Frameworks
One chain.
Every framework.
34 regimes across EU, UK, US federal, global standards, sector regimes, the Finnish sovereign set, APAC and LatAm, and pharma serialisation. Every one, at every paid tier, with no per-framework fee.
The Finnish sovereign set
No US compliance platform supports any of these three. For a Finnish public-sector supplier that is not a feature comparison — it is the difference between having tooling and not having it.
Julkri
The Finnish information-security criteria for public administration.
fi-julkri
Katakri
The national security auditing criteria used in assessments for classified information.
fi-katakri
Pitukri
The criteria for assessing information security in cloud services.
fi-pitukri
To be precise about what that means: we support the frameworks. We are not accredited by, endorsed by, or acting on behalf of any Finnish authority, and we would not claim otherwise.
Everything we render
Five formats each — PDF, HTML, Markdown, JSON and OSCAL.
What a framework mapping is, and is not
A mapping is a document: it says which evidence answers which control. That is ordinary work, and it is why adding a framework costs us a document rather than an engineering project — which is why we never charge you for one.
What the mapping is not is the evidence. The evidence is the chain underneath it, and that is the same chain regardless of which framework you render against. If a mapping is wrong, you can see that it is wrong. If evidence is unverifiable, you cannot see anything at all.