14 frameworks127 controls
CROSSWALKFramework crosswalk
14 compliance frameworks mapped to ATT&CK. Click a cell to see overlapping controls and shared techniques. Authored by Adam Lundqvist.
Cells coloured by Jaccard similarity of technique sets.
01
| DORA | ISO 27001 | PCI DSS v4 | CIS v8 | NIS2 | OWASP API Top 10 | OWASP LLM Top 10 | OWASP Top 10 | ISO 27701 | EU AI Act | GDPR | NIST CSF | EU CRA | TIBER-EU | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| DORA | 0.40 | 0.36 | 0.48 | 0.54 | 0.23 | 0.31 | 0.33 | 0.29 | 0.26 | 0.45 | 0.46 | 0.19 | ||
| ISO 27001 | 0.40 | 0.33 | 0.53 | 0.44 | 0.30 | 0.29 | 0.34 | 0.28 | 0.25 | 0.40 | 0.36 | 0.14 | ||
| PCI DSS v4 | 0.36 | 0.33 | 0.41 | 0.41 | 0.33 | 0.35 | 0.33 | 0.39 | 0.40 | 0.30 | 0.33 | 0.29 | ||
| CIS v8 | 0.48 | 0.53 | 0.41 | 0.54 | 0.33 | 0.33 | 0.39 | 0.29 | 0.30 | 0.51 | 0.48 | 0.19 | ||
| NIS2 | 0.54 | 0.44 | 0.41 | 0.54 | 0.33 | 0.36 | 0.32 | 0.32 | 0.27 | 0.45 | 0.47 | 0.22 | ||
| OWASP API Top 10 | 0.23 | 0.30 | 0.33 | 0.33 | 0.33 | 0.36 | 0.35 | 0.26 | 0.20 | 0.25 | 0.31 | 0.11 | ||
| OWASP LLM Top 10 | 0.31 | 0.29 | 0.35 | 0.33 | 0.36 | 0.36 | 0.39 | 0.39 | 0.31 | 0.37 | 0.39 | 0.21 | ||
| OWASP Top 10 | 0.33 | 0.34 | 0.33 | 0.39 | 0.32 | 0.35 | 0.39 | 0.28 | 0.27 | 0.31 | 0.35 | 0.17 | ||
| ISO 27701 | 0.29 | 0.28 | 0.39 | 0.29 | 0.32 | 0.26 | 0.39 | 0.28 | 0.30 | 0.38 | 0.26 | 0.29 | ||
| EU AI Act | 0.26 | 0.25 | 0.40 | 0.30 | 0.27 | 0.20 | 0.31 | 0.27 | 0.30 | 0.40 | 0.31 | 0.27 | ||
| GDPR | 0.45 | 0.40 | 0.30 | 0.51 | 0.45 | 0.25 | 0.37 | 0.31 | 0.38 | 0.40 | 0.44 | 0.21 | ||
| NIST CSF | 0.46 | 0.36 | 0.33 | 0.48 | 0.47 | 0.31 | 0.39 | 0.35 | 0.26 | 0.31 | 0.44 | 0.18 | ||
| EU CRA | ||||||||||||||
| TIBER-EU | 0.19 | 0.14 | 0.29 | 0.19 | 0.22 | 0.11 | 0.21 | 0.17 | 0.29 | 0.27 | 0.21 | 0.18 |
DORA ↔ NIS2 — 41 shared techniques
Clear ✕| Control A | Control B | Shared | Examples |
|---|---|---|---|
| Art. 11 Response and recovery | Art. 21(2)(a) Policies on risk analysis and information syste… | 14 | T1078, T1133, T1547, T1068 |
| Art. 25 Advanced testing of ICT tools, systems and proc… | Art. 21(2)(f) Policies and procedures to assess the effective… | 13 | T1190, T1078, T1547.001, T1068 |
| Art. 11 Response and recovery | Art. 21(2)(b) Incident handling | 12 | T1078, T1133, T1053, T1027 |
| Art. 17 ICT-related incident management process | Art. 21(2)(a) Policies on risk analysis and information syste… | 12 | T1078, T1133, T1068, T1027 |
| Art. 17 ICT-related incident management process | Art. 21(2)(b) Incident handling | 12 | T1078, T1133, T1059, T1053 |
| Art. 24 DORA-Art24__Q2.2026 | Art. 21(2)(a) Policies on risk analysis and information syste… | 12 | T1133, T1078, T1068, T1003 |
