Skip to main content
ControlFrame
Control Atlas

Reuse the audit work you already paid for.

ControlFrame maps evidence domains across the company's assurance, privacy, security, sector, and AI obligations, then shows what carries forward, what needs refresh, and what is truly net-new.

Seeded atlas
Mapped frameworks
8
Evidence domains
10
Seed mappings
80
Reusable baseline
80%

The public atlas shows a seed model. Production workspaces expand the framework set by client industry, geography, customer commitments, and source-native package requirements.

Answer once · live engine

Answer once. Surface the next framework's reusable candidates.

These numbers are computed by the same engine that runs in the product — the sandbox register's met controls, projected through source-cited equivalence clusters. Answer 6 controls once in SOC 2, and 27 equivalent controls across 6 other frameworks surface as source-cited candidate mappings for qualified reviewer validation.

Answered once
6
Candidate mappings surfaced
27
HIPAA Security4 of 10 controls
NIST CSF 2.04 of 9 controls
ISO 270014 of 9 controls
HITRUST CSF4 of 11 controls
PCI DSS 4.0.17 of 9 controls
CMS EDE4 of 6 controls

Every candidate mapping requires reviewer confirmation and contributes zero credit until accepted — never an auto-granted status. Seed atlas today: 13 equivalence clusters · 64 mapped controls · 10 frameworks. Each curated proposition carries the authority or informative reference used to support review; it is represented as an official crosswalk only when the cited publisher says so.

Run answer-once live
One cluster, read end to end
SOC 2 CC6.1Logical access — provisioninganswered once
ISO 27001A.5.15 Access control
NIST CSF 2.0PR.AA Identity management & access control
HIPAA Security§164.312(a)(1) Access control (technical)
HITRUST CSF01 — Access Control Access control
PCI DSS 4.0.1Requirement 7 Need-to-know access
PCI DSS 4.0.1Requirement 8 Identity and authentication assurance
CMS EDEEDE AC (Access Control) Least-privilege access control over consumer data
confidence: highSecure Controls Framework Councilsuggested → auditor confirms
Governed reuse walkthrough

Collect once. Reuse only what survives review.

Follow one versioned evidence object from its native CMS record into NIST and HIPAA. The artifact stays singular; every target mapping keeps its own authority, reviewer decision, freshness gate, and delta.

Synthetic reference workflowNo tenant data or write

Propose: The cited atlas proposes where the accepted source artifact may help. Every cross-framework edge remains a candidate and contributes zero.

Governed evidence objectSource accepted

consent-confirmation-event.json

EV-2048 · Runtime event

Version
v1.2
Digest
sha256:8df1…a43c
Source
Enrollment API
Owner
EDE product assurance
Sensitivity
Restricted · synthetic
Native mappings
2
Collection run
RUN-8837
Source review
Reviewer 01 · accepted
Freshness gatecurrent · 30-day policy
Current

Reuse invalidates when freshness expires, source version changes, scope changes, control changes.

Stage 01 · decision register

Find applicable controls

The cited atlas proposes where the accepted source artifact may help. Every cross-framework edge remains a candidate and contributes zero.

4 obligations · 2 frameworksNamed reviewer required
Candidate credit
0
4 awaiting review
Credited mappings
0
accepted or released only
Held deltas
0
targeted proof still required
Repeat asks avoided
0
reference framework lanes
  1. NIST CSF 2.0DE.CM-09
    Computing activity and technology usage monitoring

    Candidate support for monitoring evidence; it does not satisfy the outcome alone.

    NIST CSF 2.0
    Candidate · 0 creditNo status or request avoidance
  2. NIST CSF 2.0PR.DS-01
    Confidentiality, integrity, and availability of data at rest

    Candidate support from digest and custody metadata; reviewer confirmation is pending.

    NIST CSF 2.0
    Candidate · 0 creditNo status or request avoidance
  3. HIPAA164.312(b)
    Audit controls

    Candidate support for an audit-control record within the scoped system.

    45 CFR
    Candidate · 0 creditNo status or request avoidance
  4. HIPAA164.312(c)(1)
    Integrity

    Candidate support from the validated digest; it does not establish compliance alone.

    45 CFR
    Candidate · 0 creditNo status or request avoidance

A named reviewer must confirm scope, sufficiency, and the remaining delta.

Collection policyAsk the owner only for the delta—not for evidence already governed.

