Control framework

Vailor Control Framework: one control, many frameworks

The VCF is the control baseline of the Vailor platform. Each control is maintained once and mapped, requirement by requirement, to NIST CSF 2.0, the ANSSI hygiene guide, ReCyF (NIS2) and DORA.

What is the Vailor Control Framework?

The Vailor Control Framework (VCF) is the control baseline of the Vailor platform: a bilingual catalogue, in French and English, of security controls mapped to the requirements of the frameworks you have to meet. Version 24.15 holds 232 controls, 227 of them active, across 19 domains. It also describes 217 pieces of evidence and 400 standard actions, which say how to put a control in place and how to show that it works. One of the 19 domains, "Artificial intelligence systems", groups 21 controls. Vailor is an AI-native cyber GRC platform built in France.

Four frameworks, mapped requirement by requirement

Four frameworks are integrated today. NIST CSF 2.0 has 106 requirements, every one mapped to at least one control. The ANSSI guideline for a healthy information system, in 42 measures, is broken down into 132 requirements, all mapped. ANSSI's Référentiel Cyber France (ReCyF) v2.5, a working document that accompanies the French transposition of NIS2, still in progress, lists 152 acceptable means of compliance, of which 151 are mapped. DORA, meaning Regulation (EU) 2022/2554 and eight of its level 2 acts (as at 2 July 2025), is broken down into 431 requirements, of which 416 are mapped. In total: 821 requirements and 2,140 mappings. Each mapping carries a relation type (equivalent, included in the control, broader than the control, partial overlap), a strength scored out of 10 and a justification written in both French and English. Each unmapped requirement carries a written reason: for example a rule of interpretation, a scope rule, an obligation already carried by another requirement of the same text, or a measure that prescribes no arrangement.

One piece of evidence, several frameworks

The VCF works on one principle: a control is maintained once, and its evidence serves every framework that asks for it. The control "Periodic review of accounts and access rights", for instance, is mapped to requirements in all four frameworks, so the review is documented once rather than four times. The level of detail is deliberately in the middle. It goes further than a list of topics: each control states a verifiable arrangement, its objective, its evidence and its actions. It does not aim for the completeness of a global meta-framework such as the Secure Controls Framework, an open project that targets very broad worldwide coverage. The VCF is oriented towards Europe and France (NIS2 through ReCyF, DORA, ANSSI), and NIST CSF 2.0 acts as the bridge to international frameworks. ISO/IEC 27001, the French military programming law (LPM) and the AI Act are planned, and the Vailor team can add other frameworks by extending the VCF.

What the VCF gives you

A domain for AI systems

21 controls for artificial intelligence systems, in the same catalogue as every other domain, with their evidence and standard actions.

Collect evidence once

Evidence gathered for a control serves every framework mapped to that control. You do not repeat the same collection for each text.

Mappings you can check

2,140 mappings, each with a relation type, a strength and a bilingual justification. Every unmapped requirement has a written reason.

Built for Europe and France

NIS2 through ANSSI's ReCyF, DORA and the ANSSI hygiene guide, with NIST CSF 2.0 as the international bridge.

Why a shared control baseline

232 controls, 227 of them active, in 19 domains
821 requirements from 4 frameworks linked by 2,140 mappings
Each control maintained once, its evidence reused
A bilingual justification for every mapping
A written reason for every unmapped requirement
ISO/IEC 27001, LPM and the AI Act on the roadmap

Frequently asked questions about the Vailor Control Framework

What is the Vailor Control Framework (VCF)?

The Vailor Control Framework (VCF) is the control baseline of the Vailor platform. It is a bilingual catalogue of 232 security controls (227 active) in 19 domains, together with 217 pieces of evidence and 400 standard actions. Every control is mapped to the requirements of the integrated frameworks, so for any requirement you can see which controls answer it and what evidence to produce. The current version is 24.15.

Which frameworks does the VCF cover today?

Four frameworks are integrated, broken down into requirements: NIST CSF 2.0 (106 requirements), the ANSSI guideline for a healthy information system (42 measures, 132 requirements), ANSSI's Référentiel Cyber France (ReCyF) v2.5, a working document tied to the French transposition of NIS2, still in progress (152 requirements), and DORA, that is Regulation (EU) 2022/2554 and eight of its level 2 acts (431 requirements). That makes 821 requirements linked to the controls by 2,140 mappings. ISO/IEC 27001, the LPM and the AI Act are on the roadmap.

How is a mapping between a control and a requirement justified?

Each mapping holds three pieces of information. A relation type says how the control and the requirement overlap: equivalent, included in the control, broader than the control or partial overlap. A strength gives the weight of the link. A justification, written in French and English, explains what part of the requirement the control carries and, often, what it does not. An auditor or a CISO can read every link instead of having to trust a bare mapping table.

Why are some requirements not mapped to any control?

Because not every requirement in a text prescribes an arrangement. Of the 821 integrated requirements, 16 are mapped to no control: 15 in DORA and 1 in ReCyF. Each one has a written reason. For example, Article 4 of DORA is a rule of interpretation (proportionality) that is checked in how the other controls are calibrated, and one ReCyF measure grants an exemption from authentication for information published to the public. Most of the others are scope rules or obligations already carried by another requirement of the same text; a few are a lead-in, an internal cross-reference or a mere rule for filling in templates.

How does the VCF differ from a meta-framework such as the Secure Controls Framework?

The difference is in level of detail and scope. The Secure Controls Framework is an open project that targets very broad worldwide coverage, with a large number of controls and texts. The VCF sits deliberately in the middle: more detailed than a list of topics, without aiming for that completeness. It is oriented towards Europe and France (NIS2 through ReCyF, DORA, ANSSI), with NIST CSF 2.0 as the international bridge.

Does the VCF make an organisation compliant with NIS2 or DORA?

No. A control catalogue does not make anyone compliant: compliance depends on what the organisation actually puts in place, and it is assessed by the competent authority or the auditor. The VCF gives that work a structure. It shows which controls answer which requirements, which evidence demonstrates them and which standard actions put them in place. It also avoids handling each text on its own when several of them ask for the same thing.

Can other frameworks be added to the VCF?

Yes. ISO/IEC 27001, the French military programming law (LPM) and the AI Act are planned. Beyond that roadmap, the Vailor team can add other frameworks by extending the VCF. Their requirements are then mapped to the same controls with the same method: relation type, strength, bilingual justification, and a written reason for any requirement left without a control. An internal information security policy (PSSI) is not tracked as a framework: it is uploaded as a document, and the AI uses it as a source.

See the VCF applied to your frameworks?

Book 30 minutes: we start from the texts you have to meet and show you how the VCF links your controls, your evidence and your requirements.

Book a demo