Policy-to-Control Mapping
Map your policies across 9 compliance frameworks with cross-framework overlap analysis.
Select Compliance Frameworks
Choose the frameworks you need to comply with. Select multiple to see cross-framework overlaps.
NIST CSF 2.0
Cybersecurity Framework — Govern, Identify, Protect, Detect, Respond, Recover
ISO 27001:2022
Information Security Management — Annex A controls (A.5–A.8)
SOC 2 Type II
Trust Services Criteria — CC1 through CC9 + availability, PI, confidentiality
PCI DSS 4.0
Payment Card Industry — 12 requirements for cardholder data protection
DORA (EU)
Digital Operational Resilience Act — ICT risk management for financial entities
NIS2 Directive (EU)
Network and Information Security — cybersecurity obligations for essential/important entities
HIPAA
Health Insurance Portability — Privacy, Security, and Breach Notification Rules
EU AI Act
AI System regulation — risk-based requirements (Art 6–52)
GDPR
General Data Protection Regulation — data protection by design (Art 5–49)