← All Tools
Control Mapper: CSF ↔ ISO ↔ DORA
Search across NIST CSF 2.0 outcomes, ISO/IEC 27001:2022 Annex A controls, and DORA articles. Filter by function or theme, click any row to expand, export as CSV.
100% client-side. The mapping dataset is loaded in your browser. No queries, telemetry, or data leave your device. Editorial note: this is a summary-level cross-walk intended to accelerate analyst work — always validate against the original framework text before claiming evidence.
| CSF 2.0 | CSF outcome | ISO 27001:2022 Annex A | DORA articles |
|---|
How to use the mapping
- Start from the framework you have (e.g. ISO 27001) and find the row(s) where it matches your control objective.
- Use the linked controls / outcomes / articles as candidate evidence. Cross-check the original framework wording — mappings are summary-level, not contractual.
- Where multiple controls map, treat the relationship as "informs" rather than "satisfies".
- Export filtered rows to CSV to seed your evidence-mapping spreadsheet for ISO 27001 internal audit, DORA Article 6 ICT risk framework, or NIS2 Article 21 measures.
About the Subcategory Browser
This browser uses the canonical NIST CSF 2.0 taxonomy from CSWP 29 (6 Functions, 22 Categories, 106 Subcategories). Each subcategory shows its full text. Where the cross-walk table contains an ISO 27001:2022 / DORA mapping for that subcategory, the corresponding chips appear below.