Cross Mapping
Most compliance tools are organised around a single standard. You buy one for ISO 27001, another for SOC 2, a spreadsheet for NIS2, and the same evidence is uploaded three times. Cross-mapping breaks this pattern by making the control — rather than the framework — the unit of work.
Frameworks overlap far more than they differ
ISO 27001, NIS2, DORA, SOC 2, the GDPR and the AI Act were drawn up by different bodies for different reasons, but they all require many of the same things: access control, encryption, logging, incident response and supplier management. The wording differs; the underlying controls are the same.
A practical example: MFA
Consider a single control — “Multi-factor authentication enforced for all privileged access.” Implement it once and it simultaneously fulfils:
- ISO 27001 — access control objectives set out in Annex A.
- NIS2 — cybersecurity risk management measures.
- DORA — ICT access and authentication requirements.
- SOC 2 — logical access criteria.
- GDPR — security of processing in accordance with Article 32.
One check, one piece of evidence, five frameworks ticked off. In a single-standard tool, I would track this five times.
The architecture that makes it possible
Cross-mapping requires a shared model: laws and standards are mapped to a common library of controls; the controls are linked to risks and evidence. When you attach a document to a control, all requirements that reference it inherit the evidence — with the version history intact.
What you get
- No duplication of effort — implement and record it once.
- Faster audits — auditors see the same control mapped to their framework.
- Honest coverage — the gaps are visible across all frameworks at a glance.
- A more cost-effective expansion — adding a new standard reuses controls that are already in place.
It is the architecture on which the world’s best GRC platforms are built — and it is at the heart of iComply.