Control library and audit tool

CRAFT - Control, Risk & Audit Framework Tool

From separate control frameworks in as many spreadsheets to one library in which ISO 27001, NIS2, DORA, GDPR and the AI Act resolve to the same shared controls, and in which you then actually test against them, from audit programme to report.

From separate files to one library

Every framework has its own terminology, numbering and scope. CRAFT maps them onto the same shared controls, and lets you work in them directly.

Now

Manual crosswalks age immediately

A manual comparison table between frameworks is out of date the moment a standard is revised.

With CRAFT

The comparison lives in the library

A revised standard carries through to every link attached to it; you no longer maintain a table.

Now

The same control tested three times over

Nobody sees the connection between frameworks, so each one gets tested separately.

With CRAFT

Overlap visible, test once

Shared controls make the connection explicit: you see what a single assessment has already covered.

Now

The real work starts outside the tool

Audit programme, evidence, response and reporting live in yet more files.

With CRAFT

From audit programme to report in one environment

Testing, evidence per control, response, findings and recommendations all continue in the same tool.

A selection from CRAFT

Click a thumbnail for that screen, or the image itself for the full-size view.

Frameworks and legislation with the cross-references between them.1 / 4 shown

Verified counts, not estimates

These are the current figures from the CRAFT control library.

Frameworks52

frameworks

From ISO 27001 and DORA to the AI Act and national sector baselines, in one library.

Controls3,730

controls

Every control searchable, by framework and by domain.

Cross-references4,273

cross-references

Between controls from different frameworks, always with the source wording attached.

Record once, account for it many times over

CRAFT brings frameworks, controls and legislation together in one managed library, and lets you work in it directly.

Shared controls as the bridge

Beneath the frameworks sits a layer of framework-neutral controls that every framework maps onto, complemented by cross-references between frameworks. One assessment can serve several frameworks at once.

Coverage and overlap visible

You see which controls have already been tested elsewhere, where frameworks overlap and where a genuine gap remains, instead of walking through each framework separately.

From standard to report in one environment

Audit programme, assessment and evidence per control, response, findings and recommendations all live in the same tool. No export to Word halfway through the audit.

From framework to report in five steps

1

Choose your framework(s)

Select one or more frameworks from the library, for example ISO 27001 together with NIS2 and DORA.

Screen 1
2

Automatic linking

CRAFT maps the selected controls onto the shared controls and exposes the cross-references to other frameworks and legal articles.

Screen 2
3

Coverage and overlap in view

You see which controls have already been tested elsewhere, where frameworks overlap and where a genuine gap remains.

Screen 3
4

Test and substantiate

For each control you record the assessment and the evidence, with a response step for the responsible owner. Anything already tested under another framework does not need doing twice.

Screen 4
5

Findings and report

Findings and recommendations follow from the assessment and come together in the report.

Two starting points, the same library

Do you work with several frameworks? You have to satisfy ISO 27001, NIS2, DORA and the AI Act at the same time. CRAFT shows where those frameworks overlap and where a genuine gap remains, so you test once instead of four times.

Do you carry out audits? You start from a framework and simply want to continue: audit programme, testing with evidence, response, findings and recommendations. That all sits inside CRAFT itself.

Want to start with a single framework? Then the NIS2 Scanner is the quickest way in; it builds on the same library.

Works together with

NIS2 ScannerGap analysis on the same framework
GRIPMunicipal cybersecurity accountability
AQUAInternal audit self-assessment
Audit SuiteAnnual planning, follow-up, files

From control framework to demonstrable control

CRAFT brings ISO 27001, NIS2, DORA, GDPR and dozens of other frameworks together in one library, and lets you test and report in it directly. Curious what that looks like for your organisation?