The backbone of your compliance programme
Bring NIS2, ISO 27001, GDPR and other regulatory frameworks into a single compliance workspace. Centralise frameworks, controls, policies, evidence and audit activities in one place.
Overview
Map controls once, reuse them across every framework
Import ready-to-use libraries or build custom frameworks from your existing Excel files. Assess each control by applicability, implementation status and description, then connect it to policies, evidence, audits and equivalent controls across other standards.
Map controls once and reuse them across multiple frameworks, reducing duplication and keeping shared requirements aligned whenever updates are made.
Challenge and solution
Each framework lives in its own spreadsheet, so the same requirement is assessed, documented and evidenced separately for NIS2, ISO 27001 and GDPR — with no single view of what is applicable and implemented.
A multi-framework control library with cross-mapping and status propagation: assess a control once, attach policies and evidence once, and see its status reflected in every framework that shares it.
Features
What the Compliance module includes
Controls
Multi-framework library with cross-mapping and status propagation across equivalent controls.
Policies
Versioned bodies, approval workflow, and role or department acknowledgement scopes.
Evidence
Central library with validity, expiry, custom fields and automated artefacts.
Questionnaires
SIG, CAIQ and custom security questionnaires, answered from the same control set.
Audits
Full engagement lifecycle with a separate, signed-invite auditor portal.
Framework import
Ready-to-use NIS2, DORA, ISO 27001 and GDPR libraries, or custom frameworks built from your Excel files.
See ResilientX GRC in action
Compliance module FAQ
Which frameworks are available out of the box?
NIS2, DORA, ISO 27001 and GDPR ship as ready-to-use libraries with cross-mapping between equivalent controls. Custom frameworks can be imported from Excel and mapped to them.
How does status propagation work?
When a control is assessed as implemented and linked to evidence, every equivalent control in other frameworks inherits that status automatically, so shared requirements stay aligned.
Can employees acknowledge policies inside the platform?
Yes. Policies carry versioned bodies and an approval workflow, and acknowledgement can be scoped to roles or departments, with a complete history of who acknowledged which version.