Framework catalog

Map once, prepare deliberately

Readiness across the security, privacy, and cloud standardsyour market expects

Frameworks overlap, but their formal outcomes do not. Canonical Plus maps reusable controls and evidence while preserving the distinct assessor, certification, authorization, legal, and regulatory paths required for each program.

Assurance and certification targets
Independent attestation target

SOC 2

Readiness for Trust Services Criteria scope, control design, operating evidence, exceptions, and auditor handoff.

  • System description inputs
  • Control and evidence map
  • Type I or Type II readiness plan
Accredited certification target

ISO/IEC 27001

Readiness for an information security management system, risk treatment, documented controls, and certification-body review.

  • ISMS scope and context
  • Risk treatment and Statement of Applicability
  • Internal-audit and management-review preparation
Payment security standard

PCI DSS 4.0.1

Readiness for cardholder-data scope, technical requirements, evidence, compensating controls, and the applicable validation path.

  • Cardholder-data environment boundary
  • Requirement ownership map
  • SAQ, ROC, or QSA handoff preparation
US federal authorization program

FedRAMP

Readiness for the selected impact level, NIST control baseline, documentation package, continuous monitoring, and approved assessor path.

  • Authorization boundary and impact assumptions
  • SSP and POA&M preparation
  • 3PAO and agency handoff plan
Security and cloud programs
Cybersecurity program framework

NIST CSF 2.0

Govern, Identify, Protect, Detect, Respond, and Recover maturity assessment aligned to business risks.

  • Current and target profiles
  • Gap and priority register
  • Implementation roadmap
Control catalog

NIST SP 800-53

Readiness mapping for security and privacy controls used by federal and other high-assurance programs.

  • Baseline and tailoring decisions
  • Control implementation statements
  • Evidence and assessment plan
Defense supply-chain readiness

NIST SP 800-171 / CMMC 2.0

Readiness for protecting controlled unclassified information, documenting implementation, and preparing for the required CMMC path.

  • CUI boundary and data flow
  • SSP and POA&M preparation
  • Assessment responsibility map
Prioritized security safeguards

CIS Controls v8.1

Implementation-group-based readiness for foundational, enterprise, and higher-risk security safeguards.

  • Implementation Group selection
  • Safeguard gap map
  • Technical remediation backlog
Business continuity certification target

ISO 22301

Readiness for a business continuity management system, impact analysis, recovery objectives, exercises, and certification-body review.

  • BCMS scope and continuity policy
  • Business impact and recovery assumptions
  • Exercise, corrective-action, and handoff plan
Cloud assurance framework

CSA Cloud Controls Matrix / STAR

Readiness for cloud control mapping, shared-responsibility evidence, and the selected STAR assurance level.

  • Cloud service and responsibility map
  • CCM control mapping
  • STAR submission or assessment preparation
Privacy and digital regulation
US healthcare regulation

HIPAA

Security and privacy readiness for electronic protected health information and the organization’s covered-entity or business-associate role.

  • ePHI systems and data-flow boundary
  • Security risk analysis inputs
  • Administrative, physical, and technical safeguard plan
EU data-protection regulation

GDPR

Operational privacy readiness across roles, lawful bases, rights handling, retention, vendors, transfers, and security measures.

  • Processing and role inventory
  • DPIA and records-of-processing plan
  • Rights, retention, and transfer controls
Privacy information management

ISO/IEC 27701

Readiness to extend an information security management system with privacy-specific controller and processor controls.

  • PIMS scope and role map
  • Privacy risk treatment
  • ISO 27001 dependency plan
EU cybersecurity directive

NIS2

Readiness for governance, risk management, incident handling, supply-chain controls, reporting, and accountability obligations.

  • Entity and applicability assumptions
  • Management accountability map
  • Incident and supply-chain readiness plan
EU financial-sector resilience

DORA

Readiness for ICT risk, incident reporting, resilience testing, third-party risk, and oversight requirements.

  • ICT service and dependency inventory
  • Resilience and incident-testing plan
  • Third-party register preparation

What can be reused

Identity, access, change management, incident response, vendor management, risk assessment, asset inventory, logging, vulnerability management, and evidence operations often support multiple frameworks.

What must stay distinct

Scope rules, sampling periods, report formats, accreditation requirements, assessor qualifications, filing obligations, regulatory conclusions, and formal outcomes cannot be collapsed into one generic “compliance” result.

Custom and contractual requirements

Not every obligation has a public framework name

Customer security addenda, procurement requirements, internal standards, and sector-specific control sets can be mapped into the same readiness model, with the source and interpretation kept explicit.