Canonical controls map to each framework’s requirements through versioned mappings you can review. Add a framework and see straight away what you already meet and what is missing.
Information security
ISO/IEC 27001
The international standard for an information security management system, with its Annex A controls mapped to your canonical controls.
Statement of Applicability kept current from your records, and downloadable
Risk treatment linked to the controls that reduce each risk
Evidence ready for your certification body
Service organisations
SOC 2
The Trust Services Criteria your customers ask about, mapped to the same controls you already run.
Controls tested continuously, not once before the audit
Evidence with its provenance in a scoped auditor workspace
Findings closed only when a test proves the fix
UK government-backed
Cyber Essentials
The UK scheme’s five technical themes: firewalls, secure configuration, user access control, malware protection and security update management.
Checks from your cloud, identity and code accounts
The same controls count towards ISO 27001 and SOC 2
Gaps shown as findings you can assign
Data protection
UK GDPR
Accountability for personal data: records of processing, impact assessments, data-subject rights and security of processing.
Processing records and DPIAs linked to your systems
Data-subject requests tracked against deadlines
Security of processing shown by tested controls
AI management
ISO/IEC 42001
The standard for an AI management system, alongside a registry of the AI systems and agents you run.
AI systems and agents registered with owners and purpose
Risk classes informed by the EU AI Act
Human approval for sensitive actions
US healthcare
HIPAA Security Rule
The administrative, physical and technical safeguards for electronic health information, mapped to the controls you already run.
Risk analysis, workforce security and contingency planning
Access, audit, integrity and transmission safeguards
Business associate arrangements through vendor management
Payment cards
PCI DSS
The twelve principal requirements of PCI DSS v4.0.1 for anyone who stores, processes or transmits cardholder data.
Secure configuration, network controls and malware protection
Account data protected at rest and in transit
Access, logging and regular security testing
EU financial services
DORA
The EU Digital Operational Resilience Act: ICT risk management, incident handling, resilience testing and ICT third-party risk.
ICT risk framework and asset identification
Incident management and major-incident reporting
ICT third-party risk and contractual provisions
AI risk
NIST AI RMF
The NIST AI Risk Management Framework: govern, map, measure and manage the risks of the AI systems you build or use.
AI policies and accountability
Context and impacts of each AI system
Evaluation, monitoring and documented treatment
Framework builder
Your own frameworks
Contracts, customer requirements and internal standards, built as versioned frameworks and mapped into the same record.
Versioned, so changes are reviewable
Mapped to existing controls: see what you already meet
Reported like any other framework
How the Mapping Works
You run one set of controls, such as “privileged access is restricted and protected by MFA”. Each control maps to the requirements it satisfies in every framework. Test it once and the result counts everywhere it applies. Mappings are versioned, so a change to a mapping is itself reviewable.
Ready to prove it?
Know what you are responsible for, control whether it works, and prove it to anyone who asks.