← GRC Hub

Cross-framework Control Crosswalk

Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.

Dataset v1.0.0 · reviewed 2026-06-10 · methodology & method hierarchy →

nis2_art21 · 21_2_j — Multi-factor or continuous authentication, secured communications, secured emergency communications

iso_27001_2022

  • A.8.5 — Secure authentication (exact, enisa-guidance): Secure authentication.
  • A.8.20 — Networks security (strong, enisa-guidance): Networks security.

nist_csf_2_0

  • PR.AA-03 — Users, services, and hardware are authenticated. (strong, editorial): Authentication.
  • PR.AA-04 — Identity assertions are protected, conveyed, and verified. (strong, editorial): Identity assertions protected.

dora_rts_riskmgmt

  • rts_art13 — Identification and authentication (exact, dora-l2): Identification and authentication, MFA where risk-appropriate.
  • rts_art8 — Network security (strong, dora-l2): Network security.

nist_800_53_r5_moderate

  • IA-2 — Identification and Authentication (Organizational Users) (strong, editorial): MFA, authentication.
  • SC-7 — Boundary Protection (strong, editorial): Secured communications via boundary.

Pivot: corresponding controls per target framework

Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its method tag — filter or sort by it on the methodology page.