RxForce
Compliance Frameworks

Map your controls once. Satisfy every framework.

RxForce supports mapping to 18 major security, privacy, AI governance, financial, and industry-specific frameworks.

Security

Security

ISO 27001

ISO/IEC 27001

Map your information security management system controls and track certification readiness.

Security

SOC 2

SOC 2

Organize Trust Services Criteria evidence and streamline Type I and Type II audit cycles.

Security

PCI DSS

Payment Card Industry Data Security Standard

Track cardholder data environment controls and simplify Report on Compliance preparation.

Security

NIST CSF

NIST Cybersecurity Framework

Assess maturity across Identify, Protect, Detect, Respond, and Recover functions.

Security

CIS Controls

CIS Critical Security Controls

Benchmark technical safeguards against the CIS implementation groups relevant to your size.

Security

OWASP Top 10

OWASP Top 10

Map application security controls to the most critical web application risk categories.

Security

CSA CCM

Cloud Security Alliance Cloud Controls Matrix

Align cloud service controls to the CSA control matrix for customer and auditor assurance.

Privacy

Privacy

GDPR

General Data Protection Regulation

Track lawful basis, data subject rights, and processing records across every jurisdiction.

Privacy

DPDP Act

Digital Personal Data Protection Act

Manage consent, data principal rights, and breach obligations under India's DPDP Act.

AI Governance

AI Governance

ISO 42001

ISO/IEC 42001

Operate an AI management system aligned to the first international AI governance standard.

AI Governance

NIST AI RMF

NIST AI Risk Management Framework

Govern, map, measure, and manage AI risk across the full model lifecycle.

AI Governance

EU AI Act

EU Artificial Intelligence Act

Classify AI systems by risk tier and track the obligations that follow each classification.

AI Governance

OWASP LLM Top 10

OWASP Top 10 for Large Language Model Applications

Assess LLM-specific risks like prompt injection, data leakage, and insecure output handling.

Financial & Corporate

Financial & Corporate

COBIT

Control Objectives for Information and Related Technologies

Align IT governance objectives with enterprise goals using the COBIT control framework.

Financial & Corporate

COSO

COSO Internal Control – Integrated Framework

Structure internal control activities around the five COSO components auditors expect.

Financial & Corporate

SOX

Sarbanes-Oxley Act

Manage ICFR testing, control narratives, and quarterly certification workflows.

Industry-Specific

Industry-Specific

HIPAA

Health Insurance Portability and Accountability Act

Track administrative, physical, and technical safeguards for protected health information.

Industry-Specific

HITRUST

HITRUST Common Security Framework

Consolidate healthcare security requirements into a single certifiable control set.

How It Works

How framework mapping works

  1. Step 1

    Build one control library

    Define each control once, independent of any single framework.

  2. Step 2

    Map controls to requirements

    RxForce maps each control to every relevant clause across your selected frameworks.

  3. Step 3

    Reuse evidence everywhere

    One piece of evidence can satisfy ISO 27001, SOC 2, and other requirements at once.

Frequently asked questions

Not sure which frameworks you need?

Talk to our team — we'll help you map your compliance obligations to the right frameworks.