Skip to content
Frameworks / Reference Library

14 frameworks. 2,650 controls. Refreshed within 48 hours of any regulator update.

Manual Ends maintains the most complete, freshest-mapped compliance control library on the market — pre-built for SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, NIST CSF 2.0, and the EU AI Act high-risk tier, with cross-framework mappings and a 48-hour regulator-update SLA your auditors can verify.

Founded 2019 · San Francisco Coverage 1,840+ companies · 38 countries Backed by Atlassian Ventures · Bessemer · First Round
control-library / frameworks.index v2025.04 · 2,650 controls
Framework Controls Tier Updated
SOC 2 (TSC 2017, rev. 2022) 412 Core 47 min ago
ISO/IEC 27001:2022 386 Core 2 h ago
HIPAA Security Rule 198 Core 6 h ago
GDPR (Reg. 2016/679) 274 Core 1 d ago
PCI DSS v4.0 264 Core 12 h ago
NIST CSF 2.0 218 Mapped 3 h ago
EU AI Act — high-risk tier 156 Mapped 4 h ago
+ 7 more frameworks 742 Mapped live
Last regulator sync EU AI Act Implementing Reg. 2024/1689 · pulled 4 h ago
A live slice of the Control Library — control counts, tier, and last-updated timestamp per framework.
14 Supported frameworks SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, NIST CSF 2.0, EU AI Act high-risk, and 7 more
2,650 Pre-mapped controls One canonical library, deduplicated across every framework you operate in
≤ 48 h Regulator-update SLA Every framework refreshed within 48 hours of an issued regulator update — audit trail included
142 Evidence Sync integrations AWS, GitHub, Workday, Okta, Jira, NetSuite and more — read-only APIs, no agents
02 — The Catalog

Every framework we ship, indexed by control count, tier, and freshness.

Fourteen frameworks in production today — including the four most-searched by North American mid-market and enterprise compliance teams, plus the EU AI Act high-risk tier and seven adjacent standards. Click any tile for the control map, evidence workflow, and last regulator sync.

F-02 Core · Tier 1

ISO/IEC 27001:2022

93 Annex A controls reorganized into 4 themes (Organizational, People, Physical, Technological), plus Clauses 4–10.

Controls
386
Updated
2 h ago
Statement of Applicability
Auto-generated
F-03 Core · Tier 1

HIPAA Security Rule

Administrative, physical, and technical safeguards (§164.308–§164.312), plus the 2024 NPRM amendments and the Privacy Rule.

Controls
198
Updated
6 h ago
BAA workflow
Included
F-04 Core · Tier 1

GDPR (Reg. 2016/679)

Articles 5–49 mapped to operational controls, including DPIA workflows, ROPA, and cross-border transfer mechanisms (SCCs, IDTA).

Controls
274
Updated
1 d ago
DPDPA / UK GDPR
Included
F-05 Core · Tier 1

PCI DSS v4.0

All 12 requirements, including the 64 new v4.0 controls and the future-dated v4.0.1 items. SAQ routing logic built in.

Controls
264
Updated
12 h ago
ROC support
Auditor Workspace
F-06 Mapped · Tier 2

NIST CSF 2.0

Function → Category → Subcategory hierarchy, including the new Govern function added in CSF 2.0 (Feb 2024).

Controls
218
Updated
3 h ago
Crosswalk
800-53 r5, CSF 1.1
F-07 Mapped · Tier 2

EU AI Act — high-risk tier

Articles 6–15 operationalized for high-risk AI systems, including Annex III use cases and the 2024/1689 implementing regulation.

Controls
156
Updated
4 h ago
Conformity assessment
Workflow ready
F-08 Mapped · Tier 3

NIST SP 800-53 Rev. 5

Full 1,000+ control catalog with FedRAMP baseline overlays (Low, Moderate, High) — used for US federal and federal-adjacent workloads.

Controls
1,012
Updated
1 d ago
FedRAMP
Mod / High baselines
F-09 Mapped · Tier 3

ISO/IEC 27701:2019

Privacy information management extension to ISO 27001 — PIMS controls mapped against GDPR, CCPA, and LGPD.

Controls
174
Updated
8 h ago
Extension
ISO 27001 required
F-10 Mapped · Tier 3

CMMC 2.0

Cybersecurity Maturity Model Certification levels 1–3, mapped to NIST SP 800-171 for CUI handling across the DIB.

Controls
110 (L1) / 110 (L2) / 24 (L3)
Updated
2 d ago
C3PAO scoping
Built in
F-11 Mapped · Tier 3

CCPA / CPRA

California Consumer Privacy Act as amended by the California Privacy Rights Act — including the 2024 ADMT regulations.

