Skip to content
Framework library

Every Framework Your Reviewers Will Ask for. One Control Library.

178+ frameworks mapped to one shared control library. Add the next framework for $1,500 instead of rebuilding your entire program. Evidence stays linked, current, and ready to share.

Platform depth

Pre-Built Depth in Every Framework

Each framework ships with mapped controls, pre-linked evidence specifications, test assertions, and integration sources. Numbers computed from the live catalog.

178
Frameworks
30,956
Requirements
198
Mapped controls
19,287
Evidence specs
25,667
Test assertions
30
Integration sources
$1,500 to add the next oneUpdated Dec 27, 2025

Framework library

178 Frameworks. Search Yours.

Every framework, regulation, and state overlay your reviewers already ask about - mapped to controls with evidence specifications.

178
frameworks

Security and privacy frameworks used in audits, certifications, and customer diligence.

Framework

Adobe Common Controls Framework (Adobe CCF)

Adobe Common Controls Framework (Adobe CCF) trust center source set.

1versionAdobe Common Controls Framework (Adobe CCF) trust center source set
Framework

Anecdotes AI Framework (AAIF)

The Anecdotes AI GRC Toolkit (official public PDF).

1versionThe Anecdotes AI GRC Toolkit (official public PDF)
Framework

ASD Essential Eight

Essential Eight Maturity Model (November 2023).

1versionEssential Eight Maturity Model (November 2023)
Framework

Aurora Essentials (Baseline Control Set)

Aurora’s opinionated baseline of essential security, privacy, resilience, and SDLC controls.

1versionAurora
Framework

Australian Energy Sector Cyber Security Framework (AESCSF)

Australian Energy Sector Cyber Security Framework – current official program page with operative V2 Full Assessment requirement corpus.

1versionAustralian Energy Sector Cyber Security Framework – current official program page with operative V2 Full Assessment requirement corpus
Framework

AWS Well-Architected Framework

AWS Well-Architected Framework core source family.

1versionAWS Well-Architected Framework core source family
Framework

BSI IT Grundschutz (Grundschutz and and )

BSI IT Grundschutz (Grundschutz and and ) imported from the supplied framework package.

1versionBundesamt für Sicherheit in der Informationstechnik (BSI)
Framework

China Multi-Level Protection Scheme (MLPS) 2.0

GB/T 22239–2019 信息安全技术 网络安全等级保护基本要求.

1versionGB/T 22239–2019 信息安全技术 网络安全等级保护基本要求
Framework

CIS Controls v8

CIS Controls v8 coverage for implementation-ready security programs.

1versionCenter for Internet Security (CIS)
Framework

Cisco Cloud Controls Framework

Cisco Cloud Controls Framework.

1versionCisco Cloud Controls Framework
Framework

CMS MARS-E v2.2 – Minimum Acceptable Risk Standards for Exchanges

CMS MARS-E v2.2 – Minimum Acceptable Risk Standards for Exchanges imported from the supplied framework package.

1versionCenters for Medicare & Medicaid Services
Framework

COBIT 2019 Framework: Governance and Management Objectives

Aurora Command maps the COBIT 2019 Core Model governance and management objectives (EDM/APO/BAI/DSS/MEA) into one reusable control and evidence workflow so teams can reuse proof across repeat reviews.

1versionISACA
Framework

CSA Cloud Controls Matrix (CCM) v4.0.12

CSA Cloud Controls Matrix (CCM) v4.0.12 requirements organized for repeat reviews and controlled evidence reuse.

1versionCloud Security Alliance (CSA)
Framework

CSA Cloud Controls Matrix (CCM) v4.1

Cloud Controls Matrix and CAIQ v4.1.

1versionCloud Controls Matrix and CAIQ v4.1
Framework

Custom Frameworks (template)

Template for company-specific frameworks and reviewer requirements that do not fit a published standard.

1versionAurora
Framework

Cyber Essentials

Cyber Essentials: Requirements for IT Infrastructure v3.2.

