Skip to main content
ResiPlan
Multi-framework compliance

15 frameworks. 6 countries. One assessment.

From ISO 27001 and DORA to every country's national framework — assess a control once and ResiPlan reflects your compliance everywhere, with rationale and citation to back it up. No more duplicate evidence, no more mapping spreadsheets.

assess-once.map
MFA on privileged accounts
1 control assessed
ISO 27001:2022A.5.17
NIS2Art. 21.2.j
DORAArt. 9.4.f
NIST CSF 2.0PR.AA-01
CyFun 2.0PR.AC-7
ENSop.acc.5
6 frameworks ✓
In 100 seconds

One assessment, every framework

How ResiPlan's crosswalk engine links every assessed control to all 10 frameworks — evidence included.

The network effect

One assessment effort, fifteen compliances

Every control you assess feeds all linked frameworks. The work stops duplicating.

15
frameworks covered
6
EU countries
300+
pre-mapped controls
−60%
audit effort
< 2h
to a cross-framework audit pack
0
duplicate evidence needed
100%
evidence traceability
1
source of truth
The problem

Juggling frameworks, the old way

Every extra framework used to multiply the work. It no longer has to.

Duplicated evidence

The same MFA policy re-collected for ISO 27001, then NIS2, then DORA, then the national baseline. The same work, three or four times.

The mapping spreadsheets

Home-made Excel matrices linking controls by hand — never up to date, unreadable for the auditor, impossible to maintain.

Overlapping deadlines

DORA since 2025, NIS2 in transposition, an ISO audit coming round, a national framework per subsidiary: every framework pulls its own way.

Silent drift

A control changes, but your compliance to the other frameworks stays frozen in an old document. You find the gap on audit day.

How it works

Assess once, comply many

Four steps, and the mapping engine does the rest.

  1. 1

    Assess once

    Rate each control a single time on a 0–4 maturity scale, and attach its evidence.

  2. 2

    ResiPlan cross-maps

    The engine links the control to every framework through traced crosswalks: rationale, citation and confidence level.

  3. 3

    Prove everywhere

    Compliance score, Statement of Applicability and gap analysis fill themselves in across all 15 frameworks.

  4. 4

    Stay in sync

    Update a control and every linked framework recomputes instantly. One single source of truth.

Coverage

The European & international standards

The major cross-border frameworks, pre-mapped to one another.

ISO/IEC 27001:2022

Information security (ISMS)

93 controls

ISO 22301

Business continuity

180 controls

NIS2

EU cybersecurity

42 controls

DORA

Digital operational resilience

120 controls

CRA

Products with digital elements

45 controls

NIST CSF 2.0

Cybersecurity framework

106 controls

RGPD / GDPR

Data protection

65 controls

SOC 2

Trust Services Criteria

64 controls

CYRA

Dutch cyber rating (CCV)

42 controls
A framework per country

The national frameworks, natively

Your clients and subsidiaries answer to different frameworks per country. ResiPlan covers them all.

Belgium · CCB

🇧🇪 CyFun 2.0

CyberFundamentals — Belgium's route to NIS2, across 3 assurance levels.

23 controls
Germany · BSI

🇩🇪 BSI IT-Grundschutz

Germany's reference baseline, in modular Bausteine.

25 controls
Netherlands · government

🇳🇱 BIO

Baseline Informatiebeveiliging Overheid — the Dutch government baseline.

24 controls
France · ANSSI

🇫🇷 ANSSI — Hygiene

The cyber-hygiene guide, baseline for French entities.

22 controls
Spain · CCN

🇪🇸 ENS

Esquema Nacional de Seguridad — Spain's public-sector scheme.

20 controls
Italy · ACN

🇮🇹 FNCS

The Italian national cybersecurity framework.

18 controls
Worked example

One control, six compliances

Implementing multi-factor authentication satisfies six frameworks at once — assessed a single time.

