Frameworks
Four frameworks, and how to tell which one you need.
ISO 27001, SOC 2, NIST CSF 2.0 and CIS Controls are not four versions of the same thing. They answer different questions, they are demanded by different people, and only two of them end in a document you can hand to a customer. These pages describe what each one actually contains — and where a framework is the wrong tool for the problem you have.
Self-service signup opens shortly — we will set you up in the meantime
Frameworks in scope
5 mapped- ISO/IEC 27001:202280% ready42 controls in the catalogue
- SOC 2 (Trust Services Criteria)71% ready45 criteria in the catalogue
- Cyber Insurance Readiness82% ready22 underwriter controls in the catalogue
- NIST CSF 2.0Available59 subcategories in the catalogue
- CIS Controls v8.1Available56 safeguards in the catalogue
Frameworks are added to a workspace as scope, then mapped onto one control register. Figures are from the example workspace used throughout this site; Northstar Manufacturing Ltd. is fictional.
The shortlist
The four, in columns, without the brochure.
Two of these produce a document an outsider signs. Two do not, and are more useful for it. Read down the rows that matter to you rather than across the whole table.
| ISO/IEC 27001:2022 | SOC 2 (Trust Services Criteria) | Cyber Insurance Readiness | NIST CSF 2.0 | CIS Controls v8.1 | |
|---|---|---|---|---|---|
| What it is | A certifiable management system standard. | An attestation engagement against the Trust Services Criteria. | Voluntary guidance describing cybersecurity outcomes. | A prioritised, prescriptive list of defensive actions. | |
| Structure | Clauses 4 to 10, plus 42 Annex A controls in four themes. | 45 criteria in five categories. Security is the common criteria and is mandatory. | Six Functions, 22 Categories, 59 Subcategories. | 18 Controls, 56 Safeguards, three Implementation Groups. | |
| Who asks for it | International and enterprise procurement; European, UK, Gulf and Asian buyers; tenders. | North American software buyers, enterprise security reviews and vendor onboarding. | Boards, executives, US federal supply chains — anyone who needs shared vocabulary. | Insurers indirectly, technical teams directly, and anyone with no programme yet. | |
| What you end with | A certificate valid three years, with annual surveillance audits. | A Type I or Type II report, shared with customers under a confidentiality agreement. | A current profile, a target profile, and an argument for the gap between them. | A measurably harder environment, and evidence that maps into the other three. | |
| Who signs it | An accredited certification body. | A licensed CPA firm. | Nobody. NIST operates no certification scheme. | Nobody. CIS operates no certification scheme. | |
| Cost of the text itself | Purchased from ISO or a national standards body. | Criteria published by the AICPA; the examination is priced by the firm. | Free from NIST. | Free from the Center for Internet Security. | |
| Time to something useful | Six to twelve months to a first Stage 2 audit. | Six to nine months to a first signed Type II, most of it the observation window. | A first profile in an afternoon; the value arrives with the second one. | Weeks. Implementation Group 1 is finite and the work is visible. | |
| Where it stops | The certificate covers only the scope printed on it. | A closed period, not today — which is what bridge letters paper over. | It buys you no credential procurement recognises. | Thin on governance by design: no risk appetite, no management review. | |
| Example workspace readiness | 80% of 42 ready | 71% of 45 ready | 82% of 22 ready | 59 in the catalogue — not yet activated in the example workspace | 56 in the catalogue — not yet activated in the example workspace |
- What it is
- A certifiable management system standard.
- Structure
- Clauses 4 to 10, plus 42 Annex A controls in four themes.
- Who asks for it
- International and enterprise procurement; European, UK, Gulf and Asian buyers; tenders.
- What you end with
- A certificate valid three years, with annual surveillance audits.
- Who signs it
- An accredited certification body.
- Cost of the text itself
- Purchased from ISO or a national standards body.
- Time to something useful
- Six to twelve months to a first Stage 2 audit.
- Where it stops
- The certificate covers only the scope printed on it.
- Example workspace readiness
- 80% of 42 ready
- What it is
- An attestation engagement against the Trust Services Criteria.
- Structure
- 45 criteria in five categories. Security is the common criteria and is mandatory.
- Who asks for it
- North American software buyers, enterprise security reviews and vendor onboarding.
- What you end with
- A Type I or Type II report, shared with customers under a confidentiality agreement.
- Who signs it
- A licensed CPA firm.
- Cost of the text itself
- Criteria published by the AICPA; the examination is priced by the firm.
- Time to something useful
- Six to nine months to a first signed Type II, most of it the observation window.
- Where it stops
- A closed period, not today — which is what bridge letters paper over.
- Example workspace readiness
- 71% of 45 ready
- What it is
- Voluntary guidance describing cybersecurity outcomes.
- Structure
- Six Functions, 22 Categories, 59 Subcategories.
- Who asks for it
- Boards, executives, US federal supply chains — anyone who needs shared vocabulary.