1versionCyber Essentials: Requirements for IT Infrastructure v3.2
Framework

Cyber Risk Institute Profile (CRI)

The CRI Profile provides diagnostic statements aligned to the NIST Cybersecurity Framework (CSF) for financial services and other regulated organizations.

1versionCyber Risk Institute
Framework

Cybersecurity Capability Maturity Model

Cybersecurity Capability Maturity Model imported from the supplied framework package.

1versionU.S. Department of Energy
Framework

Cybersecurity Code of Practice for Critical Information Infrastructure

Cybersecurity Code of Practice for Critical Information Infrastructure imported from the supplied framework package.

1versionCyber Security Agency of Singapore / Commissioner of Cybersecurity
Framework

Cybersecurity Maturity Model Certification (CMMC) 2.0 – Level 1 (Foundational)

CMMC Level 1 includes 17 practices aligned to the FAR 52.204-21 basic safeguarding requirements for protecting Federal Contract Information (FCI) on covered contractor information systems.

1version1U.S. Department of Defense (CMMC)
Framework

Digital Services Act (DSA)

Digital Services Act (DSA) imported from the supplied framework package.

1versionPackage-provided framework source package
Framework

Fair Credit Reporting Act (FCRA) / Regulation V / FTC FCRA Subchapter F

FCRA imported from the supplied framework package.

1versionPackage-provided framework source package
Framework

FedRAMP Security Controls Baseline (High) - NIST SP 800-53 Rev. 5

FedRAMP High controls organized for authorization work, assessor reviews, and repeat evidence reuse.

1versionFedRAMP (U.S. General Services Administration)
Framework

FedRAMP Security Controls Baseline (Low) - NIST SP 800-53 Rev. 5

FedRAMP Low controls organized for authorization work, assessor reviews, and repeat evidence reuse.

1versionFedRAMP (U.S. General Services Administration)
Framework

FedRAMP Security Controls Baseline (Moderate) - NIST SP 800-53 Rev. 5

FedRAMP Moderate controls organized for authorization work, assessor reviews, and repeat evidence reuse.

1versionFedRAMP (U.S. General Services Administration)
Framework

FFIEC Cybersecurity Assessment Tool (CAT)

FFIEC Cybersecurity Assessment Tool (CAT), May 2017 edition.

1version1Federal Financial Institutions Examination Council (FFIEC)
Framework

FFIEC IT Examination Handbook – Information Security Booklet

FFIEC IT Examination Handbook (IT Handbook) – Information Security Booklet.

1versionFederal Financial Institutions Examination Council (FFIEC)
Framework

GFSC Handbook on Countering Financial Crime (AML/CFT/CPF)

GFSC_HANDBOOK imported from the supplied framework package.

1versionPackage-provided framework source package
Framework

HITRUST CSF

HITRUST CSF – Our Cybersecurity Framework.

1versionHITRUST CSF – Our Cybersecurity Framework
Framework

ICH E6(R3) Good Clinical Practice (Principles and Annex 1)

ICH E6(R3) Good Clinical Practice (Principles and Annex 1) imported from the supplied framework package.

1versionPackage-provided framework source package
Framework

IRS Publication 4812 Contractor Security & Privacy Controls

IRS Publication 4812 Contractor Security & Privacy Controls imported from the supplied framework package.

1versionInternal Revenue Service
Framework

ISO 14001 Environmental management systems – Requirements with guidance for use

ISO 14001 Environmental management systems – Requirements with guidance for use imported from the supplied framework package.

1versionInternational Organization for Standardization (ISO)
Framework

ISO/IEC 17024 – Conformity assessment – General requirements for bodies operating certification of persons

ISO/IEC 17024 – Conformity assessment – General requirements for bodies operating certification of persons imported from the supplied framework package.

1versionISO
Framework

ISO/IEC 27002:2022 – Information security controls

ISO/IEC 27002:2022 – Information security controls imported from the supplied framework package.

1versionISO/IEC
Framework

Mastercard Terminal Quality Management (TQM)

MASTERCARD_TQM imported from the supplied framework package.

1versionTÜV SÜD / Mastercard program page
Framework

Nacha Operating Rules

Nacha Operating Rules imported from the supplied framework package.

