Get a quote

What's new · Compliance

Answer a control once. Every framework that shares it gets credit.

Compliance programmes waste enormous time re-answering the same question for every framework that happens to ask it slightly differently — MFA enforcement shows up in Cyber Essentials, ISO 27001, GDPR, and half a dozen others, worded differently each time but asking the same thing underneath. Re-gathering the same evidence five separate times isn't rigour. It's duplication.

How the reuse works

786 Cyber maps every framework's controls down to a smaller set of canonical controls — a normalised control taxonomy shared across frameworks — so answering a control once, in one framework's wizard, automatically credits every other framework that maps to the same canonical control.

The Compliance Vault shows this working in practice: per-framework progress rings, section-by-section breakdowns, and an AI-generated gap analysis that tells you what's genuinely missing versus what's just not yet mapped.

Reviewed, never assumed. Cross-mapped equivalents are surfaced for your review — they are never silently marked as met. The mapping finds them; you confirm them.
Compliance Vault — per-framework progress and gap analysis
The Compliance Vault, showing progress per framework. Capture pending.

What it maps to

Every framework 786 Cyber supports — this is the connective tissue across all of them, not a single-framework feature. It's also the same underlying mechanism behind Capability Gap Analysis: evidence reuse is what makes "capabilities, not a thousand controls" possible in the first place.

Frequently asked questions

What is a canonical control?

A normalised control shared across frameworks. Many frameworks ask the same underlying question in different words — MFA enforcement appears in Cyber Essentials, ISO 27001, GDPR and others. 786 Cyber maps each framework control down to a shared canonical control, so answering it once can credit every framework that maps to it.

Does answering one control automatically mark the others as met?

Cross-mapped equivalents are surfaced for your review — they are never silently marked as met. The mapping does the work of finding them; you stay in control of confirming them.

Where do I see this working?

The Compliance Vault shows per-framework progress rings, section-by-section breakdowns, and an AI-generated gap analysis that separates what is genuinely missing from what is simply not yet mapped.

Prove it once, everywhere it counts

Start a 14-day free trial — no card required.

Where to go next

See it priced

The Security Universe and cross-framework mapping are unlimited on every plan.

Pricing →

Talk to us

Book a walkthrough with someone who knows the platform.

Book a walkthrough →