Multi-framework compliance is the normal condition, not the advanced case. A SaaS
company sells to a bank and needs SOC 2; sells into Europe and needs GDPR; wins a healthcare customer
and meets HIPAA; puts an AI feature in the product and meets the EU AI Act. Nobody planned that
sequence. It arrived one customer at a time.

Why multi-framework compliance is harder than the sum of its parts
Handled separately, each framework brings its own risk assessment, its own policy set, its own
internal audit programme and its own evidence collection. Three frameworks handled that way produce
three parallel systems, three sets of overlapping controls, and a compliance function that spends its
year in audits.
The waste is real and measurable: the same access control is documented three times in three
vocabularies, tested three times by three people, and evidenced three times from the same underlying
logs. Nothing about the security improves.
The alternative is one management system that satisfies several frameworks, with the mapping
maintained explicitly. That is harder to set up and dramatically cheaper to run.
Where frameworks genuinely overlap
Four areas carry most of the reuse. Knowing which they are is what makes a
multi-framework compliance programme tractable.
| Overlap | What can be shared |
|---|---|
| 1. Governance and context | Scope, interested parties, roles, policy hierarchy, management review |
| 2. Risk management | One methodology, one register, framework-specific views on top |
| 3. Core security controls | Access, change, incident, backup, supplier, awareness, logging |
| 4. Assurance machinery | Internal audit, nonconformity and corrective action, document control |
The management system standards make this easier than it used to be. ISO’s harmonized structure
gives ISO 9001, 14001, 27001, 45001, 22301 and the rest a common clause skeleton — context,
leadership, planning, support, operation, performance evaluation, improvement. One set of clause 4 to
10 documents can serve several certifications with framework-specific content slotted in.
What cannot be shared
Being precise here saves a lot of rework. The overlap is in the machinery, not in the substance.
ISO 27001’s Statement of Applicability against its 93 Annex A controls has no equivalent elsewhere.
SOC 2 requires an auditor’s opinion on your description of the system rather than a certificate.
GDPR’s records of processing and lawful basis analysis are legal artefacts, not control documents.
EU MDR’s clinical evaluation belongs to nobody else.
Attempting to force those into a shared template produces a document that satisfies none of the
frameworks it was meant to cover.
The mapping is the deliverable
The artefact that makes multi-framework compliance work is a control mapping: one row per control
you actually operate, with columns for each framework’s reference. ISO 27001 Annex A, SOC 2 criteria,
NIST CSF subcategory, whatever applies.
Two rules keep it honest. Map from your controls outward, not from the framework
inward — mapping inward produces a row for every requirement including the ones you do not
satisfy, which reads as coverage you do not have. And record the evidence source once,
against the control, so three auditors ask for the same artefact rather than three variants of it.
Version drift is the thing that bites
Frameworks move independently, and a mapping is only as good as its last review. NIST CSF 2.0,
published in February 2024, restructured the framework around six functions — adding Govern
— with 22 categories and 106 subcategories, withdrawing a substantial number of CSF 1.1
subcategories in the process. A mapping still pointing at 1.1 identifiers looks perfectly valid until
somebody checks the reference actually exists.
The same applies wherever a standard has moved: ISO 27001’s 2022 Annex A restructure, ISO 14001’s
2026 edition, ISO 9001’s sixth edition due September 2026. Put a review date on the mapping and tie it
to the standards you actually hold, or it will quietly describe a set of frameworks that no longer
exist in that form.
Every framework your clients will ask for next.
The Consultant Package covers all 71 toolkits — 6,000+ documents — spanning information security, privacy, quality, medical devices, food safety, automotive, aerospace, laboratories, financial services and AI governance. Licensed to your whole firm for unlimited client engagements, one-time $1,399, perpetual, with 12 months of updates. Bought individually the same toolkits are $6,889.
