Frameworks

Four frameworks, and how to tell which one you need.

ISO 27001, SOC 2, NIST CSF 2.0 and CIS Controls are not four versions of the same thing. They answer different questions, they are demanded by different people, and only two of them end in a document you can hand to a customer. These pages describe what each one actually contains — and where a framework is the wrong tool for the problem you have.

Self-service signup opens shortly — we will set you up in the meantime

FrameworksSentinel interface, reproduced

Frameworks in scope

5 mapped
  • ISO/IEC 27001:202280% ready
    42 controls in the catalogue
  • SOC 2 (Trust Services Criteria)71% ready
    45 criteria in the catalogue
  • Cyber Insurance Readiness82% ready
    22 underwriter controls in the catalogue
  • NIST CSF 2.0Available
    59 subcategories in the catalogue
  • CIS Controls v8.1Available
    56 safeguards in the catalogue
Requirements
224
across the four
Controls
26
one register
Unowned
2
controls

Frameworks are added to a workspace as scope, then mapped onto one control register. Figures are from the example workspace used throughout this site; Northstar Manufacturing Ltd. is fictional.

5
Frameworks mapped onto one register: ISO 27001, SOC 2, NIST CSF 2.0, CIS v8.1
224
Requirements across the four, once all of them are in scope
26
Controls they resolve onto — one control can satisfy several frameworks
2 of 4
End in a document an outsider signs. The other two have no certificate at all

The shortlist

The four, in columns, without the brochure.

Two of these produce a document an outsider signs. Two do not, and are more useful for it. Read down the rows that matter to you rather than across the whole table.

ISO/IEC 27001:2022
What it is
A certifiable management system standard.
Structure
Clauses 4 to 10, plus 42 Annex A controls in four themes.
Who asks for it
International and enterprise procurement; European, UK, Gulf and Asian buyers; tenders.
What you end with
A certificate valid three years, with annual surveillance audits.
Who signs it
An accredited certification body.
Cost of the text itself
Purchased from ISO or a national standards body.
Time to something useful
Six to twelve months to a first Stage 2 audit.
Where it stops
The certificate covers only the scope printed on it.
Example workspace readiness
80% of 42 ready
SOC 2 (Trust Services Criteria)
What it is
An attestation engagement against the Trust Services Criteria.
Structure
45 criteria in five categories. Security is the common criteria and is mandatory.
Who asks for it
North American software buyers, enterprise security reviews and vendor onboarding.
What you end with
A Type I or Type II report, shared with customers under a confidentiality agreement.
Who signs it
A licensed CPA firm.
Cost of the text itself
Criteria published by the AICPA; the examination is priced by the firm.
Time to something useful
Six to nine months to a first signed Type II, most of it the observation window.
Where it stops
A closed period, not today — which is what bridge letters paper over.
Example workspace readiness
71% of 45 ready
Cyber Insurance Readiness
What it is
Voluntary guidance describing cybersecurity outcomes.
Structure
Six Functions, 22 Categories, 59 Subcategories.
Who asks for it
Boards, executives, US federal supply chains — anyone who needs shared vocabulary.
What you end with
A current profile, a target profile, and an argument for the gap between them.
Who signs it
Nobody. NIST operates no certification scheme.
Cost of the text itself
Free from NIST.
Time to something useful
A first profile in an afternoon; the value arrives with the second one.
Where it stops
It buys you no credential procurement recognises.
Example workspace readiness
82% of 22 ready
NIST CSF 2.0
What it is
A prioritised, prescriptive list of defensive actions.
Structure
18 Controls, 56 Safeguards, three Implementation Groups.
Who asks for it
Insurers indirectly, technical teams directly, and anyone with no programme yet.
What you end with
A measurably harder environment, and evidence that maps into the other three.
Who signs it
Nobody. CIS operates no certification scheme.
Cost of the text itself
Free from the Center for Internet Security.
Time to something useful
Weeks. Implementation Group 1 is finite and the work is visible.
Where it stops
Thin on governance by design: no risk appetite, no management review.
Example workspace readiness
59 in the catalogue — not yet activated in the example workspace
CIS Controls v8.1
What it is
Structure
Who asks for it
What you end with
Who signs it
Cost of the text itself
Time to something useful
Where it stops
Example workspace readiness
56 in the catalogue — not yet activated in the example workspace

The last row is the example workspace used throughout this site, not an average and not a customer result. Timings are what first programmes typically take, and the constraint is almost always accumulated operating evidence rather than documentation.

