Every framework your organization needs — in one platform.
Twenty-plus frameworks pre-built, mapped and included in every plan. Run HIPAA and NIST CSF simultaneously — collect evidence once, credit both. Don't see one you need? It can be deployed through the same bundle architecture.
Start Free Book a Demo

4.8/5 across 223 reviews on SourceForge · #1 vCISO platform on G2, Summer 2026
Real organizations have overlapping requirements
Most compliance tools are built around one or two frameworks — SOC 2 if you're a SaaS startup, HIPAA if you're healthcare, ISO 27001 if you're enterprise. But the healthcare SaaS company needs SOC 2 and HIPAA at once; the DoD contractor needs CMMC 2.0 and NIST 800-171; the financial-services firm needs SOC 2, NIST CSF and NYS DFS 500. RealCISO handles all of them — simultaneously, in one project, with one evidence set, and without a per-framework fee.
All frameworks. One platform. One evidence set.
Every framework is assessed simultaneously and evidence is mapped automatically across all of them.
NIST Cybersecurity Framework 2.0
Govern, Identify, Protect, Detect, Respond, Recover — mapped to your controls, scored L1–L5, tracked over time. NIST CSF 1.1 remains available. RealCISO's CEO wrote Cybersecurity Risk Management: Mastering the Fundamentals Using the NIST Cybersecurity Framework (Wiley, 2021).
§ Cross-maps to CIS Controls, ISO 27001, SOC 2, HIPAA
SOC 2 (Trust Services Criteria)
Security, availability, processing integrity, confidentiality and privacy. Type I and Type II readiness, control implementation, evidence collection and an audit request list seeded from assessor requirements. Evidence mappings refreshed in August 2026 to align with auditor expectations.
§ Cross-maps to ISO 27001, NIST CSF, HIPAA
ISO/IEC 27001:2022
Annex A controls mapped, maturity scored L1–L5, risk register maintained against the ISMS. Live since July 2026 with mappings refreshed for auditors in August.
§ Cross-maps to SOC 2, NIST CSF
HIPAA Security Rule
Administrative, physical and technical safeguards for covered entities and business associates handling PHI — assessed, gap-analyzed and evidence-tracked.
§ Cross-maps to NIST CSF, SOC 2
CMMC 2.0
Levels 1 and 2 for the DoD supply chain, mapped to NIST SP 800-171 controls automatically: assessment, gap analysis, remediation tracking and evidence in one place.
§ Cross-maps to NIST 800-171, NIST 800-53
NIST SP 800-171 Rev. 3 & NIST 800-53
Controlled Unclassified Information for contractors, with SPRS scoring built in — every control carries its DoD Assessment Methodology weight so your running score matches what you would submit. 800-53 for federal information systems.
§ Cross-maps to CMMC 2.0, NIST CSF, FedRAMP
CIS Controls v8
Eighteen prioritized controls organized into Implementation Groups 1–3 — the most actionable baseline for starting a program and the on-ramp to broader governance.
§ Cross-maps to NIST CSF and all frameworks
PCI-DSS
Payment card data security, including the SAQ-A and P2PE profiles, cross-mapped to the control sets most card-handling businesses also run.
§ Cross-maps to NIST 800-53, SOC 2, NIST CSF
FedRAMP & NIST RMF
Federal cloud authorization and the Risk Management Framework. Contact sales for authorization support specific to your cloud environment and agency scope.
§ Cross-maps to NIST 800-53
NIST AI RMF
Govern, map, measure and manage AI risk alongside your existing security program.
§ Cross-maps to NIST CSF
SEC Cybersecurity Rules
Incident disclosure and annual risk-management, strategy and governance disclosure readiness for public companies and foreign filers.
§ Cross-maps to NIST CSF
GDPR · GLBA · FTC Safeguards · NYS DFS Part 500 · IRS Publication 1075
Sector and privacy regulations pre-built and cross-mapped, so a financial-services or tax-data program does not start from a blank page.
§ Cross-maps to NIST CSF, ISO 27001
Don't see one you need?
Every framework in RealCISO is a bundle of controls, risks and questions on the same architecture — 1,000+ controls pre-baked. Additional frameworks can be deployed on request. Ask us →
One evidence node, every framework
Collect once. Credit everywhere. Expire once, flag everywhere.
One control satisfies multiple frameworks simultaneously. Your AWS CloudTrail configuration satisfies NIST CSF DE.CM-7, SOC 2 CC7.2 and HIPAA §164.312(b) at the same time. In RealCISO one evidence node has edges to all three controls across all three frameworks: collect it once and all three get credit; when it expires, all three are flagged at once. That is what a single-framework tool — or a flat list of controls — cannot do.
Answer once
Shared controls are answered a single time and credited to every selected framework. Framework Health shows each standard's progress separately so you always know which is behind.
Add frameworks without restarting
Add ISO 27001 to a SOC 2 environment and the shared controls are credited immediately; only the controls unique to the new framework need answers.
Maturity across all of them
L1–L5 maturity is scored per control, so the same control's maturity carries into every framework that uses it. How continuous assessment works →
Frameworks FAQ
What compliance frameworks does RealCISO support?
SOC 2, NIST CSF 2.0 and 1.1, ISO/IEC 27001:2022, HIPAA, CMMC 2.0 Levels 1 and 2, NIST SP 800-171 Rev. 3 with SPRS scoring, NIST 800-53, CIS Controls v8, PCI-DSS (including SAQ-A and P2PE), FedRAMP, NIST RMF, NIST AI RMF, SEC cybersecurity rules, IRS Publication 1075, GDPR, FTC Safeguards, GLBA and NYS DFS Part 500 — and additional frameworks can be deployed on request through the same bundle architecture.
Can I assess multiple frameworks at once?
Yes. Select several in one environment and answer each shared control once. Cross-framework control mapping credits the answer and its evidence to every framework it satisfies, and Framework Health reports each standard separately.
How does cross-framework evidence mapping work?
One piece of evidence is a node with edges to every control it satisfies across every framework. Your CloudTrail configuration satisfies NIST CSF DE.CM-7, SOC 2 CC7.2 and HIPAA §164.312(b) at once — collect it once, all three get credit; when it expires, all three are flagged.
Which framework should I start with?
The one a customer, regulator or insurer is asking for. If nobody is asking yet, NIST CSF 2.0 or CIS Controls v8 give a practical baseline you can grow from; SOC 2 when enterprise customers ask; HIPAA for PHI; CMMC 2.0 and NIST 800-171 for the DoD supply chain.
Can I add frameworks later without restarting?
Yes. Add ISO 27001 to an environment that already holds SOC 2 answers and the shared controls are credited immediately; only the controls unique to the new framework need new answers. Nothing is re-asked.
Does RealCISO charge per framework?
No. Every framework is included in every plan — no add-on fees, no per-framework tiers. Vanta and Drata price each additional framework as an upsell; RealCISO environments are multi-framework by design.
Go deeper on any capability
How a framework becomes a running program.
Every framework your organization needs — assessed simultaneously
Start free with any framework, add the rest when you need them, and never pay per framework.
Start Free Book a Demo