Framework library
305 controls across 10 frameworks. Every control carries its requirement, the signals the gap-analysis engine looks for, the evidence an auditor will ask for, and topic tags that crosswalk it to the other frameworks.
EU General Data Protection Regulation
European Union · Regulation (EU) 2016/679, in force since 25 May 2018
The obligations of the EU General Data Protection Regulation most often examined in a policy review or audit, expressed as controls — one per article (or tightly linked group of articles), each citing the article it derives from. UK GDPR mirrors these obligations; where the UK differs, the control says so.
How to read this framework
GDPR is law, not a control framework: an obligation cannot be marked 'not applicable' because it is inconvenient, only because the processing it governs does not occur (for example Article 8 if no service is offered to children, or Article 27 if the organisation is established in the EU). Requirement text is paraphrased for assessment purposes — the articles themselves are authoritative, and this tool is not legal advice. UK GDPR (the retained version, as amended by the Data (Use and Access) Act 2025) follows the same article numbering; the supervisory authority is the ICO.
California Consumer Privacy Act, as amended by the CPRA
California Privacy Protection Agency (CPPA) and the California Attorney General · Cal. Civ. Code §1798.100 et seq. (CPRA amendments in force since 1 January 2023); CCPA Regulations, Cal. Code Regs. tit. 11, §7000 et seq., including the risk-assessment, cybersecurity-audit and ADMT rules effective 1 January 2026
The duties of the California Consumer Privacy Act as amended by the California Privacy Rights Act, and the CPPA's regulations, expressed as controls. Each cites the Civil Code section or regulation it derives from. Employee and business-contact data are in scope.
How to read this framework
Many other US states now have comprehensive privacy laws modelled on similar ideas (opt-outs of sale and targeted advertising, sensitive-data consent, universal opt-out signals); a CCPA-ready programme covers much, but not all, of them. Dates and thresholds are as published by the CPPA; the monetary threshold is CPI-adjusted every odd-numbered year. Requirement text is paraphrased; the statute and regulations are authoritative and this tool is not legal advice.
SOC 2 (Trust Services Criteria)
AICPA · 2017 TSC, revised 2022
The Trust Services Criteria underpinning a SOC 2 examination. The Common Criteria (CC1–CC9) are mandatory for every report; Availability, Confidentiality, Processing Integrity and Privacy are optional categories a service organisation may add.
How to read this framework
SOC 2 is an attestation against criteria, not a certification against a fixed control list. Auditors expect the organisation to describe its own controls and then demonstrate they operate. Requirement text below is paraphrased; cite the AICPA source for audit work.
ISO/IEC 27001:2022 — Annex A controls
ISO/IEC · 2022 (Annex A restructured from 114 to 93 controls)
A selected subset of the 93 Annex A controls of ISO/IEC 27001:2022, grouped into the four 2022 themes: Organisational (A.5), People (A.6), Physical (A.7) and Technological (A.8).
How to read this framework
Certification is against the clause 4–10 management system, with Annex A used to justify inclusions and exclusions in the Statement of Applicability. A control marked 'not applicable' with a documented rationale is a valid outcome, which this tool records as an explicit exclusion rather than a gap. Requirement text is paraphrased; the standard itself is copyright ISO.
PCI DSS v4.0.1 (Payment Card Industry Data Security Standard)
PCI Security Standards Council · v4.0.1, June 2024 (all future-dated v4.0 requirements mandatory since 31 March 2025)
The requirements of the Payment Card Industry Data Security Standard most often examined for merchants and service providers, grouped under the standard's twelve principal requirements. Each control cites the requirement numbers it derives from.
How to read this framework
PCI DSS is a contractual standard enforced through acquirers and card brands, not a law. What applies depends on how you accept cards and your validation level (SAQ type or ROC): a merchant that fully outsources payment pages may be in scope for only a handful of these requirements — mark the rest not applicable with that reason. Requirement text is paraphrased; the standard itself, available free from the PCI SSC, is authoritative.
