Compyl
Frameworks70+ · one control library

Every framework. One control library.

Compyl cross-maps a single control library to 70+ compliance frameworks, regulations, and standards. Collect your evidence once, satisfy every framework it applies to, and keep them all continuously audit-ready, instead of running a separate project for each.

70+ frameworks125+ integrationsCollect once
One evidence item · every framework it satisfiesInteractive · pick one
MFA enforced on all userspulled from Okta / Microsoft Entra ID
Collected once · satisfies 6 controls across 6 frameworks
SOC 2CC6.1
Satisfied
ISO 27001A.8.5
Satisfied
PCI DSS v4.0.1Req 8.4
Satisfied
NIST SP 800-53IA-2(1)
Satisfied
HIPAA§164.312(d)
Satisfied
NIST CSF 2.0PR.AA-03
Satisfied
Mapped to every framework that needs it70+ frameworks
Collect once, satisfy many

One piece of evidence. Every framework it satisfies.

Compyl maps each control and its evidence across every framework that requires it. So a single artifact, pulled automatically from your stack, counts everywhere at once.

  • One control library mapped to all 70+ frameworks, no duplicate work per framework
  • Add the next framework in a fraction of the time, most of it is already covered
  • Evidence Health scores every artifact on relevance, freshness, and completeness
  • Coverage for a new framework is visible instantly, so only the net-new work remains
One controlMFA enforced on all usersPulled automatically from your identity provider · evidence from Okta and Microsoft Entra ID1 piece of evidence
Satisfies at once
SOC 2CC6.1 Logical access controls
Satisfied
ISO 27001A.8.5 Secure authentication
Satisfied
PCI DSS v4.0.1Req 8.4 Multi-factor authentication
Satisfied
NIST SP 800-53IA-2(1) Multi-factor authentication
Satisfied
+ 70 more frameworks cross-mapped automatically
The full library

77 frameworks, regulations and standards, and growing

From SOC 2 to the EU AI Act, every framework runs on the same connected evidence. Filter the library, or request a demo to see yours mapped to your stack.

ACSC Essential Eight – Maturity Level 1frameworkACSC Essential Eight – Maturity Level 2frameworkACSC Essential Eight – Maturity Level 3frameworkAPRA CPS 234regulationAssured AI Framework (AAIF)frameworkAWS Foundational Technical Review (FTR)attestationBSI Cloud Computing Compliance Criteria Catalogue (C5)attestationCCPAregulationCIS AWS Foundations BenchmarkstandardCIS v8frameworkCJIS Security PolicyregulationCloud Security Alliance Cloud Controls Matrix (CCM) 4.0.1frameworkCMMC Level 1attestationCMMC Level 2attestationCMS ARS 5.0standardCMS MARS-E v2.2standardCOBIT 2019frameworkCPRAregulationCSA Code of Conduct for GDPRframeworkCSA STARattestationCyber Risk Institute (CRI) ProfileframeworkCybersecurity Capability Maturity Model (C2M2)guidanceDigital Services Act (DSA)regulationDORAregulationETSI EN 319 401standardEU AI ActregulationFedRAMP 20xframeworkFedRAMP High BaselineframeworkFedRAMP Low BaselineframeworkFedRAMP Moderate BaselineframeworkFFIEC CAT (retired Aug 2025)frameworkFIPAregulationGDPRregulationGLBAregulationGLBA Safeguards RuleregulationHIPAAregulationISO 9001certificationISO/IEC 22301certificationISO/IEC 27001:2022certificationISO/IEC 27017:2015standardISO/IEC 27018standardISO/IEC 27031:2011standardISO/IEC 27032guidanceISO/IEC 27701certificationISO/IEC 42001:2023certificationLGPDregulationMAS TRM Guidelines & Cyber Hygiene NoticeregulationMicrosoft Supplier Privacy & Security Assurance (SSPA / DPR)standardMinimum Viable Secure Product (MVSP)guidanceMITRE ATT&CKguidanceMITRE D3FENDguidanceNCSC Cyber Assessment Framework (CAF)frameworkNERCregulationNIS2 DirectiveregulationNIST AI Risk Management FrameworkframeworkNIST CSF 2.0frameworkNIST Privacy FrameworkframeworkNIST Secure Software Development Framework (SSDF)guidanceNIST SP 800-171standardNIST SP 800-53standardNIST SP 800-66 Rev.2guidanceNISTIR 8374guidanceNYDFS Cybersecurity Regulation (23 NYCRR Part 500)regulationOFDSS (Open Finance Data Security Standard)frameworkOSFI B-13regulationPCI DSS v4.0.1standardPCI DSS SAQ AattestationPCI DSS SAQ A-EPattestationSEC Regulation S-PregulationSecure Controls Framework (SCF)frameworkSOC 2attestationSOX ITGCregulationSWIFT Customer Security Controls FrameworkframeworkTISAXattestationUK Cyber EssentialsattestationUSDPframeworkWCAG 2.2standard

