← GRC Hub
Cross-framework Control Crosswalk
Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.
Dataset v1.0.0 · reviewed 2026-06-10 ·
methodology & method hierarchy →
nis2_art21 · 21_2_f — Policies and procedures to assess the effectiveness of cybersecurity risk-management measures
iso_27001_2022
- A.5.35 — Independent review of information security (strong, enisa-guidance): Independent review.
- A.5.36 — Compliance with policies, rules and standards for information security (strong, enisa-guidance): Compliance with policies.
- A.8.29 — Security testing in development and acceptance (strong, editorial): Security testing as effectiveness assessment.
- A.8.34 — Protection of information systems during audit testing (partial, editorial): Audit testing protections.
nist_csf_2_0
- ID.IM-01 — Improvements are identified from evaluations. (strong, editorial): Improvements from evaluations.
- ID.IM-02 — Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties. (strong, editorial): Improvements from security tests and exercises.
- GV.OV-01 — Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction. (strong, editorial): Strategy outcomes reviewed.
- GV.OV-03 — Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed. (strong, editorial): Performance evaluation.
- ID.IM-03 — Improvements are identified from execution of operational processes, procedures, and activities. (strong, editorial): Process improvements.
- GV.OV-02 — The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks. (strong, editorial): Strategy adjustment.
dora_level1
- art24 — General requirements for the performance of digital operational resilience testing (strong, editorial): Digital operational resilience testing programme.
- art25 — Testing of ICT tools and systems (strong, editorial): Baseline testing of ICT systems.
dora_rts_riskmgmt
- rts_art23 — Documentation and reporting on the ICT risk management framework (strong, dora-l2): Documentation and annual reporting.
Pivot: corresponding controls per target framework
Framework pair: full mapping
Coverage: if I implement X, how much of Y do I cover?
Tick the controls you have implemented in your source framework. The page computes coverage against each target framework using the formula exact = 1.0, strong = 0.75, partial = 0.4, related = 0, capped at 1.0 per target control.
Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its
method tag — filter or sort by it on the methodology page.