Any framework. Your anchor.
Pick the framework your program is organized around. Everything else maps to it, requirement by requirement, and partial coverage is shown as partial.
- You already run this in a spreadsheet, a SOC 2 automation tool, or an enterprise GRC suite
- The next customer or regulator wants a second framework and you cannot reuse the work
- You need dated, cited coverage, including partials, not a green dashboard
Security & privacy
AICPA Trust Services Criteria: Type I and Type II readiness.
→FrameworksISO 27001ISO/IEC 27001:2022 ISMS and the 93 Annex A controls.
→FrameworksNIST CSF 2.0Govern, Identify, Protect, Detect, Respond, Recover, with maturity scoring.
→FrameworksCIS Controls18 prioritized safeguards with implementation groups.
→FrameworksGDPREU data protection: records, DPIAs, processors, and breaches.
→FrameworksPCI DSS 4.0The 12 requirements for protecting cardholder data.
→Sector & regional
Security Rule risk analysis for covered entities and business associates.
→FrameworksHITRUSTThe certifiable framework common in healthcare.
→FrameworksDORAEU digital operational resilience for financial entities.
→FrameworksNIS2EU cybersecurity obligations for essential and important entities.
→FrameworksSOX ITGCIT general controls for financial reporting.
→Questions
Which compliance frameworks does TruOps support?
Any. Out of the box: SOC 2, ISO 27001, NIST CSF 2.0, NIST SP 800-53, NIST SP 800-171, CMMC 2.0, HIPAA, PCI DSS, HITRUST, DORA, NIS2, NIST AI RMF, ISO/IEC 42001, GDPR, SOX ITGC, CIS Controls, SCF, and UCF, plus any framework or internal standard you upload.
Do I have to use SCF?
No. You choose the anchor framework; SCF and UCF are optional packs.
Can I switch from another GRC or SOC 2 tool?
Yes. Upload the reports, workbooks, and exports you already have. TruOps sets up the program from them for you to review. Connectors to your cloud, identity, and code tools are read-only.
See it run on your own data.
Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.