Privacy Design®
Knowledge Base → Frameworks & law → Control Frameworks — compare & cross-walk

Control Frameworks — compare & cross-walk

ℹ️ Informational — not a substitute for the source standards, and not legal advice. Each framework is captured as control ids + our own concise summaries + taxonomy tags (no verbatim copyrighted text). Verify against the official documents.

As of 2026-09-08. Anchored on NIST CSF 2.0 functions + the five ISO/IEC 27002:2022 attributes; cross-framework links use NIST IR 8477 STRM relations. 🔶 = fast-moving.

A common, structured capture of security & privacy control frameworks so they can be combined, compared, requirement-picked for a context, and checked for gaps and incompatibilities. Each control is tagged against a shared taxonomy (NIST CSF 2.0 functions + the five ISO/IEC 27002:2022 attributes), and cross-framework links use the NIST IR 8477 STRM relation vocabulary (equal / subset / superset / intersects / none).

Pick the frameworks below, filter by CIA or capability, and click a CSF function to cross-walk the selected frameworks’ controls side by side. Captured in full: NIST CSF 2.0, NIST Privacy Framework 1.0, BSI C5:2020 and ENS (RD 311/2022); representative subsets for BSI C3A, SecNumCloud, BSI TR-03161 and BSI TR-03185. (ISO/IEC standards are copyrighted and are not reproduced here — obtain them from ISO.)

Frameworks captured

FrameworkVersionPublisherObligation modelAssuranceCoverageRef
BSI C5:20202020BSI (Germany)baseline_plus_additionalattestation (ISAE 3000 (also IDW PS 951))full
BSI C3A (Cloud Computing Autonomy) 🔶2025BSI (Germany)baseline_plus_additionalself_assessment (BSI C3A)representative-subset
NIST Cybersecurity Framework 2.02.0 (2024)NIST (US)outcomesself_assessment (CSF 2.0)full
NIST Privacy Framework 1.01.0 (2020)NIST (US)outcomesself_assessment (Privacy Framework 1.0)full
ENS — Esquema Nacional de SeguridadRD 311/2022Gobierno de Espana / CCNlevelscertification (ENS (CCN))full
SecNumCloud (ANSSI) 🔶3.2 (2022)ANSSI (France)qualificationqualification (SecNumCloud referential (built on ISO/IEC 27001))representative-subset
BSI TR-03161 (eHealth application security)currentBSI (Germany)outcomeslab_test (BSI TR-03161)representative-subset
BSI TR-03185 (Secure Software Lifecycle) 🔶currentBSI (Germany)outcomeslab_test (BSI TR-03185)representative-subset

Cross-framework mappings (NIST IR 8477 STRM)

FromControlRelationControlToConfidenceRationale
c3aDTAintersects_withPIc5-2020mediumC3A data autonomy/portability overlaps C5 Portability & Interoperability but goes further on exit/reversibility.
c3aOPAno_relationshipc5-2020mediumC3A operational autonomy (run the service independently of the provider) has no direct C5 security criterion.
tr-03161P3-cryptointersects_withCRYc5-2020highBoth require strong cryptography and key management for the backend/service.