Frameworks
19 frameworks. One evidence set.
Nineteen compliance, security and AI governance frameworks across Canada, the United States and Europe, with crosswalks between them from one evidence set.
The frameworks your regulators, customers or board ask about, in Canada, the United States and Europe, in one platform. Every framework ships with crosswalks to the others, so adding a standard does not restart your evidence program.
International and industry standards
ISO 27001:2022
Information Security Management System. The international reference standard, updated in 2022 with new Annex A controls.
SOC 2
AICPA Trust Services Criteria, reported as Type I or Type II. The most-requested security attestation for SaaS and technology companies selling into enterprise.
PCI DSS v4.0.1
Payment Card Industry Data Security Standard. Twelve requirements, quarterly vulnerability scans and an annual QSA review for any organization that stores, processes or transmits cardholder data.
TISAX
Trusted Information Security Assessment Exchange. The information security standard of the automotive industry and its supply chain, based on the VDA ISA questionnaire and administered by ENX.
NIST CSF 2.0
NIST Cybersecurity Framework, version 2.0 released in 2024 with a new Govern function. A risk-based, sector-independent approach that layers on top of the standards you already follow.
North America
HIPAA
Health Insurance Portability and Accountability Act. Security Rule, Privacy Rule and Breach Notification Rule for covered entities and their business associates.
NIST SP 800-53
Security and Privacy Controls for US federal information systems. Twenty control families and three baselines; the catalog behind FedRAMP and CMMC.
CMMC 2.0
Cybersecurity Maturity Model Certification. Required for US DoD contractors; three levels, with Level 2 practices aligned to NIST SP 800-171.
Law 25
Québec's act modernizing the protection of personal information in the private sector, in full force since September 2023: PIAs, consent, confidentiality incidents, right of access and portability.
CPCSC
Canadian Program for Cyber Security Certification for the defence supply chain. Three levels, from Level 1 self-assessment to Level 3 assessed by National Defence.
TGV
Trousse globale de vérification, the BCH/MSSS certification framework for technological products and services used in Québec's health and social services network: security, personal information protection, performance and technology.
PIPEDA
Personal Information Protection and Electronic Documents Act. Ten federal principles applicable to organizations engaged in commercial activity in Canada.
OSFI B-10 / B-13
Office of the Superintendent of Financial Institutions guidelines on outsourcing (B-10) and technology and cyber risk management (B-13) for federally regulated financial institutions.
CAN/DGSI 104
Baseline Cyber Security Controls for Small and Medium Organizations. Eighteen main controls (55 sub-controls) published by DGSI under the Standards Council of Canada; the standard behind the CyberSecure Canada program.
Europe
GDPR
General Data Protection Regulation. Lawful basis, DPIAs, data subject rights, security of processing (Article 32) and processor agreements for any organization processing data of EU residents.
NIS2
Network and Information Security Directive. Ten minimum measures under Article 21, management body accountability and 24-hour incident notification for essential and important entities.
DORA
Digital Operational Resilience Act, applicable to EU financial entities since 17 January 2025: ICT risk, incident reporting, resilience testing and the ICT third-party register.
AI governance
ISO 42001
ISO/IEC 42001:2023, the first AI management system standard. Applies to any organization developing, providing or using AI and shares the Annex SL structure of ISO 27001.
NIST AI RMF
NIST Artificial Intelligence Risk Management Framework, version 1.0 of January 2023. Four functions, Govern, Map, Measure, Manage, applicable to any sector and any maturity level.
How crosswalks work
When you add a new framework in Sentrix, the crosswalk engine maps every piece of evidence you have already collected to the controls it satisfies in the new standard. Gaps surface immediately.
- Add ISO 27001 to an existing SOC 2 program: the crosswalk shows what remains to be documented.
- Add Law 25 to an existing GDPR program: the crosswalk shows the delta immediately.
- Add DORA to an existing NIS2 program: overlap analysis from the same evidence store.
- Custom framework builder for internal standards and bespoke regulatory requirements.
Each framework page lists the crosswalks delivered to the other frameworks.
See how many frameworks your current controls already satisfy.
Framework · ISO 27001:2022
ISO 27001:2022: from ISMS to certification in one program
The international standard for information security management systems: clauses 4 to 10, 93 Annex A controls, and a two-stage certification audit.
Learn more →
Framework · SOC 2
SOC 2 is a continuous program, not a one-time audit
AICPA attestation framework across five Trust Services Criteria categories, reported as Type I or Type II. Continuous evidence, drift alerts, auditor access.
Learn more →
Framework · HIPAA
HIPAA continuous. Not HIPAA compliant once a year.
The Security Rule, Privacy Rule and Breach Notification Rule of the US HIPAA law, for covered entities and their business associates, monitored continuously.
Learn more →
Framework · GDPR
GDPR: Article 32, DPIAs and data subject rights, all mapped
The EU regulation for any organization processing data of EU residents: lawful basis, DPIAs, data subject rights, Article 32 measures and processor contracts.
