The standards your customers hold you to.

Every framework, mapped once.

SubRosa assesses against, and Sable maps your controls to, 45+ security, privacy and industry frameworks. Because their controls overlap, the evidence you collect for one carries into the rest, so the second audit is a fraction of the work of the first.

Map once, comply many

A control you implement once satisfies every framework that asks for it.

Multi-factor authentication is a SOC 2 control, an ISO 27001 control, a HIPAA control and a PCI control. Our former auditors map each control to every framework it answers, so you gather the evidence once and reuse it. Adding a framework becomes a gap review, not a fresh programme.

Control crossmapOne control · five frameworks
SOC 2ISOHIPAAPCINIST
Multi-factor authentication
Encryption in transit & at rest
Access reviews·
Continuous logging
Vendor risk management··

Illustrative. Map a control once in Sable and it satisfies every framework that requires it.

The full list

45+ frameworks, grouped the way you buy them

Find the standard by the reason you need it. Frameworks with a dedicated SubRosa page link through; the rest are covered by our compliance assessments and supported in Sable.

Security & cloud

11 frameworks

The horizontal standards most customers and auditors ask for first, plus the cloud-specific control sets.

SOC 2

AICPA Trust Services Criteria, Type I and Type II.

ISO/IEC 27001

The international standard for an information security management system.

ISO/IEC 27002

The control catalogue that supports an ISO 27001 ISMS.

ISO/IEC 27017

Cloud-specific security controls for providers and customers.

ISO/IEC 27018

Protection of personally identifiable information in public clouds.

NIST Cybersecurity Framework 2.0

The CSF's six functions: Govern, Identify, Protect, Detect, Respond, Recover.

NIST SP 800-53

The federal control catalogue, used well beyond government.

NIST SP 800-171

Protecting controlled unclassified information in non-federal systems.

CIS Critical Security Controls

The CIS Controls v8, prioritised safeguards mapped to real attacks.

CIS Benchmarks

Configuration baselines for operating systems, cloud and applications.

CSA Cloud Controls Matrix

The Cloud Security Alliance CCM and CAIQ questionnaire.

US federal & government

7 frameworks

The frameworks required to sell to, or operate within, US federal and state government.

FedRAMP

Authorisation to provide cloud services to federal agencies.

CMMC 2.0

Cybersecurity Maturity Model Certification for the defense industrial base.

FISMA

The Federal Information Security Modernization Act baseline.

StateRAMP

The state and local government equivalent of FedRAMP.

CJIS Security Policy

FBI requirements for handling criminal justice information.

IRS Publication 1075

Safeguards for federal tax information held by agencies and contractors.

FIPS 140-3

Validation requirements for cryptographic modules.

Healthcare & life sciences

5 frameworks

Protecting patient data and meeting the regulators that govern healthcare technology.

HIPAA

The Security and Privacy Rules for protected health information.

HITRUST CSF

A certifiable framework that harmonises HIPAA, ISO, NIST and more.

HITECH

Breach notification and the enforcement teeth behind HIPAA.

FDA Premarket Cybersecurity

Security expectations across the medical device lifecycle.

21 CFR Part 11

Electronic records and signatures in FDA-regulated environments.

Financial services

8 frameworks

The standards that apply to anyone handling payments, or regulated as a financial institution.

PCI DSS 4.0

The Payment Card Industry Data Security Standard, current version.

SOX

Sarbanes-Oxley IT general controls over financial reporting.

GLBA

The Gramm-Leach-Bliley Act Safeguards Rule for financial data.

FFIEC

Examination guidance for US financial institutions.

NYDFS 23 NYCRR 500

New York's cybersecurity regulation for financial services.

FTC Safeguards Rule

Information security requirements for non-bank financial institutions.

DORA

The EU Digital Operational Resilience Act for financial entities.

SWIFT CSP

The Customer Security Programme for the SWIFT messaging network.

Privacy & data protection

7 frameworks

The privacy regimes your customers, and their regulators, hold you to wherever your users are.

GDPR

The EU General Data Protection Regulation.

CCPA / CPRA

California's consumer privacy law and its amendment.

ISO/IEC 27701

A privacy information management extension to ISO 27001.

PIPEDA

Canada's federal private-sector privacy law.

LGPD

Brazil's Lei Geral de Proteção de Dados.

POPIA

South Africa's Protection of Personal Information Act.

Australian Privacy Principles

The APPs under Australia's Privacy Act.

International & regional

7 frameworks

Regional certifications and sector schemes that open specific markets and supply chains.

UK Cyber Essentials

The UK government-backed baseline and its Plus tier.

NIS2 Directive

The EU's expanded network and information security directive.

Essential Eight

The Australian Signals Directorate's mitigation strategies.

TISAX

The automotive industry's information security assessment scheme.

ENS

Spain's Esquema Nacional de Seguridad for public-sector suppliers.

BSI C5

Germany's Cloud Computing Compliance Criteria Catalogue.

COBIT

ISACA's framework for the governance of enterprise IT.

Not seeing yours?

The list grows, and Sable takes custom control sets.

We add frameworks as customers need them, and Sable lets you build a bespoke or contractual control set and map your existing evidence to it. If your requirement is a framework we have not listed, or a customer questionnaire that is nobody's published standard, tell us what you are being held to and we will confirm coverage.

Common questions

Which compliance frameworks does SubRosa support?
SubRosa assesses against and maps controls to 45+ frameworks, spanning security and cloud (SOC 2, ISO 27001, NIST CSF, CIS), US federal (FedRAMP, CMMC, NIST 800-171), healthcare (HIPAA, HITRUST), financial services (PCI DSS, SOX, GLBA, NYDFS), privacy (GDPR, CCPA, ISO 27701) and international schemes (Cyber Essentials, NIS2, TISAX). The full list is grouped on this page, and we add frameworks as customers need them.
What does it mean to map controls across frameworks?
Most security frameworks ask for the same underlying controls in different words: multi-factor authentication, encryption, access reviews, logging. When you implement a control, our assessors map it to every framework that requires it, so the evidence you collect for a SOC 2 audit also counts toward ISO 27001, HIPAA and the rest. The result is that your first framework is the expensive one and each additional framework is a gap review rather than a fresh programme.
Can Sable handle a framework that is not on this list?
Yes. Sable supports custom and contractual control sets, so if you are held to a bespoke customer questionnaire or an internal standard that is nobody's published framework, you can build it in the platform and map your existing evidence to it. If you need a recognised framework we have not listed yet, tell us what you are being asked for and we will confirm we can assess against it.
Do I need separate audits for each framework?
The formal certification or attestation for each framework is issued separately, by the body that governs it, but the preparation is shared. Because the controls and evidence overlap, running toward a second framework reuses most of the work from the first. Sable keeps the evidence in one place and shows which frameworks each control already satisfies, so you prepare once and produce evidence per audit on demand.
Does SubRosa help with the audit itself, or only the preparation?
Both. Our compliance team is made up of former auditors who run the readiness assessment, close the gaps with you, and support you through the formal audit or certification, whether that is a SOC 2 examination, an ISO 27001 certification, or a HITRUST assessment. Sable is the workspace that holds the controls, evidence and progress throughout.