HIPAA Security Rule (and selected Breach Notification Rule duties)
US Department of Health and Human Services, Office for Civil Rights · 45 CFR Part 164 Subparts C and D
Administrative, physical and technical safeguards of the HIPAA Security Rule, plus the organisational requirements and the core Breach Notification Rule duties. Applies to covered entities and, since the HITECH Act, directly to business associates.
How to read this framework
Each standard is marked Required (R) or Addressable (A). Addressable does not mean optional: the entity must implement the specification, or document why it is not reasonable and appropriate and implement an equivalent alternative. This tool records that documented-alternative path explicitly, because treating 'addressable' as 'skip' is the single most common HIPAA finding.
Gramm-Leach-Bliley Act — FTC Safeguards Rule and Privacy Rule
US Federal Trade Commission (Safeguards Rule); CFPB (Regulation P) · 16 CFR Part 314 as amended 2021 and 2023 (FTC notification duty in force since 13 May 2024); Regulation P, 12 CFR Part 1016
The FTC Safeguards Rule's required elements of a written information security program, plus the core privacy notice and opt-out duties of the GLBA Privacy Rule. Each control cites the paragraph it derives from.
How to read this framework
Institutions that maintain customer information about fewer than 5,000 consumers are exempt from 314.4(b)(1) (written risk assessment), (d)(2) (penetration testing and vulnerability assessments), (h) (written incident response plan) and (i) (annual board report) under 16 CFR 314.6 — mark those not applicable with that reason. Banks follow the equivalent Interagency Guidelines rather than the FTC rule. Requirement text is paraphrased; the regulation is authoritative and this tool is not legal advice.
Children's Online Privacy Protection Rule (COPPA)
US Federal Trade Commission · 16 CFR Part 312, as amended April 2025 (effective 23 June 2025; compliance with the amendments required by 22 April 2026)
The duties of the FTC's COPPA Rule, including the 2025 amendments on separate consent for third-party disclosure, written information security programs and written data retention policies. Each control cites the section it derives from.
How to read this framework
If the service is not directed to children and has no actual knowledge of collecting from under-13s, most of these controls are not applicable — record that assessment under 312.2-312.3. FTC-approved safe harbor programmes (312.11) offer an alternative route to demonstrate compliance. Requirement text is paraphrased; the regulation is authoritative and this tool is not legal advice.
NIST Cybersecurity Framework 2.0
NIST (US Department of Commerce) · 2.0, February 2024
Selected subcategories across the six CSF 2.0 Functions: Govern (GV), Identify (ID), Protect (PR), Detect (DE), Respond (RS) and Recover (RC). Govern is new in 2.0 and is the function most organisations are weakest on.
How to read this framework
CSF is a voluntary framework organised around outcomes, not a prescriptive control list, and is intended to be tailored to an organisation's risk profile. Subcategory text is paraphrased.
Nigeria Data Protection Act 2023
Nigeria Data Protection Commission (NDPC) · Act No. 37 of 2023, assented 12 June 2023
Core obligations of the Nigeria Data Protection Act 2023, which replaced the NITDA Data Protection Regulation 2019 and established the NDPC as an independent regulator. Included because Nigeria-facing products frequently have to satisfy both NDPA and GDPR, and the two diverge in ways that matter — notably registration of data controllers of major importance and the Nigerian data-transfer regime.
How to read this framework
Section references are to the Act as assented (Act No. 37 of 2023). Where a duty comes from the NDPC's General Application and Implementation Directive (GAID) 2025 rather than the Act itself, the control ID says so. Requirement text is paraphrased for assessment purposes and is not legal advice; the NDPC continues to issue subsidiary guidance that refines several of these duties.
Controls that overlap across frameworks
topics appearing in three or more frameworksThe crosswalk is computed from a shared topic vocabulary rather than a hand-maintained pairwise map, so adding a framework wires it into every crosswalk at once. These are the highest-leverage places to spend effort: one artefact answers controls in several frameworks.
Topic vocabulary
Every tag in use, weighted by the severity of the controls that carry it.