From a pile of standards to one library that tells you what is still missing.
More than 60 frameworks and 25 laws with their articles, cross-referenced at the level of the individual control. Pick the framework you need to meet and see per requirement what you already cover. Load your own standard and let the library compare it with a recognised one. Built and hosted in the EU.
From now to next
From a stack of PDFs to substantiated coverage
ISO 27001, NIS2, DORA, GDPR: every framework arrives as its own document with its own numbering. The question that matters is how much of framework B you already have with framework A, and where the gap is.
Every framework in its own PDF
Controls, domains and versions sit in separate documents. Every comparison starts from zero.
One catalogue with the controls included
Per framework the controls with description and testing approach, the domain structure, the version history and a frozen version an audit can refer to.
Double work for a second standard
An organisation with ISO 27001 starts again for NIS2 or DORA, although much of it is already in place.
Matrix: what do you already meet?
Choose the framework you need to meet and the frameworks you have. Per requirement you see the best matching control with a coverage percentage and the analysis behind it.
An internal policy fits no package
Your own standard, a client standard or a sector agreement stays outside every comparison.
Your own framework in the library
Load your own framework, visible only to your organisation, and request a cross-reference against a library framework. The result states per criterion what is covered and what is missing.
A percentage without reasoning
A mapping sheet says 60% without saying why. The debate returns at every audit.
Every number shows where it comes from
A cell shows whether coverage comes from a direct analysis of the pair or from a rougher estimate, and unfolds into the sub-requirements with what is covered and what is not.
An empty risk register at the start
A new organisation or a new domain begins with an empty table and a workshop.
Starter sets per sector
Processes, risks and controls for, say, a municipality or a housing association, taken over into the Risk Heat Map with a single confirmation.
This is what it looks like
A selection from Library
Click a thumbnail for that screen, or the image itself for the full-size view.
Frequently asked questions
What you want to know about Library up front
What is Library?
Library is the standards library of the Audirium suite: more than 60 frameworks and 25 laws with their articles, cross-referenced at control level. The application shows the controls per framework, puts frameworks side by side to calculate coverage, holds an organisation's own frameworks and provides starter sets for a new risk register.
Who is Library for?
For security officers, compliance officers, auditors and advisers who work with more than one framework. An organisation that has implemented ISO 27001 and needs to meet NIS2 or DORA sees per requirement what is already covered. Organisations with their own standard or a client standard load it and compare it with a recognised one. The catalogue is readable by every user with access.
What does Library do in practice?
Library shows per framework the controls with description and testing approach, searches literally or by meaning across frameworks, controls and legal articles, calculates in Matrix and Coverage per requirement how much another framework already covers, holds your own frameworks with a cross-reference against the library, and offers starter sets with risks and controls that the Risk Heat Map adopts.
How does Library differ from a mapping sheet?
A mapping sheet gives a percentage. Library adds the reasoning: per control pair an analysis of what covers what and what does not, broken down into sub-requirements, and for every cell whether the number comes from a direct analysis or an estimate. Frameworks have frozen versions an audit can refer to, and the cockpit reports which frameworks or links still lack substantiation.
How does AI work in Library and who decides?
AI does three things: semantic search, the analysis of cross-references between controls, and a proposal for an adapted control where your own framework has a gap. Every analysis and proposal is marked as such, with provenance and timestamp. Adopting, confirming or rejecting is done by an editor or administrator of your organisation; AI writes nothing into your framework by itself.
How are data and hosting handled?
The library itself is the same for every organisation and contains no organisational data. Your own frameworks are stored separately per organisation and are visible to that organisation only. Everything is hosted on servers in the EU. Texts from copyrighted frameworks such as ISO appear as a standard number or our own description, never as the source text.
What Library offers
One source for standards, laws and the links between them
The library is the same for every organisation and is maintained centrally. CRAFT and the other applications of the suite read from it, so a framework means the same thing everywhere.
AI built in, not bolted on
Semantic search, the analysis of cross-references and a proposal for an adapted control come from AI. Every proposal carries its provenance, and an editor decides whether it is adopted.
More than 60 frameworks
ISO 27001, NIS2, DORA, GDPR, the EU AI Act and the IIA Topical Requirements, with their controls. Per framework you see how many controls carry a translation.
The law behind the requirement
25 laws with their articles, linked to the controls that follow from them. Search literally or by meaning across frameworks, controls and legal articles at once.
Cross-references on two levels
Level 1 says that two standards touch, through a shared unified control. Level 2 says why and how far, per control pair, with a coverage percentage substantiated per sub-requirement.
Matrix and Coverage
Framework beside framework, per requirement covered, partly or not. Guided for those who do not know the codes, Expert for the full matrix, and a task list in Word of what is still missing.
Your own frameworks
Internal standards, client standards and sector agreements, visible only to your organisation. With a cross-reference against the library, the result in Excel and a link into your audit in CRAFT.
Starter sets
Generic risks and threats in six categories, plus sector sets with processes, risks and controls. Taken over into the Risk Heat Map after the administrator confirms.
A cockpit on the quality of the material
One score on usability: frameworks without controls, without translation, without a frozen version, cross-references without reasoning. Every shortfall is listed as a gap with a click-through.
How it works
From finding a framework to adopting it in five steps
Find the framework
Browse the catalogue or search literally or by meaning across frameworks, controls and legal articles.
Read the controls
Open a control for its description and testing approach, filter by domain or layer, check the version history.
Put frameworks side by side
In Matrix or Coverage choose what you need to meet and what you have, and read per requirement what is covered and what is missing.
Load your own framework
Add an internal or client standard to your organisation's library and request a cross-reference against a recognised standard.
Adopt
Set a validated cross-reference as a link in your audit in CRAFT, or a starter set in the risk register of the Risk Heat Map.
Want to know how much of the next framework you already meet?
Request a demo or get in touch for more information about Library for your organisation.