Multi-framework control tracker · internal self-assessment
ISO/IEC 27001:2022NIST CSF 2.0SOC 2 · Type I & II
All changes saved
This is a self-assessment template — every control starts Not Started until you record a real status. ISO/IEC 27001:2022 Annex A structure and NIST CSF 2.0 subcategories (the latter sourced directly from NIST's own CSF 2.0 Core publication) are reproduced from public guidance; SOC 2 uses the AICPA Trust Services Criteria, cross-checked across independent references. Confirm exact wording against your licensed ISO text and the AICPA TSC before citing this dashboard in front of an auditor. SOC 2 Type I and Type II track the same Trust Services Criteria — Type I is whether a control is designed and in place, Type II is whether it operated effectively over your review period — so they're tracked as two status columns on one shared list, not two separate control sets. Nothing here is a conformity or opinion determination — that's your auditor's call.
Click any card above to jump into that framework's control list. Each framework tracks its own target date and readiness independently — set them from within each tab.