Skip to main content

Frameworks & Controls

The Frameworks module is where you decide which compliance frameworks your organization answers to (CMMC, NIST, CIS, and others from the catalog) and where you watch your standing against each of them. Activating a framework builds a per-control assessment worklist for your organization; working that worklist in the Assessments module produces a compliance score, a gap list, and an evidence trail per framework. Controls sit alongside as the register of what your organization actually implements, mapped back to the framework requirements they satisfy.

ScreenshotThe Frameworks module on the Active Frameworks tab: each activated framework as an expandable row with its compliance score card — the percent compliant headline, the in-scope progress bar, and the crosswalk-satisfied chip.

The lifecycle at a glance

Compliance work in SolveGRC follows one loop, and each stage has its own page in this guide:

  1. Activate and scope. Pick a framework from the catalog and activate it. Activation seeds an assessment for every control in the framework, and the Applicability tab lets you scope out what does not apply so exclusions never drag your score down.
  2. Assess controls. In the Assessments module, set a compliance status on each control, attach the evidence behind your judgment, and let AI suggest verdicts you confirm or override.
  3. Crosswalks. Requirements that mean the same thing across frameworks are linked through a unified control catalog, so one implemented control can satisfy its equivalents everywhere. Map once, satisfy every framework.
  4. Prove it. Scores, gaps, and linked evidence flow onward into compliance reports and audit engagements, and controls you mark not compliant surface automatically in the Risk Register.

How this connects

Frameworks is a hub, not an island. It consumes:

  • Framework activations you choose from the global catalog.
  • Control assessments worked in the Assessments module.
  • Evidence links from the Evidence Locker.

From those it produces your compliance score per framework, gap lists, and crosswalk equivalences between frameworks, which feed:

  • Compliance reports, for the numbers you show leadership and customers.
  • Audit scoping, so an engagement starts from the frameworks you actually run.
  • Risk signals from gaps, so a failed control becomes a tracked risk without a separate filing step.

Two automations do the heavy lifting: activating a framework seeds an assessment for every control it contains, and crosswalks satisfy equivalent controls across frameworks so you never re-prove the same thing twice.

The Controls module completes the picture. It holds the register of controls your organization defines, each with a lifecycle state and its mappings to framework requirements, and it feeds framework satisfaction through the crosswalk, vendor questionnaire mapping, and risk mitigations.

Before you start

  • Access to the modules. Frameworks, Assessments, and Controls each appear in the sidebar only if your role has read permission for them, and activating frameworks or editing controls needs the matching create and update permissions. If something is missing, ask an administrator.
  • The right organization selected. Activation always targets the organization you currently have selected, and the confirmation dialog names it before you commit. If you manage several organizations, check the name in that dialog.
Build the evidence base early

Assessments are only as convincing as the evidence behind them. Loading your policies, procedures, and prior audit artifacts into Documents and the Evidence Locker before you start assessing means every verdict can carry a link to proof, and the AI analysis has material to reason from.

Frameworks and Assessments are two rooms of one workflow

The Frameworks module is where you activate and read scores; the Assessments module is where the per-control work happens. The Analyze Compliance action on an active framework takes you straight from one to the other.