Skip to content
FortaRisks
The whole platform

Assess once, prove across 31 frameworks

A single baseline of 1,534+ SCF controls acts as the pivot language: a control validated once advances every framework that requires it. Each framework shows its real compliance rate, materiality, readiness, gap count and a compliance path costed in person-days.

31

Frameworks covered

1,534+

Pivot SCF controls

person-days

Costed roadmap

Seven audits, seven binders, the same controls asked again under a different number.

Answering framework by framework is the most expensive way to do compliance: the same question comes back seven times, and between two audits nobody can say where the organization actually stands. US automation tools treat compliance as checkboxes; enterprise GRC is out of budget and out of time for a mid-sized company.

Value you can see

Outcomes your team will feel.

  • One effort, several frameworks

    Cross-framework leverage is shown control by control: you know what each hour advances.

  • A costed plan, not a gap list

    Effort in person-days, phases and milestones: the gap analysis becomes a fundable plan.

  • A dossier auditors accept

    Professional export, consistent with the screens, backed by evidence and published policies.

Key capabilities

  • 31 frameworks, including DORA, NIS2 and GDPR

    NIST CSF 2.0, ISO 27001, ISO 42001, ISO 27701, SOC 2, PCI DSS 4.0, CIS v8, NIST SP 800-53, IEC 62443, HIPAA, NERC CIP, SWIFT CSCF, Quebec Law 25, PIPEDA, OSFI B-13, CRA and the rest. Each with its compliance rate, materiality, readiness, gap count and costed compliance path.

  • Comply once, comply many

    This is the heart of the module. A control validated once advances every framework attached to it, and the interface shows the leverage: "this work also advances ISO 27001 and PCI DSS". For a CISO who must satisfy several frameworks with a small team, that is the budget argument.

  • A roadmap costed in person-days

    Every gap becomes an estimated effort, adjusted to the size of your organization, with a realistic floor per control. The plan is ordered into deterministic phases: quick wins of five days or less, critical gaps, what remains to reach the threshold, then beyond. Two milestones stand out: audit-ready, then full compliance. Duration is computed from the pace you can sustain.

  • Exportable auditor dossier and policies as evidence

    A professional dossier is generated server-side, consistent with the screens by construction. Document management ships 25 bilingual policy templates with a full lifecycle, and a published policy automatically becomes evidence for the SCF controls it covers.

A compliance gap becomes a dated action.

Every gap goes to the Action Center with an owner and a deadline, and to the risk register as regulatory risk. The same control that advances three frameworks stays one action, never three.

Three moments where compliance decides

  • Multi-framework

    SaaS vendor: SOC 2 and ISO 27001 in parallel

    A 120-person software vendor must produce a SOC 2 Type II for a large account and targets ISO 27001 the following year. Instead of two programs, a single SCF assessment feeds both frameworks. Cross-framework leverage shows that 60% of the SOC 2 work also advances ISO 27001. The roadmap separates what is needed for the audit threshold from what comes after.

  • Regulatory

    European subsidiary in DORA scope

    A subsidiary must prove DORA alignment. The framework attaches to the SCF baseline, and a large share of alignment comes from ISO 27001 controls already validated. DORA-specific gaps surface by name, costed in person-days, with an audit-ready milestone distinct from full compliance.

  • Evidence

    Hand over a dossier, not a spreadsheet

    At the auditor's request, the dossier is generated: domain-level detail, attached evidence, published policies covering controls, remaining gaps with their effort. It comes from the same source as the screens, so there is no gap between what the team sees and what the auditor reads.

What's included

Frameworks

  • NIST CSF 2.0
  • NIST SP 800-53 rev5
  • ISO 27001:2022
  • ISO 27701
  • ISO 42001
  • SOC 2
  • NIS2
  • DORA
  • GDPR
  • CRA
  • CIS Controls v8
  • PCI DSS 4.0.1
  • Quebec Law 25
  • PIPEDA
  • HIPAA Security Rule
  • CPCSC (ITSP.10.171)
  • OSFI B-13
  • IEC 62443
  • NERC CIP
  • SWIFT CSCF v2025
  • FedRAMP rev5
  • and 10 more
  • 1,534+ pivot SCF controls

Roadmap & dossier

  • Effort costed in person-days, sized to your organization
  • Phases: quick wins, critical gaps, threshold, beyond
  • Audit-ready then full-compliance milestones
  • Duration computed from the pace you sustain
  • Cross-framework leverage shown control by control
  • One plan per profile, never a misleading merged plan
  • Exportable auditor dossier, generated from the same source as the screens

Security policies

  • 25 bilingual policy templates
  • Lifecycle: draft, review, published, archived
  • Import DOCX, Markdown and text
  • A published policy automatically becomes evidence for the controls it covers
  • Review cadence and reminders
  • Activity log per policy

Optional AI enrichment

AI speeds this module up, it does not replace it. Every capability described above works without it. Enrichment is enabled per workspace, and can be turned off without losing a feature.

In compliance, AI targets evidence collection and policy drafting: proposing the evidence expected for a control, extracting metadata from an imported document, suggesting policy text for a human to review. Validating a control stays a human, traceable decision.

Sovereignty: the platform is built and hosted in Canada, beyond the reach of the US CLOUD Act. For AI, you decide whether enrichment is enabled, on which data and within which scope; deployment options are defined with you, according to your residency and confidentiality requirements. No customer data is used to train a model.

Compliance is not paperware. It feeds risk and action.

Isolated compliance produces binders. Here every gap becomes a regulatory risk in the register and a dated action in the Action Center, and every validated control flows back into posture. That is the divide analysts call "Assurance Intelligence": neither the US automation tools nor the European GRC suites unify it in a single product.

  • Compliance → Posture

    Controls validated for a framework feed maturity, and the other way round. One evidence collection serves both readings: your operational level and your regulatory alignment.

  • Compliance → Risk Engine

    A compliance gap enters the register as regulatory risk, distinct from the operational risk posture carries. No composite score mixes the two, because they do not call for the same decisions.

  • Compliance → TPRM

    The 1,534+ SCF controls also serve as the vendor-side reference: questionnaire answers attach to the same controls, which gives NIST, ISO, SOC 2 and GDPR coverage with no extra work.

  • Compliance → Action Center

    A control that advances ISO 27001, SOC 2 and NIST stays one action in the queue, tagged with the number of frameworks it serves. And a "done" is only confirmed at the next assessment, otherwise the action reopens.

30 minutes to know what to fix first.

A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities. No chatbot.

Frequently asked questions

How do 31 frameworks fit in a single assessment?

All of them attach to the Secure Controls Framework 2026.2.2 and its 1,534+ controls, which act as a pivot language. You assess the control once; its equivalents are marked across every linked framework, with a documented, auditable mapping you can disable if your auditor requires it.

Are DORA, NIS2 and GDPR really covered?

Yes, fully, with compliance rate, gaps and a costed compliance path like the others. Their rate is derived from your SCF assessment through crosswalk: that is exactly the "comply once, comply many" mechanism, not an approximation. A dedicated native questionnaire can be added on top for greater methodological depth.

Which compliance target should we aim for?

The target is configurable and defaults to 80%. Readiness reads in three states, ready, at risk or not ready, and the "audit-ready" milestone is distinct from full compliance: most organizations fund the first one first.

What does the auditor dossier contain?

The domain and control level detail, attached evidence, published policies covering controls, and remaining gaps with their effort. It is generated from the same source as the screens, which guarantees the auditor and you read the same number. It requires at least one completed assessment.