Coverage you can inspect, not a logo wall.
Every framework below has its own full-depth page on this site — the requirements, the timeline, and how one control model satisfies it alongside everything else you carry. Click any row.
| Framework | Kind | Coverage on this site |
|---|---|---|
| NIS2 | EU directive | Full depth · 27 country pages · incident reporting |
| DORA | EU regulation | Full depth |
| GDPR | EU regulation | Full depth |
| EU AI Act | EU regulation | Full depth |
| Cyber Resilience Act | EU regulation | Full depth |
| Supply-Chain Risk | Cross-cutting theme | Full depth |
| NIST CSF 2.0 | US framework | Full depth |
| NIST SP 800-53 | US control catalogue | Full depth |
| NIST AI RMF | US framework | Full depth |
| SOC 2 | Attestation (AICPA) | Full depth |
| CMMC | US certification program | Full depth |
| CIS Controls v8 | Baseline | Full depth |
| ISO/IEC 27001 | International standard | Full depth |
| ISO/IEC 27002 | International standard | Full depth |
| ISO/IEC 27005 | International standard | Full depth |
| ISO 31000 | International standard | Full depth |
| ISO/IEC 42001 | International standard | Full depth |
| ISO/IEC 23894 | International standard | Full depth |
| ISO 22301 | International standard | Full depth |
| ISO 27701 | International standard | Full depth |
| OpenAISF | Open standard — written in-house at TruSecure | Full specification at openaisf.org |
NIS2, twenty-seven times over
NIS2 is a directive — each member state transposes it into its own law, with its own authority, its own deadlines and its own wrinkles. Every transposition has its own page here.
How to read the matrix
The Kind column tells you what the instrument is — a regulation you must satisfy, a standard you can be certified against, a baseline you adopt. The distinction is operational, not academic: regulations carry deadlines and supervisors; standards carry audit and certification routes; baselines carry neither, but shape what both ask for.
Every row links to a page held to one depth standard — the obligation in plain terms, who it applies to, the clock, and where TruSecure answers it. The OpenAISF row is deliberately different: it is an open standard written in-house at TruSecure, and its full specification lives at openaisf.org rather than on this site.
Why breadth matters less than overlap
Twenty frameworks is not twenty programs. Each control in TruSecure's library is cited by every framework that asks for it — so NIS2's access-control requirement, ISO 27001's Annex A and SOC 2's CC6 are one piece of work, evidenced once. The matrix above is the map; the control library is the territory.