14 frameworks127 controls

CROSSWALKFramework crosswalk

14 compliance frameworks mapped to ATT&CK. Click a cell to see overlapping controls and shared techniques. Authored by Adam Lundqvist.

Cells coloured by Jaccard similarity of technique sets.

01
DORAISO 27001PCI DSS v4CIS v8NIS2OWASP API Top 10OWASP LLM Top 10OWASP Top 10ISO 27701EU AI ActGDPRNIST CSFEU CRATIBER-EU
DORA
0.400.360.480.540.230.310.330.290.260.450.460.19
ISO 270010.40
0.330.530.440.300.290.340.280.250.400.360.14
PCI DSS v40.360.33
0.410.410.330.350.330.390.400.300.330.29
CIS v80.480.530.41
0.540.330.330.390.290.300.510.480.19
NIS20.540.440.410.54
0.330.360.320.320.270.450.470.22
OWASP API Top 100.230.300.330.330.33
0.360.350.260.200.250.310.11
OWASP LLM Top 100.310.290.350.330.360.36
0.390.390.310.370.390.21
OWASP Top 100.330.340.330.390.320.350.39
0.280.270.310.350.17
ISO 277010.290.280.390.290.320.260.390.28
0.300.380.260.29
EU AI Act0.260.250.400.300.270.200.310.270.30
0.400.310.27
GDPR0.450.400.300.510.450.250.370.310.380.40
0.440.21
NIST CSF0.460.360.330.480.470.310.390.350.260.310.44
0.18
EU CRA
TIBER-EU0.190.140.290.190.220.110.210.170.290.270.210.18

ISO 27701GDPR 20 shared techniques

Clear ✕
Control AControl BSharedExamples
A.7.5.1
Identify basis for PII transfer between jurisdi…
Art. 33
Notification of a personal data breach to the s…
10T1566, T1003, T1005, T1041
A.7.4.1
Limit collection
Art. 35
Data protection impact assessment
9T1005, T1041, T1083, T1566
A.7.5.1
Identify basis for PII transfer between jurisdi…
Art. 32
GDPR-Art32__Q2.2026
9T1078, T1003, T1005, T1041
A.7.5.1
Identify basis for PII transfer between jurisdi…
Art. 35
Data protection impact assessment
9T1566, T1003, T1005, T1039
A.7.4.1
Limit collection
Art. 33
Notification of a personal data breach to the s…
8T1005, T1041, T1083, T1566
A.7.4.1
Limit collection
Art. 5
Principles relating to processing of personal data
8T1005, T1041, T1071.001, T1530
A.7.4.5
PII de-identification and deletion at the end o…
Art. 32
GDPR-Art32__Q2.2026
8T1083, T1005, T1041, T1078
A.7.5.1
Identify basis for PII transfer between jurisdi…
Art. 5
Principles relating to processing of personal data
7T1003, T1005, T1041, T1485
A.7.4.1
Limit collection
Art. 32
GDPR-Art32__Q2.2026
6T1005, T1041, T1083, T1003
A.7.4.1
Limit collection
Art. 34
Communication of a personal data breach to the …
6T1005, T1041, T1083, T1190
A.7.4.5
PII de-identification and deletion at the end o…
Art. 25
Data protection by design and by default
6T1005, T1041, T1048, T1071
A.7.4.5
PII de-identification and deletion at the end o…
Art. 33
Notification of a personal data breach to the s…
6T1083, T1005, T1041, T1071
A.7.4.5
PII de-identification and deletion at the end o…
Art. 35
Data protection impact assessment
6T1083, T1005, T1041, T1071
A.7.5.1
Identify basis for PII transfer between jurisdi…
Art. 25
Data protection by design and by default
6T1003, T1005, T1041, T1027
A.7.4.5
PII de-identification and deletion at the end o…
Art. 5
Principles relating to processing of personal data
4T1005, T1041, T1530, T1003
A.7.5.1
Identify basis for PII transfer between jurisdi…
Art. 34
Communication of a personal data breach to the …
4T1005, T1041, T1486, T1068
A.7.4.1
Limit collection
Art. 25
Data protection by design and by default
3T1005, T1041, T1003
A.7.4.5
PII de-identification and deletion at the end o…
Art. 34
Communication of a personal data breach to the …
3T1083, T1005, T1041
Show non-overlap — ISO 27701 techniques NOT covered by GDPR (9)
T1018, T1025, T1082, T1119, T1552, T1555, T1560, T1567, T1573
Sourced from cs-graph compliance_mappings (127 controls across 14 frameworks). Jaccard computed from the union of applicable_techniques per control. Refreshed hourly via ISR. Curated by Adam Lundqvist, Founder at SQUR.
Framework crosswalk — Jaccard similarity grid | SQUR Knowledge Base