Frameworks covered
| Framework | Mappings | Controls covered |
|---|---|---|
| SOC 2 (Trust Services Criteria, AICPA 2017) | 220 | 45 / 358 |
| NIST SP 800-66 Rév. 2 (HIPAA Security Rule) | 149 | 72 / 152 |
| ISO/IEC 27001:2022 | 135 | 68 / 123 |
| ISO/IEC 27701:2025 | 119 | 17 / 21 |
| ISO/IEC 42001:2023 | 115 | 31 / 67 |
| BSI C5:2020 | 113 | 67 / 121 |
| RGPD / GDPR (UE 2016/679) | 110 | 51 / 287 |
| HITRUST CSF v11 | 101 | 82 / 132 |
| Directive NIS2 (annexe technique, guidance ENISA) | 95 | 80 / 351 |
| CCB CyberFundamentals Framework 2023 | 83 | 64 / 221 |
| Règlement européen sur l'IA (EU AI Act) | 43 | 31 / 347 |
| Hébergement de données de santé (HDS) v2.0 | 12 | 11 / 71 |
| ISO 22301:2019 | 7 | 5 / 46 |
Why the TGV is unusually broad
Most frameworks cover one domain. ISO 27001 covers security, GDPR covers privacy, ISO 42001 covers AI, SOC 2 covers service trust. The TGV covers all four at once, plus interoperability, which no other framework here requires.
Important limitation. A mapping indicates overlapping intent. It
does not mean a TGV criterion automatically satisfies the target control, nor that a coverage
percentage equals a certification percentage. Certification remains a formal process conducted by an
accredited body.