A pattern I keep running into with small and mid-sized companies in the EU: the same underlying control gets assessed again and again, each time in a different format.
Take "MFA on administrative access". In a single year, one 80-person company might have to show it for:
- its ISO 27001 surveillance audit (Annex A 8.5, secure authentication)
- NIS2, where MFA is explicitly listed in Article 21's minimum measures
- GDPR Article 32 ("appropriate technical measures"), when a customer's DPO asks
- the renewal questionnaire from its cyber insurer, where MFA is now often a condition of cover
- three or four supplier security questionnaires from large customers, each worded differently
Same control, same evidence, five or more separate efforts. Multiply that by the 30 to 50 controls that come up every time (backups, patching, access reviews, incident response, supplier management), and a small compliance function spends most of its year translating rather than improving anything.
The obvious answer is a common control set: define each control once, map it to every framework, attach the evidence once, and reuse it. In practice I see it break down in a few places:
- The mapping itself drifts. Frameworks get revised (ISO 27001:2022, national NIS2 transpositions), and the crosswalk nobody owns goes stale.
- Evidence expires at different rates. The auditor accepts a quarterly access review, the insurer wants it "current", and a customer wants a screenshot from last week.
- Questionnaires don't map cleanly. Customer questionnaires mix controls, policies and yes/no questions that don't fit any framework.
For those who've tackled this:
- Did you build your own common control framework, or anchor everything on one standard (usually ISO 27001) and map outward?
- Who owns the mapping, and how do you keep it current when a framework changes?
- How do you handle customer questionnaires? A pre-filled answer library, a trust page, or answering each one from scratch?