← GRC Hub
Cross-framework Control Crosswalk
Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.
Dataset v1.0.0 · reviewed 2026-06-10 ·
methodology & method hierarchy →
nis2_art21 · 21_2_c — Business continuity and crisis management
iso_27001_2022
- A.5.29 — Information security during disruption (exact, enisa-guidance): Information security during disruption.
- A.5.30 — ICT readiness for business continuity (exact, enisa-guidance): ICT readiness for business continuity.
- A.8.13 — Information backup (strong, enisa-guidance): Information backup.
- A.8.14 — Redundancy of information processing facilities (strong, enisa-guidance): Redundancy of processing facilities.
nist_csf_2_0
- PR.DS-11 — Backups of data are created, protected, maintained, and tested. (strong, editorial): Backups are created, protected, maintained, tested.
- PR.IR-03 — Mechanisms are implemented to achieve resilience requirements in normal and adverse situations. (strong, editorial): Resilience mechanisms.
- PR.IR-04 — Adequate resource capacity to ensure availability is maintained. (partial, editorial): Capacity to ensure availability.
- RC.RP-01 — The recovery portion of the incident response plan is executed once initiated from the incident response process. (exact, editorial): Recovery plan execution.
- RC.RP-02 — Recovery actions are selected, scoped, prioritized, and performed. (strong, editorial): Recovery actions.
- RC.RP-03 — The integrity of backups and other restoration assets is verified before using them for restoration. (strong, editorial): Backup integrity verification.
- RC.RP-05 — The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed. (strong, editorial): Restoration and normal-state confirmation.
- RC.RP-06 — The end of incident recovery is declared based on criteria, and incident-related documentation is completed. (strong, editorial): Recovery completion.
- RC.CO-03 — Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders. (strong, editorial): Recovery comms.
- RC.CO-04 — Public updates on incident recovery are shared using approved methods and messaging. (partial, editorial): Public updates.
dora_level1
- art11 — Response and recovery (exact, editorial): DORA Art 11 response and recovery.
- art12 — Backup policies, restoration and recovery procedures (exact, editorial): DORA Art 12 backup, restoration, recovery.
dora_rts_riskmgmt
- rts_art16 — ICT business continuity policy (exact, dora-l2): RTS Art 16 ICT business continuity policy.
- rts_art17 — ICT response and recovery plans (strong, dora-l2): RTS Art 17 response and recovery plans.
- rts_art18 — Backup procedures and methods (strong, dora-l2): RTS Art 18 backup procedures.
gdpr_security
- art32 — Security of processing (Art. 32) (partial, editorial): Availability is one of GDPR Art 32's security objectives.
nist_800_53_r5_moderate
- CP-2 — Contingency Plan (exact, editorial): Contingency plan.
- CP-4 — Contingency Plan Testing (strong, editorial): Plan testing.
- CP-9 — System Backup (strong, editorial): Backups.
- CP-10 — System Recovery and Reconstitution (strong, editorial): Recovery.
Pivot: corresponding controls per target framework
Framework pair: full mapping
Coverage: if I implement X, how much of Y do I cover?
Tick the controls you have implemented in your source framework. The page computes coverage against each target framework using the formula exact = 1.0, strong = 0.75, partial = 0.4, related = 0, capped at 1.0 per target control.
Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its
method tag — filter or sort by it on the methodology page.