Frameworks & controls

One control set,
every framework.

Map your controls once and keep every standard you hold audit-ready from the same place. Each control is a living record linked to the policies, risks, assets and evidence that satisfy it, so renewing one framework or adding the next reuses what you already maintain instead of rebuilding a binder.

Start for freeBook a conversation
Maps toISO/IEC 27001SOC 2GDPRNIST CSFPCI DSS
++++
app.devguard.ch / dashboard
Audit Ready
ISMS Posture
Compliance posture
68%
compliant
Open risks61
High02
Medium16
Low43
Information Security Management System
34 / 93 controls
Security Governance Framework
ISO 27001 · 4.3
Leadership Commitment
ISO 27001 · 5.1
Risk Management Process
NIST · ID.RA-5
Policy Documentation
in progress
Continuous Improvement
ISO 27001 · 10.2
ISO 2700137%
SOC 252%
GDPR71%
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
How it works

Map once, reuse everywhere.

The same three steps whether you hold a single standard or ten. You maintain one control set, and every framework draws on it.

01

Map your controls once

Bring your controls into one place and link each one to the policies, risks, assets and evidence that satisfy it. It becomes a living record you maintain, not a row you copy into a fresh spreadsheet before every audit.

02

Add a framework, reuse the work

Cross-framework mapping is authored once and reads both directions. Define how a control maps in one place, and adding the next standard pulls in the controls and evidence you already maintain instead of starting a new binder.

Authored once, read both ways

You don’t re-map from each new framework’s side. The same mapping counts in both directions, so the second standard you add costs a fraction of the first.

03

Watch coverage and gaps roll up

Coverage rolls up per framework, from unknown to partial to full. Open gaps surface by control as you go, so you see them months before an audit, not in the two weeks before it.

Why it’s built this way

Built to be maintained, not rebuilt.

Four choices behind how controls and frameworks work here — each one something you can check, not an adjective.

01

One control set, not one per standard

You maintain a single set of controls and point every framework at it, instead of keeping a separate binder per certificate.

02

Mapping authored once, read both ways

A control’s cross-framework mapping is defined in one place and works in both directions, so a new standard reuses controls and evidence you already have.

03

Gaps by control, early

Coverage rolls up unknown to partial to full, and open gaps show up by control months out, not as a fire drill the week before the audit.

04

Your frameworks, plus your own

ISO 27001, ISO 27701, ISO 9001, ISO 14001, ISO 45001, SOC 2, GDPR, HIPAA, PCI DSS, NIST CSF, EU AI Act, NIS2, Swiss nFADP, OWASP and ISO 42001 work out of the box, and you can add a custom framework and custom controls.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your control set and evidence are yours and exportable to CSV and PDF at any time, with no lock-in.

See the full feature comparison

One module of the platform

Where controls connect.

Controls don’t live alone. Each one links to the policies, risks, assets, evidence and audits that prove it, all in the same workspace — so the proof is connected to the control instead of scattered across tools.

coverage86%

Coverage

See how complete each framework is, by control, in one view.

policyv1.3
access_control {
require mfa = true
}

Policies

Version, approve and review the policies your controls point to.

342
artifacts captured
linked to controls

Evidence

Keep audit-ready proof attached to the control it satisfies.

2.0SCORE

Risks

Tie each risk to the controls that treat it, and track it through.

FAQ

The questions evaluators ask.

Can I add my own framework?

Yes. ISO 27001, ISO 27701, ISO 9001, ISO 14001, ISO 45001, SOC 2, GDPR, HIPAA, PCI DSS, NIST CSF, EU AI Act, NIS2, Swiss nFADP, OWASP and ISO 42001 are supported out of the box, and you can define a custom framework with your own custom controls when you work to a standard or internal policy that isn’t pre-built.

Do mappings really sync both ways?

Yes. You author a control’s cross-framework mapping once, in one place, and it reads in both directions. So when you add a new standard, it reuses the controls and evidence already mapped, instead of asking you to re-map everything from the new framework’s side.

What about custom controls?

You can add your own controls alongside the built-in ones, link them to the policies, risks, assets and evidence that satisfy them, and map them across frameworks the same way. Your methodology stays yours, in one workspace.

How is this different from a spreadsheet or another GRC tool?

In a spreadsheet, a control is a row you rebuild before every audit, and a new framework means a new tab. Here, each control is a living record connected to the proof that satisfies it, mapped once across frameworks both ways, with coverage and gaps rolling up per framework — so you maintain one set of controls rather than reconciling several.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Your control set and evidence are yours, exportable to CSV and PDF and reachable through the API at any time, so there’s no lock-in.

Bring every framework into one control set.

Map your controls once, reuse the evidence across every standard you hold, and see the gaps by control months before the audit — not the week before.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free