Assess once, prove everywhere
One assessment, one set of evidence: a multi-framework posture across 30 frameworks, a costed 36-month roadmap and quick wins to lift your maturity. NIST CSF 2.0, ISO 27001, SOC 2, NIS2, DORA, Quebec Law 25 and more.
30
Frameworks
1,468
Mapped controls
36-month
Costed roadmap
Gap analysis that sleeps in an inbox.
Posture and compliance live in scattered spreadsheets. Audits turn into a fire drill, and nothing stays current between them.
Outcomes your team will feel.
60% less GRC effort
Stop rebuilding evidence for every framework.
SOC 2 Type II in weeks
Audit-ready in a quarter, not a year.
30 frameworks, one effort
Prove once, satisfy many.
Key capabilities
Catalog of 30 frameworks
NIST CSF 2.0, ISO 27001, SOC 2, NIS2, DORA, GDPR, Law 25 and more, kept current by our team.
1,468+ cross-framework mappings
Validate one control and its equivalents are marked across every related framework.
Configurable methodology
Six maturity levels across 33 domains, with Baseline, Evidence-based and Comprehensive assessments.
Assign owners across the team
Split the assessment so each control area has a clear owner and accountability stays intact, while your auditor stays in a read-and-validate role.
From gaps to a costed 36-month roadmap.
Your posture becomes a prioritized, costed 36-month roadmap, plus quick wins you can ship now to raise maturity fast. Defendable to the board, not a static report that ages in a drawer.
Three moments. Three uses.
- Case 1
SaaS publisher (simultaneous multi-framework)
150-employee Quebec B2B SaaS publisher. US clients (SOC 2 Type II required), EU partners (NIS2 entering force), Loi 25 obligation (Quebec clients). Before FortaRisks: 3 separate GRC tools, 3 evidence teams, massive overlaps, 9 months of SOC 2 prep. With FortaRisks: 1 platform, 1 evidence collection, 1,468+ cross-mappings. SOC 2 Type II, NIS2 Article 21, Loi 25 audit-ready in weeks. GRC effort reduction estimated at 60%.
- Case 2
French subsidiary of a Canadian group (EBIOS RM ANSSI)
Canadian manufacturing group, French subsidiary in Lyon, 200 employees. The subsidiary must produce an EBIOS RM risk analysis for its client referencing audit (French industrial group). Before FortaRisks: open-source EBIOS RM Studio, on-site workshop over 5 days, deliverables to reformat for audit. With FortaRisks: the 5 EBIOS RM workshops in the platform, reuse of the asset graph and CTI signals already ingested, deliverables exported in ANSSI format. Workshop preparation reduced to 2 days.
- Case 3
Quebec cooperative bank (DORA via EU subsidiary)
800-employee cooperative bank. French subsidiary entering DORA scope (Digital Operational Resilience Act, applicable January 2025). Subsidiary must prove DORA alignment and management of critical ICT service providers. With FortaRisks: DORA framework mapped to 1,468 SCF controls, 87% automatic alignment via already-validated ISO 27001 controls. DORA-specific gaps identified (critical ICT incident management, resilience testing). Quantified remediation roadmap. Audit-ready in 16 weeks.
What's included
Frameworks
- NIST CSF 2.0
- NIST SP 800-53 rev5
- ISO 27001:2022
- SOC 2
- NIS2
- DORA
- GDPR
- CIS Controls v8
- PCI DSS 4.0.1
- Quebec Law 25
- HIPAA Security Rule
- CPCSC / PCCC (ITSP.10.171)
- IEC 62443
- NERC CIP
- SWIFT CSCF v2025
Coverage
- 1,468 SCF controls
- 1,468+ cross-framework mappings
- 33 control domains
- 6 maturity levels (CMM 0 to 5)
- Bilingual & ANSSI-format export
Posture is not a silo.
All pillars use control maturity. Control maturity is a reference data point. Without it, other pillars decide in a vacuum. With it, they know what's defended and what's not.
Posture → CTI
Actor TTPs are contextualized by your control coverage. If BlackBasta typically exploits MFA absence and your IAM is at CMM 4, the BlackBasta alert on your stack is prioritized low. If your IAM is at CMM 1, it's prioritized high.
Posture → EASM
EASM findings (port 22 exposed, TLS 1.0 active, etc.) are contextualized by expected controls for that asset. A missing MFA control on an SSH-exposed service becomes a critical security finding, not just a technical finding.
Posture → TPRM
Frameworks declared by your third parties (SOC 2, ISO 27001) are confronted with externally observed signs. Automatic drift detection vs declaration.
Posture → AI Risk Engine
Control maturity is the "defense" component of the risk score. Without Posture, the AI doesn't know if the vulnerable asset is defended. It would prioritize a critical CVE on an already well-protected asset at the bottom of the list.
Explore the other pillars.
See your real risk in a 30-minute demo.
A member of our team walks you through FortaRisks on threats relevant to your sector. No chatbot.
Frequently asked questions
How do the 1,468+ cross-framework mappings work?
We use the SCF (Secure Controls Framework) 2026.1.1, a public meta-framework mapping 1,468 controls across the major standards. Validate one control in ISO 27001 and its equivalents in NIS2, DORA and SOC 2 are marked as validated by mapping. Every mapping is documented and auditable, and you can disable automatic mapping if your auditor requires it.
How do you keep frameworks up to date?
Our team monitors regulations continuously and updates the framework content at each official revision. You are notified of changes that affect your posture, and assessments are versioned so you can compare before and after.
What is the difference between the Baseline, Evidence-based and Comprehensive assessments?
Baseline is a quick self-assessment on essential controls (3 to 5 days). Evidence-based collects proof per control (about 2 weeks). Comprehensive evaluates every level with multiple proofs per control (4 to 6 weeks), at ISO 27001 or SOC 2 Type II readiness.
Can I create or customize my own framework?
Yes. You can build custom controls with your own scoring, or extend an official framework with internal controls. Custom frameworks stay isolated to your tenant.