Framework explorer
Compliance
One control, many regulations. Spine maps 395 requirements from 15 frameworks across the US, Canada, India, the UK and EU onto 118 common controls, so one piece of evidence answers every framework that asks the same question.
How the crosswalk works
Answer the question once, for every framework.
Regulators ask the same things in different words. A common control set turns fifteen checklists into one.
Ask the question once
Each common control is one plain question, such as "is access checked before anyone gets in". Frameworks ask it in their own words.
Map every framework to it
Each framework requirement points at exactly one common control, so SOC 2, ISO 27001 and DPDP wording all land on the same row.
Collect evidence once
The platform collects evidence against the common control, so one record answers every framework that asks. Less duplicate work before an audit.
Explorer
Pick a region or a framework, then a control.
Selecting a control lists every framework requirement it covers. This is the crosswalk the Compliance Center collects evidence against.
Frameworks (15)
Select a framework to see only its controls. Select it again to clear.
118 of 118 common controls, all frameworks.
CCF-AC-01 · Access control
Role-based access and least privilege
Access is granted by role on a need-to-know basis and the data layer enforces it.
Covers 11 requirements across 10 frameworks.
- CCPA / CPRAUS
- 1798.150 Reasonable security procedures and practices
- DPDP ActIndia
- s.8(5) Reasonable security safeguards to prevent a personal data breach
- GDPR / UK GDPRUK/EU
- Art 28(3)(c) All measures required by Article 32 taken
- GLBA SafeguardsUS
- 314.4(c)(1) Access controls limit customer information to authorised users
- HIPAA SecurityUS
- 164.308(a)(4) Information access management
- ISO/IEC 27001Global
- A.5.15 Access control
- A.8.3 Information access restriction
- NIST CSF 2.0US
- PR.AA Identity Management, Authentication and Access Control
- PCI DSSGlobal
- Req 7 Access restricted by need to know
- PIPEDACanada
- 4.7.3(c) Technological measures: authentication and tamper-evident records
- SOC 2US
- CC6.3 Least privilege at the data layer
Scope
Controls mapped, not certification.
What this page shows
Each mapping says a common control is designed to support that requirement and that the platform collects evidence for it. It is not an audit opinion and we make no claim of third party assurance on this site. Your auditors and your own compliance team decide what the evidence proves.
In the product, the Compliance Center tracks evidence, owners, attestations and waivers against these same controls, and its Guardian agent explains each gap in plain words.
Questions
Common questions about the mapping.
No. This page shows controls mapped, not certification. Mapping tells you which requirements a control is designed to support and where the evidence comes from. Your auditors still decide what the evidence proves.
It is exported from the same framework registry the Compliance Center runs on, so the site and the product cannot drift apart. It carries definitions only, never customer data or control status.
Yes. A new framework is a table of requirements, each pointing at a common control. Evidence already collected for that control then counts towards it on day one.
Map your obligations onto one control set.
Tell us which regulators you answer to. We will show where the evidence for each requirement comes from.