Research

How much do compliance frameworks actually overlap?

Teams treat each framework as a fresh project. It usually is not. We measured the overlap using our own open control library: 201 of its common controls map to the 10 frameworks in this study. The short version is that the average control does real work in 2.3 frameworks at once, so the framework you take on second never starts from zero.

The data set

Keel maintains a library of canonical security controls, each pre-mapped ("crosswalked") to the specific clauses it satisfies. This report analyzes the 201 of those controls that satisfy at least one of 10 frameworks: ISO 27001, SOC 2, NIST CSF, PCI DSS, HIPAA, ISO 9001, ESG Essentials, NIST 800-171, CIS Controls, GDPR. Across those 201 controls there are 460 control-to-framework mappings into that set, which means the average control does real work in 2.3 frameworks at once. The control library is published as an open dataset (CC BY 4.0) on our open source page.

Overlap is the rule, not the exception

The average control maps to 2.3 frameworks, and 25 of the 201 controls (12%) satisfy five or more frameworks at once. At the very top, 2 controls map to 9 of the 10 frameworks in the set: Third-party / vendor risk management, Security awareness training. Governance fundamentals are shared almost everywhere; only a handful of controls are truly framework-specific.

Controls carrying the most frameworks

Controls carrying the most frameworks
Control Frameworks satisfied
Third-party / vendor risk management 9
Security awareness training 9
Access control policy 8
User provisioning & deprovisioning 8
Multi-factor authentication 8
Encryption in transit & at rest 8
Logging & monitoring 8
Incident response 8

Where the overlap is largest: SOC 2 and ISO 27001

The clearest way to see the reuse is pairwise: of the controls that satisfy one framework, how many also satisfy another? Of the 6 pairs in the table below, SOC 2 into ISO 27001 is the largest: of the 50 controls that map to SOC 2, 32 (64%) also satisfy ISO 27001. Read the other way, those same 32 controls are 38% of what ISO 27001 draws on, so this is a head start rather than a finished framework. What the overlap buys is real, though: for every control on both sides of that line the remaining work is mapping and evidence, not standing up a new control.

Pairwise control overlap between frameworks
If you have... ...how much of this is already covered Shared controls
SOC 2 ISO 2700132 of 50 (64%)
SOC 2 PCI DSS19 of 50 (38%)
SOC 2 NIST CSF26 of 50 (52%)
SOC 2 HIPAA20 of 50 (40%)
ISO 27001 HIPAA24 of 84 (29%)
PCI DSS HIPAA18 of 38 (47%)

Percentages are of the first framework’s control count. Overlap is not symmetric: a smaller framework can be almost fully contained in a larger one while covering less of it in return.

How many controls each framework needs

Coverage in this library, ordered by breadth. Larger frameworks such as ISO 27001 and SOC 2 draw on the most controls; targeted regimes such as GDPR touch fewer, because much of their text is legal rather than technical.

Controls per framework in this library
Framework Controls in this library
ISO 27001 84 of 201
SOC 2 50 of 201
NIST CSF 50 of 201
GDPR 50 of 201
ISO 9001 43 of 201
NIST 800-171 41 of 201
PCI DSS 38 of 201
ESG Essentials 37 of 201
CIS Controls 36 of 201
HIPAA 31 of 201

What this means for sequencing

The practical lesson is to build controls once and map them many times. Because the average control serves 2.3 frameworks, the marginal cost of a second framework is dominated by mapping and evidence, not by standing up new controls. That is why a crosswalk-native approach matters: the same encryption, access-review, and incident-response controls you implement for SOC 2 are the ones an ISO 27001, PCI DSS, or HIPAA assessor will ask about next.

  • Start with the high-reuse core. The 25 controls that satisfy five or more frameworks are the highest-leverage place to begin.
  • Pick your second framework by overlap. Of the pairs measured here, SOC 2 into ISO 27001 is the smallest additional lift; a regime like GDPR shares less because it is largely legal.
  • Map, do not rebuild. Treat the second framework as a mapping exercise over existing evidence. (Explore the mappings in the crosswalk explorer.)

Methodology and limitations

Comply once, prove everywhere

Keel is the crosswalk-native, AI GRC platform for SMBs: implement a control once and Keel maps it to every framework it satisfies. Start free.