Crosswalk explorer
The same work, described 21 ways
Compliance frameworks overlap enormously. They describe the same security realities in different words. Keel is built on one crosswalked control library, so a control you implement once counts toward every framework it satisfies. The numbers below aren’t a marketing estimate: each is the count of canonical Keel controls that map to both frameworks, computed straight from our authored crosswalks and guarded by a test in our codebase.
A quick note on what these counts mean: they’re the shared canonical controls in Keel’s starter library (the reusable work), not each framework’s total clause count. See any framework’s full authored control count on its framework page.
Shared controls at a glance
| ISO/IEC 27001 | ESG Essentials | HIPAA | SOX (Sarbanes-Oxley) Section 404 | NIST SP 800-53 | SOC 2 | GDPR | PCI DSS | COPPA | CIS Critical Security Controls | ISO/IEC 42001 | NIST Cybersecurity Framework | ISO 9001 | NIST SP 800-171 | US Employment Law - Federal Baseline | Google Play Families | Apple App Store Kids Category | EU AI Act | NIST AI Risk Management Framework | Amazon Appstore Child-Directed Apps | AI Governance Essentials | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ISO/IEC 27001 | Same framework | 5 | 24 | 24 | 27 | 25 | 17 | 20 | 11 | 17 | 2 | 16 | 8 | 12 | 2 | 0 | 0 | 0 | 0 | 0 | 0 |
| ESG Essentials | 5 | Same framework | 4 | 7 | 3 | 4 | 4 | 3 | 2 | 2 | 0 | 3 | 6 | 1 | 5 | 0 | 0 | 0 | 0 | 0 | 0 |
| HIPAA | 24 | 4 | Same framework | 16 | 23 | 19 | 15 | 16 | 10 | 14 | 1 | 13 | 4 | 11 | 2 | 0 | 0 | 0 | 0 | 0 | 0 |
| SOX (Sarbanes-Oxley) Section 404 | 24 | 7 | 16 | Same framework | 20 | 23 | 14 | 16 | 9 | 13 | 1 | 15 | 6 | 9 | 1 | 0 | 0 | 0 | 0 | 0 | 0 |
| NIST SP 800-53 | 27 | 3 | 23 | 20 | Same framework | 23 | 16 | 20 | 11 | 17 | 1 | 16 | 2 | 12 | 2 | 0 | 0 | 0 | 0 | 0 | 0 |
| SOC 2 | 25 | 4 | 19 | 23 | 23 | Same framework | 16 | 18 | 11 | 15 | 1 | 15 | 4 | 10 | 2 | 0 | 0 | 0 | 0 | 0 | 0 |
| GDPR | 17 | 4 | 15 | 14 | 16 | 16 | Same framework | 13 | 12 | 12 | 0 | 13 | 1 | 9 | 2 | 1 | 2 | 0 | 0 | 0 | 0 |
| PCI DSS | 20 | 3 | 16 | 16 | 20 | 18 | 13 | Same framework | 10 | 16 | 0 | 13 | 1 | 11 | 2 | 0 | 0 | 0 | 0 | 0 | 0 |
| COPPA | 11 | 2 | 10 | 9 | 11 | 11 | 12 | 10 | Same framework | 8 | 1 | 8 | 2 | 7 | 1 | 5 | 6 | 0 | 0 | 3 | 0 |
| CIS Critical Security Controls | 17 | 2 | 14 | 13 | 17 | 15 | 12 | 16 | 8 | Same framework | 0 | 13 | 1 | 11 | 1 | 0 | 0 | 0 | 0 | 0 | 0 |
| ISO/IEC 42001 | 2 | 0 | 1 | 1 | 1 | 1 | 0 | 0 | 1 | 0 | Same framework | 0 | 3 | 0 | 0 | 0 | 0 | 7 | 6 | 0 | 2 |
| NIST Cybersecurity Framework | 16 | 3 | 13 | 15 | 16 | 15 | 13 | 13 | 8 | 13 | 0 | Same framework | 1 | 10 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| ISO 9001 | 8 | 6 | 4 | 6 | 2 | 4 | 1 | 1 | 2 | 1 | 3 | 1 | Same framework | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| NIST SP 800-171 | 12 | 1 | 11 | 9 | 12 | 10 | 9 | 11 | 7 | 11 | 0 | 10 | 0 | Same framework | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| US Employment Law - Federal Baseline | 2 | 5 | 2 | 1 | 2 | 2 | 2 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | Same framework | 0 | 0 | 0 | 0 | 0 | 0 |
