Compyl cross-maps a single control library to 70+ compliance frameworks, regulations, and standards. Collect your evidence once, satisfy every framework it applies to, and keep them all continuously audit-ready, instead of running a separate project for each.
Each runs on the same connected evidence and continuous monitoring, with its own page explaining how Compyl automates it. The full library of 70+ is just below.
The trust standard for B2B SaaS, Type I and Type II across all five Trust Services Criteria.
Explore SOC 2Run a certifiable ISMS continuously and collect Annex A evidence automatically.
Explore ISO 27001Govern your AI management system (AIMS) on the same control library as your ISMS.
Explore ISO 42001Safeguard PHI across the Security, Privacy, and Breach Notification rules.
Explore HIPAAProtect cardholder data and stay continuously aligned to PCI DSS v4.
Explore PCI DSSManage cybersecurity risk across all six functions, Govern to Recover.
Explore NIST CSF 2.0Implement and monitor the federal control catalog and keep your ATO.
Explore NIST SP 800-53Operationalize EU data-privacy obligations, DSARs, DPIAs, and the 72-hour breach clock.
Explore GDPRMeet the Cyber Hygiene Notice and TRM Guidelines, and prove it to the regulator.
Explore MAS TRMCompyl maps each control and its evidence across every framework that requires it. So a single artifact, pulled automatically from your stack, counts everywhere at once.
From SOC 2 to the EU AI Act, every framework runs on the same connected evidence. Filter the library, or request a demo to see yours mapped to your stack.
Highlighted entries have a dedicated page. Need one that isn’t listed? Custom frameworks and internal control sets cross-map to the same library.
The first framework builds the control library. Every one after it mostly reuses evidence you already have.
Controls, evidence, and mappings live in one place, connected across governance, risk, and compliance.
Evidence refreshes automatically and is scored for health, so frameworks stay audit-ready year-round.
AI drafts evidence blueprints and maps controls across frameworks, your experts approve what matters.
Compyl supports 70+ frameworks, regulations, and standards out of the box, including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, CCPA, PCI DSS, NIST CSF 2.0, NIST SP 800-53, FedRAMP, MAS, DORA, NIS2, and the EU AI Act, plus custom frameworks you define. One control library is cross-mapped to all of them, so evidence collected for one framework is already filed for every other framework that requires it, and adding the next framework mostly reuses what you already have.
The same control answers several frameworks. Cross-mapping records that once, so evidence collected for one framework is already filed for the others. Four examples from the library.
| Control | SOC 2 | ISO 27001:2022 | HIPAA | NIST CSF 2.0 |
|---|---|---|---|---|
| Access reviews | CC6.2, CC6.3 | A.5.18 | §164.308(a)(4) | PR.AA |
| Encryption at rest | CC6.1 | A.8.24 | §164.312(a)(2)(iv) | PR.DS |
| Vendor due diligence | CC9.2 | A.5.19–5.22 | §164.308(b) | GV.SC |
| Incident response | CC7.3–7.5 | A.5.24–5.28 | §164.308(a)(6) | RS.MA |
70+ frameworks out of the box, including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, CCPA, PCI DSS, NIST CSF, NIST SP 800-53, MAS, and NIS2, plus custom frameworks you define. One control library is cross-mapped to all of them.
Yes. Compyl maps each control and its evidence across every framework it satisfies. Evidence of enforced MFA, for example, can satisfy SOC 2 CC6.1, ISO 27001 A.8.5, PCI DSS 8.4, and NIST 800-53 IA-2 at once, collected one time.
Because your evidence is mapped to a single control library, adding the next framework mostly reuses what you already have. Compyl shows coverage instantly, so only the net-new requirements need attention, making the second and third framework far faster than the first.
Yes. Beyond the prebuilt catalog, you can define custom frameworks and internal control sets, then cross-map them to your existing controls and evidence so they stay continuously monitored alongside everything else.
Compyl collects evidence automatically and continuously scores every artifact on relevance, freshness, and completeness with Evidence Health. Gaps and drift surface weeks before an audit, so each framework stays in a live, audit-ready state.
One platform for the whole GRC lifecycle, with agentic AI that removes the busywork and leaves your experts in control.