# Framework assessments

> How security consultants and vCISO teams assess clients against CPCSC, ISO 27001, CIS Controls, NIST CSF, SOC 2 and TPN, and where Control+s fits.

Canonical: https://controls.run/frameworks

Practical guides for consultants and vCISO teams assessing clients against a security framework: what the framework asks for, what evidence to request, and how to reuse that evidence across frameworks.

- [CPCSC readiness assessments for consultants](https://controls.run/frameworks/cpcsc): What CPCSC Levels 1, 2 and 3 require, the 13 Level 1 controls and the evidence that supports them, and how consultants prepare defence suppliers for Level 2 certification.
- [Évaluations de préparation au PCCC pour les consultants](https://controls.run/frameworks/pccc): Ce qu’exigent les niveaux 1, 2 et 3 du Programme canadien de certification en cybersécurité (PCCC), les 13 contrôles du niveau 1 et les éléments probants à demander, et comment préparer un fournisseur de la défense au niveau 2.
- [ISO 27001 gap assessments for consultants](https://controls.run/frameworks/iso-27001): How consultants run an ISO/IEC 27001:2022 gap assessment across clauses 4 to 10 and the 93 Annex A controls, what evidence to request, and how to deliver a readiness report the client can act on.
- [NIST CSF 2.0 maturity assessments](https://controls.run/frameworks/nist-csf): How to assess a client against NIST CSF 2.0's six functions, why the framework has no built-in maturity scale, and a practical 0 to 5 scoring rubric that ties each score to evidence.
- [CIS Controls v8.1 assessments for consultants](https://controls.run/frameworks/cis-controls): How consultants assess clients against the 18 CIS Controls and 153 Safeguards in v8.1, how to pick the right Implementation Group, and how to turn Safeguard results into a prioritized roadmap.
- [SOC 2 readiness assessments for consultants](https://controls.run/frameworks/soc-2): How consultants prepare clients for a SOC 2 examination, from choosing Trust Services Criteria to testing evidence for a Type II period, and where the consultant's role ends and the CPA firm's begins.
- [TPN assessment readiness for media and entertainment vendors](https://controls.run/frameworks/tpn): How consultants prepare media and entertainment vendors for a Trusted Partner Network assessment, what each TPN Shield requires, and how to scope Site, Cloud and Application assessments.
- [Reusing evidence across ISO 27001, NIST CSF, CIS Controls, SOC 2 and CPCSC](https://controls.run/frameworks/cross-framework-evidence): How one piece of client evidence can support related controls in ISO 27001, NIST CSF 2.0, CIS Controls v8.1, SOC 2 and CPCSC, with a worked crosswalk and the limits of reuse.
