14 frameworks127 controls
CROSSWALKFramework crosswalk
14 compliance frameworks mapped to ATT&CK. Click a cell to see overlapping controls and shared techniques. Authored by Adam Lundqvist.
Cells coloured by Jaccard similarity of technique sets.
01
| DORA | ISO 27001 | PCI DSS v4 | CIS v8 | NIS2 | OWASP API Top 10 | OWASP LLM Top 10 | OWASP Top 10 | ISO 27701 | EU AI Act | GDPR | NIST CSF | EU CRA | TIBER-EU | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| DORA | 0.40 | 0.36 | 0.48 | 0.54 | 0.23 | 0.31 | 0.33 | 0.29 | 0.26 | 0.45 | 0.46 | 0.19 | ||
| ISO 27001 | 0.40 | 0.33 | 0.53 | 0.44 | 0.30 | 0.29 | 0.34 | 0.28 | 0.25 | 0.40 | 0.36 | 0.14 | ||
| PCI DSS v4 | 0.36 | 0.33 | 0.41 | 0.41 | 0.33 | 0.35 | 0.33 | 0.39 | 0.40 | 0.30 | 0.33 | 0.29 | ||
| CIS v8 | 0.48 | 0.53 | 0.41 | 0.54 | 0.33 | 0.33 | 0.39 | 0.29 | 0.30 | 0.51 | 0.48 | 0.19 | ||
| NIS2 | 0.54 | 0.44 | 0.41 | 0.54 | 0.33 | 0.36 | 0.32 | 0.32 | 0.27 | 0.45 | 0.47 | 0.22 | ||
| OWASP API Top 10 | 0.23 | 0.30 | 0.33 | 0.33 | 0.33 | 0.36 | 0.35 | 0.26 | 0.20 | 0.25 | 0.31 | 0.11 | ||
| OWASP LLM Top 10 | 0.31 | 0.29 | 0.35 | 0.33 | 0.36 | 0.36 | 0.39 | 0.39 | 0.31 | 0.37 | 0.39 | 0.21 | ||
| OWASP Top 10 | 0.33 | 0.34 | 0.33 | 0.39 | 0.32 | 0.35 | 0.39 | 0.28 | 0.27 | 0.31 | 0.35 | 0.17 | ||
| ISO 27701 | 0.29 | 0.28 | 0.39 | 0.29 | 0.32 | 0.26 | 0.39 | 0.28 | 0.30 | 0.38 | 0.26 | 0.29 | ||
| EU AI Act | 0.26 | 0.25 | 0.40 | 0.30 | 0.27 | 0.20 | 0.31 | 0.27 | 0.30 | 0.40 | 0.31 | 0.27 | ||
| GDPR | 0.45 | 0.40 | 0.30 | 0.51 | 0.45 | 0.25 | 0.37 | 0.31 | 0.38 | 0.40 | 0.44 | 0.21 | ||
| NIST CSF | 0.46 | 0.36 | 0.33 | 0.48 | 0.47 | 0.31 | 0.39 | 0.35 | 0.26 | 0.31 | 0.44 | 0.18 | ||
| EU CRA | ||||||||||||||
| TIBER-EU | 0.19 | 0.14 | 0.29 | 0.19 | 0.22 | 0.11 | 0.21 | 0.17 | 0.29 | 0.27 | 0.21 | 0.18 |
GDPR ↔ EU AI Act — 20 shared techniques
Clear ✕| Control A | Control B | Shared | Examples |
|---|---|---|---|
| Art. 33 Notification of a personal data breach to the s… | Art. 10 Data and data governance | 12 | T1190, T1566, T1547, T1068 |
| Art. 33 Notification of a personal data breach to the s… | Art. 15 Accuracy, robustness and cybersecurity | 12 | T1190, T1566, T1547, T1068 |
| Art. 35 Data protection impact assessment | Art. 10 Data and data governance | 11 | T1190, T1566, T1547, T1068 |
| Art. 35 Data protection impact assessment | Art. 15 Accuracy, robustness and cybersecurity | 11 | T1190, T1566, T1547, T1068 |
| Art. 32 GDPR-Art32__Q2.2026 | Art. 10 Data and data governance | 10 | T1078, T1547, T1068, T1027 |
| Art. 32 GDPR-Art32__Q2.2026 | Art. 15 Accuracy, robustness and cybersecurity | 9 | T1078, T1547, T1068, T1027 |
| Art. 5 Principles relating to processing of personal data | Art. 10 Data and data governance | 8 | T1190, T1068, T1027, T1003 |
| Art. 5 Principles relating to processing of personal data | Art. 15 Accuracy, robustness and cybersecurity | 7 | T1190, T1068, T1027, T1003 |
| Art. 34 Communication of a personal data breach to the … | Art. 10 Data and data governance | 6 | T1190, T1068, T1083, T1005 |
| Art. 25 Data protection by design and by default | Art. 10 Data and data governance | 5 | T1003, T1005, T1027, T1041 |
| Art. 25 Data protection by design and by default | Art. 15 Accuracy, robustness and cybersecurity | 5 | T1003, T1005, T1027, T1041 |
| Art. 34 Communication of a personal data breach to the … | Art. 15 Accuracy, robustness and cybersecurity | 5 | T1190, T1068, T1083, T1005 |
| Art. 5 Principles relating to processing of personal data | Art. 12 Record keeping | 5 | T1003, T1041, T1485, T1562.001 |
| Art. 32 GDPR-Art32__Q2.2026 | Art. 12 Record keeping | 4 | T1059, T1003, T1071, T1041 |
| Art. 33 Notification of a personal data breach to the s… | Art. 12 Record keeping | 4 | T1003, T1071, T1041, T1485 |
| Art. 25 Data protection by design and by default | Art. 12 Record keeping | 3 | T1003, T1041, T1071 |
| Art. 34 Communication of a personal data breach to the … | Art. 12 Record keeping | 3 | T1547.001, T1070.004, T1041 |
| Art. 35 Data protection impact assessment | Art. 12 Record keeping | 3 | T1003, T1071, T1041 |
Show non-overlap — GDPR techniques NOT covered by EU AI Act (23)
T1001, T1003.001, T1003.003, T1011, T1012, T1016, T1021, T1021.001, T1027.002, T1033, T1036, T1039, T1046, T1047, T1048, T1053, T1053.005, T1059.003, T1071.001, T1087.001, T1133, T1530, T1566.001
compliance_mappings (127 controls across 14 frameworks). Jaccard computed from the union of applicable_techniques per control. Refreshed hourly via ISR. Curated by Adam Lundqvist, Founder at SQUR.