| Google Play Families | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | 5 | 0 | 0 | 0 | 0 | 0 | 0 | Same framework | 7 | 0 | 0 | 5 | 0 |
| Apple App Store Kids Category | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | 6 | 0 | 0 | 0 | 0 | 0 | 0 | 7 | Same framework | 0 | 0 | 4 | 0 |
| EU AI Act | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 7 | 0 | 0 | 0 | 0 | 0 | 0 | Same framework | 3 | 0 | 1 |
| NIST AI Risk Management Framework | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | 0 | 0 | 0 | 0 | 0 | 3 | Same framework | 0 | 2 |
| Amazon Appstore Child-Directed Apps | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 3 | 0 | 0 | 0 | 0 | 0 | 0 | 5 | 4 | 0 | 0 | Same framework | 0 |
| AI Governance Essentials | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 2 | 0 | Same framework |
Each cell is the number of canonical Keel controls shared by the two frameworks. Click a number to see exactly which controls, and the clauses they satisfy on each side.
Every overlapping pair
- ISO/IEC 27001 and NIST SP 800-53 27 shared
- ISO/IEC 27001 and SOC 2 25 shared
- HIPAA and ISO/IEC 27001 24 shared
- ISO/IEC 27001 and SOX (Sarbanes-Oxley) Section 404 24 shared
- HIPAA and NIST SP 800-53 23 shared
- NIST SP 800-53 and SOC 2 23 shared
- SOC 2 and SOX (Sarbanes-Oxley) Section 404 23 shared
- ISO/IEC 27001 and PCI DSS 20 shared
- NIST SP 800-53 and PCI DSS 20 shared
- NIST SP 800-53 and SOX (Sarbanes-Oxley) Section 404 20 shared
- HIPAA and SOC 2 19 shared
- PCI DSS and SOC 2 18 shared
- CIS Critical Security Controls and ISO/IEC 27001 17 shared
- CIS Critical Security Controls and NIST SP 800-53 17 shared
- GDPR and ISO/IEC 27001 17 shared
- CIS Critical Security Controls and PCI DSS 16 shared
- GDPR and NIST SP 800-53 16 shared
- GDPR and SOC 2 16 shared
- HIPAA and PCI DSS 16 shared
- HIPAA and SOX (Sarbanes-Oxley) Section 404 16 shared
- ISO/IEC 27001 and NIST Cybersecurity Framework 16 shared
- NIST SP 800-53 and NIST Cybersecurity Framework 16 shared
- PCI DSS and SOX (Sarbanes-Oxley) Section 404 16 shared
- CIS Critical Security Controls and SOC 2 15 shared
- GDPR and HIPAA 15 shared
- NIST Cybersecurity Framework and SOC 2 15 shared
- NIST Cybersecurity Framework and SOX (Sarbanes-Oxley) Section 404 15 shared
- CIS Critical Security Controls and HIPAA 14 shared
- GDPR and SOX (Sarbanes-Oxley) Section 404 14 shared
- CIS Critical Security Controls and NIST Cybersecurity Framework 13 shared
- CIS Critical Security Controls and SOX (Sarbanes-Oxley) Section 404 13 shared
- GDPR and NIST Cybersecurity Framework 13 shared
- GDPR and PCI DSS 13 shared
- HIPAA and NIST Cybersecurity Framework 13 shared
- NIST Cybersecurity Framework and PCI DSS 13 shared
- CIS Critical Security Controls and GDPR 12 shared
- COPPA and GDPR 12 shared
- ISO/IEC 27001 and NIST SP 800-171 12 shared
- NIST SP 800-171 and NIST SP 800-53 12 shared
- CIS Critical Security Controls and NIST SP 800-171 11 shared
- COPPA and ISO/IEC 27001 11 shared
- COPPA and NIST SP 800-53 11 shared
- COPPA and SOC 2 11 shared
- HIPAA and NIST SP 800-171 11 shared
- NIST SP 800-171 and PCI DSS 11 shared
- COPPA and HIPAA 10 shared
