For Audit and certification firms

A mapping you can defend line by line

Every claim shows its working, and the claims that failed review are published beside the ones that held.

The job: Accept or reject a client assertion that evidence for one standard satisfies a control in another, and be able to say why.

Check a claim rather than take it

For any released pair you can read the individual mappings: source control, target control, reasoning, source document, verification date, and whether the claim survived a pass whose job was to refute it.

Inspect the record

Read what was thrown out

Rejected mappings are kept in the graph rather than deleted, each with the reason it failed. A crosswalk that never rejects anything has not been judged, and that is a test you can apply to any vendor.

Pick a pair and read its rejects

See where we fall short

We hold no certification of our own and say so. Our own position on all 93 ISO 27001 Annex A controls is published, including the fifteen we do not meet.

Read our own gap report

When this is the wrong tool

This is not an attestation and does not substitute for one. It is a documented judgement about requirement overlap that you are free to disagree with, row by row.

Questions

Who judged these mappings?

Claude Code, with a second pass whose job was to argue against each claim. No practitioner has read every pair line by line, which is stated on every report and in every tool response rather than in a footnote.

How do I know a control is quoted correctly?

Each control carries the document it was verified against and the date. Where we do not hold a licensed copy of a standard we return no requirement text at all and label it, rather than paraphrasing something we cannot source.

The graph holds 686 frameworks and 59,123 judged cross-framework mappings, with 29,347 more that were judged and rejected and kept where you can read them.