1versionPackage-provided framework source package
Framework

NCSC Cyber Assessment Framework (CAF)

NCSC Cyber Assessment Framework (CAF) imported from the supplied framework package.

1versionUK National Cyber Security Centre (NCSC)
Framework

NERC Critical Infrastructure Protection (CIP) Reliability Standards – Current Effective U.S. FERC-Applicable U.S. Baseline

NERC_CIP imported from the supplied framework package.

1versionPackage-provided framework source package
Framework

NERC Rules of Procedure

NERC Rules of Procedure imported from the supplied framework package.

1versionPackage-provided framework source package
Framework

NIST AI Risk Management Framework (AI RMF)

AI Risk Management Framework.

1versionAI Risk Management Framework
Framework

NIST Cybersecurity Framework (CSF) 2.0

The Cybersecurity Framework (CSF) 2.0.

1versionThe Cybersecurity Framework (CSF) 2.0
Framework

NIST Privacy Framework

NIST Privacy Framework requirements organized for repeat reviews and controlled evidence reuse.

1versionPrivacy Framework
Framework

NIST Secure Software Development Framework (SSDF)

NIST SP 800-218, Secure Software Development Framework (SSDF) Version 1.1.

1versionNIST SP 800-218, Secure Software Development Framework (SSDF) Version 1.1
Framework

NIST SP 800-161 Rev. 1 Update 1

NIST SP 800-161 Rev. 1 Update 1 requirements organized for repeat reviews and controlled evidence reuse.

1versionPackage-provided framework source package
Framework

NIST SP 800-171 (CUI)

Aurora Command maps NIST SP 800-171 families into one reusable control and evidence workflow so teams can reuse proof across repeat reviews.

1version1NIST
Framework

NIST SP 800-218A: Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile

NIST SP 800-218A: Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile imported from the supplied framework package.

1versionNational Institute of Standards and Technology (NIST)
Framework

NIST SP 800-53 Rev. 5

Electronic (OSCAL) Version of NIST SP 800-53 Rev 5.2.0 Controls and SP 800-53A Rev 5.2.0 Assessment Procedures.

1versionElectronic (OSCAL) Version of NIST SP 800-53 Rev 5.2.0 Controls and SP 800-53A Rev 5.2.0 Assessment Procedures
Framework

OSFI Guideline B-13 – Technology and Cyber Risk Management

OSFI Guideline B-13 – Technology and Cyber Risk Management imported from the supplied framework package.

1versionOSFI
Framework

OWASP Minimum Viable Secure Product (MVSP)

Open-source baseline of minimum security requirements for software products and services (MVSP v3.0-20231109, CC0).

1versionOWASP / Vendor Security Alliance (MVSP project)
Framework

PCI PIN Security Requirements and Testing Procedures

Prepared outside the target Aurora repo from the verified current official PCI SSC source set, including the ROC, FAQ, ISO Format 4 supplement, Requirement 18-3 key-block supplement, and 17 July 2020 implementation bulletin.

1versionPCI Security Standards Council
Framework

RBI Cyber Security Framework in Banks

Cyber Security Framework in Banks.

1versionCyber Security Framework in Banks
Framework

Regulation (EU) No 910/2014 on electronic identification and trust services (eIDAS)

Regulation (EU) No 910/2014 on electronic identification and trust services (eIDAS) imported from the supplied framework package.

1versionEuropean Union
Framework

SAMA Cyber Resilience Fundamental Requirements (CRFR)

Cyber Resilience Fundamental Requirements (CRFR).

1versionCyber Resilience Fundamental Requirements (CRFR)
Framework

SAMA Cyber Security Framework

SAMA Cyber Security Framework official PDF (Version 1.0, May 2017) with live SAMA rulebook in-force verification.

1versionSAMA Cyber Security Framework official PDF (Version 1.0, May 2017) with live SAMA rulebook in-force verification
Framework

SAMA Minimum Verification Controls

Minimum Verification Controls.

1versionMinimum Verification Controls
Framework

SEBI Cybersecurity and Cyber Resilience Framework (CSCRF)

SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) imported from the supplied framework package.

