Skip to main content

Frameworks

A framework is the control catalogue you assess against — NCA ECC, SOC 2, ISO 27001, NIST CSF, SAMA CSF and others.

Compliance → Frameworks

Importing from the library

  1. Browse Library opens the bundled catalogue.
  2. Filter by category or region, or search.
  3. Add imports the framework, with its full control hierarchy, scoring scale and Arabic translations.

The library takes a few seconds to load the first time — it is reading the full control set, not just a list of names.

Importing the same framework twice is safe: the second attempt is recognised and does not duplicate your controls.

Importing your own

Import Framework accepts an Excel workbook. Download Templates gives you the expected shape first — start from the template rather than building a sheet from scratch, because the importer matches on column headings.

How controls are structured

Controls form a tree: domains contain sub-domains contain assessable controls. Only the leaves are assessed; the parents exist to group and report.

Where the control text lives varies by framework

Some catalogues (NCA, NIST) put the full requirement in the control's name. Others (SOC 2, SAMA) leave the name blank and put the text in the description. Both display correctly — if a control looks like it has only a reference number and a paragraph underneath, that is the second style, not missing data.