Where several frameworks apply, C3SA maps them together so one set of controls and evidence serves all of them.
DEFENCE
CMMC & CPCSC Readiness
Readiness for U.S. and Canadian defence supply-chain cybersecurity requirements: scoping the environment that handles controlled information, assessing controls and preparing evidence. See CMMC & CPCSC.
What you get
- A scoped readiness assessment
- A gap register and remediation plan
- An evidence plan for assessment
Talk to C3SA about CMMC & CPCSC ReadinessGOVERNMENT OF CANADA
ITSG-33 & PBMM
Support for systems that must meet the Canadian Centre for Cyber Security's ITSG-33 guidance, including the Protected B, Medium Integrity, Medium Availability (PBMM) profile: control tailoring, security requirements traceability matrix (SRTM) support and gap analysis. Authorization decisions rest with the responsible government authority.
What you get
- A tailored control profile
- SRTM and evidence support
- A gap analysis and implementation guidance
Talk to C3SA about ITSG-33 & PBMMCERTIFICATION
ISO & SOC 2
Readiness for ISO/IEC 27001 and related standards (27701 for privacy, 27017 for cloud, 27034 for application security) and for SOC 2. Certification and SOC 2 reports come from independent certification bodies and CPA firms; C3SA prepares you and can run internal audits.
What you get
- A scope statement and gap assessment
- Policies, procedures and evidence mapped to requirements
- Internal audit and management-review support
Talk to C3SA about ISO & SOC 2EUROPEAN UNION
NIS2, DORA & GDPR
Alignment with the EU's NIS2 Directive for essential and important entities, the Digital Operational Resilience Act (DORA) for the financial sector, and the GDPR for personal data, mapped so shared controls satisfy overlapping requirements. Applicability depends on sector, size and national implementation; confirm with counsel.
What you get
- An applicability assessment
- A combined control and obligations map
- A remediation roadmap
Talk to C3SA about NIS2, DORA & GDPRFRAMEWORKS
NIST & CIS
Assessment against the NIST Cybersecurity Framework, NIST SP 800-53 or 800-171, or the CIS Critical Security Controls, used to measure maturity and build a practical roadmap rather than a checklist.
What you get
- A maturity baseline
- Prioritized control improvements
- A roadmap leadership can fund
Talk to C3SA about NIST & CISEVIDENCE
Evidence & Traceability
Organizing controls, owners, inherited controls from providers and supporting evidence so that you can show an assessor, customer or board exactly how each requirement is met.
What you get
- A requirements-to-controls matrix
- An evidence register with owners
- Management-ready status reporting
Talk to C3SA about Evidence & Traceability