Skip to content
FortaRisks
All pillars

Assess once, prove everywhere

One assessment, one set of evidence: a multi-framework posture across 30 frameworks, a costed 36-month roadmap and quick wins to lift your maturity. NIST CSF 2.0, ISO 27001, SOC 2, NIS2, DORA, Quebec Law 25 and more.

30

Frameworks

1,468

Mapped controls

36-month

Costed roadmap

Gap analysis that sleeps in an inbox.

Posture and compliance live in scattered spreadsheets. Audits turn into a fire drill, and nothing stays current between them.

Value you can see

Outcomes your team will feel.

  • 60% less GRC effort

    Stop rebuilding evidence for every framework.

  • SOC 2 Type II in weeks

    Audit-ready in a quarter, not a year.

  • 30 frameworks, one effort

    Prove once, satisfy many.

Key capabilities

  • Catalog of 30 frameworks

    NIST CSF 2.0, ISO 27001, SOC 2, NIS2, DORA, GDPR, Law 25 and more, kept current by our team.

  • 1,468+ cross-framework mappings

    Validate one control and its equivalents are marked across every related framework.

  • Configurable methodology

    Six maturity levels across 33 domains, with Baseline, Evidence-based and Comprehensive assessments.

  • Assign owners across the team

    Split the assessment so each control area has a clear owner and accountability stays intact, while your auditor stays in a read-and-validate role.

From gaps to a costed 36-month roadmap.

Your posture becomes a prioritized, costed 36-month roadmap, plus quick wins you can ship now to raise maturity fast. Defendable to the board, not a static report that ages in a drawer.

Three moments. Three uses.

  • Case 1

    SaaS publisher (simultaneous multi-framework)

    150-employee Quebec B2B SaaS publisher. US clients (SOC 2 Type II required), EU partners (NIS2 entering force), Loi 25 obligation (Quebec clients). Before FortaRisks: 3 separate GRC tools, 3 evidence teams, massive overlaps, 9 months of SOC 2 prep. With FortaRisks: 1 platform, 1 evidence collection, 1,468+ cross-mappings. SOC 2 Type II, NIS2 Article 21, Loi 25 audit-ready in weeks. GRC effort reduction estimated at 60%.

  • Case 2

    French subsidiary of a Canadian group (EBIOS RM ANSSI)

    Canadian manufacturing group, French subsidiary in Lyon, 200 employees. The subsidiary must produce an EBIOS RM risk analysis for its client referencing audit (French industrial group). Before FortaRisks: open-source EBIOS RM Studio, on-site workshop over 5 days, deliverables to reformat for audit. With FortaRisks: the 5 EBIOS RM workshops in the platform, reuse of the asset graph and CTI signals already ingested, deliverables exported in ANSSI format. Workshop preparation reduced to 2 days.

  • Case 3

    Quebec cooperative bank (DORA via EU subsidiary)

    800-employee cooperative bank. French subsidiary entering DORA scope (Digital Operational Resilience Act, applicable January 2025). Subsidiary must prove DORA alignment and management of critical ICT service providers. With FortaRisks: DORA framework mapped to 1,468 SCF controls, 87% automatic alignment via already-validated ISO 27001 controls. DORA-specific gaps identified (critical ICT incident management, resilience testing). Quantified remediation roadmap. Audit-ready in 16 weeks.

What's included

Frameworks

  • NIST CSF 2.0
  • NIST SP 800-53 rev5
  • ISO 27001:2022
  • SOC 2
  • NIS2
  • DORA
  • GDPR
  • CIS Controls v8
  • PCI DSS 4.0.1
  • Quebec Law 25
  • HIPAA Security Rule
  • CPCSC / PCCC (ITSP.10.171)
  • IEC 62443
  • NERC CIP
  • SWIFT CSCF v2025

Coverage

  • 1,468 SCF controls
  • 1,468+ cross-framework mappings
  • 33 control domains
  • 6 maturity levels (CMM 0 to 5)
  • Bilingual & ANSSI-format export

Posture is not a silo.

All pillars use control maturity. Control maturity is a reference data point. Without it, other pillars decide in a vacuum. With it, they know what's defended and what's not.

  • Posture → CTI

    Actor TTPs are contextualized by your control coverage. If BlackBasta typically exploits MFA absence and your IAM is at CMM 4, the BlackBasta alert on your stack is prioritized low. If your IAM is at CMM 1, it's prioritized high.

  • Posture → EASM

    EASM findings (port 22 exposed, TLS 1.0 active, etc.) are contextualized by expected controls for that asset. A missing MFA control on an SSH-exposed service becomes a critical security finding, not just a technical finding.

  • Posture → TPRM

    Frameworks declared by your third parties (SOC 2, ISO 27001) are confronted with externally observed signs. Automatic drift detection vs declaration.

  • Posture → AI Risk Engine

    Control maturity is the "defense" component of the risk score. Without Posture, the AI doesn't know if the vulnerable asset is defended. It would prioritize a critical CVE on an already well-protected asset at the bottom of the list.

See your real risk in a 30-minute demo.

A member of our team walks you through FortaRisks on threats relevant to your sector. No chatbot.

Frequently asked questions

How do the 1,468+ cross-framework mappings work?

We use the SCF (Secure Controls Framework) 2026.1.1, a public meta-framework mapping 1,468 controls across the major standards. Validate one control in ISO 27001 and its equivalents in NIS2, DORA and SOC 2 are marked as validated by mapping. Every mapping is documented and auditable, and you can disable automatic mapping if your auditor requires it.

How do you keep frameworks up to date?

Our team monitors regulations continuously and updates the framework content at each official revision. You are notified of changes that affect your posture, and assessments are versioned so you can compare before and after.

What is the difference between the Baseline, Evidence-based and Comprehensive assessments?

Baseline is a quick self-assessment on essential controls (3 to 5 days). Evidence-based collects proof per control (about 2 weeks). Comprehensive evaluates every level with multiple proofs per control (4 to 6 weeks), at ISO 27001 or SOC 2 Type II readiness.

Can I create or customize my own framework?

Yes. You can build custom controls with your own scoring, or extend an official framework with internal controls. Custom frameworks stay isolated to your tenant.