Skip to main content
FRAMEWORKS

Coverage you can inspect, not a logo wall.

Every framework below has its own full-depth page on this site — the requirements, the timeline, and how one control model satisfies it alongside everything else you carry. Click any row.

FrameworkKindCoverage on this site
NIS2EU directiveFull depth · 27 country pages · incident reporting
DORAEU regulationFull depth
GDPREU regulationFull depth
EU AI ActEU regulationFull depth
Cyber Resilience ActEU regulationFull depth
Supply-Chain RiskCross-cutting themeFull depth
NIST CSF 2.0US frameworkFull depth
NIST SP 800-53US control catalogueFull depth
NIST AI RMFUS frameworkFull depth
SOC 2Attestation (AICPA)Full depth
CMMCUS certification programFull depth
CIS Controls v8BaselineFull depth
ISO/IEC 27001International standardFull depth
ISO/IEC 27002International standardFull depth
ISO/IEC 27005International standardFull depth
ISO 31000International standardFull depth
ISO/IEC 42001International standardFull depth
ISO/IEC 23894International standardFull depth
ISO 22301International standardFull depth
ISO 27701International standardFull depth
OpenAISFOpen standard — written in-house at TruSecureFull specification at openaisf.org

NIS2, twenty-seven times over

NIS2 is a directive — each member state transposes it into its own law, with its own authority, its own deadlines and its own wrinkles. Every transposition has its own page here.

How to read the matrix

The Kind column tells you what the instrument is — a regulation you must satisfy, a standard you can be certified against, a baseline you adopt. The distinction is operational, not academic: regulations carry deadlines and supervisors; standards carry audit and certification routes; baselines carry neither, but shape what both ask for.

Every row links to a page held to one depth standard — the obligation in plain terms, who it applies to, the clock, and where TruSecure answers it. The OpenAISF row is deliberately different: it is an open standard written in-house at TruSecure, and its full specification lives at openaisf.org rather than on this site.

Why breadth matters less than overlap

Twenty frameworks is not twenty programs. Each control in TruSecure's library is cited by every framework that asks for it — so NIS2's access-control requirement, ISO 27001's Annex A and SOC 2's CC6 are one piece of work, evidenced once. The matrix above is the map; the control library is the territory.