The standards your customers hold you to.
Every framework, mapped once.
SubRosa assesses against, and Sable maps your controls to, 45+ security, privacy and industry frameworks. Because their controls overlap, the evidence you collect for one carries into the rest, so the second audit is a fraction of the work of the first.
A control you implement once satisfies every framework that asks for it.
Multi-factor authentication is a SOC 2 control, an ISO 27001 control, a HIPAA control and a PCI control. Our former auditors map each control to every framework it answers, so you gather the evidence once and reuse it. Adding a framework becomes a gap review, not a fresh programme.
| SOC 2 | ISO | HIPAA | PCI | NIST | |
|---|---|---|---|---|---|
| Multi-factor authentication | ✓ | ✓ | ✓ | ✓ | ✓ |
| Encryption in transit & at rest | ✓ | ✓ | ✓ | ✓ | ✓ |
| Access reviews | ✓ | ✓ | ✓ | ✓ | · |
| Continuous logging | ✓ | ✓ | ✓ | ✓ | ✓ |
| Vendor risk management | ✓ | ✓ | ✓ | · | · |
Illustrative. Map a control once in Sable and it satisfies every framework that requires it.
45+ frameworks, grouped the way you buy them
Find the standard by the reason you need it. Frameworks with a dedicated SubRosa page link through; the rest are covered by our compliance assessments and supported in Sable.
Security & cloud
11 frameworksThe horizontal standards most customers and auditors ask for first, plus the cloud-specific control sets.
SOC 2
AICPA Trust Services Criteria, Type I and Type II.
ISO/IEC 27001
The international standard for an information security management system.
ISO/IEC 27002
The control catalogue that supports an ISO 27001 ISMS.
ISO/IEC 27017
Cloud-specific security controls for providers and customers.
ISO/IEC 27018
Protection of personally identifiable information in public clouds.
NIST Cybersecurity Framework 2.0
The CSF's six functions: Govern, Identify, Protect, Detect, Respond, Recover.
NIST SP 800-53
→The federal control catalogue, used well beyond government.
NIST SP 800-171
Protecting controlled unclassified information in non-federal systems.
CIS Critical Security Controls
The CIS Controls v8, prioritised safeguards mapped to real attacks.
CIS Benchmarks
Configuration baselines for operating systems, cloud and applications.
CSA Cloud Controls Matrix
The Cloud Security Alliance CCM and CAIQ questionnaire.
US federal & government
7 frameworksThe frameworks required to sell to, or operate within, US federal and state government.
FedRAMP
Authorisation to provide cloud services to federal agencies.
CMMC 2.0
Cybersecurity Maturity Model Certification for the defense industrial base.
FISMA
The Federal Information Security Modernization Act baseline.
StateRAMP
The state and local government equivalent of FedRAMP.
CJIS Security Policy
FBI requirements for handling criminal justice information.
IRS Publication 1075
Safeguards for federal tax information held by agencies and contractors.
FIPS 140-3
Validation requirements for cryptographic modules.
Healthcare & life sciences
5 frameworksProtecting patient data and meeting the regulators that govern healthcare technology.
HIPAA
→The Security and Privacy Rules for protected health information.
HITRUST CSF
→A certifiable framework that harmonises HIPAA, ISO, NIST and more.
HITECH
Breach notification and the enforcement teeth behind HIPAA.
FDA Premarket Cybersecurity
Security expectations across the medical device lifecycle.
21 CFR Part 11
Electronic records and signatures in FDA-regulated environments.
Financial services
8 frameworksThe standards that apply to anyone handling payments, or regulated as a financial institution.
PCI DSS 4.0
The Payment Card Industry Data Security Standard, current version.
SOX
Sarbanes-Oxley IT general controls over financial reporting.
GLBA
The Gramm-Leach-Bliley Act Safeguards Rule for financial data.
FFIEC
Examination guidance for US financial institutions.
NYDFS 23 NYCRR 500
New York's cybersecurity regulation for financial services.
FTC Safeguards Rule
Information security requirements for non-bank financial institutions.
DORA
The EU Digital Operational Resilience Act for financial entities.
SWIFT CSP
The Customer Security Programme for the SWIFT messaging network.
Privacy & data protection
7 frameworksThe privacy regimes your customers, and their regulators, hold you to wherever your users are.
GDPR
The EU General Data Protection Regulation.
CCPA / CPRA
California's consumer privacy law and its amendment.
ISO/IEC 27701
A privacy information management extension to ISO 27001.
PIPEDA
Canada's federal private-sector privacy law.
LGPD
Brazil's Lei Geral de Proteção de Dados.
POPIA
South Africa's Protection of Personal Information Act.
Australian Privacy Principles
The APPs under Australia's Privacy Act.
International & regional
7 frameworksRegional certifications and sector schemes that open specific markets and supply chains.
UK Cyber Essentials
The UK government-backed baseline and its Plus tier.
NIS2 Directive
The EU's expanded network and information security directive.
Essential Eight
The Australian Signals Directorate's mitigation strategies.
TISAX
The automotive industry's information security assessment scheme.
ENS
Spain's Esquema Nacional de Seguridad for public-sector suppliers.
BSI C5
Germany's Cloud Computing Compliance Criteria Catalogue.
COBIT
ISACA's framework for the governance of enterprise IT.
The list grows, and Sable takes custom control sets.
We add frameworks as customers need them, and Sable lets you build a bespoke or contractual control set and map your existing evidence to it. If your requirement is a framework we have not listed, or a customer questionnaire that is nobody's published standard, tell us what you are being held to and we will confirm coverage.
Common questions
- Which compliance frameworks does SubRosa support?
- SubRosa assesses against and maps controls to 45+ frameworks, spanning security and cloud (SOC 2, ISO 27001, NIST CSF, CIS), US federal (FedRAMP, CMMC, NIST 800-171), healthcare (HIPAA, HITRUST), financial services (PCI DSS, SOX, GLBA, NYDFS), privacy (GDPR, CCPA, ISO 27701) and international schemes (Cyber Essentials, NIS2, TISAX). The full list is grouped on this page, and we add frameworks as customers need them.
- What does it mean to map controls across frameworks?
- Most security frameworks ask for the same underlying controls in different words: multi-factor authentication, encryption, access reviews, logging. When you implement a control, our assessors map it to every framework that requires it, so the evidence you collect for a SOC 2 audit also counts toward ISO 27001, HIPAA and the rest. The result is that your first framework is the expensive one and each additional framework is a gap review rather than a fresh programme.
- Can Sable handle a framework that is not on this list?
- Yes. Sable supports custom and contractual control sets, so if you are held to a bespoke customer questionnaire or an internal standard that is nobody's published framework, you can build it in the platform and map your existing evidence to it. If you need a recognised framework we have not listed yet, tell us what you are being asked for and we will confirm we can assess against it.
- Do I need separate audits for each framework?
- The formal certification or attestation for each framework is issued separately, by the body that governs it, but the preparation is shared. Because the controls and evidence overlap, running toward a second framework reuses most of the work from the first. Sable keeps the evidence in one place and shows which frameworks each control already satisfies, so you prepare once and produce evidence per audit on demand.
- Does SubRosa help with the audit itself, or only the preparation?
- Both. Our compliance team is made up of former auditors who run the readiness assessment, close the gaps with you, and support you through the formal audit or certification, whether that is a SOC 2 examination, an ISO 27001 certification, or a HITRUST assessment. Sable is the workspace that holds the controls, evidence and progress throughout.