A framework does not make you secure. It makes your security legible to somebody who is not going to take your word for it.

Which is why the choice matters less than the register underneath it. A framework is a vocabulary and an audience — the controls, the owners and the evidence are yours either way.

Choosing

Start from who is asking, not from the standard.

Nobody wakes up wanting a management system. Something happened: a deal stalled, a renewal arrived, a director asked a question. The person asking has usually already decided which document they will accept.

  • A customer

    Send us your SOC 2 report before legal will sign.

    They named the token their vendor policy recognises. Read the policy before you choose a standard — an ISO 27001 certificate will not be accepted as a substitute.

    Deadline: their security review

  • A tender

    Attach your ISO 27001 certificate with the submission.

    Outside North America this is usually the one that counts. In Europe, the UK, the Gulf and much of Asia a SOC 2 report is often not understood at all.

    Deadline: the submission date

  • Your insurer

    Is multi-factor authentication enforced for remote and administrative access?

    No underwriter asks for a certificate. They ask control questions, and CIS Controls Implementation Group 1 is the closest map to the form.

    Deadline: the renewal date

  • Your board

    How exposed are we, and is it getting better?

    NIST CSF 2.0 is the language for that room, and its GOVERN Function exists because oversight and risk appetite were the parts everyone skipped.

    Deadline: the next meeting

Two situations arrive without a name attached. If you have no programme and six weeks, start at CIS Controls Implementation Group 1 — 56 Safeguards, prescriptive, and everything you do there counts later towards ISO 27001 Annex A and the SOC 2 common criteria. If a contract or a regulator already names one, it is chosen, and the useful work is rereading the clause: contracts often ask for something narrower than a full certification, and occasionally for something no certificate can satisfy.

The overlap

They are mostly asking about the same eight things.

The frameworks differ in governance, in wording and in who checks. Underneath, a large share of the substance repeats — which is why the second framework costs a fraction of the first, provided the evidence was organised rather than emailed.

What all four want to see

  1. Asset and software inventory

    You cannot protect, patch or evidence what nobody has listed. It is the dependency the other seven quietly assume.

  2. Access control and multi-factor authentication

    Every framework asks. Every insurer asks. Every questionnaire asks. Same evidence answers all of them.

  3. Logging and monitoring

    What is collected, who looks at it, how long it is kept, and which systems nobody is watching.

  4. Vulnerability and patch management

    A defined cadence, and proof the cadence happened — including the exceptions you accepted.

  5. Backup and recovery

    Held where, restored when, tested by whom. The restore test is the item most often missing.

  6. Supplier and third-party risk

    Who you depend on, and what you checked before you depended on them.

  7. Incident response

    A plan, named roles, and evidence that it has been exercised rather than filed.

  8. Awareness training

    Completion records with dates and names, not a slide deck on a shared drive.

In Sentinel

One register, several frameworks pointing at it.

The alternative — a spreadsheet per framework — is how an organisation ends up answering the same question three different ways in the same quarter.

Mapping

Requirements point at controls you own.

A framework requirement maps to a control in your register. Several frameworks can point at the same control, and the control is maintained once — with one owner, one status and one set of evidence.

  • 224 requirementsresolving onto 26 controls once all four frameworks are in scope
  • Named owners24 of 26 assigned — the rest shown in red rather than averaged away
  • Scope is per frameworkhold one framework on a smaller plan and add others when the demand appears

See the control register

ControlsSentinel interface, reproduced
Control LibraryFramework ReadinessTest ScheduleTest HistoryFindings
Operating
18
Needs evidence
6
Not implemented
2
Owners assigned
24/26
  • A.5.1Policies for information security
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    28 Jul 2026
  • A.5.18Access rights
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    26 Jun 2026
  • A.8.5Secure authentication
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    14 Aug 2026
  • + 5 more in the workspace

Reuse

Evidence is reused, not recollected.

The access review that satisfies an Annex A control also answers the SOC 2 logical access criteria, the matching CIS Safeguard and the CSF Subcategory. It carries a status and an expiry, so a lapse is flagged in the library before an outsider finds it.

