Comply

From framework selection to full requirements map.

Comply is where your program begins. Select frameworks, define scope, map controls, and build the requirements structure your entire program runs on.

Get Access

Interactive demo

See how it works.

What Comply does

The capabilities that run your program.

Framework Library
150+ catalogued frameworks plus your own.

Ships with ISO 27001:2022, ISO 27002, ISO 22301, NIS2, DORA, GDPR, Swiss nDSG, FINMA Circulars, NIST CSF 2.0, Swiss ICT Min Standard, CIS Controls, IEC 62443, UK GDPR, CCPA/CPRA, LGPD, and more. Import custom frameworks as YAML or CSV from Admin, Frameworks.

Requirements Engine
Requirements, controls, evidence, end to end.

Framework structure (clause, control, guidance) is represented as Requirements. You link requirements to controls and evidence for traceability, and use scope tags to mark what is in or out of programme scope.

Cross-Framework Mapping
Direct links, reference measures, and AI suggestions.

Use Comply, Cross-Framework Mappings for manual direct mappings and mappings via Acuna Reference Measures (58 curated reference measures across 11 domains). Open Suggest with Measures to see measure-based possibilities; AI suggestions include confidence scores (0-100%) with auto-select from 70% upward.

Batch Operations
Map many requirements or whole domains at once.

Select multiple requirements or entire domains and apply cross-mapping in a single operation instead of one-by-one edits. Pairs well with measure-based mapping first, with AI as a complement.

Who uses it

Built for practitioners.

CISO

Run one programme across several frameworks.

For leaders who combine programmes (for example ISO 27001 plus GDPR) and need overlap visibility, shared controls, and a single requirements-to-evidence chain.

Build multi-framework programmes and reuse controls where clauses align
Keep traceability from each requirement through controls to evidence
Use scope tags so reporting reflects what is actually in programme scope
Compliance Leader

Onboard new frameworks and custom catalogues.

For owners who add regulatory or sector frameworks over time, including bespoke structures that are not in the default library.

Pull in additional frameworks from the built-in catalogue as needs change
Import organisation-specific frameworks via YAML or CSV under Admin, Frameworks
Align new requirements to existing controls using cross-framework mapping
Consulting Firm / MSSP

Repeatable delivery with shared reference content.

For firms that need the same mapping methodology and framework definitions across engagements without retyping structure for every client.

Rely on a large standard framework library as the baseline for each engagement
Use reference measures and batch cross-mapping to speed alignment work
Apply a consistent requirements, controls, evidence model across accounts

FAQ

Common questions about Comply.

How many frameworks does Acuna support?

The product ships with more than 150 frameworks and related sets, including ISO 27001:2022, ISO 27002, ISO 22301, NIS2, DORA, GDPR, Swiss nDSG, FINMA Circulars, NIST CSF 2.0, Swiss ICT Min Standard, CIS Controls, IEC 62443, UK GDPR, CCPA/CPRA, and LGPD. You can extend this with your own imports.

How does cross-framework control mapping work?

In Comply, Cross-Framework Mappings you create links between requirements in different frameworks. Mappings can be direct (manual) or derived via Acuna Reference Measures when the same underlying measure applies. AI can propose additional mappings with confidence scores; items from 70% upward can be auto-selected.

Can I import custom frameworks?

Yes. Administrators import custom framework structure through Admin, Frameworks using YAML or CSV, so proprietary or client-specific catalogues sit alongside the standard library.

What are Acuna Reference Measures?

They are a curated set of 58 reference measures organised across 11 domains. When you map via these measures, Acuna derives cross-framework relationships from shared measure coverage instead of you drawing every link by hand.

How does AI-powered mapping work?

The mapping UI can surface AI suggestions with a confidence percentage from 0-100%. You review or bulk-accept suggestions; the product can automatically select suggestions from 70% confidence and above. Practical use is to establish measure-based mappings first, then use AI to fill gaps.

Can I map many requirements at once?

Yes. Batch cross-mapping lets you select multiple requirements or whole domains and apply mappings in one operation, which cuts repetitive work on large catalogues.

Related answers

Questions practitioners ask.

What is ISO 27001?

ISO 27001 is the international standard for information security management systems (ISMS). Published by ISO/IEC, it defines requirements for establishing, implementing, maintaining, and continually improving an ISMS. The 2022 revision includes 93 controls across four themes: organisational, people, physical, and technological. Certification requires an accredited external audit demonstrating that the ISMS meets all clause requirements and that selected Annex A controls are implemented and effective. Acuna supports the full ISO 27001 lifecycle from scoping through audit preparation.

What is NIS2 and who does it apply to?

NIS2 (Directive (EU) 2022/2555) is the EU directive on cybersecurity for essential and important entities. It expands the scope of NIS1, introduces stricter security requirements under Article 21, and mandates incident reporting within 24 hours (early warning), 72 hours (notification), and one month (final report). Essential entities include energy, transport, banking, health, water, and digital infrastructure. Important entities cover postal, waste, chemicals, food, manufacturing, and digital providers with 50+ employees or EUR 10M+ turnover. Acuna maps NIS2 articles to controls, manages supply chain risk, and tracks incident reporting deadlines.