1versionPackage-provided framework source package
Framework

Secure Controls Framework (SCF)

Secure Controls Framework – SCF 2025.4 workbook.

1versionSecure Controls Framework – SCF 2025.4 workbook
Framework

Secure Controls Framework (SCF) – EU GDPR mapping / STRM

NIST IR 8477-Based Set Theory Relationship Mapping (STRM) – Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR).

1versionNIST IR 8477-Based Set Theory Relationship Mapping (STRM) – Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR)
Framework

SOC 1

AICPA SSAEs – currently effective (operative section AT-C 320, Reporting on an Examination of Controls at a Service Organization Relevant to User Entities' Internal Control Over Financial Reporting).

1versionAICPA SSAEs – currently effective (operative section AT-C 320, Reporting on an Examination of Controls at a Service Organization Relevant to User Entities' Internal Control Over Financial Reporting)
Framework

SOC 2

Aurora Command maps the SOC 2 Trust Services Criteria into one reusable control and evidence workflow so teams can reuse proof across repeat reviews.

1version1AICPA (Trust Services Criteria)
Framework

SOC 3 – SOC for Service Organizations: Trust Services Criteria for General Use Report

SOC 3 – SOC for Service Organizations: Trust Services Criteria for General Use Report imported from the supplied framework package.

1versionAICPA & CIMA
Framework

SOX IT General Controls (ITGC)

SOX IT General Controls (ITGC) requirements organized for repeat reviews and controlled evidence reuse.

1version1Aurora (derived from common SOX ITGC practice; aligned to SEC/PCAOB guidance)
Framework

State Insurance Cybersecurity Regulation (Baseline)

State Insurance Cybersecurity Regulation (Baseline) requirements organized for repeat reviews and controlled evidence reuse.

1version1NAIC / State Insurance Regulators
Framework

StateRAMP Baseline Controls for Authorization (Authorized – Low & Moderate)

StateRAMP Baseline Controls for Authorization (Authorized – Low & Moderate) requirements organized for repeat reviews and controlled evidence reuse.

1versionGovRAMP (formerly StateRAMP)
Framework

SWIFT Customer Security Controls Framework (CSCF)

Swift Customer Security Controls Framework v2026.

1versionSwift Customer Security Controls Framework v2026
Framework

Task Force on Climate-related Financial Disclosures (TCFD)

Task Force on Climate-related Financial Disclosures (TCFD) imported from the supplied framework package.

1versionPackage-provided framework source package
Framework

TISAX (VDA ISA 6.0.3)

Aurora Command maps VDA Information Security Assessment (ISA) questionnaire v6.0.3 requirements (Information Security and Prototype Protection and Data Protection) used by the TISAX assessment scheme into one reusable control and evidence workflow so teams can reuse proof across repeat reviews.

1versionENX Association / VDA
Framework

TX-RAMP Control Baselines 2.0 (Aligned to NIST SP 800-53 Rev. 5)

TX-RAMP Control Baselines 2.0 (Aligned to NIST SP 800-53 Rev. 5) requirements organized for repeat reviews and controlled evidence reuse.

1versionTexas Department of Information Resources (DIR)
Framework

US Data Privacy (USDP) – Core Multi-State Bundle

Internal Aurora bundle of common requirements across major US state comprehensive consumer privacy laws (e.g., Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA).

1version1Aurora
Framework

USA PATRIOT Act – Title III / FinCEN Operational Requirements for Covered Financial Institutions

USA PATRIOT Act – Title III / FinCEN Operational Requirements for Covered Financial Institutions imported from the supplied framework package.

1versionPackage-provided framework source package
Framework

WebTrust for Certification Authorities

WebTrust for Certification Authorities imported from the supplied framework package.

1versionCPA Canada

What customers get

Evidence, Training, and Lifecycle Built into Every Framework

Aurora maps requirements to operational evidence, training programs, and lifecycle signals so your team stays ahead of reviewers, not chasing them.

