Every compliance framework, one control library.
A compliance framework is a structured set of controls a regulator, standards body, or customer requires you to prove — ISO 27001, SOC 2, and PCI DSS are examples; so is a national data-protection law. grComply treats every one of them as the same kind of object: a versioned Framework Library built from ControlNodes, not a hardcoded page tree. That's what lets it run international standards alongside regional and national regulations in one control inventory — and map one piece of evidence to every framework it satisfies.
What's the difference between a regional and an international compliance framework? An international framework — ISO 27001, SOC 2, NIST CSF, PCI DSS — applies the same way regardless of country, built by a standards body or industry consortium. A regional framework is issued by a specific country or bloc's regulator — UK GDPR, the EU's DORA, Saudi Arabia's SAMA CSF — and usually applies alongside, not instead of, an international standard.
How grComply benefits the compliance process
One control, many frameworks
Cross-framework mappings are data — one ControlNode can satisfy clauses in ISO 27001, NIST CSF, SOC 2, and CIS simultaneously. Evidence uploaded once counts everywhere it applies; AI can suggest a mapping, a human always confirms it.
Frameworks are data, not code
Import via JSON/YAML/CSV/API, or author in-app — validated for structure before publish. Adding a new country's regulation never means waiting on a vendor release cycle or a code deployment.
Versioned, never silently changed
A published library change creates a new version with a diff of added, changed, and retired nodes. Tenants pin to a version until they choose to adopt the next; historical evidence stays tied to the version in effect at the time.
Completion is computed, never a checklist
A control's status — compliant, partial, gap, N/A — is derived live from evidence, scans, observations, and N/A decisions over the assigned tree, never from a pre-seeded checklist someone ticks by hand.
Mapping sets bundle related standards
A curated stack of frameworks plus cross-links and propagation rules imports and activates as one profile — for example an AI-governance stack spanning ISO/IEC 42001, ISO/IEC 27001, and the NIST AI Risk Management Framework.
Tenant-authored baselines, same rigor
A client's own internal policy — a "Client Security Baseline" or vendor-specific requirement set — uses the identical ControlNode model, scoped to that tenant unless promoted to the global library.
13 frameworks, ready to assign
Two are comprehensive, audit-ready libraries out of the box. The rest are structural seed packs — the full domain/control hierarchy is in place, ready to expand to complete sub-control depth via import.
| Framework | Publisher | Jurisdiction | Structure | Depth |
|---|---|---|---|---|
| NIST Cybersecurity Framework 2.0 | NIST | US / International | 6 Functions · 22 Categories · 106 Subcategories | Comprehensive |
| SOC 2 Type I | AICPA | US / International | 5 TSC series · 20 Criteria · 61 Points of focus | Comprehensive |
| SOC 2 Type II | AICPA | US / International | 5 TSC series · 20 Criteria · 61 Points of focus | Comprehensive |
| CIS Controls v8 | Center for Internet Security | International | 3 Implementation Groups · 18 Controls | Structural seed |
| ISO/IEC 27001:2022 | ISO/IEC | International | Annex themes · Annex A control set | Structural seed |
| ISO/IEC 27017 (Cloud Security) | ISO/IEC | International | Cloud-specific control extension to 27001/27002 | Structural seed |
| ISO/IEC 27018 (Cloud Privacy) | ISO/IEC | International | PII-in-cloud control extension | Structural seed |
| ISO/IEC 42001:2023 (AI Management System) | ISO/IEC | International | Clause themes · Annex A AI controls | Structural seed |
| HIPAA | U.S. HHS — OCR | United States | Rule areas · Safeguards · Implementation specs | Structural seed |
| PCI DSS 4.0 | PCI Security Standards Council | International | 6 Goals · Requirements 1–12 | Structural seed |
| DORA — Digital Operational Resilience Act | European Union | European Union | 5 pillars · ICT risk, incident, resilience, third-party | Structural seed |
| MITRE ATT&CK (Enterprise) | MITRE Corporation | International | Tactics · Techniques · Sub-techniques | Structural seed |
| ISA/IEC 62443 | ISA / IEC | International | Foundational Requirements · Security requirements (OT/ICS) | Structural seed |
Reading "structural seed": the domain and control hierarchy is seeded and assignable today; sub-control depth expands as a tenant imports the full official text or Mutex publishes an expanded pack — the same versioned import path used for any new framework, so nothing is ever a hardcoded dead end.
