⚡ Every Mutex Systems product starts at £0 — create an account and go live today. See pricing →
grComply Compliance Frameworks Security Awareness Training TiLedger FlowChat Pricing Partners Resources About Reviews Contact Sign in to grComply Sign in to TiLedger Sign in to FlowChat
grComply module · Compliance framework library

Every compliance framework, one control library.

A compliance framework is a structured set of controls a regulator, standards body, or customer requires you to prove — ISO 27001, SOC 2, and PCI DSS are examples; so is a national data-protection law. grComply treats every one of them as the same kind of object: a versioned Framework Library built from ControlNodes, not a hardcoded page tree. That's what lets it run international standards alongside regional and national regulations in one control inventory — and map one piece of evidence to every framework it satisfies.

13 frameworks seeded today. Any framework loads as data — import, author, or request a new seed pack.
Back to grComply overview WhatsApp us
13Frameworks seeded today
5Mapping relationship types
1Control tree, every framework
AnyFramework loads as data, not code

What's the difference between a regional and an international compliance framework? An international framework — ISO 27001, SOC 2, NIST CSF, PCI DSS — applies the same way regardless of country, built by a standards body or industry consortium. A regional framework is issued by a specific country or bloc's regulator — UK GDPR, the EU's DORA, Saudi Arabia's SAMA CSF — and usually applies alongside, not instead of, an international standard.

Why it's different

How grComply benefits the compliance process

One control, many frameworks

Cross-framework mappings are data — one ControlNode can satisfy clauses in ISO 27001, NIST CSF, SOC 2, and CIS simultaneously. Evidence uploaded once counts everywhere it applies; AI can suggest a mapping, a human always confirms it.

Frameworks are data, not code

Import via JSON/YAML/CSV/API, or author in-app — validated for structure before publish. Adding a new country's regulation never means waiting on a vendor release cycle or a code deployment.

Versioned, never silently changed

A published library change creates a new version with a diff of added, changed, and retired nodes. Tenants pin to a version until they choose to adopt the next; historical evidence stays tied to the version in effect at the time.

Completion is computed, never a checklist

A control's status — compliant, partial, gap, N/A — is derived live from evidence, scans, observations, and N/A decisions over the assigned tree, never from a pre-seeded checklist someone ticks by hand.

Mapping sets bundle related standards

A curated stack of frameworks plus cross-links and propagation rules imports and activates as one profile — for example an AI-governance stack spanning ISO/IEC 42001, ISO/IEC 27001, and the NIST AI Risk Management Framework.

Tenant-authored baselines, same rigor

A client's own internal policy — a "Client Security Baseline" or vendor-specific requirement set — uses the identical ControlNode model, scoped to that tenant unless promoted to the global library.

Seeded today

13 frameworks, ready to assign

Two are comprehensive, audit-ready libraries out of the box. The rest are structural seed packs — the full domain/control hierarchy is in place, ready to expand to complete sub-control depth via import.

FrameworkPublisherJurisdictionStructureDepth
NIST Cybersecurity Framework 2.0NISTUS / International6 Functions · 22 Categories · 106 SubcategoriesComprehensive
SOC 2 Type IAICPAUS / International5 TSC series · 20 Criteria · 61 Points of focusComprehensive
SOC 2 Type IIAICPAUS / International5 TSC series · 20 Criteria · 61 Points of focusComprehensive
CIS Controls v8Center for Internet SecurityInternational3 Implementation Groups · 18 ControlsStructural seed
ISO/IEC 27001:2022ISO/IECInternationalAnnex themes · Annex A control setStructural seed
ISO/IEC 27017 (Cloud Security)ISO/IECInternationalCloud-specific control extension to 27001/27002Structural seed
ISO/IEC 27018 (Cloud Privacy)ISO/IECInternationalPII-in-cloud control extensionStructural seed
ISO/IEC 42001:2023 (AI Management System)ISO/IECInternationalClause themes · Annex A AI controlsStructural seed
HIPAAU.S. HHS — OCRUnited StatesRule areas · Safeguards · Implementation specsStructural seed
PCI DSS 4.0PCI Security Standards CouncilInternational6 Goals · Requirements 1–12Structural seed
DORA — Digital Operational Resilience ActEuropean UnionEuropean Union5 pillars · ICT risk, incident, resilience, third-partyStructural seed
MITRE ATT&CK (Enterprise)MITRE CorporationInternationalTactics · Techniques · Sub-techniquesStructural seed
ISA/IEC 62443ISA / IECInternationalFoundational Requirements · Security requirements (OT/ICS)Structural seed

