Skip to main content
PLATFORM · FRAMEWORK CROSSWALKS

One control. Every framework it satisfies.

Most governance tooling treats every framework as its own control set: NIS2 in one module, ISO 27001 in another, SOC 2 in a spreadsheet. The same safeguard gets implemented once and then documented three, four, six times — and the documents drift apart.

TruSecure models controls independently of frameworks. A framework is a citation list pointing at controls, not a separate control set. One control — "multi-factor authentication enforced for all privileged access" — carries citations to NIS2 Art. 21(2)(j), DORA's ICT risk chapter, ISO 27001 Annex A, NIST CSF 2.0's Protect function, NIST SP 800-53 IA-2, and SOC 2's security criteria simultaneously — and to every other framework that asks the same question. One piece of evidence satisfies them all.

How it works

  1. Model the control once

    Each control has one operational definition — what it means in a running system, not what an annex paragraph says about it.

  2. Attach the citations

    Every framework clause the control satisfies is attached as a citation. The mapping is curated by TruSecure and versioned when frameworks change.

  3. Let evidence fan out

    Evidence collected against the control automatically counts toward every citation on it. Assess once; comply many.

  4. Absorb new frameworks

    When a new regime lands — or a transposition changes — the work is a new citation set on existing controls, not a new control programme.

What a crosswalk looks like

One control card, every framework it satisfies hanging off it — this is the architecture drawn, not asserted:

One control · One piece of evidence
MFA on all privileged access
NIS2 ART. 21(2)(J)
DORA ART. 9
ISO 27001 A.8.5
NIST CSF PR.AA
SOC 2 CC6.1
CIS CONTROL 6
⋯ AND EVERY OTHER

One control. One piece of evidence. Every framework citation it satisfies — that's the architecture, not a slogan.

And the same structure in register form — the view an auditor works from:

Crosswalk excerpt · illustrative
ControlNIS2ISO 27001DORA
MFA enforced for all privileged accessArt. 21(2)(j)A.8.5Art. 9
Access rights provisioned, reviewed, revokedArt. 21(2)(i)A.5.18Art. 9
Incident detection and handlingArt. 21(2)(b)A.5.24Art. 17
Supply-chain security policyArt. 21(2)(d)A.5.19Art. 28

Where the citations come from

TruSecure maintains the crosswalk as versioned content: when ISO revises an annex or a member state transposes NIS2 with a national twist, the citation set is updated centrally and the change lands in your control model as a reviewable proposal — not as a gap-analysis project you commission separately.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.