Compliance guide

Reuse Controls across frameworks and interpret readiness drivers

Understand how PurpleWASP reuses organisation Controls across ISO 27001, SOC 2, Cyber Essentials, NIST CSF 2.0 and CIS Controls v8.1, and how framework dashboards turn underlying assurance records into readiness drivers.

Compliance Manager, Control Owner, Risk Manager or auditor/reviewer Reference guide Updated 18 September 2026

One organisation Control can support several frameworks

PurpleWASP keeps reusable canonical Controls and organisation-adopted Controls separate from framework requirements. A single organisation Control can therefore support ISO 27001, SOC 2, Cyber Essentials, NIST CSF 2.0 and CIS Controls v8.1 without creating separate framework-specific implementations.

Framework requirement → organisation Control → shared assurance records is the core model.

Framework mapping is not implementation

A mapping means the Control can support a requirement. It does not prove the Control is applicable, fully implemented or effective. Keep these facts separate:

  • framework coverage/mapping;
  • scope and applicability;
  • implementation status;
  • assessment conclusion;
  • evidence and test results;
  • issues, exceptions and remediation.

Use the shared Control assurance context

Control Management is the authoritative operating record for the organisation Control. The Control workspace can connect governance documents, Risks, evidence, assessments, tests/test runs, issues and exceptions around the same Control. Framework pages consume that context rather than maintaining separate copies.

Evidence should be attached to what it proves. A document can support a Control, assessment, test, issue or other governed conclusion, but the existence of a file alone is not an assurance decision.

Readiness scores should lead to Drivers / Improve Score

Where PurpleWASP displays an internal readiness percentage, use the associated drivers to understand the denominator and the records that are reducing the score. The improvement view should point to concrete work—such as an unimplemented Control, missing evidence, an open issue, an incomplete questionnaire item or an unresolved gap—rather than leaving the user with a percentage only.

Framework dashboards are intentionally different because the underlying frameworks ask different questions.

Framework-specific meanings remain distinct

FrameworkPrimary PurpleWASP model
ISO 27001ISMS governance, Clauses 4–10, SoA, operational registers, internal audit, management review and continual improvement.
SOC 2Engagement readiness and audit preparation: scope, criteria, selected Control coverage, evidence, testing, issues/exceptions and audit-readiness decisions.
Cyber Essentials / PlusQuestionnaire/technical-area readiness, remediation and submission preparation; Plus adds technical sampling/testing and assessor evidence preparation.
NIST CSF 2.0Organizational Profiles, Current/Target outcomes, shared Control assurance, gap analysis, improvement planning and Implementation Tiers.
CIS Controls v8.1Implementation Group programme, targeted Safeguards, shared Control coverage/implementation, assurance signals, Drivers / Improve Score and integrity checks.

Good operating practice

  • Adopt or create the organisation Control once and reuse it across framework mappings.
  • Review mapping strength instead of assuming every relationship is full coverage.
  • Keep framework-specific applicability/selection decisions explicit.
  • Use the framework's readiness drivers to find the underlying Control, evidence, test, issue or assessment that needs work.
  • Do not describe an internal PurpleWASP percentage as an external certification, attestation or NIST score.