Automated Evidence Collection

19,287 evidence specifications across all public frameworks. 30 integration sources for automated collection from BC/DR Program Owner, GRC, Operations, Risk Management, and more.
BC/DR Program OwnerGRCOperationsRisk ManagementService OwnersAWSAzureAzure Monitor Logs Pull+22 more

Training Tied to Controls

Training requirements linked to framework controls with module assignments, cadence tracking, and completion evidence. Assessment question banks mapped to reviewer expectations.
Training modules tied to controls
Assessment questions with approved answers
Cadence and completion tracking
Audience-targeted assignments

Proactive Alerts and Remediation

Automated gap detection, deadline tracking, and remediation workflows across every framework. Stay ahead of review windows instead of reacting to them.
Evidence freshness alerts
Automation gap detection
Calendar deadline tracking
Remediation workflows

How it works

Map Once. Reuse Across Every Framework.

Five steps from framework selection to reviewer handoff. Evidence links to controls, controls map to requirements, and every new framework reuses the same proof.

01
Choose Frameworks
Select the frameworks that apply to your next review cycle. Add more as your program grows.
02
Map to Controls
Link external requirements to one control library. Evidence stays reusable across frameworks.
03
Link Evidence
Attach evidence to controls with owners and freshness expectations. Set cadence and reminders.
04
Keep Current
Track approvals, changes, and cadence over time. Automate collection where integrations support it.
05
Share When Asked
Give reviewers structured access through Trust Center. Export organized files on demand.
Aurora control mapping workspace showing one control reused across multiple frameworks and evidence records.

AC-2 Account Management · 4 linked items

SOC 2 CC6.1, ISO A.9.2.1, CMMC AC.L2-3.1.1 stay attached to the same shared control instead of splitting into separate framework trackers.

Control coverage

One Library. Every Domain.

26 control domains spanning 198 controls. Each domain maps to multiple frameworks so evidence collected once covers overlapping requirements.

AI Governance
Access Control
Application Controls
Asset Management
Business Continuity
Change Management
Cloud Security
Configuration Management
Data Protection
Endpoint Security
Governance
HR Security
IT Service Management
Incident Response
Monitoring
Monitoring & Logging
Network Security
Physical Security
Privacy
Quality Management
Risk Management
Secure Software Development
Service Management
Training & Awareness
Vendor Management
Vulnerability Management

What reviewers ask

Different Frameworks, Same Six Questions

Reviewers ask the same six things regardless of framework. Aurora organizes your evidence so you respond consistently every time.

Access Control and Identity

What you can show

Evidence linked with source and timestamp

Governance and Approvals

What you can show

Policy versions, approval history, and decision trails

Incident Readiness

What you can show

Tabletop records, playbooks, and after-action items

Training Completion

What you can show

Assignment and completion records with dates

Vendor and Supplier Risk

What you can show

Due diligence records with follow-ups and decisions

Freshness and Timing

What you can show

Freshness tracking and change history between cycles

Common questions

Framework Questions, Answered Plainly

Clear answers about framework coverage, evidence reuse, and reviewer handoffs.

Can I manage multiple frameworks at once?
Yes. Map multiple frameworks to one control library. Evidence linked to controls is designed to be reusable across overlapping frameworks. Plan limits apply.
Do I have to remap controls for each framework?
No. Mapping is designed to be reused and updated instead of rebuilt. Add new frameworks or review cycles without starting over.
How do you prevent evidence from going stale?
Every evidence item has an owner, a freshness cadence, and automated reminders. Aurora flags what is expiring before reviewers notice.
What happens when a reviewer asks for something new?
Give reviewers structured access through Trust Center, or export organized evidence packages when someone needs offline documents.
Does Aurora guarantee compliance outcomes?
No. Aurora runs and documents compliance work. It does not guarantee certification, audit outcomes, or reviewer decisions.
Live walkthrough
Start with the Frameworks You Need This Quarter
Tell us the frameworks, renewals, or security reviews already on your calendar. We will show how Aurora reuses the same proof across all of them.
15-minute walkthrough. No obligation. See Aurora applied to your workflow with the exact outputs reviewers receive. (No compliance guarantees.)