Skip to content
ControlVerdict
Catalog

Frameworks

ControlVerdict’s data model is framework-agnostic: a framework declares its own vocabulary for domains, controls and objectives, so adding one is a data change rather than a rewrite. CMMC Level 2 is the current focus.

Vote: which catalog should we quote next?

CMMC Level 2 is the current focus. The schema already supports other frameworks; which one should we quote next? Be the first to vote.

  • CMMC Level 3

    0

    Higher-assurance practices beyond Level 2.

  • FedRAMP

    0

    Cloud authorization baselines built on 800-53.

  • ISO/IEC 27001

    0

    Annex A controls with internationally familiar numbering.

  • NIST SP 800-53

    0

    Families and controls used across federal systems.

  • SOX ITGC

    0

    IT general controls for financial reporting environments.

Sign in to cast or change your vote. One vote per account.

Why seeding is slow on purpose

CMMC Level 3, ISO/IEC 27001:2022 Annex A, NIST SP 800-53 Rev. 5, SOX ITGC, and FedRAMP are all expressible in the existing schema. Each still needs a seed file with accurately quoted control text — which is the slow part, and deliberately so: ControlVerdict never paraphrases normative language. Votes above help us prioritize that work; they are not a shipping commitment.