Platform/Frameworks

Compliance frameworks,
natively mapped.

Fourteen frameworks ship with control mappings and evidence types, cross-walked to each other so one signal satisfies every control that depends on it. Custom frameworks live next to them with the same control model.

14
Frameworks mapped
5
Public cross-walks seeded
Custom
Frameworks supported
0
Certifications held by us
Coverage matrix

Every framework. Every control.

Mapping is bidirectional: pair-wise cross-walks are seeded from published crosswalks (NIST 800-53 ↔ SOC 2, ISO 27001 ↔ NIST 800-53, PCI DSS v4 ↔ NIST 800-53, NIST 800-53 ↔ FedRAMP, NIS2 ↔ DORA) and the transitive closure is computed on demand. SecurityVault maps your controls; it holds no certification of its own.

FrameworkVersionStatus
SOC 2AICPA TSC 2017 (rev. 2022)Mapped
ISO/IEC 270012022Mapped
NIST SP 800-53Rev. 5Mapped
NIST CSF2.0Mapped
PCI DSSv4.0Mapped
HIPAA Security Rule45 CFR 164Mapped
GDPREU 2016/679 · article mappingMapped
CCPA / CPRACaliforniaMapped
CIS Controlsv8Mapped
NIS2EU 2022/2555Mapped
DORAEU 2022/2554Mapped
SOX ITGCIT general controlsMapped
FedRAMPModerate baseline · mapping onlyMapped
HECVATv3Mapped
CustomYour own controls · preventive / detective / corrective / compensatingSupported
Mapping engine

One signal. Many frameworks.

Evidence is collected once, then projected against every framework that requires it.

01

Signal collection

Scanners, cloud APIs, and identity systems emit signals into a unified evidence stream. Each carries a hash, a source, and a UTC timestamp.

02

Control mapping

Each framework control declares the signals that satisfy it. A single SOC 2 CC6.1 signal also satisfies ISO A.9.2 and PCI 7.1 — no duplicate work.

03

Auditor projection

At audit time, the projector renders the evidence package per framework: control narrative, signed evidence, sample period, exceptions log.

Custom frameworks

Bring your own controls.

Internal standards, regulator-specific obligations, supplier requirements — defined with the same control model as the shipped frameworks and cross-walked into them.

Framework as code

Custom frameworks are first-class: same control types, same evidence frequencies, same auditor portal and the same cross-walk graph as the shipped frameworks. Add an equivalence edge and every mapped signal flows into your control.

  • Reuse evidence from shipped frameworks
  • Cross-walk to any shipped framework
  • Per-control type, owner and evidence frequency
  • Managed through the API and the GRC console
# custom framework · control definition
framework_id: internal-2026
control_id: CC-INT-01
title: Customer key isolation
control_type: preventive   # detective · corrective · compensating
evidence_frequency: continuous   # daily · weekly · monthly
evidence_sources:
  - cloud.kms.key_segregation
  - tenant.boundary_test
cross_walk:
  - SOC2:CC6.1
  - ISO27001:A.8.24
Evidence, not spreadsheets

Hand the auditor
signed evidence.

See how a scan result becomes evidence for a control, and how the auditor portal exposes it read-only with signed access.