What is DORA in financial services?

The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) applies to financial entities in the EU. It establishes requirements for ICT risk management, ICT-related incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing on cyber threats. DORA became applicable on 17 January 2025. Acuna covers DORA requirements across all four panes: framework mapping in Comply, ICT controls and asset inventory in Implement, incident and third-party management in Operate, and TLPT findings and corrective actions in Assure.

What is the difference between GRC and ISMS?

GRC (Governance, Risk, and Compliance) is a broad management discipline covering how an organisation directs strategy, manages risk, and meets regulatory obligations across all domains. An ISMS (Information Security Management System) is a specific implementation of governance and risk management focused on information security, typically conforming to ISO 27001. An ISMS is one component within a wider GRC programme. Acuna is a GRC platform that supports ISMS management as one of its use cases alongside privacy, business continuity, supplier risk, and enterprise risk management.

What is cross-framework control mapping?

Cross-framework control mapping identifies where requirements from different frameworks overlap — for example, ISO 27001 A.8.5 (access control) and NIS2 Article 21(2)(i) (access management) describe essentially the same practice. By mapping these overlaps, organisations implement and evidence a control once instead of duplicating effort per framework. In Acuna, mappings can be direct (manual), derived via 58 curated reference measures across 11 domains, or suggested by AI with confidence scores. Batch mapping lets you align entire domains in one operation.

What is a Statement of Applicability in ISO 27001?

The Statement of Applicability (SoA) is a mandatory document in ISO 27001 that lists all Annex A controls, states whether each is applicable or not applicable to the organisation's ISMS scope, provides justification for exclusions, and references the implementation status of each applicable control. The SoA is a key audit artefact — auditors use it to verify that control selection is risk-based and that excluded controls have documented rationale. In Acuna, the SoA is managed directly in the Comply pane with applicability markings and justification fields per control.

What is the difference between a measure and a control in GRC?

In Acuna, a measure is a template-level practice drawn from curated libraries aligned with frameworks like ISO 27001 and NIST CSF. It describes what should be done. A control is the operational record you create from a measure — typed (preventive, detective, or corrective), owned, statused, and linked to specific requirements, assets, processes, and risks. You implement and attest at the control level; measures standardise the underlying practice across your programme. One measure can spawn multiple controls in different scopes.

What does the Comply pane do in Acuna?

Comply is where you manage frameworks, requirements, and applicability. You import or create regulatory frameworks (ISO 27001, NIS2, DORA, SOC 2, GDPR, and others), review each requirement, mark applicability with justification, and establish cross-framework mappings so overlapping requirements share the same measures and controls. The pane shows a real-time compliance posture per framework — coverage percentage, gap counts, and requirement-level status — so compliance managers and auditors see the programme state without opening spreadsheets.

How does applicability marking work for framework requirements?

In Comply, each requirement can be marked Applicable or Not Applicable with a mandatory justification field. For ISO 27001, this produces the Statement of Applicability (SoA). Applicability decisions propagate downstream: when a requirement is marked not applicable, its linked measures and controls are excluded from coverage calculations. Auditors can filter the requirement list by applicability status and export the SoA as a versioned artefact. Changing applicability after initial marking is tracked in the audit trail with the user, timestamp, and reason for change.

How do measures and controls link to requirements in Acuna?

In Implement, each measure represents a security or compliance practice (e.g. 'Access reviews are performed quarterly'). Measures are linked upward to one or more requirements across frameworks — one measure can satisfy clauses in ISO 27001, NIS2, and SOC 2 simultaneously. Controls are the operational instances of measures: they carry an owner, implementation status, control type (preventive, detective, corrective), and linked evidence. This three-tier hierarchy (requirement → measure → control) is how Acuna avoids duplicate work across multi-framework programmes.

What are the best Vanta alternatives for multi-framework compliance programs?

Vanta is purpose-built for companies getting their first SOC 2. For organizations running multiple frameworks simultaneously (ISO 27001, SOC 2, NIS2, DORA, GDPR), Vanta's single-framework origins show. The best Vanta alternatives for multi-framework programs include platforms built for continuous compliance across mature, overlapping obligations. Acuna is designed from the ground up for multi-framework control mapping, shared evidence, and audit defensibility at enterprise scale. Drata and OneTrust each address adjacent problems. Choose based on whether your program is scaling compliance depth or adding your first certification.

What are the best OneTrust alternatives for GRC teams running compliance programs?

OneTrust positions itself as a privacy-led enterprise platform, strongest for organizations where privacy (GDPR, CCPA) sits at the center of the GRC program. The best OneTrust alternatives for broader GRC depth are platforms that integrate privacy, security, quality, and audit programs in one operating rhythm rather than parallel silos. Acuna is built for compliance leaders running multi-framework programs where privacy is one obligation among many (ISO 27001, SOC 2, NIS2, ISO 9001, GDPR). Pricing is organization-based, not per-seat, and the architecture supports quality, privacy, and security in shared evidence.

Ready to see Comply in action?

Get access and our team will walk you through Comply and the full Acuna platform.

Get Access