Controls
88
Updated
1 d ago
DSAR workflow
Included
F-12 Mapped · Tier 3

HITRUST CSF v11

Healthcare-focused certification, inheriting from NIST, HIPAA, and ISO. Maturity-level PRISMA-based scoring.

Controls
156
Updated
18 h ago
Inheritance
SOC 2, ISO 27001
F-13 Mapped · Tier 3

SOX ITGC

Sarbanes-Oxley IT general controls covering access, change management, and operations across financial-reporting systems.

Controls
62
Updated
4 d ago
Walkthroughs
Auto-generated
F-14 On request

Don't see your framework?

Upload a custom standard, map it against the existing 2,650-control library, and ship a private tenant in 14 days.

Request a framework
03 — Deep Dives

Four flagship frameworks, dissected — control counts, common failure modes, and the evidence hooks that change the audit math.

SOC 2, ISO 27001, HIPAA, and GDPR account for ~84% of every audit Manual Ends has supported in 2024. Here is exactly what each program ships, where teams typically break, and which one-click evidence workflows compress a 77-day audit into 11.

F-01 · Flagship

SOC 2 — Type I in 14 days, Type II on the first attempt

412 controls across Security, Availability, Processing Integrity, Confidentiality, and Privacy. The Type II 96% first-time pass rate holds across 612 audits in 2024 — versus the 38% industry baseline — because every evidence hook is pre-wired before the audit window opens.

  • One-click evidence — change-management tickets from Jira, deployment logs from GitHub Actions, MDM exports from Jamf, and access reviews from Okta, all pulled on a schedule.
  • Auditor Workspace — your external assessor requests, reviews, and signs off inside a dedicated portal; no more zipping evidence over email.
  • Exception flow — a failed control triggers a remediation ticket with an owner, due date, and re-test loop built in.
9 days Median SOC 2 Type II audit cycle (vs. 11 weeks industry baseline)
SOC 2 control table mockup with evidence status and audit workspace timeline.
F-02 · Flagship

ISO 27001:2022 — Statement of Applicability in a single click

93 Annex A controls mapped to the 2022 reorganization (Organizational, People, Physical, Technological), plus Clauses 4–10. The Statement of Applicability is auto-generated from your scoping decisions and risk treatment — no 90-page Word document to maintain.

  • Risk register — qualitative and quantitative scoring with automatic control suggestions from the library.
  • Internal audit module — schedule, assign, and report Clause 9.2 audits without leaving the platform.
  • Stage 1 / Stage 2 readiness — gap analysis surfaces missing evidence 30 days before your certification body's site visit.
386 Annex A controls pre-mapped, including the 11 new 2022 controls (e.g., A.5.7 threat intelligence)
ISO 27001 risk register and Statement of Applicability excerpt mockup.
F-03 · Flagship

HIPAA — Security Rule + Privacy Rule + 2024 NPRM amendments

198 controls covering the Administrative, Physical, and Technical Safeguards (§164.308–§164.312) and the Privacy Rule, with the 2024 Notice of Proposed Rulemaking amendments layered in so you're ready the day the final rule lands.

  • BAA workflow — Business Associate Agreement lifecycle tracked per vendor, with renewal alerts 60 days out.
  • Workforce training — the Training Studio ships 9 HIPAA-specific courses (Privacy for Clinicians, Minimum Necessary, Breach Response) at a 94% average completion rate.
  • Breach notification timer — incident workflow counts down to the 60-day HHS notification deadline and routes to your privacy officer automatically.
94% Average training completion across HIPAA workforce modules (vs. 31% LMS industry benchmark)
HIPAA breach notification timeline and BAA tracker mockup.
F-04 · Flagship

GDPR — DPIA, ROPA, and cross-border transfers, operationalized

274 controls mapping Articles 5–49 to operational practice — DPIA workflows for high-risk processing, ROPA auto-built from your system inventory, and Standard Contractual Clauses / IDTA workflows for cross-border data transfers.

  • DSAR portal — data subject access requests intake with a 30-day SLA timer and redaction workflows for third-party data.
  • Transfer impact assessment — Schrems II-style assessment templates with country-by-country risk scoring.
  • Processor due-diligence — every sub-processor catalogued with contract evidence and review cadence.
274 GDPR controls mapped to operational evidence — covering Articles 5–49 and the EDPB guidelines
GDPR Record of Processing Activities (ROPA) and DPIA mockup.
04 — Cross-Framework Intelligence

One control. Four frameworks. Zero duplicated evidence.

