Skip to content

Compliance mapping

Implement once. Prove it many times over.

KaitoSec connects the control, risk and evidence to every genuinely related requirement. Security and audit can see where work is reusable and where a real gap remains.

Where friction starts today

Doing the same control five times for five frameworks

Access control shows up in ISO 27001, in NIS2, in SOC 2, in TISAX, and in BSI Grundschutz. It is the same control each time, but if your frameworks live in separate tools or separate tabs, you document it five times, evidence it five times, and explain to five auditors why the wording is slightly different in each. The work multiplies with every standard you add, even though the underlying security barely changes.

What you actually want is to implement a control once and have it count everywhere it applies. A single change should update the Statement of Applicability, the NIS2 measure register, and every other artefact that references it, without anyone retyping a thing. Until controls are mapped across frameworks in one place, compliance scales by headcount, and the gap analysis before each audit is really just a hunt for what fell out of sync.

One data model

What you enter here, the other modules already know

Modules are views on the same record, not separate databases. A change made here is the change every other module reads, with no export step and no second entry.

A change in this module is written to the shared data model, which the other modules read immediately.

This module

Compliance Mapping

Shared data model

One asset, one risk, one control, one piece of evidence

  • Risk ManagementCurrent at once
  • Business ContinuityCurrent at once
  • Asset ManagementCurrent at once

Entry to evidence

Every change carries its own proof

An auditor rarely asks what the register says today. They ask who changed it, when, and on what basis. That trail is written while the work happens, so nothing has to be reconstructed at the end of the year.

One change writes its previous value, its owner and its date, and surfaces in the management report, the audit evidence and the customer questionnaire.

One change

A risk is re-assessed

Written with it

  • Previous value and version
  • Person responsible
  • Date and reason

Where it surfaces

  • Management report
  • Audit evidence
  • Customer questionnaire

What changes for your team

01

Limit duplicate work to genuine differences

Connect one control to every genuinely related requirement and keep framework-specific additions visible. The team maintains the implementation once without overstating its coverage.

02

Prioritise controls by practical impact

Compare selected frameworks in one view and examine status, owner, residual risk and missing evidence. This makes visible which open control closes several relevant gaps.

03

Keep the SoA and related artefacts tied to current work

SoA, control registers, gap views and audit evidence use the same working state. A read-only auditor view or versioned export shows status, owner, risk and evidence without a second audit list.

The workflow

01

Inspect mappings where the work happens

Connect requirements, controls and evidence in one model and inspect crosswalks at the point of work. Add your own controls and mappings without losing the source context of the standard library.

02

Gap analysis dashboard

See compliance posture across all active frameworks on one dashboard. Drill down per framework to view control status, owners and outstanding evidence. The same view powers management reviews for the ISMS, BCMS, DSMS and AIMS.

03

Keep audit evidence with the implemented control

Link controls to documents, screenshots, exercise reports and system records. Audit views and exports then use the same current context rather than a separately maintained collection.

From framework silos to traceable reuse.

What runs twice today
What changes in a shared model
Maintain each framework separately
One shared control model
Collect evidence multiple times
Link evidence once
Keep Excel mappings up to date
A maintained mapping library
Audit preparation by hand
Audit view and export straight from the system
Hunt for gaps framework by framework
Prioritise measures by multi-framework impact

FAQ

Which frameworks does KaitoSec support?

ISO 27001:2022, NIS2, SOC 2, TISAX, BSI Grundschutz, GDPR, DORA, ISO 22301, EU AI Act and ISO 42001 are supported today. New frameworks are added regularly. You can request a specific framework from the roadmap page.

How accurate are the cross-framework mappings?

Mappings come from a curated library that the KaitoSec compliance team builds and maintains, not from keyword matching. Where authoritative crosswalks exist (for example ENISA guidance for ISO 27001 to NIS2) they are the primary source. Customer-specific mappings are versioned alongside the library.

Can we customise the control library?

Yes. Custom controls can be added to a workspace and mapped manually to framework requirements. Custom controls behave identically to the library in gap analysis, SoA generation and reporting.

How does the SoA export work for ISO 27001 certification?

KaitoSec creates a structured SoA with applicability, justification and implementation state for Annex A controls. Export the approved version as PDF or share a controlled auditor view of the current working state.

What happens when one control covers multiple requirements?

KaitoSec shows the impact of a control across every relevant framework, including open gaps, missing evidence and the responsible owners.