Predefined framework library
ISO 27001, CIS18, NIS2, DORA, D-seal and more, with controls, article numbers and naming 1:1 with the standard.
Switch on the frameworks you need and let one shared set of evidence tasks count across all of them. Document a control once, and watch progress move on every framework it belongs to.
Unlimited users • Free onboarding and support • No commitment
Maria Holm is group GRC lead at Meridian Nordic. As an energy company they run an ISO 27001-certified ISMS, they have to meet NIS2 as an essential entity, and they use CIS18 as a security baseline. The three overlap heavily, but they used to live in three separate spreadsheets, so the same evidence, an access review here, a backup test there, got written up again and again. Now Maria switches the frameworks on in .legal, the controls arrive predefined, and each one hangs off a shared evidence task. She documents the task once, and progress moves on every framework it belongs to.
Document once, count everywhere
One evidence task satisfies every control it's mapped to, across frameworks.
Frameworks, ready to go
Controls come predefined, 1:1 with the standard, so you don't type them in.
See a head start
A simulated score shows how far a framework you haven't switched on already is.
Audit-ready per framework
Documentation still shows in each framework's own structure for the auditor.
You don't build the framework, you choose it. The standards are predefined, so you start from the real controls rather than a blank sheet, and you decide how much is in scope.
Underneath every control sits an evidence task, the thing you actually do and document. That task can be linked to more than one control, and .legal has done the mapping for you.
Because the evidence is shared, finishing one task moves more than one bar. You see where each framework stands, and you can look ahead too.
The point of doing the work once is that it keeps working. You delegate the tasks, and the platform keeps the right people moving without you chasing them.
Sharing the evidence underneath doesn't blur the frameworks on top. An auditor wants to see your documentation in the context they're auditing, so we keep each framework's own shape.
We stand up the frameworks and the mapping so the whole picture is easy to see. We don't decide your compliance for you, and we don't write it.
ISO 27001, CIS18, NIS2, DORA, D-seal and more, with controls, article numbers and naming 1:1 with the standard.
Switch a framework on and pick which controls are in scope for you, instead of starting from a blank sheet.
One library of evidence tasks sits underneath the controls, decoupled from any single framework.
Each task is pre-mapped to the controls it satisfies, whether they sit in one framework or several.
See how far you already are on a framework you haven't activated, from the evidence you're collecting anyway.
Assign who does what, when and how often, let reminders find the right person, and follow progress and overdue items per framework.
Different frameworks, one set of evidence underneath.
NIS2
The risk-management measures an essential entity must run, evidenced by the same tasks that feed your other frameworks.
ISO 27001
The Annex A controls, predefined and mapped to your evidence, so a certified ISMS reuses work you've already done.
CIS18
The 18 controls as a security baseline, mapped to the same tasks so you can see how far you already are.
Run your ISMS and meet NIS2, ISO 27001, CIS18 and more from one shared set of evidence.
Explore Information Security ManagementThe same do-it-once logic extends to your GDPR work, keeping Article 30 records current and audit-ready.
Explore GDPRBrowse the predefined frameworks the platform ships with, from ISO 27001 and CIS18 to NIS2, DORA and the D-seal.
Explore Frameworkscompanies
users
contracts
processing activities
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Your frameworks share one catalogue of evidence tasks. When someone does a task and documents it, it counts towards every control it's mapped to, in one framework or across several, so the same work isn't repeated framework by framework.
No. The frameworks come predefined. You pick the ones you want to meet and set your scope, and the controls, article numbers and naming match the standard 1:1.
Because the evidence tasks sit below the frameworks, not inside them. .legal has mapped each task to the controls it satisfies, so completing it moves progress on every framework that control belongs to.
Yes. Because the evidence is shared, the platform can give you a simulated score for a framework you haven't switched on yet, based on the documentation you're already collecting for the others.
Yes. An auditor usually wants to see the documentation in the context of the framework being audited, so we keep each framework's own structure. You run and present the audit framework by framework.
A range of predefined ones, both IT-security standards like ISO 27001, CIS18 and the D-seal, and legal requirements like NIS2, DORA, the Cyber Resilience Act and the Data Act. Because the evidence catalogue is decoupled from the framework, it works across all of them.
No. It stands up the frameworks and the mapping so it's easy to see, but it doesn't tell you which controls to bring into scope, and it doesn't produce the documentation. You still document your own compliance and security.
You delegate each evidence task to the right owner with a frequency, and the system reminds them when it's due. From there you follow progress across your frameworks and spot anywhere things aren't being closed on time.
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.