For GRC consultants

Your second client asks the same question as your first

Crosswalks you build once, with the reasoning attached, so a client can check the work instead of taking your word for it.

The job: Bill for judgement, not for rebuilding the same mapping spreadsheet every engagement.

Start from a signed-off pair

Released pairs carry the coverage, the evidenced controls, the gaps and the claims that were rejected. Where a pair is not released, it is built to order at the same price rather than approximated.

See the released pairs

Hand over something the client can audit

Every claim names the control that does the work, what it satisfies, why, the document each side was verified against and the date. When a client pushes back on one row, you have the row.

Read a claim end to end

Answer the multi-standard question directly

A client holding two certifications and facing a third wants the marginal number, not three standalone ones. The combined coverage tool answers what two frameworks cover together and what neither reaches.

Run it without an account

When this is the wrong tool

If your engagement is collecting evidence out of a client cloud estate, this is the wrong tool. It maps requirements to requirements; it does not touch their systems.

Questions

Can I put my own name on the output?

The report is yours to use in an engagement. It states its own level of review on the face of it, which is the part you should not strip: your client is entitled to know a machine judged the mappings and a second pass argued against them, rather than that a practitioner read every line.

What happens when a pair I need is not released?

It is built to order at the same price, usually within minutes. Occasionally a pair does not pass its checks because the two frameworks genuinely have little in common, and then it is refused and refunded rather than padded.

The graph holds 686 frameworks and 59,123 judged cross-framework mappings, with 29,347 more that were judged and rejected and kept where you can read them.