Comply is where your program begins. Select frameworks, define scope, map controls, and build the requirements structure your entire program runs on.
Get AccessInteractive demo
What Comply does
Ships with ISO 27001:2022, ISO 27002, ISO 22301, NIS2, DORA, GDPR, Swiss nDSG, FINMA Circulars, NIST CSF 2.0, Swiss ICT Min Standard, CIS Controls, IEC 62443, UK GDPR, CCPA/CPRA, LGPD, and more. Import custom frameworks as YAML or CSV from Admin, Frameworks.
Framework structure (clause, control, guidance) is represented as Requirements. You link requirements to controls and evidence for traceability, and use scope tags to mark what is in or out of programme scope.
Use Comply, Cross-Framework Mappings for manual direct mappings and mappings via Acuna Reference Measures (58 curated reference measures across 11 domains). Open Suggest with Measures to see measure-based possibilities; AI suggestions include confidence scores (0-100%) with auto-select from 70% upward.
Select multiple requirements or entire domains and apply cross-mapping in a single operation instead of one-by-one edits. Pairs well with measure-based mapping first, with AI as a complement.
Who uses it
For leaders who combine programmes (for example ISO 27001 plus GDPR) and need overlap visibility, shared controls, and a single requirements-to-evidence chain.
For owners who add regulatory or sector frameworks over time, including bespoke structures that are not in the default library.
For firms that need the same mapping methodology and framework definitions across engagements without retyping structure for every client.
FAQ
The product ships with more than 150 frameworks and related sets, including ISO 27001:2022, ISO 27002, ISO 22301, NIS2, DORA, GDPR, Swiss nDSG, FINMA Circulars, NIST CSF 2.0, Swiss ICT Min Standard, CIS Controls, IEC 62443, UK GDPR, CCPA/CPRA, and LGPD. You can extend this with your own imports.
In Comply, Cross-Framework Mappings you create links between requirements in different frameworks. Mappings can be direct (manual) or derived via Acuna Reference Measures when the same underlying measure applies. AI can propose additional mappings with confidence scores; items from 70% upward can be auto-selected.
Yes. Administrators import custom framework structure through Admin, Frameworks using YAML or CSV, so proprietary or client-specific catalogues sit alongside the standard library.
They are a curated set of 58 reference measures organised across 11 domains. When you map via these measures, Acuna derives cross-framework relationships from shared measure coverage instead of you drawing every link by hand.
The mapping UI can surface AI suggestions with a confidence percentage from 0-100%. You review or bulk-accept suggestions; the product can automatically select suggestions from 70% confidence and above. Practical use is to establish measure-based mappings first, then use AI to fill gaps.
Yes. Batch cross-mapping lets you select multiple requirements or whole domains and apply mappings in one operation, which cuts repetitive work on large catalogues.
Related answers
ISO 27001 is the international standard for information security management systems (ISMS). Published by ISO/IEC, it defines requirements for establishing, implementing, maintaining, and continually improving an ISMS. The 2022 revision includes 93 controls across four themes: organisational, people, physical, and technological. Certification requires an accredited external audit demonstrating that the ISMS meets all clause requirements and that selected Annex A controls are implemented and effective. Acuna supports the full ISO 27001 lifecycle from scoping through audit preparation.
NIS2 (Directive (EU) 2022/2555) is the EU directive on cybersecurity for essential and important entities. It expands the scope of NIS1, introduces stricter security requirements under Article 21, and mandates incident reporting within 24 hours (early warning), 72 hours (notification), and one month (final report). Essential entities include energy, transport, banking, health, water, and digital infrastructure. Important entities cover postal, waste, chemicals, food, manufacturing, and digital providers with 50+ employees or EUR 10M+ turnover. Acuna maps NIS2 articles to controls, manages supply chain risk, and tracks incident reporting deadlines.
The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) applies to financial entities in the EU. It establishes requirements for ICT risk management, ICT-related incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing on cyber threats. DORA became applicable on 17 January 2025. Acuna covers DORA requirements across all four panes: framework mapping in Comply, ICT controls and asset inventory in Implement, incident and third-party management in Operate, and TLPT findings and corrective actions in Assure.