A repeat request is avoided only after a named reviewer accepts the mapping and while the exact artifact version remains current. The counts above explain this reference workflow; they are not measured customer savings.

Instructional projection over checked-in synthetic evidence. Stage controls do not write tenant state or represent customer, assessor, or regulator acceptance.

One evidence spine
Controls map once, then project into each audit.
Carryover math
Reusable, refresh-needed, and net-new evidence stay separate.
AI review
Agents flag policy deltas, stale proof, and missing framework language.
Evidence spine

One proof model. Multiple audit outputs.

Frameworks should not create duplicate evidence rooms. ControlFrame captures a clean proof object once, preserves its chain of custody, and projects it into the audit package each client actually needs. The examples here are a target set, not a ceiling.

01
Capture

Policies, tickets, screenshots, logs, API traces, videos, inventories, and approvals enter one evidence model.

02
Normalize

Every artifact keeps owner, source system, date, scope, reviewer state, hash, and freshness metadata.

03
Project

Framework modules read from the same proof object, then add only the native IDs, formats, and deltas each audit requires.

Target framework families

The catalog prioritizes the obligations enterprise teams buy and audit against: common assurance, sector-specific mandates, and the fast-moving AI and resilience layer.

Enterprise assurance

Buyer-trust and board-level security proof that shows up across SaaS procurement.

SOC 2 · ISO 27001 · NIST CSF 2.0 · CIS Controls
Regulated sectors

Healthcare, payment, public-sector, defense, and marketplace programs with prescriptive evidence asks.

CMS EDE · HIPAA · HITRUST · PCI DSS 4.0.1 · FedRAMP Rev. 5 · CMMC 2.0
Next pressure wave

AI governance, operational resilience, product security, and public-company cyber disclosure.

EU AI Act · ISO 42001 · NIST AI RMF · DORA · NIS2 · Cyber Resilience Act · SEC cyber disclosure
Selected domain

Access and Identity

Who can access scoped systems, how is access approved, and how often is it reviewed?

Reusable evidence
MFA policy and configuration export
Provisioning/deprovisioning tickets
Privileged access review
Native audit differences
CMS EDE adds IDM, Okta, RIDP/FARS, and auditor-observed proofing paths.
PCI adds stronger CDE scoping and cardholder-data access evidence.
Reuse path

Show the client what carries forward before the audit starts.

This is the one-click value: point ControlFrame at completed evidence and a new framework, then generate the reuse, refresh, and net-new workplan.

58% reusable24% refresh18% net new
Reusable
58%

Security policies, access reviews, risk management, incident response, vendor governance, logging, and continuity evidence.

Control narratives that already describe cloud, identity, monitoring, and security operations.

Refresh
24%

Policies need CMS EDE-specific language for consumer handling, roles, oversight, and EDE operating responsibilities.

Evidence freshness needs to match the CMS audit window and source row expectations.

Net new
18%

Application UI Toolkit screenshots and browser traces.

Eligibility/API FIT outputs, partner test cases, communications toolkit artifacts, RIDP/FARS, IDM/Okta, and CMS UAT-gated evidence.

CMS EDE · answer once

The audit vertical no GRC dashboard touches.

CMS Enhanced Direct Enrollment is the hardest connection in US healthcare marketplaces — an annual third-party Business Audit before a partner can touch the Federally-Facilitated Marketplace. ControlFrame maps each EDE safeguard onto the common assurance and security frameworks, so evidence proven once for the EDE audit can surface candidate mappings for SOC 2, HIPAA, HITRUST, and NIST CSF review.

Each candidate carries the authority or informative reference used to support review; NIST SP 800-63 applies specifically to the identity-proofing candidate. Every candidate requires reviewer validation and contributes zero credit until accepted. Run it live with CMS EDE as the source framework.

The live answer-once workspace is available above; this section keeps the CMS EDE-specific mapping rationale in view.
Access control (least privilege)
EDE AC
SOC 2 CC6.1HIPAA §164.312(a)(1)NIST CSF PR.AAISO 27001 A.5.15
Transmission encryption (TLS)
EDE TLS
HIPAA §164.312(e)(1)NIST CSF PR.DSISO 27001 A.8.24SOC 2 C1.1
Audit logging
EDE AL
SOC 2 CC7.2HIPAA §164.312(b)NIST CSF DE.CMISO 27001 A.8.16
Vulnerability scanning
EDE VULN
ISO 27001 A.8.8NIST CSF RS.MIHIPAA §164.308(a)(6)
Identity proofing (RIDP)
EDE IDP
NIST CSF PR.AAHITRUST 01HIPAA §164.312(a)(1)
Privacy notice & consent
EDE PRIV
SOC 2 P4.1
Crosswalk explorer

Pick any two regimes. See what carries over and what is left.

