← GRC Hub

Cross-framework Control Crosswalk

Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.

Dataset v1.0.0 · reviewed 2026-06-10 · methodology & method hierarchy →

dora_level1 · art11 — Response and recovery

dora_rts_riskmgmt

  • rts_art16 — ICT business continuity policy (exact, dora-l2): ICT BCP policy.
  • rts_art17 — ICT response and recovery plans (strong, dora-l2): Response and recovery plans.

iso_27001_2022

  • A.5.29 — Information security during disruption (strong, editorial): Security during disruption.
  • A.5.30 — ICT readiness for business continuity (strong, editorial): ICT readiness for BC.

nist_800_53_r5_moderate

  • CP-2 — Contingency Plan (strong, editorial): Contingency plan.
  • IR-8 — Incident Response Plan (strong, editorial): IR plan.

Pivot: corresponding controls per target framework

Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its method tag — filter or sort by it on the methodology page.