| Art. 10 DORA-Art10__Q2.2026 | Art. 21(2)(a) Policies on risk analysis and information syste… | 11 | T1078, T1068, T1027, T1003 |
| Art. 10 DORA-Art10__Q2.2026 | Art. 21(2)(b) Incident handling | 11 | T1078, T1059, T1053, T1027 |
| Art. 13 Learning and evolving | Art. 21(2)(b) Incident handling | 11 | T1046, T1087, T1059, T1071 |
| Art. 24 DORA-Art24__Q2.2026 | Art. 21(2)(b) Incident handling | 11 | T1133, T1078, T1059, T1053 |
| Art. 28 General principles for ICT third-party risk | Art. 21(2)(a) Policies on risk analysis and information syste… | 11 | T1133, T1078, T1068, T1003 |
| Art. 6 DORA-Art6__Q2.2026 | Art. 21(2)(b) Incident handling | 11 | T1078, T1133, T1059, T1053 |
| Art. 10 DORA-Art10__Q2.2026 | Art. 21(2)(d) Supply chain security | 10 | T1068, T1027, T1003, T1087 |
| Art. 11 Response and recovery | Art. 21(2)(d) Supply chain security | 10 | T1547, T1068, T1027, T1003 |
| Art. 7 DORA-Art7__Q2.2026 | Art. 21(2)(f) Policies and procedures to assess the effective… | 10 | T1190, T1068, T1021.001, T1005 |
| Art. 9 DORA-Art9__Q2.2026 | Art. 21(2)(i) Human resources security, access control polici… | 10 | T1003, T1005, T1016, T1018 |
| Art. 12 Backup policies and recovery methods | Art. 21(2)(i) Human resources security, access control polici… | 9 | T1003, T1005, T1016, T1018 |
| Art. 13 Learning and evolving | Art. 21(2)(a) Policies on risk analysis and information syste… | 9 | T1046, T1087, T1071, T1078 |
| Art. 17 ICT-related incident management process | Art. 21(2)(d) Supply chain security | 9 | T1068, T1027, T1003, T1087 |
| Art. 17 ICT-related incident management process | Art. 21(2)(g) Basic cyber hygiene practices and cybersecurity… | 9 | T1078, T1133, T1059, T1027 |
| Art. 24 DORA-Art24__Q2.2026 | Art. 21(2)(e) Security in network and information systems acq… | 9 | T1190, T1078, T1059, T1053 |
| Art. 24 DORA-Art24__Q2.2026 | Art. 21(2)(f) Policies and procedures to assess the effective… | 9 | T1190, T1078, T1068, T1003 |
| Art. 24 DORA-Art24__Q2.2026 | Art. 21(2)(g) Basic cyber hygiene practices and cybersecurity… | 9 | T1133, T1078, T1059, T1003 |
| Art. 25 Advanced testing of ICT tools, systems and proc… | Art. 21(2)(a) Policies on risk analysis and information syste… | 9 | T1078, T1068, T1027, T1003 |
| Art. 25 Advanced testing of ICT tools, systems and proc… | Art. 21(2)(b) Incident handling | 9 | T1078, T1059, T1055, T1027 |
Showing top 25 of 140 control pairs.
Show non-overlap — DORA techniques NOT covered by NIS2 (19)
T1007, T1008, T1009, T1011, T1013, T1020, T1022, T1031, T1036.003, T1036.005, T1048.003, T1057, T1069, T1070, T1082, T1090, T1098.003, T1566.001, T1566.002
compliance_mappings (127 controls across 14 frameworks). Jaccard computed from the union of applicable_techniques per control. Refreshed hourly via ISR. Curated by Adam Lundqvist, Founder at SQUR.