← GRC Hub

Cross-framework Control Crosswalk

Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.

Dataset v1.0.0 · reviewed 2026-06-10 · methodology & method hierarchy →

nis2_art21 · 21_2_d — Supply chain security

iso_27001_2022

  • A.5.19 — Information security in supplier relationships (exact, enisa-guidance): Information security in supplier relationships.
  • A.5.20 — Addressing information security in supplier agreements (exact, enisa-guidance): Addressing security in supplier agreements.
  • A.5.21 — Managing information security in the ICT supply chain (strong, enisa-guidance): Managing security in the ICT supply chain.
  • A.5.22 — Monitoring, review and change management of supplier services (strong, enisa-guidance): Monitoring of supplier services.
  • A.5.23 — Information security for use of cloud services (strong, enisa-guidance): Cloud services security.

nist_csf_2_0

  • GV.SC-01 — A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders. (exact, editorial): Supply chain risk management programme.
  • GV.SC-05 — Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties. (strong, editorial): Contractual cybersecurity requirements.
  • GV.SC-07 — The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship. (strong, editorial): Ongoing supplier risk monitoring.
  • GV.SC-03 — Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes. (strong, editorial): SCRM integration with ERM.
  • GV.SC-04 — Suppliers are known and prioritized by criticality. (strong, editorial): Supplier prioritisation by criticality.
  • GV.SC-06 — Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships. (strong, editorial): Due diligence.
  • GV.SC-08 — Relevant suppliers and other third parties are included in incident planning, response, and recovery activities. (strong, editorial): Third parties in incident planning.
  • GV.SC-09 — Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle. (strong, editorial): SC integration through life cycle.

dora_level1

  • art28 — General principles for sound management of ICT third-party risk (exact, editorial): DORA Art 28 ICT third-party risk principles.
  • art29 — Preliminary assessment of ICT concentration risk at entity level (strong, editorial): Concentration risk assessment.
  • art30 — Key contractual provisions (strong, editorial): Mandatory contractual provisions.

gdpr_security

  • art28 — Processor (Art. 28) (strong, editorial): Processor (Art 28 GDPR) is the privacy lens on the same supplier relationship.

cra_essential

  • annex1_p2_01 — Identify and document vulnerabilities and components (partial, editorial): SBOM disclosure feeds supplier assurance.

nist_800_53_r5_moderate

  • SR-3 — Supply Chain Controls and Processes (strong, editorial): Supply chain controls.
  • SR-6 — Supplier Assessments and Reviews (strong, editorial): Supplier assessments.
  • SA-9 — External System Services (strong, editorial): External services.

Pivot: corresponding controls per target framework

Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its method tag — filter or sort by it on the methodology page.