This table shows the 12 compliance areas where CMMC 2.0 and GDPR controls overlap. When you mark a control as implemented in either framework, Venvera automatically propagates the status to the equivalent control in the other.

Compliance AreaCMMC 2.0GDPR
Access ControlAC.L2-3.1.1, AC.L2-3.1.2gdpr-se-05
Least PrivilegeAC.L2-3.1.5, AC.L2-3.1.6gdpr-se-05
Authentication & MFAIA.L2-3.5.3, IA.L2-3.5.4gdpr-se-05
Audit LoggingAU.L2-3.3.1, AU.L2-3.3.2gdpr-se-02
Encryption (Data at Rest)SC.L2-3.13.11, MP.L2-3.8.6gdpr-se-04
Encryption (Data in Transit)SC.L2-3.13.8gdpr-se-04
Media SanitizationMP.L2-3.8.3gdpr-se-04, gdpr-pr-05
Incident ResponseIR.L2-3.6.1, IR.L2-3.6.2gdpr-bn-01
Incident & Breach ReportingIR.L2-3.6.3gdpr-bn-02, gdpr-bn-04
Risk AssessmentRA.L2-3.11.1gdpr-se-02
Security TestingCA.L2-3.12.1, CA.L2-3.12.3gdpr-se-02
Supplier ContractsCA.L2-3.12.4, SC.L2-3.13.6gdpr-cp-04
ℹ️
For details on how propagation works, thresholds, and the auto-mapped badge, see the Cross-Framework Control Propagation overview article.