framework fluency · 24 control domains

Control crosswalk
mapper

Map your security program once. Check off the control domains you actually run and read your coverage against NIST CSF 2.0, ISO 27001:2022, SOC 2, and CIS Controls v8 at the same time, with a gap register ranked by how many requirements each missing domain would unlock.

This is an unofficial, plain-English crosswalk for planning, not an audit. Coverage is measured against the requirements this crosswalk maps, not every clause of each framework. Your checklist lives only in your browser; nothing is uploaded.

Frameworks to measure against

Your controls