- COPPA and PCI DSS 10 shared
- NIST SP 800-171 and NIST Cybersecurity Framework 10 shared
- NIST SP 800-171 and SOC 2 10 shared
- COPPA and SOX (Sarbanes-Oxley) Section 404 9 shared
- GDPR and NIST SP 800-171 9 shared
- NIST SP 800-171 and SOX (Sarbanes-Oxley) Section 404 9 shared
- CIS Critical Security Controls and COPPA 8 shared
- COPPA and NIST Cybersecurity Framework 8 shared
- ISO/IEC 27001 and ISO 9001 8 shared
- Apple App Store Kids Category and Google Play Families 7 shared
- COPPA and NIST SP 800-171 7 shared
- ESG Essentials and SOX (Sarbanes-Oxley) Section 404 7 shared
- EU AI Act and ISO/IEC 42001 7 shared
- Apple App Store Kids Category and COPPA 6 shared
- ESG Essentials and ISO 9001 6 shared
- ISO/IEC 42001 and NIST AI Risk Management Framework 6 shared
- ISO 9001 and SOX (Sarbanes-Oxley) Section 404 6 shared
- Amazon Appstore Child-Directed Apps and Google Play Families 5 shared
- COPPA and Google Play Families 5 shared
- ESG Essentials and ISO/IEC 27001 5 shared
- ESG Essentials and US Employment Law - Federal Baseline 5 shared
- Amazon Appstore Child-Directed Apps and Apple App Store Kids Category 4 shared
- ESG Essentials and GDPR 4 shared
- ESG Essentials and HIPAA 4 shared
- ESG Essentials and SOC 2 4 shared
- HIPAA and ISO 9001 4 shared
- ISO 9001 and SOC 2 4 shared
- Amazon Appstore Child-Directed Apps and COPPA 3 shared
- ESG Essentials and NIST SP 800-53 3 shared
- ESG Essentials and NIST Cybersecurity Framework 3 shared
- ESG Essentials and PCI DSS 3 shared
- EU AI Act and NIST AI Risk Management Framework 3 shared
- ISO/IEC 42001 and ISO 9001 3 shared
- AI Governance Essentials and ISO/IEC 42001 2 shared
- AI Governance Essentials and NIST AI Risk Management Framework 2 shared
- Apple App Store Kids Category and GDPR 2 shared
- CIS Critical Security Controls and ESG Essentials 2 shared
- COPPA and ESG Essentials 2 shared
- COPPA and ISO 9001 2 shared
- GDPR and US Employment Law - Federal Baseline 2 shared
- HIPAA and US Employment Law - Federal Baseline 2 shared
- ISO/IEC 27001 and ISO/IEC 42001 2 shared
- ISO/IEC 27001 and US Employment Law - Federal Baseline 2 shared
- ISO 9001 and NIST SP 800-53 2 shared
- NIST SP 800-53 and US Employment Law - Federal Baseline 2 shared
- PCI DSS and US Employment Law - Federal Baseline 2 shared
- SOC 2 and US Employment Law - Federal Baseline 2 shared
- AI Governance Essentials and EU AI Act 1 shared
- CIS Critical Security Controls and ISO 9001 1 shared
- CIS Critical Security Controls and US Employment Law - Federal Baseline 1 shared
- COPPA and ISO/IEC 42001 1 shared
- COPPA and US Employment Law - Federal Baseline 1 shared
- ESG Essentials and NIST SP 800-171 1 shared
- GDPR and Google Play Families 1 shared
- GDPR and ISO 9001 1 shared
- HIPAA and ISO/IEC 42001 1 shared
- ISO/IEC 42001 and NIST SP 800-53 1 shared
- ISO/IEC 42001 and SOC 2 1 shared
- ISO/IEC 42001 and SOX (Sarbanes-Oxley) Section 404 1 shared
- ISO 9001 and NIST Cybersecurity Framework 1 shared
- ISO 9001 and PCI DSS 1 shared
- SOX (Sarbanes-Oxley) Section 404 and US Employment Law - Federal Baseline 1 shared
No credit card. Watch how much of your next framework your existing controls already cover.