This table shows the 26 compliance areas where NIST CSF and DORA controls overlap. When you mark a control as implemented in either framework, Venvera automatically propagates the status to the equivalent control in the other.

Compliance AreaNIST CSFDORA
EncryptionPR.DS-01, PR.DS-02ict-10
Access ControlPR.AA-01ict-11
Identity ManagementPR.AA-01, PR.AA-03ict-11
Authentication & MFAPR.AA-03ict-11
Network SecurityPR.IR-01ict-09
Vulnerability ManagementID.RA-01, PR.PS-01ict-12
Logging & MonitoringDE.CM-01, DE.AE-02ict-14
Incident ManagementRS.MA-01, RS.AN-03inc-01
Incident ClassificationDE.AE-04inc-03, inc-04
Incident ReportingRS.CO-02inc-05, inc-06
Incident Response TeamRS.MA-02inc-09
Post-Incident ReviewRS.AN-08inc-08
Business ContinuityRC.RP-01, RC.RP-03ict-15
Backup & RestorationRC.RP-03ict-16
Crisis ManagementRS.CO-03ict-19
Third-Party Risk ManagementGV.SC-03tpr-01
Supplier Due DiligenceGV.SC-06tpr-03
Supplier ContractsGV.SC-05tpr-06, tpr-07
Supplier MonitoringGV.SC-09tpr-04
Risk AssessmentID.RA-03, ID.RA-05ict-07
Information Security PolicyGV.PO-01ict-08
Security Awareness & TrainingPR.AT-01ict-18
Change ManagementPR.PS-01ict-13
Security TestingID.IM-02res-01
Penetration TestingID.RA-01res-04
Configuration ManagementPR.PS-01ict-04
ℹ️
For details on how propagation works, thresholds, and the auto-mapped badge, see the Cross-Framework Control Propagation overview article.