The Global Compliance Crosswalk
One matrix mapping every control domain across ISO 27001, SOC 2, NIST CSF, CIS Controls, GDPR, NIS2, DORA, HIPAA, PCI DSS and CCPA — see equivalents and gaps at a glance.
EquivalentPartialRelated—No direct requirement (gap)
Two-framework crosswalks
Prefer a side-by-side view? Jump straight to any pair.
- ISO 27001 ↔ NIST CSF 2.015
- ISO 27001 ↔ NIST 800-5315
- NIST 800-53 ↔ NIST CSF 2.014
- NIST CSF 2.0 ↔ PCI DSS13
- ISO 27001 ↔ PCI DSS11
- DORA ↔ ISO 2700111
- DORA ↔ NIST 800-5311
- CIS Controls v8 ↔ ISO 2700110
- Essential Eight ↔ ISO 2700110
- CIS Controls v8 ↔ NIST CSF 2.010
- Essential Eight ↔ NIST CSF 2.010
- NIST 800-53 ↔ PCI DSS10
- Cyber Essentials ↔ Essential Eight10
- ISO 27001 ↔ NIST 800-1719
- HIPAA ↔ ISO 270019
- GLBA ↔ ISO 270019
- NIST 800-171 ↔ NIST CSF 2.09
- DORA ↔ NIST CSF 2.09
- NIST 800-171 ↔ NIST 800-539
- HIPAA ↔ NIST 800-539
- NIS2 ↔ NIST 800-539
- Essential Eight ↔ PCI DSS9
- ISO 27001 ↔ NIS28
- NIST CSF 2.0 ↔ SOC 28
- GLBA ↔ NIST CSF 2.08
- CIS Controls v8 ↔ NIST 800-538
- CIS Controls v8 ↔ Essential Eight8
- GLBA ↔ NIST 800-538
- Essential Eight ↔ NIST 800-538
- DORA ↔ HIPAA8
- ISO 27001 ↔ SOC 27
- HIPAA ↔ NIST CSF 2.07
- CIS Controls v8 ↔ PCI DSS7
- PCI DSS ↔ SOC 27
- NIST 800-171 ↔ PCI DSS7
- Essential Eight ↔ NIST 800-1717
- GLBA ↔ PCI DSS7
- HIPAA ↔ NIS27
- DORA ↔ NIS27
- GDPR ↔ NIST 800-537
- LGPD ↔ NIST 800-537
- NIS2 ↔ NIST CSF 2.06
- NIST 800-53 ↔ SOC 26
- HIPAA ↔ NIST 800-1716
- DORA ↔ NIST 800-1716
- DORA ↔ PCI DSS6
- DORA ↔ GLBA6
- GDPR ↔ ISO 270016
- Cyber Essentials ↔ ISO 270015
- Cyber Essentials ↔ NIST CSF 2.05
- CIS Controls v8 ↔ NIST 800-1715
- GLBA ↔ SOC 25
- GLBA ↔ NIST 800-1715
- NIS2 ↔ NIST 800-1715
- HIPAA ↔ PCI DSS5
- Cyber Essentials ↔ PCI DSS5
- NIS2 ↔ PCI DSS5
- GLBA ↔ HIPAA5
- GLBA ↔ NIS25
- ISO 27001 ↔ LGPD5
- GDPR ↔ NIST CSF 2.05
- LGPD ↔ NIST CSF 2.05
- LGPD ↔ NIS25
- DORA ↔ GDPR5
- DORA ↔ LGPD5
- CIS Controls v8 ↔ SOC 24
- CIS Controls v8 ↔ GLBA4
- CIS Controls v8 ↔ Cyber Essentials4
- CIS Controls v8 ↔ DORA4
- NIST 800-171 ↔ SOC 24
- Essential Eight ↔ SOC 24
- DORA ↔ SOC 24
- Cyber Essentials ↔ NIST 800-534
- Cyber Essentials ↔ NIST 800-1714
- Essential Eight ↔ GLBA4
- GDPR ↔ LGPD4
- GDPR ↔ NIS24
- HIPAA ↔ LGPD4
- CIS Controls v8 ↔ HIPAA3
- HIPAA ↔ SOC 23
- NIS2 ↔ SOC 23
- DORA ↔ Essential Eight3
- CCPA / CPRA ↔ NIST CSF 2.03
- CIS Controls v8 ↔ GDPR3
- CCPA / CPRA ↔ NIST 800-533
- CCPA / CPRA ↔ LGPD3
- LGPD ↔ NIST 800-1713
- GDPR ↔ PCI DSS3
- LGPD ↔ PCI DSS3
- GDPR ↔ HIPAA3
- GDPR ↔ GLBA3
- GLBA ↔ LGPD3
- CIS Controls v8 ↔ NIS22
- Cyber Essentials ↔ SOC 22
- Essential Eight ↔ HIPAA2
- Cyber Essentials ↔ GLBA2
- Essential Eight ↔ NIS22
- CCPA / CPRA ↔ ISO 270012
- CIS Controls v8 ↔ LGPD2
- CCPA / CPRA ↔ GDPR2
- GDPR ↔ NIST 800-1712
- GDPR ↔ SOC 22
- LGPD ↔ SOC 22
- CCPA / CPRA ↔ NIS22
- CCPA / CPRA ↔ DORA2
- Cyber Essentials ↔ HIPAA1
- Cyber Essentials ↔ NIS21
- Cyber Essentials ↔ DORA1
- CCPA / CPRA ↔ CIS Controls v81
- Essential Eight ↔ GDPR1
- CCPA / CPRA ↔ SOC 21
- CCPA / CPRA ↔ GLBA1
- CCPA / CPRA ↔ PCI DSS1
- CCPA / CPRA ↔ NIST 800-1711
- CCPA / CPRA ↔ HIPAA1