Coverage at a glance
Every Framework Mapped.
Every Control Connected.
179 compliance frameworks mapped to one control library, verified by 860 automated tests, updated every build.
Integration Landscape
By Module Type
By Category
Control Domain Distribution
Governance
44 controls1 integration feed evidence
Privacy
21 controls1 integration feed evidence
AI Governance
16 controls1 integration feed evidence
Data Protection
15 controls7 integrations feed evidence
IT Service Management
12 controls5 integrations feed evidence
Quality Management
10 controls1 integration feed evidence
Access Control
9 controls11 integrations feed evidence
Secure Development
9 controls3 integrations feed evidence
Application Controls
7 controls1 integration feed evidence
Business Continuity
7 controls2 integrations feed evidence
Monitoring
7 controls8 integrations feed evidence
Endpoint Security
6 controls8 integrations feed evidence
Incident Response
6 controls5 integrations feed evidence
Vendor Management
5 controls1 integration feed evidence
Network Security
4 controls35 integrations feed evidence
Risk Management
4 controls1 integration feed evidence
Configuration Management
3 controls1 integration feed evidence
Physical Security
3 controls1 integration feed evidence
Training & Awareness
3 controls2 integrations feed evidence
Vulnerability Management
3 controls5 integrations feed evidence
Cloud Security
2 controls4 integrations feed evidence
Asset Management
1 controls4 integrations feed evidence
Change Management
1 controls1 integration feed evidence
HR Security
1 controls1 integration feed evidence
How It All Connects
Avg controls per framework
Avg evidence specs per framework
Avg tests per integration
Control domains
Global Jurisdiction Coverage
International
US Federal
US State
Asia-Pacific
Latin America
Canada
Africa
All Frameworks
Showing 30 of 178 frameworks
HITRUST CSF
HITRUST CSF – Our Cybersecurity Framework
Secure Controls Framework (SCF)
Secure Controls Framework – SCF 2025.4 workbook
CMS Acceptable Risk Safeguards (ARS)
Acceptable Risk Safeguards 5.1x
CMS Information Systems Security & Privacy Policy (IS2P2) + CMS Acceptable Risk Safeguards (ARS)
CMS IS2P2 + CMS ARS current policy-and-standards source family
EU AI Act (Regulation (EU) 2024/1689)
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act)
NIST SP 800-53 Rev. 5
Electronic (OSCAL) Version of NIST SP 800-53 Rev 5.2.0 Controls and SP 800-53A Rev 5.2.0 Assessment Procedures
Australian ISM for IRAP and ASD
Information security manual (March 2026)
Australian Information Security Manual (ISM)
Information security manual (March 2026)
BSI IT Grundschutz (Grundschutz++)
Bundesamt für Sicherheit in der Informationstechnik (BSI)
TX-RAMP Control Baselines 2.0 (Aligned to NIST SP 800-53 Rev. 5)
Texas Department of Information Resources (DIR)
IRS Publication 1075 – Tax Information Security Guidelines for Federal, State and Local Agencies
Internal Revenue Service
FFIEC Cybersecurity Assessment Tool (CAT)
Federal Financial Institutions Examination Council (FFIEC)
SAMA Cyber Security Framework
SAMA Cyber Security Framework official PDF (Version 1.0, May 2017) with live SAMA rulebook in-force verification
Secure Controls Framework (SCF) – EU GDPR mapping / STRM
NIST IR 8477-Based Set Theory Relationship Mapping (STRM) – Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR)
StateRAMP Baseline Controls for Authorization (Authorized – Low & Moderate)
GovRAMP (formerly StateRAMP)
CMS ARC-AMPE – ACA Administering Entity Mandatory Baseline
ARC-AMPE Volume II System Security and Privacy Plan for ACA Administering Entities
FedRAMP Security Controls Baseline (High) - NIST SP 800-53 Rev. 5
FedRAMP (U.S. General Services Administration)
CMS MARS-E v2.2 – Minimum Acceptable Risk Standards for Exchanges
Centers for Medicare & Medicaid Services
Cybersecurity Capability Maturity Model
U.S. Department of Energy
Australian Energy Sector Cyber Security Framework (AESCSF)
Australian Energy Sector Cyber Security Framework – current official program page with operative V2 Full Assessment requirement corpus
OWASP Application Security Verification Standard (ASVS)
OWASP Foundation
EASA Part-IS
Easy Access Rules for Information Security (Regulations (EU) 2023/203 and 2022/1645)
FedRAMP Security Controls Baseline (Moderate) - NIST SP 800-53 Rev. 5
FedRAMP (U.S. General Services Administration)
ETSI EN 319 401
ETSI EN 319 401 V3.2.1 (2026-01) – Electronic Signatures and Trust Infrastructures (ESI); General Policy Requirements for Trust Service Providers
Cyber Risk Institute Profile (CRI)
Cyber Risk Institute
Adobe Common Controls Framework (Adobe CCF)
Adobe Common Controls Framework (Adobe CCF) trust center source set
AWS Well-Architected Framework
AWS Well-Architected Framework core source family
ASD Essential Eight
Essential Eight Maturity Model (November 2023)
IRS Publication 4812 Contractor Security & Privacy Controls
Internal Revenue Service
Dubai Information Security Regulation (ISR)
Information Security Regulation (ISR)