GRC (Governance, Risk, and Compliance) is a broad management discipline covering how an organisation directs strategy, manages risk, and meets regulatory obligations across all domains. An ISMS (Information Security Management System) is a specific implementation of governance and risk management focused on information security, typically conforming to ISO 27001. An ISMS is one component within a wider GRC programme. Acuna is a GRC platform that supports ISMS management as one of its use cases alongside privacy, business continuity, supplier risk, and enterprise risk management.
Cross-framework control mapping identifies where requirements from different frameworks overlap — for example, ISO 27001 A.8.5 (access control) and NIS2 Article 21(2)(i) (access management) describe essentially the same practice. By mapping these overlaps, organisations implement and evidence a control once instead of duplicating effort per framework. In Acuna, mappings can be direct (manual), derived via 58 curated reference measures across 11 domains, or suggested by AI with confidence scores. Batch mapping lets you align entire domains in one operation.
The Statement of Applicability (SoA) is a mandatory document in ISO 27001 that lists all Annex A controls, states whether each is applicable or not applicable to the organisation's ISMS scope, provides justification for exclusions, and references the implementation status of each applicable control. The SoA is a key audit artefact — auditors use it to verify that control selection is risk-based and that excluded controls have documented rationale. In Acuna, the SoA is managed directly in the Comply pane with applicability markings and justification fields per control.
In Acuna, a measure is a template-level practice drawn from curated libraries aligned with frameworks like ISO 27001 and NIST CSF. It describes what should be done. A control is the operational record you create from a measure — typed (preventive, detective, or corrective), owned, statused, and linked to specific requirements, assets, processes, and risks. You implement and attest at the control level; measures standardise the underlying practice across your programme. One measure can spawn multiple controls in different scopes.
Comply is where you manage frameworks, requirements, and applicability. You import or create regulatory frameworks (ISO 27001, NIS2, DORA, SOC 2, GDPR, and others), review each requirement, mark applicability with justification, and establish cross-framework mappings so overlapping requirements share the same measures and controls. The pane shows a real-time compliance posture per framework — coverage percentage, gap counts, and requirement-level status — so compliance managers and auditors see the programme state without opening spreadsheets.
In Comply, each requirement can be marked Applicable or Not Applicable with a mandatory justification field. For ISO 27001, this produces the Statement of Applicability (SoA). Applicability decisions propagate downstream: when a requirement is marked not applicable, its linked measures and controls are excluded from coverage calculations. Auditors can filter the requirement list by applicability status and export the SoA as a versioned artefact. Changing applicability after initial marking is tracked in the audit trail with the user, timestamp, and reason for change.
In Implement, each measure represents a security or compliance practice (e.g. 'Access reviews are performed quarterly'). Measures are linked upward to one or more requirements across frameworks — one measure can satisfy clauses in ISO 27001, NIS2, and SOC 2 simultaneously. Controls are the operational instances of measures: they carry an owner, implementation status, control type (preventive, detective, corrective), and linked evidence. This three-tier hierarchy (requirement → measure → control) is how Acuna avoids duplicate work across multi-framework programmes.
Vanta is purpose-built for companies getting their first SOC 2. For organizations running multiple frameworks simultaneously (ISO 27001, SOC 2, NIS2, DORA, GDPR), Vanta's single-framework origins show. The best Vanta alternatives for multi-framework programs include platforms built for continuous compliance across mature, overlapping obligations. Acuna is designed from the ground up for multi-framework control mapping, shared evidence, and audit defensibility at enterprise scale. Drata and OneTrust each address adjacent problems. Choose based on whether your program is scaling compliance depth or adding your first certification.
OneTrust positions itself as a privacy-led enterprise platform, strongest for organizations where privacy (GDPR, CCPA) sits at the center of the GRC program. The best OneTrust alternatives for broader GRC depth are platforms that integrate privacy, security, quality, and audit programs in one operating rhythm rather than parallel silos. Acuna is built for compliance leaders running multi-framework programs where privacy is one obligation among many (ISO 27001, SOC 2, NIS2, ISO 9001, GDPR). Pricing is organization-based, not per-seat, and the architecture supports quality, privacy, and security in shared evidence.
Get access and our team will walk you through Comply and the full Acuna platform.
Get Access