- What you end with
- A current profile, a target profile, and an argument for the gap between them.
- Who signs it
- Nobody. NIST operates no certification scheme.
- Cost of the text itself
- Free from NIST.
- Time to something useful
- A first profile in an afternoon; the value arrives with the second one.
- Where it stops
- It buys you no credential procurement recognises.
- Example workspace readiness
- 82% of 22 ready
- What it is
- A prioritised, prescriptive list of defensive actions.
- Structure
- 18 Controls, 56 Safeguards, three Implementation Groups.
- Who asks for it
- Insurers indirectly, technical teams directly, and anyone with no programme yet.
- What you end with
- A measurably harder environment, and evidence that maps into the other three.
- Who signs it
- Nobody. CIS operates no certification scheme.
- Cost of the text itself
- Free from the Center for Internet Security.
- Time to something useful
- Weeks. Implementation Group 1 is finite and the work is visible.
- Where it stops
- Thin on governance by design: no risk appetite, no management review.
- Example workspace readiness
- 59 in the catalogue — not yet activated in the example workspace
- What it is
- Structure
- Who asks for it
- What you end with
- Who signs it
- Cost of the text itself
- Time to something useful
- Where it stops
- Example workspace readiness
- 56 in the catalogue — not yet activated in the example workspace
The last row is the example workspace used throughout this site, not an average and not a customer result. Timings are what first programmes typically take, and the constraint is almost always accumulated operating evidence rather than documentation.
A framework does not make you secure. It makes your security legible to somebody who is not going to take your word for it.
Which is why the choice matters less than the register underneath it. A framework is a vocabulary and an audience — the controls, the owners and the evidence are yours either way.
Choosing
Start from who is asking, not from the standard.
Nobody wakes up wanting a management system. Something happened: a deal stalled, a renewal arrived, a director asked a question. The person asking has usually already decided which document they will accept.
- A customer
“Send us your SOC 2 report before legal will sign.”
They named the token their vendor policy recognises. Read the policy before you choose a standard — an ISO 27001 certificate will not be accepted as a substitute.
Deadline: their security review
- A tender
“Attach your ISO 27001 certificate with the submission.”
Outside North America this is usually the one that counts. In Europe, the UK, the Gulf and much of Asia a SOC 2 report is often not understood at all.
Deadline: the submission date
- Your insurer
“Is multi-factor authentication enforced for remote and administrative access?”
No underwriter asks for a certificate. They ask control questions, and CIS Controls Implementation Group 1 is the closest map to the form.
Deadline: the renewal date
- Your board
“How exposed are we, and is it getting better?”
NIST CSF 2.0 is the language for that room, and its GOVERN Function exists because oversight and risk appetite were the parts everyone skipped.
Deadline: the next meeting
Two situations arrive without a name attached. If you have no programme and six weeks, start at CIS Controls Implementation Group 1 — 56 Safeguards, prescriptive, and everything you do there counts later towards ISO 27001 Annex A and the SOC 2 common criteria. If a contract or a regulator already names one, it is chosen, and the useful work is rereading the clause: contracts often ask for something narrower than a full certification, and occasionally for something no certificate can satisfy.
The overlap
They are mostly asking about the same eight things.
The frameworks differ in governance, in wording and in who checks. Underneath, a large share of the substance repeats — which is why the second framework costs a fraction of the first, provided the evidence was organised rather than emailed.
What all four want to see
Asset and software inventory
You cannot protect, patch or evidence what nobody has listed. It is the dependency the other seven quietly assume.
Access control and multi-factor authentication
Every framework asks. Every insurer asks. Every questionnaire asks. Same evidence answers all of them.
Logging and monitoring
What is collected, who looks at it, how long it is kept, and which systems nobody is watching.
Vulnerability and patch management
A defined cadence, and proof the cadence happened — including the exceptions you accepted.
Backup and recovery
Held where, restored when, tested by whom. The restore test is the item most often missing.
Supplier and third-party risk
Who you depend on, and what you checked before you depended on them.
Incident response
A plan, named roles, and evidence that it has been exercised rather than filed.
Awareness training
Completion records with dates and names, not a slide deck on a shared drive.
In Sentinel
One register, several frameworks pointing at it.
The alternative — a spreadsheet per framework — is how an organisation ends up answering the same question three different ways in the same quarter.
Mapping
Requirements point at controls you own.
A framework requirement maps to a control in your register. Several frameworks can point at the same control, and the control is maintained once — with one owner, one status and one set of evidence.
