← GRC Hub

Cross-framework Control Crosswalk

Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.

Dataset v1.0.0 · reviewed 2026-06-10 · methodology & method hierarchy →

nis2_art21 · 21_2_e — Security in network and information systems acquisition, development and maintenance

iso_27001_2022

  • A.8.25 — Secure development life cycle (exact, enisa-guidance): Secure development life cycle.
  • A.8.26 — Application security requirements (strong, enisa-guidance): Application security requirements.
  • A.8.27 — Secure system architecture and engineering principles (strong, enisa-guidance): Secure system architecture.
  • A.8.28 — Secure coding (strong, enisa-guidance): Secure coding.
  • A.8.29 — Security testing in development and acceptance (strong, enisa-guidance): Security testing in development.
  • A.8.32 — Change management (strong, enisa-guidance): Change management.
  • A.8.8 — Management of technical vulnerabilities (strong, enisa-guidance): Technical vulnerability management.

nist_csf_2_0

  • PR.PS-06 — Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle. (exact, editorial): Secure software development practices.
  • PR.PS-02 — Software is maintained, replaced, and removed commensurate with risk. (strong, editorial): Software maintenance and replacement.
  • ID.RA-01 — Vulnerabilities in assets are identified, validated, and recorded. (strong, editorial): Vulnerability identification.
  • ID.RA-09 — The authenticity and integrity of hardware and software are assessed prior to acquisition and use. (strong, editorial): Authenticity/integrity of hardware and software.
  • ID.RA-10 — Critical suppliers are assessed prior to acquisition. (partial, editorial): Critical supplier assessment.

dora_rts_riskmgmt

  • rts_art9 — Project and change management (exact, dora-l2): Project and change management for ICT projects.
  • rts_art10 — Patch and vulnerability management (strong, dora-l2): Patch and vulnerability management.

cra_essential

  • annex1_p1_01 — No known exploitable vulnerabilities at release (partial, editorial): No known exploitable vulnerabilities at release.

nist_800_53_r5_moderate

  • SA-3 — System Development Life Cycle (strong, editorial): SDLC.
  • SA-11 — Developer Testing and Evaluation (strong, editorial): Testing.
  • SI-2 — Flaw Remediation (strong, editorial): Flaw remediation.

Pivot: corresponding controls per target framework

Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its method tag — filter or sort by it on the methodology page.