Skip to main content
FRAMEWORKS

Map once. Satisfy many.

A single control — multi-factor authentication on privileged access — maps to NIS2 Art. 21, DORA, ISO 27001 Annex A, NIST CSF 2.0, NIST SP 800-53, SOC 2 — and every other framework that asks for it — simultaneously.

EU Regulations

NIS2

EU directive, 27 national transpositions.

Learn more

DORA

Financial entities, ICT third-party risk.

Learn more

GDPR

Accountability principle, DPIAs, breach notification.

Learn more

EU AI Act

Risk-tiered AI obligations for providers and deployers.

Learn more

Cyber Resilience Act

Security-by-design, SBOM, 24h vulnerability reporting.

Learn more

Supply-Chain Risk

The cross-cutting theme across NIS2/DORA/CRA.

Learn more

US & International Standards

NIST CSF 2.0

Six functions, common crosswalk language.

Learn more

NIST SP 800-53

Federal control catalog, FedRAMP baselines.

Learn more

NIST AI RMF

Govern, Map, Measure, Manage for AI risk.

Learn more

SOC 2

Trust services criteria, Type I/II.

Learn more

CMMC

US Defense Industrial Base only.

Learn more

CIS Controls v8

18 controls, three Implementation Groups.

Learn more

ISO/IEC 27001:2022

ISMS requirements, Annex A controls.

Learn more

ISO/IEC 27002

Annex A implementation guidance.

Learn more

ISO/IEC 27005

Information security risk management.

Learn more

ISO 31000

Enterprise risk management principles.

Learn more

ISO/IEC 42001

Certifiable AI management system.

Learn more

ISO/IEC 23894

AI risk management guidance.

Learn more

ISO 22301

Business continuity management.

Learn more

ISO 27701

Privacy information management (PIMS).

Learn more

What "full depth" means on every page

Each framework page answers the same questions in the same order: the obligation in plain terms, who it applies to, the clock, what it asks in operating terms — mapped to where TruSecure answers it — and a labeled sample of the artifact you would actually inspect.

The frameworks do not just coexist. One control library serves them all, so the work done for one is evidence for the next: the supply-chain page shows how one register feeds every regime that references third-party risk, and the coverage matrix shows the whole map on one inspectable page.

Start where your supervisor is

If a specific regime named you — NIS2, DORA, the EU AI Act — start with its page: the obligation and the clock first, then where the controls answer it. If you carry several at once, the crosswalk is the point of the whole family: every framework below reads one control library, so the second regime costs evidence, not a second program.

The full coverage matrix

Every framework on one inspectable page — what kind of instrument it is, how deep this site goes on it, and all 27 NIS2 country transpositions.

See the coverage matrix