Regional & international frameworks the same engine runs
Because the control engine has no standard-specific knowledge baked in, any of the following load via import, in-app authoring, or a requested seed pack — the same mechanism behind the 13 frameworks seeded today.
Cross-border & international standards 13 more
| Framework | Scope & usage |
|---|---|
| ISO/IEC 27002 | Companion to ISO 27001 — detailed implementation guidance for each Annex A control. |
| ISO/IEC 27701 | Extends an ISMS into a Privacy Information Management System (PIMS); maps GDPR-style privacy controls onto ISO 27001. |
| ISO 22301 | Business continuity management — disruption planning, recovery objectives, and exercise/testing evidence. |
| ISO/IEC 20000-1 | IT service management system, used by MSPs and IT service providers to prove service-delivery discipline. |
| NIST SP 800-53 | Full security and privacy control catalog behind FedRAMP and most US federal system authorizations; also used internationally as a reference. |
| NIST SP 800-171 | Protecting Controlled Unclassified Information (CUI) — the control baseline behind CMMC for the US Defense Industrial Base. |
| NIST AI Risk Management Framework | Govern / Map / Measure / Manage structure for AI system risk, commonly paired with ISO/IEC 42001. |
| SOC 1 (SSAE 18) | Internal-control-over-financial-reporting attestation, used where SOC 2's trust-services scope isn't the driver. |
| COBIT 2019 | ISACA's IT governance and management framework, often layered above a technical control set like CIS or ISO 27001. |
| CSA Cloud Controls Matrix | Cloud-specific control catalog from the Cloud Security Alliance, frequently mapped alongside ISO 27017/27018. |
| OWASP ASVS & LLM Top 10 | Application- and AI-application-security testing baselines, used to scope secure-development and AI-risk evidence. |
| FedRAMP | US federal cloud-authorization programme built on NIST 800-53; referenced globally as a cloud-security bar. |
| SWIFT Customer Security Programme | Mandatory control baseline for banks and payment institutions connected to the SWIFT network. |
United Kingdom 3 frameworks
| Framework | Scope & usage |
|---|---|
| Cyber Essentials / Cyber Essentials Plus | NCSC-backed baseline covering five technical controls; increasingly a contractual requirement for UK government and supply-chain work. |
| UK GDPR & Data Protection Act 2018 | The UK's post-Brexit data-protection regime, run alongside — not instead of — an information-security framework. |
| NCSC Cyber Assessment Framework (CAF) | Outcome-based framework for UK critical national infrastructure and regulated essential services. |
European Union 5 frameworks
| Framework | Scope & usage |
|---|---|
| GDPR | The EU's baseline data-protection regulation; usually mapped onto an ISMS rather than run as a standalone control set. |
| NIS2 Directive | Network-and-information-security obligations for essential and important entities across EU member states. |
| DORA — Digital Operational Resilience Act | ICT risk, incident reporting, resilience testing, and third-party oversight for EU financial entities. Seeded today — see the table above. |
| eIDAS 2.0 | Electronic identification and trust-services regulation, relevant to organisations issuing or relying on EU digital identity/trust services. |
| Cyber Resilience Act | Emerging EU product-security regulation for connected hardware and software placed on the EU market. |
United States 6 frameworks
| Framework | Scope & usage |
|---|---|
| HIPAA | Safeguards for protected health information across covered entities and business associates. Seeded today — see the table above. |
| SOX (Sarbanes-Oxley) | Internal-control requirements for public-company financial reporting. |
| GLBA (Gramm-Leach-Bliley) | Safeguarding requirements for US financial institutions' customer data. |
| CCPA / CPRA | California's consumer privacy law — the most-referenced US state privacy regime. |
