Skip to main content
FRAMEWORK PACKS

Real framework packs, on day one.

A framework pack is the mapping and obligation model for a specific regulation or standard — built on the same control library used everywhere else. Community Edition ships with real framework packs on a standard release cadence.

What a pack contains

Each pack carries the obligations a framework imposes, mapped onto controls in the shared library through citation links — never a parallel set of framework-specific controls. Install a second pack and its requirements resolve onto controls you already have, which is what makes multi-framework programs tractable: one implementation, many citations.

Packs are versioned artifacts, not database states: install one, update it when a release lands, and hold the set you run in version control alongside the rest of your configuration. Adding or updating a pack is a documented operation, the same for a self-hoster as for anyone else.

Community Edition and TruSecure GRC

Community Edition packs update on the standard release cadence. TruSecure GRC adds premium regulatory updates — faster-turnaround pack updates when a regulation changes — as a paid, managed service. The mappings themselves come from the same source either way; the difference is how quickly a transposition change reaches your instance, and who does the updating.

When a pack update lands, it arrives as a reviewable change against the controls it cites — never a silent rewrite of your control model. You see what moved, what it touches, and what it obligates before the update is applied.

See which framework packs are included

Frequently Asked Questions

What are framework packs?
The framework mappings as standalone, inspectable data — the citation of each framework’s obligations against the shared control library.
Which frameworks have packs?
The packs track the frameworks the platform covers — NIS2 and its national transpositions, DORA, GDPR, ISO 27001 and the rest of the coverage list.
Can I audit the mappings?
That is the point of publishing them: every mapping is inspectable data under FSL-1.1-ALv2, not an assertion.