Complies
CM-02 CONTROL MAP

Control mapping software: implement once, satisfy every framework

Your access control policy satisfies SOC 2 CC6.1, ISO 27001 A.5.15, and GDPR Art. 32 at the same time. Complies maps it once and gives you credit everywhere.

See pricing

Control mapping software links each internal control to every framework requirement it satisfies, so you implement a control once and it counts across SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS at the same time. The crosswalk is real: a solid access control policy satisfies SOC 2 CC6.1, ISO 27001 A.5.15, and GDPR Article 32 simultaneously, and frameworks overlap far more than their page counts suggest. Complies ships that crosswalk built in. Add ISO 27001 after your SOC 2 work has started and the new framework arrives roughly 60% pre-filled, because existing controls and their evidence carry over automatically instead of being re-documented from zero. Cross-mapping is included on every plan from Growth up, at $199 per month billed yearly, which is $2,388 for the year against a typical $10,000-plus Vanta year on an annual contract. One honest limitation: cross-mapping does not erase framework-specific work. ISO 27001 still requires its own management clauses, GDPR still has processing records no SOC 2 control covers, and Complies flags exactly those unique gaps rather than pretending the overlap is total. What it removes is the duplicated majority, which is where most of the wasted effort lives.

It works alongside compliance tracking software and audit readiness, and plugs straight into soc 2 compliance software, iso 27001 compliance software on every plan from Growth up.

CM-02 CONTROL MAP

What changes when it is in place

One control, many frameworks

Each control carries every framework code it satisfies: CC6.1, A.5.15, Art. 32 on a single card. Update the control once and its status updates in every mapped framework simultaneously.

Add a framework, start at 60%

When a customer asks for ISO 27001 mid-SOC 2, you add the framework and your readiness score starts roughly 60% pre-filled from work you already did, instead of at zero.

Evidence carries across the map

Evidence attached to a control counts for every framework that control satisfies. One access review screenshot does the job for SOC 2 and ISO 27001 instead of being collected twice.

Unique gaps flagged honestly

The crosswalk is not total and Complies says so. Framework-specific requirements like ISO management clauses or GDPR processing records are flagged as unique gaps with plain-language guidance on closing them.

QUESTIONS

Common questions

It is software that maintains a crosswalk between your internal controls and the framework requirements they satisfy, so one implemented control gets credit in every framework that recognizes it. Complies ships the crosswalk for SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS built in, and keeps it current as frameworks revise, so you never maintain the mapping yourself.

Roughly 60% in our mapping, for teams with a completed or in-progress SOC 2 control set. The overlap is heaviest in access control, change management, and logging. It is not total: ISO 27001 adds management system clauses, internal audit requirements, and a risk methodology that SOC 2 never asks for, and Complies flags those as unique gaps from day one.

Not strictly, and the Starter plan at $79 per month covers a single framework without it. In practice most companies get a second framework request within a year or two of the first, usually from an enterprise customer or a European deal, and mapped controls mean that request costs weeks instead of another full cycle.

Put control mapping on autopilot

All plans include it. Prices are public. Start today.