← GRC Hub

Cross-framework Control Crosswalk

Implement once, comply many. 623 edges connecting NIST CSF 2.0, SP 800-53 r5 Moderate, ISO 27001:2022 Annex A, DORA Level 1 + RTS 2024/1774, NIS2 Article 21 + IR 2024/2690, GDPR security and CRA Annex I.

Dataset v1.0.0 · reviewed 2026-06-10 · methodology & method hierarchy →

nis2_art21 · ir_2024_2690_vuln — Vulnerability and patch management (IR 2024/2690)

iso_27001_2022

  • A.8.8 — Management of technical vulnerabilities (exact, editorial): Technical vulnerability management.

nist_csf_2_0

  • ID.RA-01 — Vulnerabilities in assets are identified, validated, and recorded. (exact, editorial): Vulnerability identification.
  • ID.RA-08 — Processes for receiving, analyzing, and responding to vulnerability disclosures are established. (strong, editorial): Vulnerability disclosure handling.

dora_rts_riskmgmt

  • rts_art10 — Patch and vulnerability management (exact, dora-l2): Patch and vulnerability management.

cra_essential

  • annex1_p2_02 — Address vulnerabilities without delay (partial, editorial): Address vulnerabilities without delay (manufacturer side).

Pivot: corresponding controls per target framework

Informational only — not legal advice. Mapping method hierarchy (in order of preference): NIST OLIR machine-readable mappings → ENISA NIS2 implementation guidance → DORA Level 2 RTS/ITS → editorial. Every edge in this dataset is labelled with its method tag — filter or sort by it on the methodology page.