Skip to main content

Custom Frameworks

The Custom Frameworks editor lets you create and maintain compliance frameworks that aren’t shipped out of the box — national transpositions of EU regulations (e.g. country-specific DORA or NIS2 implementations), industry-specific standards (TISAX, CIS Controls, internal policies), or proprietary control sets your organization or auditors require. Custom frameworks behave exactly like built-in ones: they participate in cross-framework control mapping, support evidence automation, and produce audit-ready reports.

When to Use Custom Frameworks

  • National transposition layers — Add country-specific articles on top of an EU base framework (e.g. German BSI IT-Grundschutz on top of NIS2, Italian or French DORA national transposition)
  • Industry standards — TISAX, CIS Controls, NIST SP 800-171, FedRAMP overlays, sector-specific schemes
  • Internal control catalogs — Your own corporate security baseline, supplier code of conduct, ESG framework
  • Auditor-requested frameworks — Custom control sets your auditor or regulator needs you to track

What You Can Build

A custom framework in Matproof has the same structure as a built-in one: Each requirement can be linked to one or more controls; controls can be linked to one or more policy templates; and policy/task templates can be reused across multiple custom and built-in frameworks.

Building a Custom Framework

1

Open the Framework Editor

Go to Settings > Custom Frameworks and click Create Framework.
2

Define the framework metadata

Set the name, version, regulator/issuing body, jurisdiction, and a description. Choose whether the framework is mandatory or voluntary in your context.
3

Add requirements

Open the framework and add requirements one by one — each gets an identifier (e.g. “A.5.1”), a title, and a description. You can group requirements into chapters or domains.
4

Attach controls

For each requirement, attach one or more control templates. You can reuse controls already defined in built-in frameworks (so a single control can satisfy ISO 27001 A.5.15 and your custom framework’s section 3.2).
5

Attach policies and tasks

Optionally link policy templates and task templates to controls so the framework drives the right document and evidence creation when adopted.
6

Publish and adopt

Publish the framework version. It now appears in Settings > Frameworks alongside built-in ones — your team adopts it the same way as DORA or NIS2.

Versioning

Custom frameworks are versioned. When the underlying regulation or standard changes, create a new version of the framework — Matproof tracks the diff between versions and lets you migrate adopted controls forward without losing evidence history.

API Access

Every custom framework operation is also available via the REST API — useful when you maintain framework definitions in source control or want to sync them from an external system. Endpoints cover frameworks, requirements, controls, policies, and tasks.

Limitations

  • Custom frameworks count against your plan’s framework limit. See Plans & Pricing. Enterprise plans include unlimited custom frameworks.
  • Cross-framework control mapping is automatic for controls you reuse across frameworks; Matproof does not auto-map between custom frameworks based on text similarity (you control the linkage explicitly).

Getting Started

Frameworks Overview

See built-in frameworks before deciding what to build custom

API Reference

Manage custom frameworks programmatically