AI-FIRST CYBERSECURITY · Always Wise. Always Ahead. +91-95851-60363 info@semperwise.com DOVER, DE, USA

Platform capability

Five frameworks. One set of work.

An organisation holding ISO 27001, SOC 2, DPDP and SEBI CSCRF is not doing four programmes. It is doing one programme and maintaining four registers of it — which is why the fourth framework feels as expensive as the first.

Each one assumes the one above it is finished 1 Data map 2 Notice & consent 3 Rights 4 Breach 5 Retention 6 Children's data 7 Processors 8 Safeguards 9 SDF duties start not here Map first — starting at two means doing two twice
29Control subjects
20Frameworks mapped
502Clauses in the library
ProposesNever asserts

Why the second framework costs almost as much as the first

Read any two frameworks side by side and the overlap is striking. Access control, least privilege and periodic recertification. Patch management with timelines. Hardened configuration. Encryption in transit and at rest. Logging that is retained and reviewed. Testing with findings closed and retested. Backups with restoration actually tested. The same control set, expressed in four vocabularies.

Most platforms model this as a list of clauses per framework. So when you adopt your second one, it arrives as a fresh list of rows in the "not assessed" state, and somebody re-documents work that was already done — because nothing in the system knows that ISO 27001 A.5.15, SOC 2 CC6.1, RBI Annex1.8 and IRDAI ACC.1 are all about restricting who can reach what.

We model the subject instead. Every clause in the library is reduced to one or more of 29 canonical control subjects, so the platform knows what a clause is about independently of who wrote it. That one change is what makes the crosswalk work in every direction at once — and what makes adding a twenty-first framework a mapping pass rather than a new programme.

Coverage

What it gives you

Three things, in ascending order of value.

A new framework inherits what you have done

Adopt one and the platform works out which of its clauses are about subjects you have already implemented or verified, and offers them — clause by clause, with the source named.

Evidence comes across with its dates

Accepting a proposal carries the supporting artefacts too, keeping their original collection and expiry dates. An artefact that was already stale stays stale rather than arriving looking fresh.

It proposes; a person accepts

Nothing is ever marked verified on your behalf. Inherited positions arrive as implemented at most, because verified means evidenced within its test window and the evidence has to be pointed at the new clause deliberately.

A deliberate exclusion is never overwritten

If you have marked a clause not applicable with a reason, the crosswalk leaves it alone. A register that changes positions you took is a register nobody trusts.

Gaps read as one hole, not five

Coverage is reported by subject across every framework you hold. A subject with nothing verified anywhere shows up once, rather than as the same finding repeated in five registers.

Findings land everywhere at once

Because the subject is the unit, a penetration test finding reaches the clauses it affects across every framework you track — including the ones you added last week.

Approach

What adopting a second framework looks like

  1. 01 · Add it

    The clause library for that framework is already there. Nothing is imported or configured.

  2. 02 · See what carries

    The platform shows which clauses are about subjects you have already covered, and from where.

  3. 03 · Accept what genuinely applies

    Clause by clause, or in bulk once you have read them. The wording of the new framework still has to be satisfied, and only you can judge that.

  4. 04 · Close the real gaps

    What is left is the actual delta — usually far smaller than the clause count suggested, and now visible rather than buried.

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Coverage by subject

Every control subject across your whole programme, weakest first.

An inheritance view per framework

What carries across, from where, and what state the source is in.

Provenance on every inherited control

Which framework and clause it came from, what state that source was in, and when it was accepted.

A real delta

The clauses that genuinely need new work, separated from the ones that do not.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • You are about to adopt a second or third framework.
  • A customer or regulator has added a framework you do not yet hold.
  • You maintain the same control in several registers and reconcile them by hand.
  • You cannot answer "which subjects are weak across our whole programme" without a spreadsheet.
  • Your ISO programme and your SEBI or RBI programme are run by different people who do not compare notes.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

Unified Control Model — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Does holding one framework mean I comply with another?

No, and the platform is careful never to suggest it. A shared subject means two clauses are about the same thing — it does not mean satisfying one satisfies the other. That is precisely why inheritance proposes rather than asserts, and why nothing inherited ever arrives verified. The value is in not starting from a blank page, not in skipping the work.

How is the mapping produced?

Rules over each clause's own title, plus an explicit override list for the clauses the rules read wrongly — and every clause in the library is checked to have at least one subject. The mapping is reviewed rather than trusted: there is a command that prints every clause under its subject so a human can read what the rules decided.

Which frameworks are in the library?

Twenty: ISO 27001, ISO 42001, SOC 2, PCI DSS, HIPAA, GDPR and NIST CSF; the India set — DPDP, CERT-In Directions, RBI, SEBI CSCRF, IRDAI, UIDAI and MeitY GIGW; AI assurance — the NIST AI RMF and the EU AI Act; and DORA, NIS2, TISAX and CMMC for work outside India.

What happens when a framework is revised?

The clause library is versioned and seeded centrally, so a corrected title reaches every client. A clause that is withdrawn is retired rather than deleted — a tenant may have recorded a position against it, and removing the clause an auditor was shown last year to tidy up a revision would be the wrong trade.

Is this the same as a compliance mapping spreadsheet?

A mapping spreadsheet maps framework to framework, which is quadratic: twelve frameworks is sixty-six pairs, and the thirteenth needs twelve new mappings before it is useful. Mapping each clause to a subject is linear — a new framework needs one pass and immediately crosswalks to every framework in the library, including ones added afterwards.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.