Crosswalk explorer

The same work, described 13 ways

Compliance frameworks overlap enormously. They describe the same security realities in different words. Keel is built on one crosswalked control library, so a control you implement once counts toward every framework it satisfies. The numbers below aren't a marketing estimate: each is the count of canonical Keel controls that map to both frameworks, computed straight from our authored crosswalks and guarded by a test in our codebase.

A quick note on what these counts mean: they're the shared canonical controls in Keel's starter library (the reusable work), not each framework's total clause count. See any framework's full authored control count on its framework page.

Shared controls at a glance

ISO/IEC 27001 SOC 2 NIST SP 800-53 PCI DSS NIST Cybersecurity Framework CIS Critical Security Controls ESG Essentials HIPAA ISO/IEC 42001 ISO 9001 EU AI Act NIST AI Risk Management Framework AI Governance Essentials
ISO/IEC 27001 24 23 19 18 17 5 15 1 6 0 0 0
SOC 2 24 23 19 18 17 4 15 1 7 0 0 0
NIST SP 800-53 23 23 19 18 17 4 15 1 5 0 0 0
PCI DSS 19 19 19 15 15 4 13 0 4 0 0 0
NIST Cybersecurity Framework 18 18 18 15 15 4 12 0 4 0 0 0
CIS Critical Security Controls 17 17 17 15 15 3 11 0 3 0 0 0
ESG Essentials 5 4 4 4 4 3 4 0 3 0 0 0
HIPAA 15 15 15 13 12 11 4 0 3 0 0 0
ISO/IEC 42001 1 1 1 0 0 0 0 0 1 9 7 3
ISO 9001 6 7 5 4 4 3 3 3 1 0 0 0
EU AI Act 0 0 0 0 0 0 0 0 9 0 5 3
NIST AI Risk Management Framework 0 0 0 0 0 0 0 0 7 0 5 2
AI Governance Essentials 0 0 0 0 0 0 0 0 3 0 3 2

Each cell is the number of canonical Keel controls shared by the two frameworks. Click a number to see exactly which controls, and the clauses they satisfy on each side.

Every overlapping pair

ISO/IEC 27001 SOC 2 24 shared ISO/IEC 27001 NIST SP 800-53 23 shared NIST SP 800-53 SOC 2 23 shared ISO/IEC 27001 PCI DSS 19 shared NIST SP 800-53 PCI DSS 19 shared PCI DSS SOC 2 19 shared ISO/IEC 27001 NIST Cybersecurity Framework 18 shared NIST SP 800-53 NIST Cybersecurity Framework 18 shared NIST Cybersecurity Framework SOC 2 18 shared CIS Critical Security Controls ISO/IEC 27001 17 shared CIS Critical Security Controls NIST SP 800-53 17 shared CIS Critical Security Controls SOC 2 17 shared CIS Critical Security Controls NIST Cybersecurity Framework 15 shared CIS Critical Security Controls PCI DSS 15 shared HIPAA ISO/IEC 27001 15 shared HIPAA NIST SP 800-53 15 shared HIPAA SOC 2 15 shared NIST Cybersecurity Framework PCI DSS 15 shared HIPAA PCI DSS 13 shared HIPAA NIST Cybersecurity Framework 12 shared CIS Critical Security Controls HIPAA 11 shared EU AI Act ISO/IEC 42001 9 shared ISO/IEC 42001 NIST AI Risk Management Framework 7 shared ISO 9001 SOC 2 7 shared ISO/IEC 27001 ISO 9001 6 shared ESG Essentials ISO/IEC 27001 5 shared EU AI Act NIST AI Risk Management Framework 5 shared ISO 9001 NIST SP 800-53 5 shared ESG Essentials HIPAA 4 shared ESG Essentials NIST SP 800-53 4 shared ESG Essentials NIST Cybersecurity Framework 4 shared ESG Essentials PCI DSS 4 shared ESG Essentials SOC 2 4 shared ISO 9001 NIST Cybersecurity Framework 4 shared ISO 9001 PCI DSS 4 shared AI Governance Essentials EU AI Act 3 shared AI Governance Essentials ISO/IEC 42001 3 shared CIS Critical Security Controls ESG Essentials 3 shared CIS Critical Security Controls ISO 9001 3 shared ESG Essentials ISO 9001 3 shared HIPAA ISO 9001 3 shared AI Governance Essentials NIST AI Risk Management Framework 2 shared ISO/IEC 27001 ISO/IEC 42001 1 shared ISO/IEC 42001 ISO 9001 1 shared ISO/IEC 42001 NIST SP 800-53 1 shared ISO/IEC 42001 SOC 2 1 shared
Start free: apply a second framework

No credit card. Watch how much of your next framework your existing controls already cover.