Multi-framework programs are where compliance cost spirals. Manual Ends ships a deduplicated control graph so the same evidence satisfies SOC 2 CC6.1, ISO 27001 A.5.15, HIPAA §164.308(a)(1), and PCI DSS 7.1 in a single evidence pull.

CC6.1 · Logical access controls — least privilege, MFA, quarterly review
CC7.2 · Continuous monitoring — SIEM alerting, anomaly triage, incident escalation
CC8.1 · Change management — peer review, separation of duties, production deploy gate
C1.2 · Vendor risk — due diligence, contract review, ongoing monitoring
A.5.10 · Information classification & handling — public, internal, confidential, restricted
Custom mappings

Bring your own standard

Upload a custom framework (regulator-issued, customer-imposed, or internal policy) and our team maps it against the existing 2,650-control library within 14 days — included for every Scale-tier customer.

04 /Talk to a Solutions Architect
05 — Proof, not promises

Breadth of coverage, measured in audit outcomes — not slides.

1,840+ companies have shipped a framework program on Manual Ends. Here is what changed for them, in numbers you can paste straight into your steering-committee deck.

96% First-time SOC 2 Type II pass rate Across 612 audits in 2024. Industry baseline: 38%.
77 → 11 Median audit cycle, days Auditor Workspace cuts the back-and-forth that drags audits out.
142 SaaS evidence integrations AWS, GitHub, Workday, Okta, Jira, NetSuite, and 136 more — read-only APIs, no agents.
≤ 48 h Regulator-update SLA Every framework refreshed within 48 hours of an issued regulator update, with an audit trail your assessor can verify.
#1 — G2 Spring 2025 Grid for GRC (Usability & Implementation) 1,840+ customer companies · 38 countries SOC 2 Type II since 2021 · ISO 27001:2022 since 2022 · HIPAA-aligned since 2023
06 — Common questions

What compliance leads ask before they book a call.

Six questions we hear every week. Answers are factual, sourced from customer data, and explicitly do not constitute legal advice — for legal outcomes, defer to qualified counsel.

Q.01 We run SOC 2 and ISO 27001 at the same time. How much duplicate evidence work does Manual Ends actually eliminate?

The platform's deduplicated control graph maps every evidence source to every framework that accepts it. In a customer benchmark covering 187 multi-framework programs in 2024, the median team replaced ~412 duplicate evidence-collection tasks per quarter with a single pull that satisfied all target frameworks. The $214K/year average reduction in compliance overhead comes mostly from this elimination of duplicate evidence — not from headcount reduction.

Q.02 A framework we rely on just retired (or was superseded). How fast does the library update?

Our 48-hour regulator-update SLA is contractual for Scale-tier customers. When a framework is superseded — most recently NIST CSF 1.1 → CSF 2.0 and PCI DSS 3.2.1 → 4.0 — we publish the new control mapping within 48 hours, mark retired controls as deprecated (not deleted), and notify your tenant admin by email. The deprecated controls remain in your historical evidence so prior audit reports remain valid.

Q.03 We need a framework that isn't in the 14 you ship — a regulator-issued standard, a customer-imposed regime, or an internal policy. Can we upload our own?

Yes. The Custom Framework Module accepts an uploaded control set (CSV, XLSX, or PDF with structured fields), normalizes it to the same canonical control schema, and crosswalks it against the existing 2,650-control library. Standard turnaround is 14 days for Scale-tier customers; Enterprise customers can self-serve via the Framework Studio API. We have onboarded customer-imposed regimes including a defense-sector CMMC Level 3 overlay, a payment-orchestrator PCI P2PE variant, and several large-customer SOC 2 + custom addenda.

Q.04 The EU AI Act's high-risk tier is brand new. How is your mapping different from a vendor retrofitting the controls into ISO 27001?

The EU AI Act high-risk tier (Articles 6–15 plus Annex III) imposes obligations that don't exist in ISO 27001 or SOC 2 — risk-management system for the AI lifecycle (§9), data-governance for training/validation/test sets (§10), technical documentation and logging (§11, §12), transparency and human oversight (§13, §14), and accuracy/robustness/cybersecurity (§15). Our 156-control mapping treats the Act as a first-class framework and inherits only what is genuinely shared (e.g., access controls) from the existing library. Conformity assessment workflows for Annex III high-risk use cases ship pre-built. We do not provide legal advice on classification; defer to qualified counsel.

Still mapping out your framework roadmap?

A solutions architect will walk through your target frameworks, evidence sources, and audit calendar — 30 minutes, no slide deck.