100% client-side — your answers never leave your browser

Control Mapper + Gap Assessment

See how controls map across ISO/IEC 27001:2022, NIST CSF 2.0 and SOC 2 (Trust Services Criteria) — then run a CMMI-style maturity self-assessment and export a prioritized gap report.

Browse a framework, select a control

Select a control on the left to see its cross-framework mappings.

Confidence: Exact direct counterpart · Partial covers part of the control · Related touches the same topic. Mappings are many-to-many and judgement-based — where no clean mapping exists, we say so rather than forcing one. Verify against the official standards before relying on a mapping in an audit.

Self-assessment
0 of 0 scored

Maturity scale (CMMI-style): 0 Not implemented · 1 Initial / ad-hoc · 2 Repeatable · 3 Defined · 4 Managed · 5 Optimized · N/A Not applicable (justification required).

Maturity radar

Maturity by domain
Gap heatmap — lowest-scoring domains
Top gaps — prioritized

Need help closing these gaps?

Hands-on consulting for ISO 27001, NIST CSF and SOC 2 readiness — remediation, documentation and audit prep.

Book a consultation →

Frequently asked questions

Which frameworks does the Control Mapper cross-map?

It maps controls across ISO/IEC 27001:2022 Annex A, NIST CSF 2.0 and SOC 2 Trust Services Criteria, with each crosswalk tagged by confidence (strong / partial / related) so you know how tightly two controls align.

How does the maturity gap assessment work?

You score each control area on a CMMI-style scale (e.g. Initial → Optimizing). The tool rolls your scores into a radar chart and heatmap, highlights the widest gaps, and generates a prioritized gap report you can export to PDF.

Is my assessment data sent anywhere?

No. Everything runs in your browser — there is no account and nothing is uploaded. You can save your work to a local JSON file and re-import it later. For the underlying control text, see the ISO 27001 Control Reference.

Can I map ISO 27001 to NIST CSF for free?

Yes — this tool is completely free with no sign-up. It is built for GRC analysts who need a quick ISO 27001 ↔ NIST CSF ↔ SOC 2 crosswalk and a defensible maturity baseline without paying for a GRC platform.