Research

How much do compliance frameworks actually overlap?

Teams treat each framework as a fresh project. It usually is not. We measured the overlap against our own open control library: 42 common controls mapped to 10 frameworks. The short version is that once you have done one framework, most of the next one is already sitting in your evidence.

The data set

Keel maintains a library of 42 canonical security controls, each pre-mapped ("crosswalked") to the specific clauses it satisfies across 10 frameworks: ISO 27001, SOC 2, NIST CSF, PCI DSS, HIPAA, ISO 9001, ESG Essentials, NIST 800-171, CIS Controls, GDPR. That library is published as an open dataset (CC BY 4.0) on our open source page, so the figures in this report are reproducible. Across those 42 controls there are 177 control-to-framework mappings, which means the average control does real work in 4.2 frameworks at once.

Overlap is the rule, not the exception

The average control maps to 4.2 frameworks, and 22 of the 42 controls (52%) satisfy five or more frameworks at once. At the very top, 2 controls map to 10 of the 10 frameworks in the set: Risk assessment & treatment, Security awareness training. Governance fundamentals are shared almost everywhere; only a handful of controls are truly framework-specific.

Controls carrying the most frameworks

Control Frameworks satisfied
Risk assessment & treatment 10
Security awareness training 10
Third-party / vendor risk management 9
Access control policy 8
User provisioning & deprovisioning 8
Multi-factor authentication 8
Encryption in transit & at rest 8
Logging & monitoring 8

If you have SOC 2, ISO 27001 is mostly done

The clearest way to see the reuse is pairwise: of the controls that satisfy one framework, how many also satisfy another? Reading the table below: of the 25 controls that map to SOC 2, 24 (96%) also satisfy ISO 27001. The two frameworks are near-mirror images at the control level; the remaining work is mapping and evidence, not new controls.

If you have... ...how much of this is already covered Shared controls
SOC 2 ISO 27001 24 of 25 (96%)
SOC 2 PCI DSS 19 of 25 (76%)
SOC 2 NIST CSF 18 of 25 (72%)
SOC 2 HIPAA 15 of 25 (60%)
ISO 27001 HIPAA 15 of 25 (60%)
PCI DSS HIPAA 13 of 19 (68%)

Percentages are of the first framework's control count. Overlap is not symmetric: a smaller framework can be almost fully contained in a larger one while covering less of it in return.

How many controls each framework needs

Coverage in this library, ordered by breadth. Larger frameworks such as ISO 27001 and SOC 2 draw on the most controls; targeted regimes such as GDPR touch fewer, because much of their text is legal rather than technical.

Framework Controls in this library
ISO 27001 25 of 42
SOC 2 25 of 42
PCI DSS 19 of 42
GDPR 19 of 42
NIST CSF 18 of 42
ESG Essentials 17 of 42
CIS Controls 17 of 42
HIPAA 15 of 42
ISO 9001 11 of 42
NIST 800-171 11 of 42

What this means for sequencing

The practical lesson is to build controls once and map them many times. Because the average control serves nearly four frameworks, the marginal cost of a second framework is dominated by mapping and evidence, not by standing up new controls. That is why a crosswalk-native approach matters: the same encryption, access-review, and incident-response controls you implement for SOC 2 are the ones an ISO 27001, PCI DSS, or HIPAA assessor will ask about next.

  • Start with the high-reuse core. The 22 controls that satisfy five or more frameworks are the highest-leverage place to begin.
  • Pick your second framework by overlap. From SOC 2, ISO 27001 is the smallest additional lift; a regime like GDPR shares less because it is largely legal.
  • Map, do not rebuild. Treat the second framework as a mapping exercise over existing evidence. (Explore the mappings in the crosswalk explorer.)

Methodology and limitations

Figures are computed directly from Keel's canonical starter control library of 42 controls, the same data published as the open compliance-crosswalks dataset (CC BY 4.0), so they are fully reproducible. "Overlap" counts a control as covering a framework when the control is crosswalked to at least one clause of that framework. This measures control-level reuse, not clause-for-clause equivalence: satisfying a framework in practice still requires the specific evidence and scoping each assessor expects, and no crosswalk removes the need for an audit. The library covers common security, privacy, quality, and ESG frameworks and grows as more are authored; it is not the complete text of any standard. This is general information, not audit or legal advice.

Comply once, prove everywhere

Keel is the crosswalk-native, AI GRC platform for SMBs: implement a control once and Keel maps it to every framework it satisfies. Start free.

Start free Get the open dataset

Companion report: this analysis deliberately excludes AI governance, which behaves very differently. See how much ISO 42001, the NIST AI RMF, and the EU AI Act overlap — and why your security program barely covers them.

← All research