You finish SOC 2. Sales lands a European prospect who wants ISO 27001. It feels like starting over, and it shouldn't, because 60–80% of the controls overlap. The reason it feels like a second project is that most teams re-collect the same evidence under a new framework's labels. A crosswalk fixes that.

What a crosswalk actually is

A crosswalk is a mapping from one control to every framework requirement it satisfies. Implement multi-factor authentication once, and that single control maps to:

  • SOC 2: Logical & Physical Access (CC6)
  • ISO 27001: Annex A access-control requirements
  • PCI DSS: the requirement to secure access to cardholder data
  • HIPAA: the corresponding access-control safeguard

Same control. One implementation. One piece of evidence. Four frameworks satisfied.

Why the overlap is so large

Frameworks are written by different bodies for different audiences, but they're all trying to answer the same question: is this organization managing its risks responsibly? So they converge on the same fundamentals: access control, encryption, logging, backups, vendor management, incident response, training. The wording differs; the underlying control doesn't. Once you see compliance as a set of controls rather than a set of framework checklists, the duplication becomes obvious, and avoidable.

Collect evidence once

The real time sink in any audit is evidence: the screenshots, exports, and logs that prove a control is operating. Tie a piece of evidence to a control, not to a framework, and the crosswalk does the rest. That one artifact now proves every requirement the control maps to. No re-uploading the same access-review export under three different audit folders.

Watch your readiness, per framework, in real time

When your program is a crosswalked control library, "how ready are we?" stops being a guess. Your readiness score is simply the share of in-scope requirements covered by at least one implemented control, and it updates as you work, for every framework at once. Adding a framework becomes a matter of seeing which few requirements aren't already covered, rather than rebuilding from scratch.

How Keel helps

This is the engine at the center of Keel. The controls & crosswalk feature maintains one library mapped across SOC 2, ISO 27001, PCI DSS, HIPAA, and more. Evidence attaches to a control once and counts everywhere. And a one-click starter control set gives you a working, pre-mapped program instead of a blank grid.

The payoff: your second framework, and your fifth, is a fraction of the work of your first.

Start free and map one control library across every framework you need.