← GRC Hub

Cross-framework Control Crosswalk

Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.

Dataset v1.0.0 · reviewed 2026-06-10 · methodology & method hierarchy →

gdpr_security · art33 — Notification of a personal data breach to the supervisory authority (Art. 33)

nist_csf_2_0

  • RS.CO-02 — Internal and external stakeholders are notified of incidents. (strong, editorial): Stakeholder notification.

iso_27001_2022

  • A.5.26 — Response to information security incidents (strong, editorial): Response to incidents.

dora_level1

  • art19 — Reporting of major ICT-related incidents and voluntary notification of significant cyber threats (partial, editorial): Different report content but parallel notification logic.

nis2_art21

  • 21_2_b — Incident handling (partial, editorial): Personal-data breach reporting parallels incident handling.

nist_800_53_r5_moderate

  • IR-6 — Incident Reporting (strong, editorial): Incident reporting.

Pivot: corresponding controls per target framework

Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its method tag — filter or sort by it on the methodology page.