One library. Global standards
and national regimes.

Your team picks a country and only the relevant frameworks appear. A unified crosswalk means evidence collected once counts toward many standards at the same time.

🌐 Global
ISO/IEC 27001Information security management ISO/IEC 42001AI management systems PCI DSSPayment card data security SOC 2Trust services criteria NIST CSF 2.0Cybersecurity framework NIST AI RMFAI risk management CMMICapability & process maturity
🇦🇺 Australia

Native coverage of the frameworks Australian organisations are measured against — with engineering depth on the Essential Eight to the tool level (WDAC, Intune, Conditional Access, LAPS/PIM).

Essential EightML1–ML3, ASD’s own profiles ISMAll 1,150 controls, June 2026 release APRA CPS 234Information security prudential standard APRA CPS 230Operational risk management SOCICritical infrastructure & CIRMP Privacy Act13 APPs & the NDB scheme
🇸🇦 Saudi Arabia

The full NCA and SAMA regime, natively — the door-opener for NCA- and SAMA-regulated organisations across the Kingdom and the GCC.

NCA ECCEssential controls NCA CCCCloud controls NCA DCCData controls NCA CSCCCritical systems NCA TCCTelework NCA OSMACCSocial media SAMA CSFCybersecurity SAMA BCMBusiness continuity SAMA ITGFIT governance SAMA CTIThreat intelligence PDPLPersonal Data Protection Law
🇪🇺 Europe
GDPREU data protection NIS2Network & information security DORADigital operational resilience EU AI ActProhibitions, high-risk, GPAI TISAXVDA ISA automotive Cyber EssentialsUK five technical themes
🇦🇪 UAE, Qatar & the wider GCC

The regional regimes a Gulf group is measured against, alongside the Saudi suite — so one platform covers a business operating across the GCC.

UAE IAInformation Assurance Regulation ADHICSAbu Dhabi healthcare information security Qatar NIASNational information assurance v2.1 UAE PDPLPersonal data protection Qatar PDPPLPersonal data privacy
🇺🇸 United States & Asia-Pacific

For groups with US federal, healthcare or listed-company obligations, and for operations across Singapore and New Zealand.

NIST SP 800-171All 110 requirements NIST SP 800-53Curated baseline, importable in full CMMCLevels 1 & 2 HIPAASecurity Rule & breach notification CCPA / CPRACalifornia consumer privacy SOX ITGCIT general controls baseline MAS TRMSingapore technology risk NZISMNew Zealand information security CIS Controls v818 controls CSA CCMCloud controls matrix SWIFT CSCFCustomer security controls
Unified crosswalk

Assess once, satisfy many

Controls overlap far more than most teams realise. GRCorb maps controls to a hub standard, so one piece of evidence can count toward several frameworks at once — and a programme matrix shows exactly which standards each piece of work advances. Where a mapping is a domain-level match rather than a clause-level one, the product tells you, so nothing is claimed that an assessor could not check.

  • Country-aware — only relevant frameworks appear for each client.
  • Evidence reuse works on day one.
Crosswalk · MFA enforcement
1 evidence item
Auto-collected
Counts toward
ISO 27001 · Essential Eight · NCA ECC · SAMA CSF
4 frameworks

Have a framework we don't list yet?

A build-your-own framework studio lets you model any standard — internal, sector-specific or brand new — with the same assessment, evidence and reporting the native frameworks use.

Discuss your frameworks