Frameworks

Implement Once. Satisfy Many.

Canonical controls map to each framework’s requirements through versioned mappings you can review. Add a framework and see straight away what you already meet and what is missing.

Information security

ISO/IEC 27001

The international standard for an information security management system, with its Annex A controls mapped to your canonical controls.

  • Statement of Applicability kept current from your records, and downloadable
  • Risk treatment linked to the controls that reduce each risk
  • Evidence ready for your certification body

Service organisations

SOC 2

The Trust Services Criteria your customers ask about, mapped to the same controls you already run.

  • Controls tested continuously, not once before the audit
  • Evidence with its provenance in a scoped auditor workspace
  • Findings closed only when a test proves the fix

UK government-backed

Cyber Essentials

The UK scheme’s five technical themes: firewalls, secure configuration, user access control, malware protection and security update management.

  • Checks from your cloud, identity and code accounts
  • The same controls count towards ISO 27001 and SOC 2
  • Gaps shown as findings you can assign

Data protection

UK GDPR

Accountability for personal data: records of processing, impact assessments, data-subject rights and security of processing.

  • Processing records and DPIAs linked to your systems
  • Data-subject requests tracked against deadlines
  • Security of processing shown by tested controls

AI management

ISO/IEC 42001

The standard for an AI management system, alongside a registry of the AI systems and agents you run.

  • AI systems and agents registered with owners and purpose
  • Risk classes informed by the EU AI Act
  • Human approval for sensitive actions

US healthcare

HIPAA Security Rule

The administrative, physical and technical safeguards for electronic health information, mapped to the controls you already run.

  • Risk analysis, workforce security and contingency planning
  • Access, audit, integrity and transmission safeguards
  • Business associate arrangements through vendor management

Payment cards

PCI DSS

The twelve principal requirements of PCI DSS v4.0.1 for anyone who stores, processes or transmits cardholder data.

  • Secure configuration, network controls and malware protection
  • Account data protected at rest and in transit
  • Access, logging and regular security testing

EU financial services

DORA

The EU Digital Operational Resilience Act: ICT risk management, incident handling, resilience testing and ICT third-party risk.

  • ICT risk framework and asset identification
  • Incident management and major-incident reporting
  • ICT third-party risk and contractual provisions

AI risk

NIST AI RMF

The NIST AI Risk Management Framework: govern, map, measure and manage the risks of the AI systems you build or use.

  • AI policies and accountability
  • Context and impacts of each AI system
  • Evaluation, monitoring and documented treatment

Framework builder

Your own frameworks

Contracts, customer requirements and internal standards, built as versioned frameworks and mapped into the same record.

  • Versioned, so changes are reviewable
  • Mapped to existing controls: see what you already meet
  • Reported like any other framework

How the Mapping Works

You run one set of controls, such as “privileged access is restricted and protected by MFA”. Each control maps to the requirements it satisfies in every framework. Test it once and the result counts everywhere it applies. Mappings are versioned, so a change to a mapping is itself reviewable.

Ready to prove it?

Know what you are responsible for, control whether it works, and prove it to anyone who asks.

Use your Invitation