Venvera automatically propagates compliance status across overlapping frameworks. When you mark a control as implemented in one framework, equivalent controls in your other enabled frameworks are automatically updated. This eliminates duplicate work and ensures consistency across your compliance programme.

How It Works

Many regulatory frameworks share common requirements. For example, both ISO 27001 (A.8.24) and SOC 2 (CC6.1) require encryption controls, and DORA (ICT-10) covers the same area. Venvera maps these overlaps through 38 control mapping groups, each representing a specific compliance area.

When you update a control status:

You update a control

For example, you mark ISO 27001 control A.8.24 (Encryption) as Implemented.

Venvera finds mapped controls

The system looks up all controls in other enabled frameworks that belong to the same mapping group ("encryption").

Equivalent controls are updated

SOC 2 CC6.1, NIST CSF PR.DS-01, and any active DORA gap assessment question for ICT-10 are automatically marked as implemented (or score 4 for gap assessments).

An audit trail is created

Every propagation is logged with the source framework, target framework, old value, new value, and timestamp.

Propagation Rules

RuleDescription
Forward onlyPropagation never downgrades a control. If a target control is already marked "Implemented", it stays that way even if the source is changed to "Partial".
BidirectionalAny framework can be the source or target. Updating SOC 2 can propagate to ISO 27001, and vice versa.
ThresholdFor control-type frameworks (ISO 27001, SOC 2, NIST CSF), only "Implemented" status triggers propagation. For gap assessment frameworks (DORA, NIS2, GDPR, AI Act), a score of 3 or higher triggers propagation.
Active assessments onlyFor gap assessment frameworks, propagation only targets assessments with "In Progress" status. Completed assessments are not modified.
No loopsIf ISO 27001 propagates to SOC 2, that update does not trigger SOC 2 to propagate back to ISO 27001.

Status Translation

Control-type and gap assessment frameworks use different status systems. Venvera translates between them:

SourceTarget
Control "Implemented"Gap score 4 (Optimised/Managed)
Gap score ≥ 3Control "Implemented"

The "Auto-mapped" Badge

Controls and gap assessment responses that were updated by propagation display a small blue "Auto-mapped from [Framework]" badge. This badge tells you:

  • The control was set automatically, not manually by a user
  • Which source framework triggered the update
  • Which mapping group links the two controls

If you manually change a propagated control's status, the badge is automatically removed — your manual assessment takes precedence.

Framework Activation Backfill

When a platform administrator enables a new framework for your organisation, Venvera automatically backfills compliance status from your existing frameworks. For example, if you already have ISO 27001 controls marked as "Implemented" and you enable SOC 2, the equivalent SOC 2 criteria will be pre-populated with "Implemented" status based on your existing ISO 27001 data.

Supported Mapping Groups

The 38 mapping groups cover all major compliance areas:

AreaFrameworks Covered
Encryption & Key ManagementISO 27001, SOC 2, NIST CSF, DORA, NIS2, GDPR
Access Control & IdentityISO 27001, SOC 2, NIST CSF, DORA, NIS2, GDPR
Incident ManagementISO 27001, SOC 2, NIST CSF, DORA, NIS2, GDPR
Business ContinuityISO 27001, SOC 2, NIST CSF, DORA, NIS2, GDPR
Third-Party & Supply ChainISO 27001, SOC 2, NIST CSF, DORA, NIS2, GDPR
Risk & GovernanceISO 27001, SOC 2, NIST CSF, DORA, NIS2
Vulnerability & Security TestingISO 27001, SOC 2, NIST CSF, DORA, NIS2, GDPR, AI Act
AI-Specific ControlsAI Act, NIST CSF, DORA, NIS2, GDPR
Network & ConfigurationISO 27001, SOC 2, NIST CSF, DORA, NIS2
Logging & MonitoringISO 27001, SOC 2, NIST CSF, DORA, NIS2
Training & AwarenessISO 27001, SOC 2, NIST CSF, DORA, NIS2
💡
To get the most out of cross-framework propagation, start by completing your most mature framework first. Once those controls are marked "Implemented", enable additional frameworks and let Venvera backfill the overlapping controls automatically. This can save significant time when onboarding new frameworks.
ℹ️
Propagation only works for controls that have been seeded in your organisation. If you enable a new control-type framework (ISO 27001, SOC 2, or NIST CSF), visit the Controls page first to seed the controls, then propagation from your existing frameworks will take effect.