Multi-framework compliance Multi-framework compliance: do the work once

Switch on the frameworks you need and let one shared set of evidence tasks count across all of them. Document a control once, and watch progress move on every framework it belongs to.

Unlimited users  •  Free onboarding and support  •  No commitment

A framework progress view in .legal, listing each framework's status as completed or overdue next to its completion bar
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell
A framework progress view in .legal, with each framework marked completed or overdue alongside its completion bar

Multi-framework compliance Meridian meets NIS2, ISO 27001 and CIS18 without documenting everything three times

Maria Holm is group GRC lead at Meridian Nordic. As an energy company they run an ISO 27001-certified ISMS, they have to meet NIS2 as an essential entity, and they use CIS18 as a security baseline. The three overlap heavily, but they used to live in three separate spreadsheets, so the same evidence, an access review here, a backup test there, got written up again and again. Now Maria switches the frameworks on in .legal, the controls arrive predefined, and each one hangs off a shared evidence task. She documents the task once, and progress moves on every framework it belongs to.

  • The same evidence task counts towards NIS2, ISO 27001 and CIS18 at once.
  • Controls arrive predefined, with the standard's own ids and numbering.
  • A simulated score shows how far CIS18 already is from the ISO work.
  • Each framework can still be audited in its own structure.

  • Document once, count everywhere

    One evidence task satisfies every control it's mapped to, across frameworks.

  • Frameworks, ready to go

    Controls come predefined, 1:1 with the standard, so you don't type them in.

  • See a head start

    A simulated score shows how far a framework you haven't switched on already is.

  • Audit-ready per framework

    Documentation still shows in each framework's own structure for the auditor.

Why .legal?

The framework overview in .legal, listing the frameworks already in use with their owner and compliance areas, above a library of ready-made frameworks to add

Multi-framework compliance Frameworks come ready, you set the scope

You don't build the framework, you choose it. The standards are predefined, so you start from the real controls rather than a blank sheet, and you decide how much is in scope.

  • Pick from IT-security standards like ISO 27001 and CIS18 and legal requirements like NIS2.
  • Controls, article numbers and naming match the standard 1:1, nothing to retype.
  • Switch a framework on and choose which controls apply to you.
One violet task tile at the centre, with lines fanning out to three separate clusters of control chips, several of them marked with a green tick

Multi-framework compliance One evidence task, many controls

Underneath every control sits an evidence task, the thing you actually do and document. That task can be linked to more than one control, and .legal has done the mapping for you.

  • A single task can cover several controls in the same framework.
  • The same task can also cover controls in a different framework entirely.
  • Do the work, upload the documentation, and it lands on every control it's mapped to.
The framework library in .legal, where ISO 27001, NIS2, GDPR, CIS-18, DORA and others each show a readiness percentage before they have been added

Multi-framework compliance Progress on every framework at once

Because the evidence is shared, finishing one task moves more than one bar. You see where each framework stands, and you can look ahead too.

  • Complete a task and watch progress tick up across every mapped framework.
  • Get a simulated score on frameworks you haven't switched on yet.
  • The head start comes from the documentation you're already collecting.
An evidence task in .legal, showing its deadline, responsible owner and notification period, and the ISO 27001 and NIS2 controls it is mapped to

Multi-framework compliance Set it up, then let it run

The point of doing the work once is that it keeps working. You delegate the tasks, and the platform keeps the right people moving without you chasing them.

  • Assign each task to an owner, with how often it needs doing.
  • The right person gets reminded at the right time, automatically.
  • Follow progress and spot anywhere things aren't closed on time.
Three upright panels side by side showing the same rows of evidence, with the middle one lifted forward and marked with a green tick

Multi-framework compliance Still audit framework by framework

Sharing the evidence underneath doesn't blur the frameworks on top. An auditor wants to see your documentation in the context they're auditing, so we keep each framework's own shape.

