Control Mapper + Gap Assessment
See how controls map across ISO/IEC 27001:2022, NIST CSF 2.0 and SOC 2 (Trust Services Criteria) — then run a CMMI-style maturity self-assessment and export a prioritized gap report.
Select a control on the left to see its cross-framework mappings.
Confidence: Exact direct counterpart · Partial covers part of the control · touches the same topic. Mappings are many-to-many and judgement-based — where no clean mapping exists, we say so rather than forcing one. Verify against the official standards before relying on a mapping in an audit.
Maturity scale (CMMI-style): 0 Not implemented · 1 Initial / ad-hoc · 2 Repeatable · 3 Defined · 4 Managed · 5 Optimized · N/A Not applicable (justification required).
Need help closing these gaps?
Hands-on consulting for ISO 27001, NIST CSF and SOC 2 readiness — remediation, documentation and audit prep.