- 224 requirements — resolving onto 26 controls once all four frameworks are in scope
- Named owners — 24 of 26 assigned — the rest shown in red rather than averaged away
- Scope is per framework — hold one framework on a smaller plan and add others when the demand appears
| Control | Owner | Status | Evidence | Last tested |
|---|---|---|---|---|
| A.5.1Policies for information security | Priya Raman | Passed | Accepted | 28 Jul 2026 |
| A.5.18Access rights | Priya Raman | Passed | Accepted | 26 Jun 2026 |
| A.8.5Secure authentication | Priya Raman | Passed | Accepted | 14 Aug 2026 |
| A.8.13Information backup | Jordan Blake | Passed | Accepted | 18 Jun 2026 |
| A.8.2Privileged access rights | Priya Raman | Failed | Needs Review | 20 Aug 2026 |
| A.8.7Protection against malware | Jordan Blake | Tested | Accepted | 28 Aug 2026 |
| CC9.2Vendor and business partner risk management | Elena Kowalski | Failed | Accepted | 12 Aug 2026 |
| PR.AA-01Identities and credentials are managed | Unassigned | Not Tested | Missing | — |
- A.5.1Policies for information security
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 28 Jul 2026
- A.5.18Access rights
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 26 Jun 2026
- A.8.5Secure authentication
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 14 Aug 2026
- + 5 more in the workspace
Reuse
Evidence is reused, not recollected.
The access review that satisfies an Annex A control also answers the SOC 2 logical access criteria, the matching CIS Safeguard and the CSF Subcategory. It carries a status and an expiry, so a lapse is flagged in the library before an outsider finds it.
- Status and expiry — on every item: Accepted, Under Review, Pending, Expired, Missing
- Attached to the control — so the requirement, the proof and the owner stay connected across frameworks
- Readiness per framework — reported from what is actually in the register, not from a self-declared percentage
Evidence status
26 controls- Accepted41
- Needs Review2
- Pending1
- Expired1
- Missing1
Register
Expiring first| Evidence | Control | Owner | Status | Validity |
|---|---|---|---|---|
| Backup restore test report — Q3 2026 | A.8.13 | Jordan Blake | Missing | Due 30 Sep 2026 |
| Penetration test report — external (2025) | A.8.8 | Priya Raman | Expired | Expired 20 Jul 2026 |
| Privileged account inventory | A.8.2 | Priya Raman | Needs Review | Uploaded 4 Sep 2026 |
| Statement of Applicability — draft v3 | C.6 | Elena Kowalski | Pending | Due 31 Aug 2026 |
| MFA enforcement — Microsoft 365 Conditional Access | A.8.5 | Priya Raman | Accepted | Valid to 14 Aug 2027 |
| EDR coverage report — 98% of endpoints | A.8.7 | Jordan Blake | Accepted | Valid to 28 Nov 2026 |
- Backup restore test report — Q3 2026
- Control
- A.8.13
- Owner
- Jordan Blake
- Status
- Missing
- Validity
- Due 30 Sep 2026
- Penetration test report — external (2025)
- Control
- A.8.8
- Owner
- Priya Raman
- Status
- Expired
- Validity
- Expired 20 Jul 2026
- Privileged account inventory
- Control
- A.8.2
- Owner
- Priya Raman
- Status
- Needs Review
- Validity
- Uploaded 4 Sep 2026
- + 3 more in the workspace
Sequence
The order that works, whichever framework you picked.
Six steps, and the order is the point. Teams that skip straight to collecting documents end up with a folder nobody can defend, because nothing in it is attached to a requirement or a person.
- 01
Name the demand
Write down who is asking, what document they want, and the date. One sentence. Almost every over-scoped programme started without this sentence.
- 02
Draw the boundary
Which entity, which product, which systems, which people. A narrow, defensible scope you can actually evidence beats a broad one you cannot.
- 03
Baseline honestly
Walk the framework once and record where you really are. A first pass that reads mostly “not assessed” is a correct first pass, and far more useful than an optimistic one.
- 04
Put names against controls
Every control gets an owner who knows they own it. This is the step that decides whether the register is still true in six months.
- 05
Collect evidence once
Attach the policy, the ticket, the configuration export, the training record. Give each item a status and an expiry date so you learn it went stale before someone external does.
- 06
Work the gaps, then invite the outsider
Gaps become dated, assigned actions. Only when the register is real do you book the audit, return the questionnaire or submit to the underwriter.
Straight answers
Where these pages stop.
CyberWave is a readiness tool. Readiness is not an audit result, and nothing on this site is a certification.
Questions
What buyers actually ask us.
Mostly variations on “how much of this can we avoid”, which is a reasonable question.
Do we have to pick just one?
Which is cheapest and fastest?
Can Sentinel certify us, or issue the report?
Our customer sent a 200-question security questionnaire. Which framework is that?
How do framework mappings work in Sentinel?
What if we start down one path and it turns out to be the wrong one?
Bring the framework somebody is asking you about.
You do not need to choose a strategy first. Put the one that is blocking a deal or a renewal into a workspace, see the gap honestly, and decide from there.
Self-service signup opens shortly — we will set you up in the meantime
- Published pricing — no quote-on-request tier
- No credit card required for the trial
- No automatic charge when a trial ends
- Tenant-isolated architecture, data stored in Canada
- Clear data-processing terms
- No compliance guarantee — human judgement still required