← GRC Hub

Cross-framework Control Crosswalk

Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.

Dataset v1.0.0 · reviewed 2026-06-10 · methodology & method hierarchy →

gdpr_security · art28 — Processor (Art. 28)

iso_27001_2022

  • A.5.20 — Addressing information security in supplier agreements (strong, editorial): Processor contract clauses.
  • A.5.19 — Information security in supplier relationships (exact, editorial): Supplier relationships.

dora_level1

  • art30 — Key contractual provisions (partial, editorial): Contractual clauses — financial sector parallel.

nist_csf_2_0

  • GV.SC-05 — Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties. (strong, editorial): Processor contracts mirror supply chain requirements.
  • GV.SC-05 — Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties. (strong, editorial): Contractual supplier requirements.
  • GV.SC-07 — The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship. (strong, editorial): Ongoing monitoring of processor.

nist_800_53_r5_moderate

  • SA-9 — External System Services (strong, editorial): External services.

Pivot: corresponding controls per target framework

Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its method tag — filter or sort by it on the methodology page.