet Applications - defines semantics for UI widgets, structures, and behaviors to improve accessibility.

w3.org

HTML Living Standard

The continuously-updated specification for HTML maintained by WHATWG - the definitive reference for HTML elements and APIs.

html.spec.whatwg.org

CSS Specifications

W3C CSS specifications hub - the authoritative source for all CSS modules, from layout to animations.

w3.org

🏛️ Federal & Government Standards

digital.gov

GSA's hub for digital government guidance - best practices for federal web teams on design, content, and technology.

digital.gov

U.S. Web Design System (USWDS)

A design system of principles, guidance, and code to build accessible, mobile-friendly federal government websites.

designsystem.digital.gov

Section 508

Federal accessibility requirements for ICT - ensures technology is accessible to people with disabilities.

section508.gov

NIST SP 800-53

Security and privacy controls for information systems - the comprehensive catalog of controls used across federal agencies.

csrc.nist.gov

NIST SP 800-171r3

Protecting Controlled Unclassified Information (CUI) in nonfederal systems - required for defense contractors.

csrc.nist.gov

NIST AI RMF

AI Risk Management Framework playbook - voluntary guidance for managing risks in AI system design, development, and deployment.

airc.nist.gov

FedRAMP

Federal Risk and Authorization Management Program - standardized approach to cloud security assessment for government use.

fedramp.gov

CMMC

Cybersecurity Maturity Model Certification - DoD framework ensuring defense contractors meet cybersecurity requirements.

dodcio.defense.gov

Compliance Frameworks

SOC 2

Service Organization Control 2 - audit framework for service providers covering security, availability, processing integrity, confidentiality, and privacy.

aicpa-cima.com

ISO 27001

International standard for information security management systems (ISMS) - the global benchmark for security governance.

iso.org

ISO 42001 (AI Management)

International standard for AI management systems - provides requirements for responsible AI development and deployment.

iso.org

HIPAA

Health Insurance Portability and Accountability Act - U.S. regulations for protecting health information privacy and security.

hhs.gov

GDPR

General Data Protection Regulation - EU regulation governing data protection, privacy rights, and cross-border data transfers.

gdpr.eu

PCI DSS

Payment Card Industry Data Security Standard - requirements for organizations handling credit card data.

pcisecuritystandards.org

DORA

Digital Operational Resilience Act - EU regulation for ICT risk management in the financial sector.

digital-operational-resilience-act.com

NIS 2

EU Network and Information Security Directive - cybersecurity requirements for essential and important entities across member states.

digital-strategy.ec.europa.eu

OSCAL

Open Security Controls Assessment Language - NIST standard for machine-readable security control catalogs and assessment results.

pages.nist.gov

🔒 Security

OWASP Top 10

The most critical web application security risks - the industry-standard awareness document for developers and security teams.

owasp.org

OWASP Secure Headers

Best practices for HTTP security response headers - CSP, HSTS, X-Frame-Options, and more.

owasp.org

OWASP Cheat Sheet Series

Concise, actionable security guidance for developers - covering authentication, injection prevention, session management, and more.

cheatsheetseries.owasp.org

Mozilla Observatory

Free website security scanner by Mozilla - grades your site on HTTP headers, TLS configuration, and security best practices.

observatory.mozilla.org

Security Headers

Analyze and grade HTTP security headers for any website - quick validation of header configuration.

securityheaders.com

Performance & SEO

web.dev - Core Web Vitals

Google's essential metrics for web performance - LCP, FID/INP, and CLS explained with optimization guidance.

web.dev

Google Search Central

Official Google documentation for search optimization - crawling, indexing, structured data, and ranking guidance.

developers.google.com

Schema.org

Shared vocabulary for structured data markup - used by Google, Bing, and other search engines for rich results.

schema.org

Lighthouse

Automated auditing tool for performance, accessibility, SEO, and best practices - built into Chrome DevTools.

developer.chrome.com

🛠️ Development Tools & Frameworks

Vite

Next-generation frontend build tool - blazing fast HMR and optimized production builds with native ES modules.

vitejs.dev

Express.js

Minimal and flexible Node.js web application framework - the de facto standard for building APIs and web servers.

expressjs.com

React

JavaScript library for building user interfaces - component-based architecture with declarative rendering.

react.dev

Next.js

Full-stack React framework with server-side rendering, static generation, and API routes built in.

nextjs.org

Unreal Engine

Industry-leading real-time 3D creation tool for games, simulations, and interactive experiences.

unrealengine.com

GitHub Actions

CI/CD and workflow automation platform - automate builds, tests, and deployments directly from GitHub repositories.

docs.github.com

CodeQL

Semantic code analysis engine by GitHub - find vulnerabilities across codebases with query-based static analysis.

codeql.github.com

OWASP ZAP

Free open-source web application security scanner - dynamic testing (DAST) for finding vulnerabilities in running applications.

zaproxy.org

Snyk

Developer-first security platform - find and fix vulnerabilities in dependencies, containers, and infrastructure as code.

snyk.io

Accessibility Resources

USWDS Accessibility

Accessibility guidance from the U.S. Web Design System - practical implementation patterns for federal compliance.

designsystem.digital.gov

Inclusive Design Principles

Seven principles for designing inclusive digital experiences - provide comparable experience, consider situation, be consistent.

inclusivedesignprinciples.info

A11Y Project

Community-driven accessibility resource hub - checklists, patterns, and guides for building accessible websites.

a11yproject.com

WebAIM

Web accessibility evaluation and training organization - home of the WAVE tool and contrast checker.

webaim.org

Deque axe

Industry-standard accessibility testing engine - automated detection of WCAG violations in browsers and CI pipelines.

deque.com

🎨 Design & UX

USWDS Components

Ready-to-use accessible UI components - buttons, forms, alerts, navigation, and more for federal websites.

designsystem.digital.gov

USWDS Design Tokens

Design tokens for color, spacing, typography, and more - the foundation of USWDS's consistent design language.

designsystem.digital.gov

Material Design

Google's open-source design system - Material 3 with dynamic color, updated components, and adaptive design guidance.

m3.material.io

Inclusive Components

A pattern library of accessible component designs - practical, inclusive approaches to common UI patterns.

inclusive-components.design

Building Something Compliant?

Structured For Growth implements these standards into production-ready, audit-proof solutions. Let's build it right.

Get in Touch