Skip to main content
Coverage

Every regime in exactly one state, against one control spine.

Bawin maintains one canonical, versioned control catalogue. Every framework below is a projection of it — a crosswalk, published with its relationship type, its confidence, its source and the date it was last reviewed. No other platform publishes those four fields, and they are the only fields that let you check our work.

Spine edition v1.0 · Crosswalk edition v1.0

FrameworkStatus0102030405060708
NIST · Global
Mapped
ISO/IEC · Global
Mapped
AICPA · Global
Mapped·
PCI SSC · Global
Mapped···
NCSC / IASME · UK
Mapped·····
NIST · Global
Mapped
CIS · Global
Mapped···
ISO/IEC · Global
In review······
ISO/IEC · Global
In review·······
ISO/IEC · Global
In review······
NCSC · UK
Mapped
Cabinet Office · UK
Mapped
NHS England · UK
Mapped····
DBIST · UK
In review····
ICO · UK
Mapped·····
NCSC · UK
In review·······
MoD / DBIST · UK
In review······
EU · EU
Mapped····
EU · EU
Mapped····
EU · EU
Mapped······
EU · EU
In review······
EU · EU
Mapped·····
EU · EU
Declared·······
CCN · EU
Declared······
1
BSI · EU
In review······
ENX · EU
Declared·····
ISO/IEC · Global
Mapped······
NIST · Global
In review·······
ISO/IEC · Global
Declared·······
ISO/IEC · Global
Declared······
US DoD · US
Declared·····
NIST · US
In review·····
GSA · US
Declared
HHS · US
Declared·····
HITRUST · US
Declared
SEC / PCAOB · US
Declared······
FTC · US
Declared······
CPPA · US
Declared·······
StateRAMP · US
Declared
Texas DIR · US
Declared
CSA · Global
In review······
SWIFT · Sector
Declared·····
FCA / PRA · UK
In review······
CIS · Global
Mapped·······
ISO · Global
In review·······
ASD · APAC
Declared
METI · APAC
Declared
KISA · APAC
Declared
OPC · Global
Declared·······
  1. 1 BSI. The issuing body for C5 is the Bundesamt für Sicherheit in der Informationstechnik, the German federal cyber security authority. It is unrelated to the British Standards Institution, which also uses the initials BSI and operates as a certification body in the United Kingdom. Bawin maps C5 and holds no relationship with either organisation.

The eight domains

§01

Governance & accountability

CSF GV

Ownership, scope, risk appetite, board reporting and attested policy acceptance. Documentary rather than API-derived — which is why almost nobody evidences it well.

§02

Asset & cloud posture

CSF ID, PR

Configuration, exposure and drift across clouds, normalised into one comparable view.

§03

Identity & privileged access

CSF PR.AA

Standing privilege, stale roles, MFA coverage and recertification evidence.

§04

Data protection & privacy operations

CSF PR.DS

Retention enforcement, DSAR readiness, transfer mechanisms, lawful-basis records — the operational evidence, not the policy.

§05

Software supply chain & SBOM

CSF ID.RA, PR.PS

SBOM currency, end-of-life exposure, build provenance, exploited-CVE reachability.

§06

Third-party & concentration risk

CSF GV.SC

Supplier register completeness, residency and concentration analysis across contracted providers.

§07

Detection, response & reporting

CSF DE, RS

Detection coverage, triage evidence and the statutory reporting clocks that follow it.

§08

Resilience & tested recovery

CSF RC

Backup immutability, tested restore evidence, RTO/RPO attainment. Everyone measures configuration; almost nobody measures whether the restore worked.

Frameworks are added as crosswalks, not rebuilds. Adding one does not change the score formula — see the method.