Reading "structural seed": the domain and control hierarchy is seeded and assignable today; sub-control depth expands as a tenant imports the full official text or Mutex publishes an expanded pack — the same versioned import path used for any new framework, so nothing is ever a hardcoded dead end.

Loadable as data

Regional & international frameworks the same engine runs

Because the control engine has no standard-specific knowledge baked in, any of the following load via import, in-app authoring, or a requested seed pack — the same mechanism behind the 13 frameworks seeded today.

Cross-border & international standards 13 more

FrameworkScope & usage
ISO/IEC 27002Companion to ISO 27001 — detailed implementation guidance for each Annex A control.
ISO/IEC 27701Extends an ISMS into a Privacy Information Management System (PIMS); maps GDPR-style privacy controls onto ISO 27001.
ISO 22301Business continuity management — disruption planning, recovery objectives, and exercise/testing evidence.
ISO/IEC 20000-1IT service management system, used by MSPs and IT service providers to prove service-delivery discipline.
NIST SP 800-53Full security and privacy control catalog behind FedRAMP and most US federal system authorizations; also used internationally as a reference.
NIST SP 800-171Protecting Controlled Unclassified Information (CUI) — the control baseline behind CMMC for the US Defense Industrial Base.
NIST AI Risk Management FrameworkGovern / Map / Measure / Manage structure for AI system risk, commonly paired with ISO/IEC 42001.
SOC 1 (SSAE 18)Internal-control-over-financial-reporting attestation, used where SOC 2's trust-services scope isn't the driver.
COBIT 2019ISACA's IT governance and management framework, often layered above a technical control set like CIS or ISO 27001.
CSA Cloud Controls MatrixCloud-specific control catalog from the Cloud Security Alliance, frequently mapped alongside ISO 27017/27018.
OWASP ASVS & LLM Top 10Application- and AI-application-security testing baselines, used to scope secure-development and AI-risk evidence.
FedRAMPUS federal cloud-authorization programme built on NIST 800-53; referenced globally as a cloud-security bar.
SWIFT Customer Security ProgrammeMandatory control baseline for banks and payment institutions connected to the SWIFT network.

United Kingdom 3 frameworks

FrameworkScope & usage
Cyber Essentials / Cyber Essentials PlusNCSC-backed baseline covering five technical controls; increasingly a contractual requirement for UK government and supply-chain work.
UK GDPR & Data Protection Act 2018The UK's post-Brexit data-protection regime, run alongside — not instead of — an information-security framework.
NCSC Cyber Assessment Framework (CAF)Outcome-based framework for UK critical national infrastructure and regulated essential services.

European Union 5 frameworks

FrameworkScope & usage
GDPRThe EU's baseline data-protection regulation; usually mapped onto an ISMS rather than run as a standalone control set.
NIS2 DirectiveNetwork-and-information-security obligations for essential and important entities across EU member states.
DORA — Digital Operational Resilience ActICT risk, incident reporting, resilience testing, and third-party oversight for EU financial entities. Seeded today — see the table above.
eIDAS 2.0Electronic identification and trust-services regulation, relevant to organisations issuing or relying on EU digital identity/trust services.
Cyber Resilience ActEmerging EU product-security regulation for connected hardware and software placed on the EU market.