This runs the same equivalence-cluster engine behind the "answer once" numbers above, for every framework pair in the seeded atlas — not only SOC 2. Every candidate carries the published crosswalk it is grounded in; the delta list is arithmetic, not an estimate.

Pick a regime pair
Evidence produced forcarries into
EU AI Act — high-risk provider obligations (Art. 9–15) controls met
4/ 7
ISO/IEC 42001:2023 — AI management system candidates surfaced
3/ 6
Gap remaining
3/ 6
Carries over — 3 of 6 (50%)
  1. Cl. 6.1.2medium confidence
    AI risk assessment

    ISO 27001 6.1.2, HIPAA §164.308(a)(1), NIST CSF GV.RM, HITRUST category 03, and PCI DSS Requirement 12.3 overlap on documented risk identification, evaluation, and treatment. PCI is CDE-specific and includes targeted-risk-analysis conditions. The AI controls extend the discipline to AI risk, so confidence remains medium rather than implying interchangeability.

    NIST OLIR — Online Informative References (framework-to-framework mappings) (opens in a new tab)
  2. Cl. 7.5medium confidence
    Documented information

    EU AI Act Art. 12 (record-keeping / logging) aligns with ISO 42001 7.5 (documented information) for traceability and with NIST CSF DE.CM (continuous monitoring) for the operational logging substrate — strong directional overlap; AI-scoped, so medium.

    ControlFrame judgement — EU AI Act ↔ ISO/IEC 42001:2023 / NIST AI RMF alignment references (opens in a new tab)
  3. Cl. 8.3 / A.6.2high confidence
    AI system impact assessment

    EU AI Act Art. 14 (human oversight, incl. stop/override) and NIST AI RMF MANAGE 2.4 (mechanisms to supersede/disengage/deactivate) are near 1:1 on the human-control intent. ISO 42001 8.3 / A.6.2 (impact assessment) is the design-time analogue feeding oversight design.

    ControlFrame judgement — EU AI Act ↔ ISO/IEC 42001:2023 / NIST AI RMF alignment references (opens in a new tab)
Delta — 3 ISO/IEC 42001:2023 — AI management system controls with no suggested carryover
  1. Cl. 6.1.3AI risk treatment
  2. Cl. 9.2Internal audit
  3. Cl. 10.2Nonconformity & corrective action

Every candidate is a zero-credit SUGGESTION a qualified reviewer confirms — never an automatic met-status. Control IDs and references are the same ones the sandbox register scores; the driving satisfaction state is synthetic reference data, not a certification. The gap list is arithmetic — this framework's controls minus the candidates above — not a completeness claim about the target standard.

Mapping sources & licensing
  1. NIST OLIR — Online Informative References (opens in a new tab)Public domain (U.S. federal government work).
  2. NIST Cybersecurity and Privacy Reference Tool (CPRT) (opens in a new tab)Public domain (U.S. federal government work).
  3. NIST SP 800-66r2 — HIPAA Security Rule implementation crosswalk (opens in a new tab)Public domain (U.S. federal government work).
  4. Secure Controls Framework — cross-framework control mapping (opens in a new tab)Licensed CC BY-ND 4.0 — cited and read unmodified; ControlFrame does not republish or alter the SCF matrix.
  5. PCI DSS v4.0.1 and supporting-document library (opens in a new tab)PCI's own published standard and mapping guidance.
  6. CMS Enhanced Direct Enrollment — Audit, Privacy & Security requirements (opens in a new tab)Public domain (U.S. federal government work).

ControlFrame never reproduces AICPA Trust Services Criteria text or the HITRUST CSF catalogue on a public page — where a mapping touches either, the candidate above cites the control identifier and a plain-language paraphrase only, and links the authoritative source in full at the SOC 2 module and the HITRUST module. A mapping without a named published source above is ControlFrame's own judgement, not a citation to an external crosswalk.

Control Atlas | ControlFrame