Frameworks

Map once. Comply everywhere.

Veritra maintains unified control mappings across the frameworks your customers, regulators, and board care about — so a single piece of evidence satisfies many tests at once.

US / Global

SOC 2

SOC 2 Type II

Trust Services Criteria covering security, availability, processing integrity, confidentiality, and privacy.

Global

ISO 27001

ISO/IEC 27001

International standard for information security management systems with Annex A controls.

US Healthcare

HIPAA

HIPAA Security Rule

Administrative, physical, and technical safeguards for protected health information.

EU / EEA

GDPR

GDPR Readiness

European data protection regulation — lawful basis, DSARs, processor agreements, and breach notification.

Payments

PCI DSS

PCI DSS

Payment Card Industry Data Security Standard for organizations handling cardholder data.

US Federal

NIST CSF

NIST Cybersecurity Framework

Identify, Protect, Detect, Respond, Recover, Govern — the function-based model.

India

DPDP

DPDP Act 2023

India's Digital Personal Data Protection Act — notice, consent, breach reporting, and data principal rights.

India — BFSI

RBI IT

RBI / NBFC IT Framework

Reserve Bank of India IT framework for banks and NBFCs — system audit, BCP, and cyber resilience.

Every workspace opens with a mapped starter control set for these frameworks. Add your own controls, import a full control set, or define a custom internal framework — cross-framework mapping reuses the evidence you have already collected instead of asking for it twice.

Unified Mapping

One control. Many frameworks.

Implementing access revocation once gives you credit against SOC 2 CC6.1, ISO 27001 A.9.2.6, HIPAA §164.308(a)(3), and GDPR Art. 32 — simultaneously.

▸ Control: Timely Access Revocation
↳ SOC 2 — CC6.1, CC6.2
↳ ISO 27001 — A.9.2.6, A.9.4.1
↳ HIPAA — §164.308(a)(3)(ii)(C)
↳ GDPR — Art. 32(1)(b)
↳ NIST CSF — PR.AC-1, PR.AC-4

Need a framework we haven't listed?

Talk to Compliance