Framework comparisons
Every comparison below is built from the same graph the rest of the platform runs on: 686 frameworks, 21,696+ controls and 310K+ cross-framework mappings, each carrying the confidence behind it.
Coverage is reported in each direction separately, because it is not symmetric. What ISO 27001 does for a security catalogue is not what that catalogue does for ISO 27001, and a single similarity percentage hides exactly the gap you are trying to find. Where a mapping was considered and rejected, the comparison says so rather than quietly dropping it.
ISO 27001:2022 vs NIST CSF 2.0
The most requested pair. A certifiable management system against an outcome-worded framework.
SOC 2 vs ISO 27001:2022
The two most common asks from enterprise buyers, and the pair most often assumed to be interchangeable.
ISO 27001:2022 vs NIST SP 800-53 Rev 5
A 93-control annex against a parameterised catalogue of 300. Coverage is very uneven by direction.
ISO 27001:2022 vs PCI DSS 4.0
General security management against a data-type-scoped standard for cardholder data.
ISO 27001:2022 vs CIS Controls v8
Governance clauses against prescriptive technical safeguards.
HIPAA Security Rule vs ISO 27001:2022
The Security Rule only. No 164.5xx privacy provisions are in scope here, and the page says so.
HIPAA Security Rule vs NIST SP 800-53 Rev 5
The mapping most US healthcare providers are asked for during federal procurement.
DORA vs ISO 27001:2022
EU financial-sector operational resilience against an information security management system.
GDPR vs ISO 27001:2022
A security standard has real depth for Article 32 and almost nothing for lawful basis or data subject rights.
GDPR vs ISO 27701:2019
The privacy extension built to be mapped to GDPR, which makes this the densest privacy pair in the graph.
ISO 27001:2022 vs ISO 27002:2022
Requirements against implementation guidance for the same annex. Useful for seeing what a crosswalk cannot claim.
SOC 2 vs NIST CSF 2.0
Trust services criteria against CSF functions and categories.
A pair that is not listed
Any two frameworks in the graph can be compared at /compare/{framework-a}-vs-{framework-b}. Start from the framework list to get the exact slugs. The pairs above are listed because they were checked; others are generated on request and a few combinations have too little in common to be worth publishing.