Frameworks
20+ standards. Including the ones US platforms skip.
Most GRC platforms support SOC 2 and ISO 27001. Sentrix supports those—and every framework your regulators, customers, or board are asking about next. Including Law 25, CPCSC, TGV, DORA, NIS2 and CMMC. All with pre-built crosswalks so adding a new framework does not restart your evidence program.
International & industry standards
SOC 2
AICPA Trust Services Criteria. Type I and Type II. The most-requested security certification for SaaS and technology companies selling into enterprise. Sentrix gets you to Type I in 30 days, Type II in 6 months.
ISO 27001:2022
Information Security Management System. The international gold standard for information security, updated in 2022 with new Annex A controls. Sentrix maintains updated crosswalks for the 2022 revision automatically.
PCI DSS v4.0
Payment Card Industry Data Security Standard. Version 4.0 adds customized approach and enhanced authentication requirements. Sentrix covers all 12 PCI DSS requirements with continuous cardholder data environment monitoring.
HIPAA
Health Insurance Portability and Accountability Act. Security Rule, Privacy Rule, and Breach Notification Rule. All 75 implementation specifications monitored continuously. BAA tracking and PHI data flow mapping included.
GDPR
General Data Protection Regulation. EU data protection requirements including lawful basis tracking, DPIA templates, data subject rights workflows, and processor agreement management for organizations with EU operations or customers.
NIST CSF 2.0
NIST Cybersecurity Framework version 2.0, updated in 2024 with a new Govern function. Pre-built crosswalks to SOC 2, ISO 27001, and Canadian standards. Ideal for organizations seeking a risk-based approach independent of sector.
NIST SP 800-53
Security and Privacy Controls for federal information systems. 20 control families with over 1,000 controls. Used by US federal agencies and defence contractors. Sentrix maps 800-53 to CMMC, ISO 27001, and SOC 2 automatically.
CMMC 2.0
Cybersecurity Maturity Model Certification. Required for DoD contractors. Levels 1, 2, and 3 with pre-built practice mapping to NIST SP 800-171. Sentrix helps defence contractors achieve and maintain CMMC certification.
AI governance frameworks
ISO 42001
ISO/IEC 42001:2023 — the world’s first AI management system (AIMS) standard. Applies to any organization developing, providing, or using AI. Shares the Annex SL structure with ISO 27001—organizations already certified start ISO 42001 with 60%+ already satisfied. Sentrix pre-maps AI system impact assessments, Annex A controls, and third-party AI provider risk continuously.
NIST AI RMF
NIST Artificial Intelligence Risk Management Framework 1.0 (January 2023). Four core functions: GOVERN, MAP, MEASURE, MANAGE—applicable to any sector and any AI maturity level. Sentrix operationalizes all four functions continuously and cross-maps to ISO 42001 so both frameworks are satisfied from one evidence set.
European regulatory frameworks
DORA
Digital Operational Resilience Act. EU regulation for financial entities in force since January 2025. Covers ICT risk management, incident reporting, resilience testing, and third-party ICT provider oversight. Sentrix is one of the only platforms with full DORA coverage from day one.
NIS2
Network and Information Security Directive 2. Expanded scope covering essential and important entities across sectors. Ten minimum security measures with board-level accountability requirements. Pre-built crosswalks to ISO 27001 and DORA for financial sector overlap.
TISAX
Trusted Information Security Assessment Exchange. Information security standard for the automotive industry and its supply chain. Required by major OEMs for tier-1 and tier-2 suppliers. Sentrix maps TISAX to ISO 27001 for organizations holding both.
Canadian frameworks — native support
Law 25
Québec Act Respecting the Protection of Personal Information in the Private Sector. Full enforcement since September 2023. Sentrix covers all Law 25 obligations: PIA, consent, breach notification (72-hour CAI reporting), data minimization, and right of access. Bilingual documentation included.
CPCSC
Canadian Programme de cybersécurité de la chaîne d’approvisionnement. Federal cybersecurity certification for defence and critical infrastructure supply chains. Level 1 and Level 2 readiness programs with pre-built controls, evidence collection, and audit-ready packages.
TGV
Trousse Globale de Vérification - the BCH/MSSS certification framework for technological products and services (PST) used in Québec's health and social services network. Covers security, personal information protection (PRP), performance and technology. Sentrix maps TGV domains to Law 25 and ISO 27001 so you satisfy all three from one evidence set.
PIPEDA / Bill C-27
Personal Information Protection and Electronic Documents Act and its forthcoming successor, the Consumer Privacy Protection Act. Federal private sector privacy requirements applicable to organizations operating in Canada or handling Canadian personal data across provincial borders.
OSFI B-10 / B-13
Office of the Superintendent of Financial Institutions guidelines for outsourcing (B-10) and technology and cyber risk management (B-13). Required for federally regulated financial institutions. Pre-built control sets with crosswalks to DORA, SOC 2, and ISO 27001.
CAN/DGSI 104
Baseline Cyber Security Controls for Small and Medium Organizations (formerly Cybersecure Canada). 13 mandatory controls published by DGSI under the Standards Council of Canada, updated Rev 1:2024. Designed for organizations under 500 employees. Underpins the CyberSecure Canada national certification program. Crosswalks to NIST CSF and CIS Controls included.
How crosswalks work
Add a framework. Do not rebuild your evidence program.
When you add a new framework in Sentrix, our crosswalk engine maps every piece of evidence you have already collected to the controls it satisfies in the new standard. Gaps surface immediately. Most organizations already satisfy 60–80% of a new framework before collecting a single new piece of evidence.
- Add ISO 27001 to an existing SOC 2 program—typically 70%+ already satisfied
- Add Law 25 to an existing GDPR program—crosswalk shows the delta immediately
- Add DORA to an existing NIS2 program—overlap analysis in minutes, not months
- Custom framework builder for internal standards and bespoke regulatory requirements
Adding ISO 27001 → existing SOC 2 program
ISO 27001 controls total93
Already satisfied (SOC 2 overlap)68 (73%)
Gaps requiring new evidence25 (27%)
Estimated time to close gaps~45 days
See how many frameworks your current controls already satisfy.
We run your crosswalk analysis live in the demo and show you your gap before the call ends.