Custom Frameworks
The Custom Frameworks editor lets you create and maintain compliance frameworks that aren’t shipped out of the box — national transpositions of EU regulations (e.g. country-specific DORA or NIS2 implementations), industry-specific standards (TISAX, CIS Controls, internal policies), or proprietary control sets your organization or auditors require. Custom frameworks behave exactly like built-in ones: they participate in cross-framework control mapping, support evidence automation, and produce audit-ready reports.When to Use Custom Frameworks
- National transposition layers — Add country-specific articles on top of an EU base framework (e.g. German BSI IT-Grundschutz on top of NIS2, Italian or French DORA national transposition)
- Industry standards — TISAX, CIS Controls, NIST SP 800-171, FedRAMP overlays, sector-specific schemes
- Internal control catalogs — Your own corporate security baseline, supplier code of conduct, ESG framework
- Auditor-requested frameworks — Custom control sets your auditor or regulator needs you to track
What You Can Build
A custom framework in Matproof has the same structure as a built-in one:
Each requirement can be linked to one or more controls; controls can be linked to one or more policy templates; and policy/task templates can be reused across multiple custom and built-in frameworks.
Building a Custom Framework
1
Open the Framework Editor
Go to Settings > Custom Frameworks and click Create Framework.
2
Define the framework metadata
Set the name, version, regulator/issuing body, jurisdiction, and a description. Choose whether the framework is mandatory or voluntary in your context.
3
Add requirements
Open the framework and add requirements one by one — each gets an identifier (e.g. “A.5.1”), a title, and a description. You can group requirements into chapters or domains.
4
Attach controls
For each requirement, attach one or more control templates. You can reuse controls already defined in built-in frameworks (so a single control can satisfy ISO 27001 A.5.15 and your custom framework’s section 3.2).
5
Attach policies and tasks
Optionally link policy templates and task templates to controls so the framework drives the right document and evidence creation when adopted.
6
Publish and adopt
Publish the framework version. It now appears in Settings > Frameworks alongside built-in ones — your team adopts it the same way as DORA or NIS2.
Versioning
Custom frameworks are versioned. When the underlying regulation or standard changes, create a new version of the framework — Matproof tracks the diff between versions and lets you migrate adopted controls forward without losing evidence history.API Access
Every custom framework operation is also available via the REST API — useful when you maintain framework definitions in source control or want to sync them from an external system. Endpoints cover frameworks, requirements, controls, policies, and tasks.Limitations
- Custom frameworks count against your plan’s framework limit. See Plans & Pricing. Enterprise plans include unlimited custom frameworks.
- Cross-framework control mapping is automatic for controls you reuse across frameworks; Matproof does not auto-map between custom frameworks based on text similarity (you control the linkage explicitly).
Getting Started
Frameworks Overview
See built-in frameworks before deciding what to build custom
API Reference
Manage custom frameworks programmatically