{"id":2834,"date":"2026-07-06T13:21:42","date_gmt":"2026-07-06T12:21:42","guid":{"rendered":"https:\/\/icomply.pm\/resources\/article-cross-mapping\/"},"modified":"2026-09-08T12:27:49","modified_gmt":"2026-09-08T11:27:49","slug":"cross-mapping","status":"publish","type":"post","link":"https:\/\/icomply.pt\/en\/resources\/cross-mapping\/","title":{"rendered":"One control, six frameworks: how cross mapping really works"},"content":{"rendered":"<h2 data-dc-tpl=\"25\">Cross Mapping<\/h2>\n<p data-dc-tpl=\"25\">Most compliance tools are organised around a single standard. You buy one for ISO 27001, another for SOC 2, a spreadsheet for NIS2, and the same evidence is uploaded three times. Cross-mapping breaks this pattern by making the <strong data-dc-tpl=\"26\">control<\/strong> \u2014 rather than the framework \u2014 the unit of work.  <\/p>\n<h2 data-dc-tpl=\"27\">Frameworks overlap far more than they differ<\/h2>\n<p data-dc-tpl=\"28\">ISO 27001, NIS2, DORA, SOC 2, the GDPR and the AI Act were drawn up by different bodies for different reasons, but they all require many of the same things: access control, encryption, logging, incident response and supplier management. The wording differs; the underlying controls are the same. <\/p>\n<h2 data-dc-tpl=\"29\">A practical example: MFA<\/h2>\n<p data-dc-tpl=\"30\">Consider a single control \u2014 \u201cMulti-factor authentication enforced for all privileged access.\u201d Implement it once and it simultaneously fulfils: <\/p>\n<ul data-dc-tpl=\"31\">\n<li data-dc-tpl=\"32\"><strong data-dc-tpl=\"33\">ISO 27001<\/strong> \u2014 access control objectives set out in Annex A.<\/li>\n<li data-dc-tpl=\"34\"><strong data-dc-tpl=\"35\">NIS2<\/strong> \u2014 cybersecurity risk management measures.<\/li>\n<li data-dc-tpl=\"36\"><strong data-dc-tpl=\"37\">DORA <\/strong>\u2014 ICT access and authentication requirements.<\/li>\n<li data-dc-tpl=\"38\"><strong data-dc-tpl=\"39\">SOC 2<\/strong> \u2014 logical access criteria.<\/li>\n<li data-dc-tpl=\"40\"><strong data-dc-tpl=\"41\">GDPR <\/strong>\u2014 security of processing in accordance with Article 32.<\/li>\n<\/ul>\n<p data-dc-tpl=\"42\">One check, one piece of evidence, five frameworks ticked off. In a single-standard tool, I would track this five times. <\/p>\n<h2 data-dc-tpl=\"43\">The architecture that makes it possible<\/h2>\n<p data-dc-tpl=\"44\">Cross-mapping requires a shared model: laws and standards are mapped to a common library of controls; the controls are linked to risks and evidence. When you attach a document to a control, all requirements that reference it inherit the evidence \u2014 with the version history intact. <\/p>\n<h2 data-dc-tpl=\"45\">What you get<\/h2>\n<ul data-dc-tpl=\"46\">\n<li data-dc-tpl=\"47\"><strong data-dc-tpl=\"48\">No duplication of effort <\/strong>\u2014 implement and record it once.<\/li>\n<li data-dc-tpl=\"49\"><strong data-dc-tpl=\"50\">Faster audits<\/strong> \u2014 auditors see the same control mapped to their framework.<\/li>\n<li data-dc-tpl=\"51\"><strong data-dc-tpl=\"52\">Honest coverage<\/strong> \u2014 the gaps are visible across all frameworks at a glance.<\/li>\n<li data-dc-tpl=\"53\"><strong data-dc-tpl=\"54\">A more cost-effective expansion<\/strong> \u2014 adding a new standard reuses controls that are already in place.<\/li>\n<\/ul>\n<p data-dc-tpl=\"55\">It is the architecture on which the world\u2019s best GRC platforms are built \u2014 and it is at the heart of iComply.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Why a control-centred architecture is superior to single-standard tools \u2014 explained using a practical example of multi-factor authentication.<\/p>\n","protected":false},"author":1,"featured_media":2850,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_ice_seo_score":0,"_ice_review":"","footnotes":""},"categories":[44],"tags":[],"class_list":["post-2834","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-iso-and-security"],"_links":{"self":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts\/2834","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/comments?post=2834"}],"version-history":[{"count":4,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts\/2834\/revisions"}],"predecessor-version":[{"id":4067,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts\/2834\/revisions\/4067"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/media\/2850"}],"wp:attachment":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/media?parent=2834"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/categories?post=2834"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/tags?post=2834"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}