United States 6 frameworks

FrameworkScope & usage
HIPAASafeguards for protected health information across covered entities and business associates. Seeded today — see the table above.
SOX (Sarbanes-Oxley)Internal-control requirements for public-company financial reporting.
GLBA (Gramm-Leach-Bliley)Safeguarding requirements for US financial institutions' customer data.
CCPA / CPRACalifornia's consumer privacy law — the most-referenced US state privacy regime.
CMMC 2.0Cybersecurity Maturity Model Certification for the US Defense Industrial Base, built on the NIST 800-171 control baseline.
FERPASafeguards for US student education records.

Middle East 7 frameworks

FrameworkScope & usage
SAMA Cyber Security FrameworkSaudi Central Bank's mandatory control baseline for banks, insurers, and finance companies.
NCA Essential Cybersecurity Controls (ECC)Saudi National Cybersecurity Authority's baseline for government and critical-sector entities.
Saudi PDPLPersonal Data Protection Law governing personal data processing in the Kingdom.
UAE Information Assurance RegulationUAE Cyber Security Council's control baseline for government and critical infrastructure entities (formerly NESA).
UAE PDPLFederal personal-data-protection law, plus free-zone regimes (DIFC, ADGM) with their own data-protection rules.
Qatar National Cyber Security FrameworkQatar's sector-wide cybersecurity control baseline.
Bahrain & Oman PDPLGulf-region personal-data-protection laws with GDPR-influenced structures.

South Asia 4 frameworks

FrameworkScope & usage
State Bank of Pakistan frameworksSBP's IT governance and cybersecurity control requirements for Pakistani banks and financial institutions.
PTA regulationsPakistan Telecommunication Authority's security and data-handling requirements for telecom and licensed service providers.
India DPDP Act 2023Digital Personal Data Protection Act — India's cross-sector personal-data law.
India RBI Cybersecurity FrameworkReserve Bank of India's baseline for banks and NBFCs, plus CERT-In incident-reporting directions.

Asia-Pacific 6 frameworks

FrameworkScope & usage
Singapore PDPAPersonal Data Protection Act — Singapore's cross-sector data-protection law.
Singapore MAS TRM GuidelinesMonetary Authority of Singapore's Technology Risk Management baseline for financial institutions.
Australia Essential EightACSC's prioritised mitigation strategies, widely used as a practical control baseline.
Australia Privacy Act & APRA CPS 234Cross-sector privacy law plus APRA's information-security prudential standard for regulated financial entities.
Japan APPIAct on the Protection of Personal Information — Japan's cross-sector data-protection law.
China PIPL & MLPS 2.0Personal Information Protection Law plus the Multi-Level Protection Scheme's graded security-classification requirements.

Americas & Africa 4 frameworks

FrameworkScope & usage
Canada PIPEDAFederal private-sector data-protection law.
Brazil LGPDLei Geral de Proteção de Dados — Brazil's GDPR-influenced data-protection law.
South Africa POPIAProtection of Personal Information Act — South Africa's cross-sector data-protection law.
Nigeria NDPRNigeria Data Protection Regulation — the country's baseline data-protection framework.
How it works

How grComply processes any framework

Import or author

Frameworks are added via JSON/YAML/CSV/API import, or built in-app with the same authoring tools Mutex uses for its own seed packs. Import validates structure — unique IDs, no orphaned nodes — before anything publishes.

Arbitrary depth, one data model

Every framework — international, regional, or a client's internal policy — is a versioned Framework Library made of ControlNodes: domain → control → sub-control → optional deeper levels. Some standards are shallow, others deeply nested; both are supported by the same tree.

Cross-framework mapping

Mappings are data, not code, using five relationship types — equivalent, partially_satisfies, supports, implements, mitigates_risk_for. One ControlNode can satisfy clauses in multiple standards; evidence uploaded once counts everywhere it applies; AI can suggest a mapping, a human always confirms it.

