FRAMEWORKS

Map once. Preserve what each requirement means.

Map a fact once across 30+ supported frameworks. Each requirement keeps its own meaning, owner, and review state.

30+ supported frameworks · availability varies by deployment

PUBLIC CATALOG VIEW

The public list, with the maturity state attached.

The list below marks active lenses, registered references, and portfolio targets. A name on this page is not a promise of identical coverage, certification, or readiness.

  • Active lensNIST SP 800-53 Rev. 5NIST · Federal controls
  • RegisteredNIST SP 800-171 Rev. 3NIST · DIB safeguarding
  • Active lensCMMC Level 2U.S. Department of Defense · DIB cybersecurity
  • RegisteredISO/IEC 27001:2022ISO and IEC · Information security
  • RegisteredNIST Cybersecurity Framework 2.0NIST · Cyber risk management
  • RegisteredSOC 2® Trust Services CriteriaAICPA · Assurance criteria
  • Active lensCMMC Level 1U.S. Department of Defense · Foundational DIB cybersecurity
  • RegisteredNIST AI Risk Management FrameworkNIST · AI risk management
  • RegisteredNIST Secure Software Development FrameworkNIST · Secure software development
  • RegisteredEU Artificial Intelligence ActEuropean Union · AI governance regulation
  • PortfolioCMMC Level 3U.S. Department of Defense · Advanced DIB cybersecurity
  • PortfolioNIST SP 800-172 Rev. 3NIST · Enhanced CUI protection
  • PortfolioNIST Privacy FrameworkNIST · Privacy risk management
  • PortfolioHIPAA Security RuleU.S. Department of Health and Human Services · Health information safeguards
  • PortfolioGeneral Data Protection RegulationEuropean Union · Data protection and privacy
  • PortfolioNIS2 DirectiveEuropean Union · Cybersecurity risk measures
  • PortfolioDigital Operational Resilience ActEuropean Union · Financial operational resilience
  • PortfolioFBI CJIS Security PolicyFederal Bureau of Investigation · Criminal justice information

Eighteen catalogs are shown here as examples, across active, registered, and portfolio states. Availability, version, mapping depth, and enabled workflows are confirmed per deployment. The seals are ComplAI’s own navigation artwork—not official publisher marks, certifications, authorizations, or endorsements, and not assessment results or compliance guarantees.

MAPPING MODEL

Reuse facts without creating false equivalence.

One evidence item can support more than one requirement. You should still be able to see why, and each program keeps its own decision.

  1. 01

    Keep the official requirement text and version distinct.

  2. 02

    Record why a shared item is relevant to each mapping.

  3. 03

    Show missing evidence, conflicts, and stale links.

  4. 04

    A person reviews the mapping before it becomes a governed record.

NEXT DECISION

Confirm the catalogs and versions in your scope.

Coverage, version, and mapping depth are confirmed during scoping.

Discuss framework coverage