Sentrix

Frameworks

19 frameworks. One evidence set.

Nineteen compliance, security and AI governance frameworks across Canada, the United States and Europe, with crosswalks between them from one evidence set.

The frameworks your regulators, customers or board ask about, in Canada, the United States and Europe, in one platform. Every framework ships with crosswalks to the others, so adding a standard does not restart your evidence program.

International and industry standards

ISO 27001:2022

Information Security Management System. The international reference standard, updated in 2022 with new Annex A controls.

SOC 2

AICPA Trust Services Criteria, reported as Type I or Type II. The most-requested security attestation for SaaS and technology companies selling into enterprise.

PCI DSS v4.0.1

Payment Card Industry Data Security Standard. Twelve requirements, quarterly vulnerability scans and an annual QSA review for any organization that stores, processes or transmits cardholder data.

TISAX

Trusted Information Security Assessment Exchange. The information security standard of the automotive industry and its supply chain, based on the VDA ISA questionnaire and administered by ENX.

NIST CSF 2.0

NIST Cybersecurity Framework, version 2.0 released in 2024 with a new Govern function. A risk-based, sector-independent approach that layers on top of the standards you already follow.

North America

HIPAA

Health Insurance Portability and Accountability Act. Security Rule, Privacy Rule and Breach Notification Rule for covered entities and their business associates.

NIST SP 800-53

Security and Privacy Controls for US federal information systems. Twenty control families and three baselines; the catalog behind FedRAMP and CMMC.

CMMC 2.0

Cybersecurity Maturity Model Certification. Required for US DoD contractors; three levels, with Level 2 practices aligned to NIST SP 800-171.

Law 25

Québec's act modernizing the protection of personal information in the private sector, in full force since September 2023: PIAs, consent, confidentiality incidents, right of access and portability.

CPCSC

Canadian Program for Cyber Security Certification for the defence supply chain. Three levels, from Level 1 self-assessment to Level 3 assessed by National Defence.

TGV

Trousse globale de vérification, the BCH/MSSS certification framework for technological products and services used in Québec's health and social services network: security, personal information protection, performance and technology.

PIPEDA

Personal Information Protection and Electronic Documents Act. Ten federal principles applicable to organizations engaged in commercial activity in Canada.

OSFI B-10 / B-13

Office of the Superintendent of Financial Institutions guidelines on outsourcing (B-10) and technology and cyber risk management (B-13) for federally regulated financial institutions.

CAN/DGSI 104

Baseline Cyber Security Controls for Small and Medium Organizations. Eighteen main controls (55 sub-controls) published by DGSI under the Standards Council of Canada; the standard behind the CyberSecure Canada program.

Europe

GDPR

General Data Protection Regulation. Lawful basis, DPIAs, data subject rights, security of processing (Article 32) and processor agreements for any organization processing data of EU residents.

NIS2

Network and Information Security Directive. Ten minimum measures under Article 21, management body accountability and 24-hour incident notification for essential and important entities.

DORA

Digital Operational Resilience Act, applicable to EU financial entities since 17 January 2025: ICT risk, incident reporting, resilience testing and the ICT third-party register.

AI governance

ISO 42001

ISO/IEC 42001:2023, the first AI management system standard. Applies to any organization developing, providing or using AI and shares the Annex SL structure of ISO 27001.

NIST AI RMF

NIST Artificial Intelligence Risk Management Framework, version 1.0 of January 2023. Four functions, Govern, Map, Measure, Manage, applicable to any sector and any maturity level.

How crosswalks work

When you add a new framework in Sentrix, the crosswalk engine maps every piece of evidence you have already collected to the controls it satisfies in the new standard. Gaps surface immediately.

  • Add ISO 27001 to an existing SOC 2 program: the crosswalk shows what remains to be documented.
  • Add Law 25 to an existing GDPR program: the crosswalk shows the delta immediately.
  • Add DORA to an existing NIS2 program: overlap analysis from the same evidence store.
  • Custom framework builder for internal standards and bespoke regulatory requirements.

Each framework page lists the crosswalks delivered to the other frameworks.

See how many frameworks your current controls already satisfy.

Contact us

Frequently asked questions

Which frameworks does Sentrix support?
Nineteen frameworks, each with its own page: ISO 27001, SOC 2, PCI DSS, TISAX and NIST CSF; HIPAA, NIST SP 800-53, CMMC, Law 25, PIPEDA, CPCSC, TGV, OSFI guidelines B-10 and B-13, and CAN/DGSI 104; GDPR, NIS2 and DORA; ISO 42001 and the NIST AI RMF. Each page describes what the framework requires, what Sentrix provides and the crosswalks to the other frameworks.
What happens when you add a framework to an existing program?
When you add a new framework in Sentrix, the crosswalk engine maps every piece of evidence you have already collected to the controls it satisfies in the new standard. Gaps surface immediately, without restarting your evidence program. Adding ISO 27001 to a SOC 2 program, Law 25 to a GDPR program or DORA to a NIS2 program means seeing the delta rather than starting from zero.
Can evidence collected once serve several frameworks?
Yes. Every control you configure in Sentrix is mapped to every active framework in your program. Evidence collected for one requirement, such as access logging, satisfies the equivalent requirements of the other standards you follow at the same time. Each framework page lists the crosswalks delivered to the other pages.
Can we track an internal standard or a contractual requirement that is not on the list?
Yes. A custom framework builder lets you create a control set for an internal standard, a contractual requirement or a sector regulation that is not on the list, then map it to your existing evidence like any supported framework. The same connectors, the same evidence store and the same reports apply.

Let's talk about your compliance program.

Last updated: 2026-09-17