Mapping sets bundle related frameworks

A curated stack — frameworks plus cross-links plus propagation rules — imports, versions, and activates per tenant as one profile. Illustrative example: an AI-governance mapping set linking ISO/IEC 42001 (AI management), ISO/IEC 27001 (information assets), the NIST AI Risk Management Framework (Govern/Map/Measure/Manage), OWASP's LLM Top 10 (application risk), and the CSA AI Controls Matrix (cloud-native AI controls) — strategy, data security, risk, application security, and cloud controls connected in one graph, achieved through mapping sets, not application logic.

Versioning that never disturbs history

A published library change creates a new version with a diff of added, changed, and retired nodes. Tenants pin to a version until they adopt the next; historical evidence and observations remain tied to the version that was in effect at the time.

Completion, computed live

A control's status — compliant, partial, gap, stale, N/A — is derived live from evidence, scans, observations, and N/A decisions over the assigned library tree, never from a pre-seeded checklist. N/A and exemption logic applies at any node level and generalises to any framework.

Product screens

The control library, in the live workspace

The same screens shown on the grComply overview — focused on how frameworks, controls, and cross-mapping actually work day to day.

FAQ

Compliance frameworks in grComply

What is a compliance framework?

A structured set of controls — organised into domains, controls, and sub-controls — that a regulator, standards body, or customer requires an organisation to implement and prove with evidence. ISO 27001, SOC 2, and PCI DSS are examples; so is a national data-protection law like UK GDPR or Saudi Arabia's PDPL.

What's the difference between a regional and an international compliance framework?

An international framework applies the same way regardless of country, built by a standards body or industry consortium. A regional framework is issued by a specific country or bloc's regulator, and usually applies alongside — not instead of — an international standard.

Which compliance frameworks does grComply support today?

13 frameworks are seeded today: NIST CSF 2.0 and SOC 2 Type I/II as comprehensive, audit-ready libraries, plus CIS Controls v8, ISO/IEC 27001, 27017, 27018, and 42001, HIPAA, PCI DSS 4.0, DORA, MITRE ATT&CK, and ISA/IEC 62443 as structural seed packs ready to expand.

Can grComply support a country-specific regulation that isn't pre-built?

Yes. The control engine has no standard-specific knowledge baked in — frameworks load as data via import or in-app authoring. Adding a new country's regulation never means waiting on a vendor release cycle.

Does uploading evidence once cover multiple frameworks?

Yes, where the controls are genuinely equivalent. Cross-framework mappings are data — one control can satisfy clauses in several standards at once — so evidence uploaded once counts everywhere it applies.

Can one tenant run multiple frameworks at the same time?

Yes. A tenant is assigned one or more framework libraries, each with its own completion status, and a mapping-set profile can bundle several related frameworks and activate them together.

What happens when a framework publishes a new version?

A published change creates a new version with a diff of added, changed, and retired nodes. Tenants stay pinned to their current version until they adopt the next, and historical evidence remains tied to the version in effect at the time.

Can grComply support an internal, company-specific control baseline?

Yes. A tenant can create an internal framework using the exact same ControlNode model as any published standard, scoped to that tenant unless later promoted to the global library. See the full module breakdown on the grComply overview.

Tell us which frameworks your programme needs

Powered by Mutex Systems. Back to grComply overview → · Security Awareness Training → · grComply vs GRC platforms →

Get in touch

Talk to us about your frameworks

Tell us which international standards and regional regulations your programme needs to cover, and we'll route it to the right product specialist.

  • A product specialist replies personally — not a bot
  • No obligation after the first conversation
  • WhatsApp support also available 24/7

By submitting, you agree to be contacted about your enquiry. We respect your privacy.

Prefer to talk it through?

Book a meeting directly

Pick a time that works for you — 30 minutes with a product specialist, no sales script.

Ready to map your compliance programme?

We respond within one working day — or reach us instantly on WhatsApp.

WhatsApp us