| CMMC 2.0 | Cybersecurity Maturity Model Certification for the US Defense Industrial Base, built on the NIST 800-171 control baseline. |
| FERPA | Safeguards for US student education records. |
Middle East 7 frameworks
| Framework | Scope & usage |
|---|---|
| SAMA Cyber Security Framework | Saudi Central Bank's mandatory control baseline for banks, insurers, and finance companies. |
| NCA Essential Cybersecurity Controls (ECC) | Saudi National Cybersecurity Authority's baseline for government and critical-sector entities. |
| Saudi PDPL | Personal Data Protection Law governing personal data processing in the Kingdom. |
| UAE Information Assurance Regulation | UAE Cyber Security Council's control baseline for government and critical infrastructure entities (formerly NESA). |
| UAE PDPL | Federal personal-data-protection law, plus free-zone regimes (DIFC, ADGM) with their own data-protection rules. |
| Qatar National Cyber Security Framework | Qatar's sector-wide cybersecurity control baseline. |
| Bahrain & Oman PDPL | Gulf-region personal-data-protection laws with GDPR-influenced structures. |
South Asia 4 frameworks
| Framework | Scope & usage |
|---|---|
| State Bank of Pakistan frameworks | SBP's IT governance and cybersecurity control requirements for Pakistani banks and financial institutions. |
| PTA regulations | Pakistan Telecommunication Authority's security and data-handling requirements for telecom and licensed service providers. |
| India DPDP Act 2023 | Digital Personal Data Protection Act — India's cross-sector personal-data law. |
| India RBI Cybersecurity Framework | Reserve Bank of India's baseline for banks and NBFCs, plus CERT-In incident-reporting directions. |
Asia-Pacific 6 frameworks
| Framework | Scope & usage |
|---|---|
| Singapore PDPA | Personal Data Protection Act — Singapore's cross-sector data-protection law. |
| Singapore MAS TRM Guidelines | Monetary Authority of Singapore's Technology Risk Management baseline for financial institutions. |
| Australia Essential Eight | ACSC's prioritised mitigation strategies, widely used as a practical control baseline. |
| Australia Privacy Act & APRA CPS 234 | Cross-sector privacy law plus APRA's information-security prudential standard for regulated financial entities. |
| Japan APPI | Act on the Protection of Personal Information — Japan's cross-sector data-protection law. |
| China PIPL & MLPS 2.0 | Personal Information Protection Law plus the Multi-Level Protection Scheme's graded security-classification requirements. |
Americas & Africa 4 frameworks
| Framework | Scope & usage |
|---|---|
| Canada PIPEDA | Federal private-sector data-protection law. |
| Brazil LGPD | Lei Geral de Proteção de Dados — Brazil's GDPR-influenced data-protection law. |
| South Africa POPIA | Protection of Personal Information Act — South Africa's cross-sector data-protection law. |
| Nigeria NDPR | Nigeria Data Protection Regulation — the country's baseline data-protection framework. |
How grComply processes any framework
Import or author
Frameworks are added via JSON/YAML/CSV/API import, or built in-app with the same authoring tools Mutex uses for its own seed packs. Import validates structure — unique IDs, no orphaned nodes — before anything publishes.
Arbitrary depth, one data model
Every framework — international, regional, or a client's internal policy — is a versioned Framework Library made of ControlNodes: domain → control → sub-control → optional deeper levels. Some standards are shallow, others deeply nested; both are supported by the same tree.
Cross-framework mapping
Mappings are data, not code, using five relationship types — equivalent, partially_satisfies, supports, implements, mitigates_risk_for. One ControlNode can satisfy clauses in multiple standards; evidence uploaded once counts everywhere it applies; AI can suggest a mapping, a human always confirms it.
