← GRC Hub

Cross-framework Control Crosswalk

Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.

Dataset v1.0.0 · reviewed 2026-06-10 · methodology & method hierarchy →

nis2_art21 · 21_2_h — Cryptography and, where appropriate, encryption

iso_27001_2022

  • A.8.24 — Use of cryptography (exact, enisa-guidance): Use of cryptography.

nist_csf_2_0

  • PR.DS-01 — The confidentiality, integrity, and availability of data-at-rest are protected. (strong, editorial): Data at rest confidentiality and integrity.
  • PR.DS-02 — The confidentiality, integrity, and availability of data-in-transit are protected. (strong, editorial): Data in transit.

dora_rts_riskmgmt

  • rts_art7 — Cryptography and key management (exact, dora-l2): Cryptography and key management.

gdpr_security

  • art32 — Security of processing (Art. 32) (strong, editorial): Encryption is a named technical measure in GDPR Art 32.

cra_essential

  • annex1_p1_05 — Confidentiality of data (strong, editorial): Confidentiality protection via encryption.
  • annex1_p1_06 — Integrity of data (strong, editorial): Integrity protection.

nist_800_53_r5_moderate

  • SC-12 — Cryptographic Key Establishment and Management (strong, editorial): Key management.
  • SC-13 — Cryptographic Protection (strong, editorial): Cryptographic protection.
  • SC-28 — Protection of Information at Rest (strong, editorial): Information at rest.
  • SC-8 — Transmission Confidentiality and Integrity (strong, editorial): Transmission protection.

Pivot: corresponding controls per target framework

Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its method tag — filter or sort by it on the methodology page.