Control Frameworks — compare & cross-walk
ℹ️ Informational — not a substitute for the source standards, and not legal advice. Each framework is captured as control ids + our own concise summaries + taxonomy tags (no verbatim copyrighted text). Verify against the official documents.
As of 2026-09-08. Anchored on NIST CSF 2.0 functions + the five ISO/IEC 27002:2022 attributes; cross-framework links use NIST IR 8477 STRM relations. 🔶 = fast-moving.
A common, structured capture of security & privacy control frameworks so they can be combined, compared, requirement-picked for a context, and checked for gaps and incompatibilities. Each control is tagged against a shared taxonomy (NIST CSF 2.0 functions + the five ISO/IEC 27002:2022 attributes), and cross-framework links use the NIST IR 8477 STRM relation vocabulary (equal / subset / superset / intersects / none).
Pick the frameworks below, filter by CIA or capability, and click a CSF function to cross-walk the selected frameworks’ controls side by side. Captured in full: NIST CSF 2.0, NIST Privacy Framework 1.0, BSI C5:2020 and ENS (RD 311/2022); representative subsets for BSI C3A, SecNumCloud, BSI TR-03161 and BSI TR-03185. (ISO/IEC standards are copyrighted and are not reproduced here — obtain them from ISO.)
Compare & cross-walk
Coverage counts controls tagged to the chosen axis; an empty cell is a coverage gap for that framework. Click a row to cross-walk the selected frameworks' controls. The obligation filter matches a control's level (or, for tiered schemes like ENS, a category where it applies). Indicative — verify against the standards.
Frameworks captured
| Framework | Version | Publisher | Obligation model | Assurance | Coverage | Ref |
|---|---|---|---|---|---|---|
| BSI C5:2020 | 2020 | BSI (Germany) | baseline_plus_additional | attestation (ISAE 3000 (also IDW PS 951)) | full | ↗ |
| BSI C3A (Cloud Computing Autonomy) 🔶 | 2025 | BSI (Germany) | baseline_plus_additional | self_assessment (BSI C3A) | representative-subset | ↗ |
| NIST Cybersecurity Framework 2.0 | 2.0 (2024) | NIST (US) | outcomes | self_assessment (CSF 2.0) | full | ↗ |
| NIST Privacy Framework 1.0 | 1.0 (2020) | NIST (US) | outcomes | self_assessment (Privacy Framework 1.0) | full | ↗ |
| ENS — Esquema Nacional de Seguridad | RD 311/2022 | Gobierno de Espana / CCN | levels | certification (ENS (CCN)) | full | ↗ |
| SecNumCloud (ANSSI) 🔶 | 3.2 (2022) | ANSSI (France) | qualification | qualification (SecNumCloud referential (built on ISO/IEC 27001)) | representative-subset | ↗ |
| BSI TR-03161 (eHealth application security) | current | BSI (Germany) | outcomes | lab_test (BSI TR-03161) | representative-subset | ↗ |
| BSI TR-03185 (Secure Software Lifecycle) 🔶 | current | BSI (Germany) | outcomes | lab_test (BSI TR-03185) | representative-subset | ↗ |
Cross-framework mappings (NIST IR 8477 STRM)
| From | Control | Relation | Control | To | Confidence | Rationale |
|---|---|---|---|---|---|---|
| c3a | DTA | intersects_with | PI | c5-2020 | medium | C3A data autonomy/portability overlaps C5 Portability & Interoperability but goes further on exit/reversibility. |
| c3a | OPA | no_relationship | — | c5-2020 | medium | C3A operational autonomy (run the service independently of the provider) has no direct C5 security criterion. |
| tr-03161 | P3-crypto | intersects_with | CRY | c5-2020 | high | Both require strong cryptography and key management for the backend/service. |