Highlighted entries have a dedicated page. Need one that isn’t listed? Custom frameworks and internal control sets cross-map to the same library.

Why Compyl

Built to make every framework take less time than the last

The first framework builds the control library. Every one after it mostly reuses evidence you already have.

One source of truth

Controls, evidence, and mappings live in one place, connected across governance, risk, and compliance.

Continuous, not point-in-time

Evidence refreshes automatically and is scored for health, so frameworks stay audit-ready year-round.

Agentic AI does the busywork

AI drafts evidence blueprints and maps controls across frameworks, your experts approve what matters.

How many frameworks does Compyl support?

Compyl supports 70+ frameworks, regulations, and standards out of the box, including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, CCPA, PCI DSS, NIST CSF 2.0, NIST SP 800-53, FedRAMP, MAS, DORA, NIS2, and the EU AI Act, plus custom frameworks you define. One control library is cross-mapped to all of them, so evidence collected for one framework is already filed for every other framework that requires it, and adding the next framework mostly reuses what you already have.

Cross-mapping

How does cross-framework mapping work?

The same control answers several frameworks. Cross-mapping records that once, so evidence collected for one framework is already filed for the others. Four examples from the library.

ControlSOC 2ISO 27001:2022HIPAANIST CSF 2.0
Access reviewsCC6.2, CC6.3A.5.18§164.308(a)(4)PR.AA
Encryption at restCC6.1A.8.24§164.312(a)(2)(iv)PR.DS
Vendor due diligenceCC9.2A.5.19–5.22§164.308(b)GV.SC
Incident responseCC7.3–7.5A.5.24–5.28§164.308(a)(6)RS.MA
Frameworks FAQ

Questions about framework coverage

How many frameworks does Compyl support?

70+ frameworks out of the box, including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, CCPA, PCI DSS, NIST CSF, NIST SP 800-53, MAS, and NIS2, plus custom frameworks you define. One control library is cross-mapped to all of them.

Can one control satisfy multiple frameworks?

Yes. Compyl maps each control and its evidence across every framework it satisfies. Evidence of enforced MFA, for example, can satisfy SOC 2 CC6.1, ISO 27001 A.8.5, PCI DSS 8.4, and NIST 800-53 IA-2 at once, collected one time.

How fast can I add a new framework?

Because your evidence is mapped to a single control library, adding the next framework mostly reuses what you already have. Compyl shows coverage instantly, so only the net-new requirements need attention, making the second and third framework far faster than the first.

Can I add a custom or industry-specific framework?

Yes. Beyond the prebuilt catalog, you can define custom frameworks and internal control sets, then cross-map them to your existing controls and evidence so they stay continuously monitored alongside everything else.

How does Compyl keep framework evidence audit-ready?

Compyl collects evidence automatically and continuously scores every artifact on relevance, freshness, and completeness with Evidence Health. Gaps and drift surface weeks before an audit, so each framework stays in a live, audit-ready state.

GRC your way

See your frameworks, cross-mapped to your stack

One platform for the whole GRC lifecycle, with agentic AI that removes the busywork and leaves your experts in control.

Last reviewed September 2026 by the Compyl GRC team
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies