This table shows the 18 compliance areas where CMMC 2.0 and DORA controls overlap. When you mark a control as implemented in either framework, Venvera automatically propagates the status to the equivalent control in the other.

Compliance AreaCMMC 2.0DORA
Access ControlAC.L2-3.1.1, AC.L2-3.1.2ict-11
Least PrivilegeAC.L2-3.1.5, AC.L2-3.1.6ict-11
Remote AccessAC.L2-3.1.12, AC.L2-3.1.14ict-09, ict-11
Authentication & MFAIA.L2-3.5.3, IA.L2-3.5.4ict-11
Security Awareness & TrainingAT.L2-3.2.1, AT.L2-3.2.2ict-18
Audit LoggingAU.L2-3.3.1, AU.L2-3.3.2ict-14
Configuration ManagementCM.L2-3.4.1, CM.L2-3.4.2ict-04
Change ControlCM.L2-3.4.3, CM.L2-3.4.4ict-13
Incident ResponseIR.L2-3.6.1, IR.L2-3.6.2inc-01
Incident ReportingIR.L2-3.6.3inc-05, inc-06
Vulnerability ManagementRA.L2-3.11.2, RA.L2-3.11.3ict-12
Risk AssessmentRA.L2-3.11.1ict-07
Security Assessment & TestingCA.L2-3.12.1, CA.L2-3.12.3res-01
EncryptionSC.L2-3.13.8, SC.L2-3.13.11ict-10
Network SecuritySC.L2-3.13.1, SC.L2-3.13.5ict-09
Business ContinuitySC.L2-3.13.13ict-15
Information Security PolicyCA.L2-3.12.4ict-08
Third-Party Risk ManagementCA.L2-3.12.4, SC.L2-3.13.6tpr-01
ℹ️
For details on how propagation works, thresholds, and the auto-mapped badge, see the Cross-Framework Control Propagation overview article.