Skip to main content
TruSecure — Home
PLATFORM · FRAMEWORK CROSSWALKS

One control. Every framework it satisfies.

Most governance tooling treats every framework as its own control set: NIS2 in one module, ISO 27001 in another, SOC 2 in a spreadsheet. The same safeguard gets implemented once and then documented three, four, six times — and the documents drift apart.

TruSecure models controls independently of frameworks. A framework is a citation list pointing at controls, not a separate control set. One control — "multi-factor authentication enforced for all privileged access" — carries citations to NIS2 Art. 21(2)(j), DORA's ICT risk chapter, ISO 27001 Annex A, NIST CSF 2.0's Protect function, NIST SP 800-53 IA-2, and SOC 2's security criteria simultaneously. One piece of evidence satisfies all six.

How it works

  1. Model the control once

    Each control has one operational definition — what it means in a running system, not what an annex paragraph says about it.

  2. Attach the citations

    Every framework clause the control satisfies is attached as a citation. The mapping is curated by TruSecure and versioned when frameworks change.

  3. Let evidence fan out

    Evidence collected against the control automatically counts toward every citation on it. Assess once; comply many.

  4. Absorb new frameworks

    When a new regime lands — or a transposition changes — the work is a new citation set on existing controls, not a new control programme.

What a crosswalk looks like

One control card, every framework it satisfies hanging off it — this is the architecture drawn, not asserted:

One control · One piece of evidence
MFA on all privileged access
NIS2 ART. 21(2)(J)
DORA ART. 9
ISO 27001 A.8.5
NIST CSF PR.AA
SOC 2 CC6.1
CIS CONTROL 6

Six citations. One control. One piece of evidence. That's the architecture, not a slogan.

And the same structure in register form — the view an auditor works from:

Crosswalk excerpt · illustrative
ControlNIS2ISO 27001DORA
MFA enforced for all privileged accessArt. 21(2)(j)A.8.5Art. 9
Access rights provisioned, reviewed, revokedArt. 21(2)(i)A.5.18Art. 9
Incident detection and handlingArt. 21(2)(b)A.5.24Art. 17
Supply-chain security policyArt. 21(2)(d)A.5.19Art. 28

Where the citations come from

TruSecure maintains the crosswalk as versioned content: when ISO revises an annex or a member state transposes NIS2 with a national twist, the citation set is updated centrally and the change lands in your control model as a reviewable proposal — not as a gap-analysis project you commission separately.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.