Multi-factor authentication on privileged accounts
1 control assessed · 6 frameworks satisfied
ISO 27001:2022
A.5.17Authentication information
NIS2
Art. 21.2.jMulti-factor authentication
DORA
Art. 9.4.fStrong authentication
NIST CSF 2.0
PR.AA-01Identities & credentials managed
CyFun 2.0
PR.AC-7User & device authentication
ENS
op.acc.5Authentication mechanism
Before / after

Yesterday's spreadsheet, or ResiPlan

TaskThe old wayResiPlan
Collect evidenceRe-collected framework by framework, scattered across foldersOne evidence library, reused across all 15 frameworks
Link the controlsHand-built Excel matrices, never up to date300+ pre-mapped controls, maintained for you
When a control changesEvery document to fix one by oneEvery linked framework recomputes automatically
Add a frameworkStart from scratch, re-assess everythingAI-assisted mapping, pre-filled from your existing assessments
Prepare an audit packDays consolidating manual exportsA cross-framework pack exportable in under 2 hours
Run several entitiesOne workbook per client or subsidiary, no overviewA single portfolio, one-click comparison

← Scroll horizontally →

Your own framework

A custom framework? Mapped by AI.

Import your controls or proprietary framework. AI-assisted mapping proposes the crosswalks to ISO 27001, NIS2 and the other 13 frameworks — every suggestion reviewed and approved by your team before it goes live.

Import your controls
CSV or manual framework creation.
AI-proposed crosswalks
To all 15 frameworks, with rationale and confidence.
Mandatory human review
Nothing goes live without your team's approval.
GRC consultancies & multi-entity groups

Your entire client base, one console

Run your cross-framework gap analyses across all your clients and subsidiaries from a single portfolio.

Assess each client's or subsidiary's maturity from a single portfolio.
Compare one entity against several frameworks — and entities against each other.
Surface gaps per framework and the gaps common across the portfolio.
Recommend the best-fit framework, backed by data.
Reuse one assessment across every framework — no duplicate evidence.
Guided training included for every module — your teams ramp up fast.
FAQ

Frequently asked questions

Which frameworks are built in?

15 frameworks, pre-mapped onto a common ISO 27001 + NIS2 core: ISO/IEC 27001:2022, ISO 22301, NIS2, DORA, CRA, NIST CSF 2.0, GDPR and SOC 2, the Dutch CYRA assessment, plus six national frameworks — CyFun (Belgium), BSI IT-Grundschutz (Germany), BIO (Netherlands), ANSSI (France), ENS (Spain) and FNCS (Italy).

How does "assess once, comply many" work?

Every assessed control is linked to the equivalent controls in other frameworks through maintained crosswalks (exact, partial or related). ResiPlan materialises those links and propagates your status automatically — each mapping carries a rationale, a citation and a confidence level, so it stays defensible in an audit.

How much work does it really save?

Entities subject to DORA + NIS2 + ISO 22301 typically spend €200–500K/year on duplicated audits. By reusing a single assessment across the 15 frameworks, ResiPlan cuts audit effort by roughly 60% and generates a cross-framework audit pack in under 2 hours, with zero duplicate evidence.

Can I add my own or a proprietary framework?

Yes. Import your controls, create a custom framework and let AI-assisted mapping propose the crosswalks to ISO 27001, NIS2 and the rest; every suggestion stays subject to your team's review and approval before it goes live.

Does my posture stay in sync when a control changes?

Yes. Update a control once and the compliance score and gap analysis of every linked framework recompute automatically. One single source of truth, no silent drift.

Is data hosted in the EU?

Yes. ResiPlan is hosted within the European Union.

Is it suitable for GRC consultancies and multi-entity groups?

Yes. Multi-entity mode lets you assess each client's or subsidiary's maturity, compare it against multiple frameworks, benchmark entities against each other and recommend the best-fit framework — all from a single portfolio.

In-depth guides

Explore each framework

A dedicated guide per framework: scope, key requirements and how ResiPlan gets you there.

Assess once. Prove it to every regulator.

Start your free trial or request a guided demo of the cross-framework mapping engine.

15 frameworks · 6 countries · 300+ pre-mapped controls · hosted in the EU

Compliance frameworks — 15 frameworks, 6 countries, one assessment | ResiPlan