Sequencing a multi-framework compliance programme
- Establish the anchor framework first. Usually the broadest management system you
need — frequently ISO 27001 for security, ISO 9001 for quality. It supplies the clause structure
everything else attaches to. - Build the shared spine once. Scope, context, roles, risk methodology, document
control, internal audit, management review, corrective action. - Add frameworks by exception. For each new one, identify only what the spine does
not already satisfy. That delta is the real project, and it is usually far smaller than the framework
document suggests. - Run one internal audit programme. Audit the system once against all applicable
requirements, not once per framework. Auditors accept this; scheduling three separate programmes is a
self-inflicted cost. - Hold one management review. With framework-specific inputs as agenda items rather
than as separate meetings. - Maintain the mapping as a controlled document. With an owner and a review cycle,
like any other.
Do not integrate everything by reflex
Integration has a cost. A single system covering five frameworks means a nonconformity anywhere can
put more than one certificate at risk, and the audit becomes a bigger event with more people in the
room. Where a framework covers a genuinely separate part of the business — a different site, a
different legal entity, a different product line — keeping it separate is often the better call.
Integrate where the controls really are shared, not on principle.
What multi-framework compliance costs, and where the saving is
The saving from integration is real but it is not where people expect. Certification fees barely
move — an auditor still has to audit each scheme, and a combined audit saves some days rather
than most of them. The saving is internal, and it compounds.
It shows up in four places: one risk assessment instead of three, one internal audit programme
instead of three, one document set to maintain through edition changes instead of three, and one
evidence collection burden on the operational teams who actually produce the artefacts. That last one
is the one clients feel most, because it is their engineers and administrators being asked for the
same screenshots repeatedly.
The cost is concentration. An integrated system means a systemic nonconformity is a systemic
problem, and the audit becomes a larger event. That trade is usually worth making, but it should be
made knowingly rather than discovered.
Sequencing when the client is already certified
Most multi-framework compliance work starts from something rather than nothing, which is harder
than a clean build. The existing system has its own vocabulary, its own document numbering and its own
audit history, and ripping it out to impose a tidier structure is rarely justified.
The workable approach is to leave the existing system where it is and add the mapping layer first
— establish what the current controls satisfy in the new framework, then treat only the genuine
delta as the project. That produces an unglamorous programme and a short one, which is generally what
the client is paying for.
Frequently asked questions
What is multi-framework compliance?
Operating one management system that satisfies several standards or regulations at once, with an
explicit mapping between your controls and each framework’s requirements.
Can one internal audit cover several frameworks?
Yes, and it should. Audit the system once against all applicable requirements rather than running a
separate programme per certificate.
Which framework should come first?
The broadest management system you need. It provides the clause structure and the shared documents
that later frameworks attach to.
How much of ISO 27001 carries over to SOC 2?
Most of the control substance; none of the form. SOC 2 is an attestation report on your description of
the system, not a certification, so the evidence and the output differ even where the controls are
identical.
How often should the control mapping be reviewed?
Annually as a minimum, and whenever any mapped framework publishes a new edition. Frameworks move
independently and a stale mapping fails silently.
Where this leaves you
Multi-framework compliance rewards doing the structural work once and resisting the urge to
integrate everything. Pick an anchor framework, build the shared spine, add each new framework by
exception rather than in full, run one audit programme and one management review, and keep the control
mapping as a controlled document with a review date on it. The saving is not in certification fees
— it is in the risk assessment you write once, the audit programme you run once, and the evidence
your operational teams are asked for once instead of three times.
References
- ISO/IEC 27001:2022 — information security management systems, on the ISO catalogue.
- NIST Cybersecurity Framework — CSF 2.0, published February 2024.
More for compliance consultants
- Multi-framework compliance — you are here
- Building a compliance consulting practice
- White label compliance templates
- The virtual CISO model
- Integrated management systems
- ISO 27001 vs SOC 2
All 71 toolkits are licensed for client work in the Consultant Package, or start with the free ISO templates.