35+ built-in frameworks, ready on day one.
Pre-built control libraries, gap assessments, and evidence requirements for every major framework. Start immediately. No configuration required.
Frameworks for every obligation.
Whether you're managing ISO 27001 or HIPAA, ClearGRC has a pre-built, auditor-reviewed framework ready to go.
The most-used frameworks, ready to deploy.
Every control library is auditor-reviewed, kept current with the latest revision, and cross-mapped to the full framework library.
ISO/IEC 27001:2022
International standard for information security management. 93 controls across 4 themes, pre-mapped and ready for certification audit.
SOC 2 Type II
AICPA Trust Services Criteria covering Security, Availability, Confidentiality, Processing Integrity, and Privacy principles.
NIST CSF 2.0
NIST Cybersecurity Framework with all six functions (Govern, Identify, Protect, Detect, Respond, Recover), fully mapped.
GDPR
Full EU General Data Protection Regulation compliance framework. Article-level control mapping with DSAR workflow integration.
HIPAA
Health Insurance Portability and Accountability Act. Administrative, Physical, and Technical safeguard controls pre-built.
PCI-DSS v4.0
Payment Card Industry Data Security Standard. All 12 requirements with sub-controls, testing procedures, and evidence templates.
ISO/IEC 27701
Privacy Information Management System extension to ISO 27001. Maps to GDPR requirements for a unified privacy-security programme.
NIST SP 800-53
Security and privacy controls for federal information systems. 20 control families with overlay support for FedRAMP and FISMA.
RBI Cybersecurity Framework
Reserve Bank of India's cybersecurity guidelines for regulated entities. Complete control mapping with RBI reporting templates.
And many more, including custom builds.
Cross-framework mapping identifies when one control satisfies multiple frameworks. Implement once, comply everywhere.
ISO 31000:2018
International risk management standard. Principles, framework, and process for enterprise risk management programmes.
CIS Controls v8
Center for Internet Security critical security controls. 18 control groups with implementation groups (IG1, IG2, IG3) pre-configured.
Custom Frameworks
Build any internal or bespoke framework using the drag-and-drop control builder. Import from CSV or map to existing frameworks.
One control. Multiple frameworks.
Pre-built cross-mapping for 30+ framework pairs. One upload to the evidence library satisfies all mapped frameworks simultaneously, with no duplication and no extra effort.
Pre-built cross-mapping
30+ framework pairs already mapped. A control implemented for ISO 27001 is automatically credited against SOC 2, NIST CSF, and PCI-DSS.
Unified evidence library
Upload evidence once and it satisfies all mapped frameworks automatically. No re-uploading, no manual re-tagging.
Full control visibility
See which frameworks each control satisfies at a glance. Understand coverage gaps and where one implementation closes multiple obligations.
Start your first framework assessment.
We'll show you how ClearGRC handles your specific framework obligations in 30 minutes.