Multi-framework compliance

The compliance management tool that links every framework to one set of controls

Maintain each control in one place, collect each piece of evidence once and see its effect across all your frameworks.

The challenge of modern compliance

Organizations now have to meet multiple frameworks at once (ISO 27001, NIS2, DORA, GDPR, SecNumCloud), each with its own requirements and deadlines. Without a dedicated compliance management tool, tracking controls, gathering evidence and producing reports relies on scattered spreadsheets and time-consuming manual work. That fragmentation creates blind spots, multiplies the risk of non-compliance and overloads already stretched teams.

How Vailor organizes your compliance

Vailor is built on the Vailor Control Framework (VCF): each control is maintained once and linked to every framework that asks for it. Evidence collected once is reused everywhere, each control leads to its evidence and then to one or more actions, and indicators track each control. Each requirement gets a justified verdict that is submitted and reviewed, and every validated version of the posture is frozen. Every decision is recorded in an audit log with no delete function, so you can justify your choices to auditors and regulators.

Why choose a unified compliance solution built in France

Reasoning by control, evidence and action rather than by siloed requirements changes day-to-day work: a change to a control shows up immediately on each of your frameworks, and the auditor reviews the validated versions and their history with read-only access. On hosting, as SaaS, data is stored in France (AWS Paris region) and AI processing runs on AWS Bedrock in EU regions. Vailor also installs on your premises (Docker), a decisive criterion for regulated sectors.

A complete compliance management platform

One control, every framework

With the Vailor Control Framework, a control is maintained once and linked to every framework that asks for it. No more duplicates from one standard to the next.

Ready-to-use frameworks

NIS2 and ReCyF, DORA, NIST CSF 2.0 and the ANSSI hygiene guide. Other frameworks can be added by the Vailor team, which extends the VCF; ISO 27001 is planned.

Traceable, auditable evidence

Every control, piece of evidence and decision is recorded in an audit log with no delete function. Validated versions are frozen and open to your auditors with read-only access.

Data in France, deployed your way

As SaaS, data stored in France (AWS Paris region). Or installed on your premises (Docker): your choice.

The benefits of a unified compliance tool

Track NIS2, DORA, NIST CSF 2.0 and the ANSSI hygiene guide from a single platform
Collect a piece of evidence once and reuse it across all your frameworks
Spot compliance gaps before the audit, not during it
Justify every decision with an audit log with no delete function
Reuse controls shared across frameworks to avoid duplicate effort
Keep your data stored in France as SaaS, or install Vailor on your premises

Frequently asked questions about GRC and compliance tools

What does the GRC acronym stand for?

Governance, risk and compliance. Governance sets roles, decision rights and trade-offs; risk management identifies what could prevent the organisation from meeting its objectives and decides how to treat it; compliance checks that applicable obligations are met and can be evidenced. IT GRC is the same discipline narrowed to IT systems and cybersecurity. The three are not separate lanes: a risk that governance accepts becomes a decision to justify in an audit, and a requirement nobody covers becomes a risk.

What does integrated GRC mean?

Integrated GRC means one control library, one risk register and one evidence base shared across every obligation you track, instead of one silo per framework. An access management control is described once, linked to each requirement it covers, and its evidence counts for all of them. The alternative, a file per framework, produces contradictory statements: the same control reads as compliant on one side and as a gap on the other, depending on which sheet was updated last.

Is a compliance management tool mandatory?

No regulation mandates software. NIS2, DORA and the GDPR set outcomes: measures defined, implemented, kept current and demonstrable on request, and ISO/IEC 27001 works the same way. It is that duty to demonstrate, rather than any rule about tooling, that makes a platform necessary past a certain volume. With a single framework and a stable scope, well-kept documentation can hold. Once several regimes overlap, deadlines multiply and evidence has to stay current, manual upkeep costs more than the tool.

Can software make my organisation certified?

No. Only an accredited certification body can issue an ISO/IEC 27001 certificate, and only after a two-stage initial audit; surveillance audits follow, then a recertification audit three years on. No software vendor issues that certificate. What a platform provides is the file behind it: scope, risk assessment, statement of applicability, dated evidence and tracked gaps. The auditor judges that file and the way you actually work, not your software.

Does the same control count for more than one framework?

Yes, and that is where most of the effort is saved. Supplier management, access control, incident handling and business continuity all appear in some form in ISO/IEC 27001, in NIS2 and in DORA. The control is reusable; the evidence rather less so, because each regime keeps its own requirements, such as the incident reporting deadlines to the authority under NIS2, or the register of information on ICT third-party providers under DORA. Good mapping separates what is shared from what stays specific.

When does a compliance spreadsheet stop holding up?

The day someone asks what was in place at a past date. An auditor or a supervisory authority is not satisfied with today's snapshot: they want to know what was running when an incident happened, or across the whole period under review, and who signed it off. A workbook overwrites that history on every save. It also has no notion of one control serving several frameworks, so the control is re-entered once per framework and the copies drift apart. On a narrow scope that holds. Beyond it, rebuilding the file becomes the real audit budget.

Who stays accountable when AI prepares the file?

You do, and the regulation leaves no room for doubt: NIS2 and DORA both put approval and oversight of the risk management framework at management body level, with the CISO and the business preparing the decisions. Vailor works upstream. In risk assessment, the AI reads your documents and prefills fields from excerpts. In compliance, the Vailor Control Framework links each control to the frameworks that ask for it and to its evidence. Accepting a risk or settling a treatment plan stays human, recorded and dated.

See Vailor in a live demo

Book 30 minutes: we listen to your context and tell you concretely how Vailor organizes your multi-framework compliance.

Book a demo