Frameworks
Your readiness for every framework, from one set of controls
Frameworks shows how ready you are for NIS2 Article 21(2) and ISO/IEC 27001:2022 Annex A, worked out from your controls, and holds your Statement of Applicability. DORA, the CRA, ISO 22301, TISAX, SOC 2, ENS and BSI IT-Grundschutz use the same controls.

How it works
Link controls to codes
A control counts for a requirement when it names the code, for example ISO 27001 A.5.15 or NIS2 21(2)(d). Library controls already do.
Read your readiness
Each requirement shows implemented, in progress, not started, no control yet or not applicable.
Keep the SoA
Decide for each Annex A control whether it applies and why, then download the Statement of Applicability for Excel.
What changes for you
Work once, count everywhere
One control can count for NIS2, ISO 27001 and other frameworks at the same time.
See the gaps
Requirements without a control are listed, with a direct way to add one.
Ready for the auditor
The Statement of Applicability with reasons is one download away.
What it covers
- NIS2 21(2)(a)-(j)
- ISO 27001 Annex A
- ISO 27001 6.1.3
Works together with
Questions
Why are only codes shown?
The ISO texts are copyrighted, so CloudSignLab stores the codes. Keep your copy of the standard at hand. The NIS2 measures are public law text.
Can I exclude requirements?
ISO Annex A requirements can be marked as not applicable with a reason. NIS2 measures always apply to entities in scope.
See where you stand
Add controls from the library and watch your readiness per framework grow.
