CRAFT - Control, Risk & Audit Framework Tool
From separate control frameworks in as many spreadsheets to one library in which ISO 27001, NIS2, DORA, GDPR and the AI Act resolve to the same shared controls, and in which you then actually test against them, from audit programme to report.
The challenge
From separate files to one library
Every framework has its own terminology, numbering and scope. CRAFT maps them onto the same shared controls, and lets you work in them directly.
Manual crosswalks age immediately
A manual comparison table between frameworks is out of date the moment a standard is revised.
The comparison lives in the library
A revised standard carries through to every link attached to it; you no longer maintain a table.
The same control tested three times over
Nobody sees the connection between frameworks, so each one gets tested separately.
Overlap visible, test once
Shared controls make the connection explicit: you see what a single assessment has already covered.
The real work starts outside the tool
Audit programme, evidence, response and reporting live in yet more files.
From audit programme to report in one environment
Testing, evidence per control, response, findings and recommendations all continue in the same tool.
This is what it looks like
A selection from CRAFT
Click a thumbnail for that screen, or the image itself for the full-size view.
The library in figures
Verified counts, not estimates
These are the current figures from the CRAFT control library.
frameworks
From ISO 27001 and DORA to the AI Act and national sector baselines, in one library.
controls
Every control searchable, by framework and by domain.
cross-references
Between controls from different frameworks, always with the source wording attached.
What CRAFT offers
Record once, account for it many times over
CRAFT brings frameworks, controls and legislation together in one managed library, and lets you work in it directly.
Shared controls as the bridge
Beneath the frameworks sits a layer of framework-neutral controls that every framework maps onto, complemented by cross-references between frameworks. One assessment can serve several frameworks at once.
Coverage and overlap visible
You see which controls have already been tested elsewhere, where frameworks overlap and where a genuine gap remains, instead of walking through each framework separately.
From standard to report in one environment
Audit programme, assessment and evidence per control, response, findings and recommendations all live in the same tool. No export to Word halfway through the audit.
How it works
From framework to report in five steps
Choose your framework(s)
Select one or more frameworks from the library, for example ISO 27001 together with NIS2 and DORA.
Screen 1Automatic linking
CRAFT maps the selected controls onto the shared controls and exposes the cross-references to other frameworks and legal articles.
Screen 2Coverage and overlap in view
You see which controls have already been tested elsewhere, where frameworks overlap and where a genuine gap remains.
Screen 3Test and substantiate
For each control you record the assessment and the evidence, with a response step for the responsible owner. Anything already tested under another framework does not need doing twice.
Screen 4Findings and report
Findings and recommendations follow from the assessment and come together in the report.
Who it is for
Two starting points, the same library
Do you work with several frameworks? You have to satisfy ISO 27001, NIS2, DORA and the AI Act at the same time. CRAFT shows where those frameworks overlap and where a genuine gap remains, so you test once instead of four times.
Do you carry out audits? You start from a framework and simply want to continue: audit programme, testing with evidence, response, findings and recommendations. That all sits inside CRAFT itself.
Want to start with a single framework? Then the NIS2 Scanner is the quickest way in; it builds on the same library.
Works together with
From control framework to demonstrable control
CRAFT brings ISO 27001, NIS2, DORA, GDPR and dozens of other frameworks together in one library, and lets you test and report in it directly. Curious what that looks like for your organisation?