Skip to main content

Supported frameworks

Matproof supports the following compliance frameworks out of the box:
FrameworkRegionKey audience
DORAEUFinancial institutions, ICT providers
ISO 27001:2022GlobalAny organization
SOC 2 Type IIUS/GlobalSaaS companies, service providers
NIS2EUOperators of essential/important services
GDPREU/EEAAny org processing EU personal data
CSRD/ESRSEULarge companies, listed SMEs
BaFin BAIT/ZAITGermanyGerman banks, insurance companies

Cross-framework mapping

Matproof automatically maps controls across frameworks. When you collect evidence for one framework, it often satisfies requirements in others:
Example:
MFA policy → satisfies:
  - ISO 27001 A.8.5 (Secure authentication)
  - SOC 2 CC6.1 (Logical access controls)
  - DORA Art. 9 (ICT security controls)
  - NIS2 Art. 21 (Authentication measures)
This reduces duplication significantly — especially for organizations pursuing multiple certifications simultaneously.

Adding a framework

  1. Go to Frameworks in the sidebar
  2. Click Add framework
  3. Select your framework and scope
  4. Matproof runs a gap assessment against your existing evidence

Framework structure

Each framework is broken down into:
Framework
  └── Category (e.g., "Access Control")
        └── Control (e.g., "Implement MFA")
              ├── Description
              ├── Guidance
              ├── Evidence requirements
              └── Status (Met / Partial / Not met)

Readiness score

Each framework shows a readiness score — the percentage of controls with sufficient evidence. This gives you a quick view of audit readiness.
Use the readiness score as a leading indicator. Aim for >90% before scheduling an audit.

Audit export

When you’re ready for an audit, export a complete evidence package:
  • Control list with status
  • Evidence documents
  • Policy versions
  • Risk register
  • Vendor register
Exported as a ZIP with folder structure matching the framework’s control categories.