Adopting Frameworks
Adopt a compliance framework to map your controls to its requirements, see coverage, and prepare for an audit — SOC 2, ISO 27001, and the other frameworks most teams need.
Overview
Once you are running Controls, a framework organizes them against a specific standard. Adopting a framework maps your controls to that standard's requirements, shows you where you are covered and where you have gaps, and gives an auditor a scoped way to review your evidence.
Concord supports the top security, privacy, and AI frameworks most companies need, including SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, ISO 42001, the NIST AI Risk Management Framework, ISO 27701, the NIST Privacy Framework, and CCPA/CPRA, with more added over time.
Frameworks are a paid add-on to a Premium or Enterprise Trust plan. You buy them as framework packs sized to how many frameworks you want to run at once.
Buying a framework pack
Go to Global Settings → Billing → Trust plan and open the Framework Packs card. Choose the pack that covers how many frameworks you plan to run, and confirm. Billing is prorated, and you can move between pack sizes later as your program grows. (The Framework Packs card appears once Controls is enabled on your plan; for current pack sizes and pricing, see the pricing shown on the card.)
Adopting a framework
With a pack in place, adopt a framework from the frameworks area. Adopting a framework:
- Brings in the standard's requirements and a starter set of tests for that framework.
- Computes coverage — each requirement shows which of your controls satisfy it, so controls you already maintain immediately count toward the new framework.
- Turns on auditor access for that framework (see Auditor access).
Reading coverage
Open an adopted framework to see its requirements and the controls mapped to each one. A requirement is covered when a mapped control is passing; it needs attention when a mapped control is in review or failing, or when nothing is mapped yet. Work the gaps by adding or fixing the underlying controls and their evidence — coverage updates as your controls do.
Changing or removing frameworks
You can swap pack sizes or step down at any time from the same Framework Packs card. If you remove a framework, the work you did is not thrown away: your adopted framework data is preserved, and the framework's surfaces simply lock until you add it back. If you are over a smaller pack's limit, archive frameworks you are not actively running to free up slots before you downsize.
Next steps
- Auditor access — invite an auditor to review an adopted framework.
- Controls and Evidence — the controls that satisfy these requirements.
Controls and Evidence
Adopt security and privacy controls, assign owners, and prove them with evidence that stays current on a schedule — the foundation of a compliance program in Concord Trust.
Auditor Access
Give an external auditor scoped, time-boxed, read-only access to review a framework and its evidence — without adding them as a full team member.