Skip to main content
Compliance frameworks define the specific requirements that auditors and regulators expect you to meet. SecurAtlas maps your existing security controls to those requirements automatically, so you can pursue multiple certifications without repeating implementation work. This page explains how the unified control model works, which frameworks are available, and how to read your readiness percentages.

The unified control model

Most compliance frameworks share significant overlap in what they require. SecurAtlas takes advantage of this by maintaining a single library of 64 security controls that covers the requirements of all supported frameworks simultaneously. When you implement a control and attach evidence, that work is credited toward every framework requirement that the control maps to.
Adding a framework to your workspace does not create new controls. It maps your existing controls to that framework’s requirements. If you have already implemented relevant controls, your readiness percentage will reflect that immediately.
This means that if you have already implemented access control, incident response, and data protection controls for SOC 2, activating ISO 27001 will show you an immediate readiness baseline — without any additional implementation steps.

Supported frameworks

SecurAtlas supports the following compliance frameworks:
FrameworkDescription
ISO 27001International standard for information security management systems
SOC 2 Type IIAICPA trust service criteria covering security, availability, and confidentiality
NIST CSFNIST Cybersecurity Framework for identifying and managing cyber risk
HIPAAUS healthcare data privacy and security requirements
PCI DSSPayment Card Industry Data Security Standard
CIS ControlsPrioritized security actions from the Center for Internet Security
Additional frameworks may be available depending on your subscription. Contact your account team for the full list.

Adding a framework

To activate a framework for your workspace:
1

Open Settings

Navigate to SettingsCompliance Frameworks in the sidebar.
2

Select a framework

Choose the framework you want to track from the available list and enable it.
3

Review your readiness

SecurAtlas immediately maps your existing controls to the framework’s requirements and displays your current readiness percentage on the Compliance page.

Framework readiness

Your readiness percentage for a framework is calculated as the proportion of the framework’s aligned SecurAtlas controls that are marked implemented out of the total number of aligned controls. For example, if a framework maps to 40 SecurAtlas controls and you have implemented 30 of them, your readiness is 75%. The Compliance page shows for each active framework:
  • Readiness percentage — overall implementation progress
  • Aligned controls count — total controls that contribute to this framework
  • Implemented vs. not started — breakdown of control statuses
When two frameworks differ by 5 or more percentage points, SecurAtlas highlights your best-performing and worst-performing frameworks so you can see where effort will have the most impact.

Next steps

To see how controls map to specific framework requirements and to track your readiness in detail, visit the Compliance guide.