Mapping sets bundle related frameworks
A curated stack — frameworks plus cross-links plus propagation rules — imports, versions, and activates per tenant as one profile. Illustrative example: an AI-governance mapping set linking ISO/IEC 42001 (AI management), ISO/IEC 27001 (information assets), the NIST AI Risk Management Framework (Govern/Map/Measure/Manage), OWASP's LLM Top 10 (application risk), and the CSA AI Controls Matrix (cloud-native AI controls) — strategy, data security, risk, application security, and cloud controls connected in one graph, achieved through mapping sets, not application logic.
Versioning that never disturbs history
A published library change creates a new version with a diff of added, changed, and retired nodes. Tenants pin to a version until they adopt the next; historical evidence and observations remain tied to the version that was in effect at the time.
Completion, computed live
A control's status — compliant, partial, gap, stale, N/A — is derived live from evidence, scans, observations, and N/A decisions over the assigned library tree, never from a pre-seeded checklist. N/A and exemption logic applies at any node level and generalises to any framework.
The control library, in the live workspace
The same screens shown on the grComply overview — focused on how frameworks, controls, and cross-mapping actually work day to day.






Compliance frameworks in grComply
What is a compliance framework?
A structured set of controls — organised into domains, controls, and sub-controls — that a regulator, standards body, or customer requires an organisation to implement and prove with evidence. ISO 27001, SOC 2, and PCI DSS are examples; so is a national data-protection law like UK GDPR or Saudi Arabia's PDPL.
What's the difference between a regional and an international compliance framework?
An international framework applies the same way regardless of country, built by a standards body or industry consortium. A regional framework is issued by a specific country or bloc's regulator, and usually applies alongside — not instead of — an international standard.
Which compliance frameworks does grComply support today?
13 frameworks are seeded today: NIST CSF 2.0 and SOC 2 Type I/II as comprehensive, audit-ready libraries, plus CIS Controls v8, ISO/IEC 27001, 27017, 27018, and 42001, HIPAA, PCI DSS 4.0, DORA, MITRE ATT&CK, and ISA/IEC 62443 as structural seed packs ready to expand.
Can grComply support a country-specific regulation that isn't pre-built?
Yes. The control engine has no standard-specific knowledge baked in — frameworks load as data via import or in-app authoring. Adding a new country's regulation never means waiting on a vendor release cycle.
Does uploading evidence once cover multiple frameworks?
Yes, where the controls are genuinely equivalent. Cross-framework mappings are data — one control can satisfy clauses in several standards at once — so evidence uploaded once counts everywhere it applies.
Can one tenant run multiple frameworks at the same time?
Yes. A tenant is assigned one or more framework libraries, each with its own completion status, and a mapping-set profile can bundle several related frameworks and activate them together.
What happens when a framework publishes a new version?
A published change creates a new version with a diff of added, changed, and retired nodes. Tenants stay pinned to their current version until they adopt the next, and historical evidence remains tied to the version in effect at the time.
Can grComply support an internal, company-specific control baseline?
Yes. A tenant can create an internal framework using the exact same ControlNode model as any published standard, scoped to that tenant unless later promoted to the global library. See the full module breakdown on the grComply overview.
Tell us which frameworks your programme needs
Powered by Mutex Systems. Back to grComply overview → · Security Awareness Training → · grComply vs GRC platforms →
Talk to us about your frameworks
Tell us which international standards and regional regulations your programme needs to cover, and we'll route it to the right product specialist.
- A product specialist replies personally — not a bot
- No obligation after the first conversation
- WhatsApp support also available 24/7
By submitting, you agree to be contacted about your enquiry. We respect your privacy.
Book a meeting directly
Pick a time that works for you — 30 minutes with a product specialist, no sales script.
Ready to map your compliance programme?
We respond within one working day — or reach us instantly on WhatsApp.