01
Limit duplicate work to genuine differences
Connect one control to every genuinely related requirement and keep framework-specific additions visible. The team maintains the implementation once without overstating its coverage.
Compliance mapping
KaitoSec connects the control, risk and evidence to every genuinely related requirement. Security and audit can see where work is reusable and where a real gap remains.
Where friction starts today
Access control shows up in ISO 27001, in NIS2, in SOC 2, in TISAX, and in BSI Grundschutz. It is the same control each time, but if your frameworks live in separate tools or separate tabs, you document it five times, evidence it five times, and explain to five auditors why the wording is slightly different in each. The work multiplies with every standard you add, even though the underlying security barely changes.
What you actually want is to implement a control once and have it count everywhere it applies. A single change should update the Statement of Applicability, the NIS2 measure register, and every other artefact that references it, without anyone retyping a thing. Until controls are mapped across frameworks in one place, compliance scales by headcount, and the gap analysis before each audit is really just a hunt for what fell out of sync.
One data model
Modules are views on the same record, not separate databases. A change made here is the change every other module reads, with no export step and no second entry.
This module
Compliance Mapping
Shared data model
One asset, one risk, one control, one piece of evidence
Entry to evidence
An auditor rarely asks what the register says today. They ask who changed it, when, and on what basis. That trail is written while the work happens, so nothing has to be reconstructed at the end of the year.
One change
A risk is re-assessed
Written with it
Where it surfaces
01
Connect one control to every genuinely related requirement and keep framework-specific additions visible. The team maintains the implementation once without overstating its coverage.
02
Compare selected frameworks in one view and examine status, owner, residual risk and missing evidence. This makes visible which open control closes several relevant gaps.
03
SoA, control registers, gap views and audit evidence use the same working state. A read-only auditor view or versioned export shows status, owner, risk and evidence without a second audit list.
01
Connect requirements, controls and evidence in one model and inspect crosswalks at the point of work. Add your own controls and mappings without losing the source context of the standard library.
02
See compliance posture across all active frameworks on one dashboard. Drill down per framework to view control status, owners and outstanding evidence. The same view powers management reviews for the ISMS, BCMS, DSMS and AIMS.
03
Link controls to documents, screenshots, exercise reports and system records. Audit views and exports then use the same current context rather than a separately maintained collection.
ISO 27001:2022, NIS2, SOC 2, TISAX, BSI Grundschutz, GDPR, DORA, ISO 22301, EU AI Act and ISO 42001 are supported today. New frameworks are added regularly. You can request a specific framework from the roadmap page.
Mappings come from a curated library that the KaitoSec compliance team builds and maintains, not from keyword matching. Where authoritative crosswalks exist (for example ENISA guidance for ISO 27001 to NIS2) they are the primary source. Customer-specific mappings are versioned alongside the library.
Yes. Custom controls can be added to a workspace and mapped manually to framework requirements. Custom controls behave identically to the library in gap analysis, SoA generation and reporting.
KaitoSec creates a structured SoA with applicability, justification and implementation state for Annex A controls. Export the approved version as PDF or share a controlled auditor view of the current working state.
KaitoSec shows the impact of a control across every relevant framework, including open gaps, missing evidence and the responsible owners.