← GRC Hub
Cross-framework Control Crosswalk
Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.
Dataset v1.0.0 · reviewed 2026-06-10 ·
methodology & method hierarchy →
nis2_art21 · 21_2_a — Policies on risk analysis and information system security
iso_27001_2022
- A.5.1 — Policies for information security (exact, enisa-guidance): Both require a top-level information security policy.
- A.5.2 — Information security roles and responsibilities (strong, enisa-guidance): Roles and responsibilities for security implementation flow from policy framework.
- A.5.31 — Legal, statutory, regulatory and contractual requirements (strong, enisa-guidance): Legal/regulatory requirements identification fits the policy and risk-analysis dimension of Art 21(2)(a).
nist_csf_2_0
- GV.PO-01 — Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities; the policy is communicated and enforced. (exact, editorial): GV.PO-01 mandates policy for managing cybersecurity risks — directly aligns with Art 21(2)(a) requirement.
- GV.RM-06 — A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated. (strong, editorial): Standardised method for documenting and prioritising cybersecurity risks supports Art 21(2)(a) risk-analysis aspect.
- ID.RA-05 — Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization. (strong, editorial): Risk assessment outputs underpin Art 21(2)(a).
dora_level1
- art6 — ICT risk management framework (strong, editorial): DORA Art 6 ICT risk management framework is the parallel framework requirement for financial entities.
dora_rts_riskmgmt
- rts_art3 — ICT security policy (exact, dora-l2): RTS Art 3 mandates ICT security policy.
gdpr_security
- art24 — Responsibility of the controller (Art. 24) (partial, editorial): Art 24 GDPR's risk-based controller measures share the risk-based logic.
nist_800_53_r5_moderate
- PM-1 — Information Security Program Plan (strong, editorial): Programme plan.
- PM-9 — Risk Management Strategy (strong, editorial): Risk management strategy.
- RA-3 — Risk Assessment (strong, editorial): Risk assessment.
Pivot: corresponding controls per target framework
Framework pair: full mapping
Coverage: if I implement X, how much of Y do I cover?
Tick the controls you have implemented in your source framework. The page computes coverage against each target framework using the formula exact = 1.0, strong = 0.75, partial = 0.4, related = 0, capped at 1.0 per target control.
Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its
method tag — filter or sort by it on the methodology page.