Learn more →
Framework · PCI DSS v4.0.1
PCI DSS v4.0.1: 12 requirements, one evidence program
Payment Card Industry Data Security Standard: twelve requirements, quarterly vulnerability scans and annual validation by a QSA report or self-assessment.
Learn more →
Framework · NIS2
NIS2: ten measures, management liability, 24-hour warning
The EU network and information security directive: ten minimum measures under Article 21, management body accountability and 24-hour incident early warning.
Learn more →
Framework · DORA
DORA is in force. Your ICT risk framework needs to be too.
The EU Digital Operational Resilience Act for financial entities, applicable since 17 January 2025: ICT risk, incident reporting, testing and ICT third parties.
Learn more →
Framework · NIST CSF 2.0
NIST CSF 2.0: the risk framework your board understands
The NIST Cybersecurity Framework, version 2.0 of 2024: six outcome-based functions, including the new Govern function, that layer on top of your standards.
Learn more →
Framework · NIST SP 800-53
NIST SP 800-53: the control catalog behind FedRAMP and CMMC
NIST catalog of security and privacy controls for US federal information systems: 20 control families, three baselines, Revision 5, behind FedRAMP and CMMC.
Learn more →
Framework · CMMC 2.0
CMMC 2.0: required to keep and win DoD contracts
US DoD Cybersecurity Maturity Model Certification: three levels, 110 NIST SP 800-171 practices at Level 2, triennial C3PAO assessment and SPRS score tracking.
Learn more →
Framework · Law 25
Law 25: PIAs, incidents, access and portability, documented
Québec's private-sector privacy law, in full force since September 2023: privacy impact assessments, confidentiality incidents, access rights and portability.
Learn more →
Framework · CPCSC
CPCSC: self-assessment, third party, National Defence
Canadian Program for Cyber Security Certification for defence suppliers: Levels 1, 2 and 3, ITSP.10.171 controls, accredited assessment and a crosswalk to CMMC.
Learn more →
Framework · TGV
TGV: four domains, one BCH certification dossier
The BCH/MSSS Trousse globale de vérification for technological products and services in Québec's health and social services network: four evaluation domains.
Learn more →
Framework · ISO 42001
ISO 42001: the first AI management system standard
ISO/IEC 42001:2023: requirements for an AI management system for any organization that develops, provides or uses AI, on the Annex SL structure of ISO 27001.
Learn more →
Framework · NIST AI RMF
NIST AI RMF: the risk framework for trustworthy AI
The NIST AI Risk Management Framework, version 1.0 of January 2023: four functions, Govern, Map, Measure, Manage, across the full AI lifecycle in any sector.
Learn more →
Framework · CAN/DGSI 104
CAN/DGSI 104: the cybersecurity baseline for Canadian SMEs
Canada's baseline cyber security controls standard for SMEs: 18 main controls, 55 sub-controls, two levels, and the CyberSecure Canada certification program.
Learn more →
Framework · PIPEDA
PIPEDA: ten principles, enforceable obligations
Canada's federal private-sector privacy law: ten fair information principles, breach reporting to the Privacy Commissioner and the bridge to GDPR adequacy.
Learn more →
Framework · OSFI B-10 / B-13
OSFI B-10 and B-13: outsourcing, technology and cyber risk
OSFI guidelines on outsourcing (B-10) and technology and cyber risk management (B-13) for Canada's federally regulated financial institutions, in one program.
Learn more →
Framework · TISAX
TISAX: VDA ISA controls, ENX assessment, shared label
The automotive industry's information security standard: VDA ISA questionnaire, three assessment levels, ENX-accredited providers, label valid three years.
Learn more →
Frequently asked questions
- Which frameworks does Sentrix support?
- Nineteen frameworks, each with its own page: ISO 27001, SOC 2, PCI DSS, TISAX and NIST CSF; HIPAA, NIST SP 800-53, CMMC, Law 25, PIPEDA, CPCSC, TGV, OSFI guidelines B-10 and B-13, and CAN/DGSI 104; GDPR, NIS2 and DORA; ISO 42001 and the NIST AI RMF. Each page describes what the framework requires, what Sentrix provides and the crosswalks to the other frameworks.
- What happens when you add a framework to an existing program?
- When you add a new framework in Sentrix, the crosswalk engine maps every piece of evidence you have already collected to the controls it satisfies in the new standard. Gaps surface immediately, without restarting your evidence program. Adding ISO 27001 to a SOC 2 program, Law 25 to a GDPR program or DORA to a NIS2 program means seeing the delta rather than starting from zero.
- Can evidence collected once serve several frameworks?
- Yes. Every control you configure in Sentrix is mapped to every active framework in your program. Evidence collected for one requirement, such as access logging, satisfies the equivalent requirements of the other standards you follow at the same time. Each framework page lists the crosswalks delivered to the other pages.
- Can we track an internal standard or a contractual requirement that is not on the list?
- Yes. A custom framework builder lets you create a control set for an internal standard, a contractual requirement or a sector regulation that is not on the list, then map it to your existing evidence like any supported framework. The same connectors, the same evidence store and the same reports apply.
Let's talk about your compliance program.
Last updated: 2026-09-17