  • Present an ISO 27001 audit in ISO 27001's structure, NIS2 in NIS2's.
  • The same evidence appears wherever it's relevant, in each framework's terms.
  • Run one framework's audit without dragging the others into it.
Two parallel rails with marker cards placed along them, one already ticked, and a figure at the end holding the next card to place

Multi-framework compliance Rails, not the roadmap

We stand up the frameworks and the mapping so the whole picture is easy to see. We don't decide your compliance for you, and we don't write it.

  • You choose which frameworks and which controls belong in your scope.
  • You document your own compliance and security, we give it somewhere to live.
  • The platform makes the work visible and reusable, the judgement stays yours.
.legal in practice

Features for multi-framework compliance

Predefined framework library

ISO 27001, CIS18, NIS2, DORA, D-seal and more, with controls, article numbers and naming 1:1 with the standard.

Choose your scope

Switch a framework on and pick which controls are in scope for you, instead of starting from a blank sheet.

Shared evidence-task catalogue

One library of evidence tasks sits underneath the controls, decoupled from any single framework.

Cross-framework mapping

Each task is pre-mapped to the controls it satisfies, whether they sit in one framework or several.

Simulated readiness score

See how far you already are on a framework you haven't activated, from the evidence you're collecting anyway.

Delegate, remind, track

Assign who does what, when and how often, let reminders find the right person, and follow progress and overdue items per framework.

Multi-framework compliance Frameworks this covers

Different frameworks, one set of evidence underneath.

  • icon-framework-NIS2

    NIS2

    The risk-management measures an essential entity must run, evidenced by the same tasks that feed your other frameworks.

    Learn about NIS2
  • icon-framework-ISO

    ISO 27001

    The Annex A controls, predefined and mapped to your evidence, so a certified ISMS reuses work you've already done.

    Learn about ISO 27001
  • Ikon frameworks

    CIS18

    The 18 controls as a security baseline, mapped to the same tasks so you can see how far you already are.

    Learn about CIS18
.legal compliance platform

Meet several frameworks with...

Do you need to meet more than one framework at a time? We recommend the following modules for that task.

GDPR / Data Protection

The same do-it-once logic extends to your GDPR work, keeping Article 30 records current and audit-ready.

Explore GDPR

Frameworks

Browse the predefined frameworks the platform ships with, from ISO 27001 and CIS18 to NIS2, DORA and the D-seal.

Explore Frameworks

Our Customers

+400

companies

+10.000

users

+79.000

contracts

+14.000

processing activities

Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.

Frequently Asked Questions about multi-framework compliance

What does "do the work once" actually mean here?

Your frameworks share one catalogue of evidence tasks. When someone does a task and documents it, it counts towards every control it's mapped to, in one framework or across several, so the same work isn't repeated framework by framework.

Do we have to type in all the controls ourselves?

No. The frameworks come predefined. You pick the ones you want to meet and set your scope, and the controls, article numbers and naming match the standard 1:1.

How can one task count towards several frameworks?

Because the evidence tasks sit below the frameworks, not inside them. .legal has mapped each task to the controls it satisfies, so completing it moves progress on every framework that control belongs to.

Can we see how far we are on a framework we haven't started?

Yes. Because the evidence is shared, the platform can give you a simulated score for a framework you haven't switched on yet, based on the documentation you're already collecting for the others.

If everything shares one catalogue, can we still audit one framework on its own?

Yes. An auditor usually wants to see the documentation in the context of the framework being audited, so we keep each framework's own structure. You run and present the audit framework by framework.

Which frameworks are available?

A range of predefined ones, both IT-security standards like ISO 27001, CIS18 and the D-seal, and legal requirements like NIS2, DORA, the Cyber Resilience Act and the Data Act. Because the evidence catalogue is decoupled from the framework, it works across all of them.

Does the platform decide which frameworks apply to us, or write the documentation?

No. It stands up the frameworks and the mapping so it's easy to see, but it doesn't tell you which controls to bring into scope, and it doesn't produce the documentation. You still document your own compliance and security.

Who keeps the work moving day to day?

You delegate each evidence task to the right owner with a frequency, and the system reminds them when it's due. From there you follow progress across your frameworks and spot anywhere things aren't being closed on time.

Still unsure?

Ask Johannes directly, he runs most demos personally

Book him here
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell