Framework mappings

Compliance framework mappings:
generated from a live control library.

Crosswalks between the DPDP Act, GDPR, SOC 2, ISO 27001, ISO 27701, ISO 42001 and the EU AI Act, built from the controls the product actually tests, with the gaps listed and every row copyable.

45 shared controls716 mappings30 frameworksCopy as CSV
01

What is a compliance framework mapping?

A compliance framework mapping, or crosswalk, pairs the requirements of two frameworks that can be satisfied by the same work. TryTrustable builds its mappings from a shared control library: each requirement is mapped to the controls that evidence it, and two requirements are paired only when they share a control that is actually tested.

Most published crosswalks are drawn by hand from the text of two standards and say that clause X is similar to clause Y. These are narrower and more useful for audit: a pair appears only when a single tested control is evidence for both. That also makes the gaps exact, because a requirement with no shared control is listed rather than stretched to fit.

MappingWhat it showsShared controlsRequirements reached (A · B)
DPDP Act to GDPRWhere India's DPDP Act and the EU GDPR are evidenced by the same control, and the DPDP duties with no GDPR counterpart.1115/15 · 17/20
SOC 2 to ISO 27001SOC 2 criteria and ISO/IEC 27001:2022 Annex A controls that share a control.2055/61 · 87/93
ISO 27701 to DPDP ActWhat the privacy management standard covers of the DPDP Act, and what it leaves.512/16 · 12/15
ISO 42001 to EU AI ActAI management system controls and AI Act articles that share evidence.932/38 · 18/18

Counts are computed from the control library when the pages are built.

02

Why a shared control library, not a spreadsheet

A spreadsheet crosswalk tells you what should overlap. A control library tells you what does, because the same control result moves every requirement mapped to it. Test MFA once and SOC 2 CC6.1, ISO 27001 A.8.5 and DPDP section 8(5) all move together; a requirement with no mapped control is shown as not modelled rather than scored as passing. The cross-framework mapping engine does this in the product, the integrations feed it live results, and coverage lists all 30 frameworks.

Questions

The things people ask us

How are these mappings made?

From the product's control library. It holds 45 shared controls and 716 mappings to 594 requirements across 30 frameworks. Each page joins two frameworks through the controls they share and lists what is left on each side. Mappings that did not survive review are withheld until the library is corrected.

Does a shared control mean two requirements are equivalent?

No. It means the same implemented control is tested against both, so one result is evidence for both. The requirements can still differ in scope, legal effect and what an auditor or regulator asks of that evidence. Each mapping page states the differences that matter.

Can I use these mappings in my own spreadsheet?

Yes. Each mapping page has a Copy as CSV button that copies every row, one line per control and requirement with the library's description. Nothing needs to be downloaded and no email is asked for.

Why is my framework pair not here?

These four pairs are the ones people ask about most. The library holds 30 frameworks, listed on the coverage page, and the platform computes the overlap for any pair once you enable them. Tell us which pair you need when you book a demo.

How often do the mappings change?

When the control library changes. The pages are regenerated from the same data the product reads, so a mapping added or corrected in the product appears here at the next build rather than being edited by hand.

Book a walkthrough

Your next audit could be a link.

Thirty minutes. We connect one cloud account live and show you real evidence landing in the ledger before the call ends.