  • Status and expiryon every item: Accepted, Under Review, Pending, Expired, Missing
  • Attached to the controlso the requirement, the proof and the owner stay connected across frameworks
  • Readiness per frameworkreported from what is actually in the register, not from a self-declared percentage

See evidence workflows

EvidenceSentinel interface, reproduced

Evidence status

26 controls
  • Accepted41
  • Needs Review2
  • Pending1
  • Expired1
  • Missing1

Register

Expiring first
  • Backup restore test report — Q3 2026
    Control
    A.8.13
    Owner
    Jordan Blake
    Status
    Missing
    Validity
    Due 30 Sep 2026
  • Penetration test report — external (2025)
    Control
    A.8.8
    Owner
    Priya Raman
    Status
    Expired
    Validity
    Expired 20 Jul 2026
  • Privileged account inventory
    Control
    A.8.2
    Owner
    Priya Raman
    Status
    Needs Review
    Validity
    Uploaded 4 Sep 2026
  • + 3 more in the workspace

Sequence

The order that works, whichever framework you picked.

Six steps, and the order is the point. Teams that skip straight to collecting documents end up with a folder nobody can defend, because nothing in it is attached to a requirement or a person.

  1. 01

    Name the demand

    Write down who is asking, what document they want, and the date. One sentence. Almost every over-scoped programme started without this sentence.

  2. 02

    Draw the boundary

    Which entity, which product, which systems, which people. A narrow, defensible scope you can actually evidence beats a broad one you cannot.

  3. 03

    Baseline honestly

    Walk the framework once and record where you really are. A first pass that reads mostly “not assessed” is a correct first pass, and far more useful than an optimistic one.

  4. 04

    Put names against controls

    Every control gets an owner who knows they own it. This is the step that decides whether the register is still true in six months.

  5. 05

    Collect evidence once

    Attach the policy, the ticket, the configuration export, the training record. Give each item a status and an expiry date so you learn it went stale before someone external does.

  6. 06

    Work the gaps, then invite the outsider

    Gaps become dated, assigned actions. Only when the register is real do you book the audit, return the questionnaire or submit to the underwriter.

See how the evidence library handles expiry

Straight answers

Where these pages stop.

CyberWave is a readiness tool. Readiness is not an audit result, and nothing on this site is a certification.

Questions

What buyers actually ask us.

Mostly variations on “how much of this can we avoid”, which is a reasonable question.

Do we have to pick just one?
No, and most organisations end up with more than one over time. The mistake is starting two at once. Pick the one that unblocks the nearest deadline, build the control register and evidence library for it, then add the second framework as a mapping over work you have already done. In Sentinel that second framework reuses the same evidence rather than asking for it again.
Which is cheapest and fastest?
CIS Controls and NIST CSF 2.0 are free to download and need no external party, so the only cost is the work itself. SOC 2 and ISO 27001 both require an external firm, and the audit fee is usually the smaller half of the cost — the larger half is the months of operating evidence you have to accumulate before the audit is worth booking.
Can Sentinel certify us, or issue the report?
No. Certification against ISO 27001 comes from an accredited certification body, and a SOC 2 report comes from a licensed CPA firm. CyberWave is neither, and cannot be both your readiness tool and your independent assessor. Sentinel gets you to the point where that external engagement is worth paying for.
Our customer sent a 200-question security questionnaire. Which framework is that?
Usually none of them exactly. Most questionnaires are an internal document assembled from several sources, which is why answering them repeatedly is so unrewarding. The workable approach is to treat the questionnaire as another set of requirements, map its questions onto controls you already hold evidence for, and reuse that evidence for the next one.
How do framework mappings work in Sentinel?
A requirement from a framework is mapped to a control in your register, and the control holds the owner, the status and the evidence. One control commonly satisfies requirements in several frameworks at once, so the second and third framework cost far less than the first. The mappings are informational readiness mappings, not a determination that a requirement is met.
What if we start down one path and it turns out to be the wrong one?
The scoping, the control register, the named owners and the evidence library carry over almost entirely. What does not carry over is framework-specific documentation, such as an ISO Statement of Applicability or a SOC 2 system description. That is a real cost, but it is a fraction of the programme.

Bring the framework somebody is asking you about.

You do not need to choose a strategy first. Put the one that is blocking a deal or a renewal into a workspace, see the gap honestly, and decide from there.

Book a walkthrough

Self-service signup opens shortly — we will set you up in the meantime

  • Published pricing — no quote-on-request tier
  • No credit card required for the trial
  • No automatic charge when a trial ends
  • Tenant-isolated architecture, data stored in Canada
  • Clear data-processing terms
  • No compliance guarantee — human judgement still required