DTCF

One objective. Many frameworks. Honest gaps.

DTCF normalises what an organization must achieve into 22 objectives across 10 families, then maps each to the frameworks practitioners face. Mappings are graded: fully addressed, partially addressed, or deliberately absent with the reason recorded. An empty cell is a finding about the framework, not a gap in your programme.

DTCF 2026.1 · published 10 Sep 2026 · CC BY 4.0 · free to use with attribution

22Objectives
312Graded mappings
49Deliberate absences
8Frameworks
GOV-01Governance and Accountability

Accountable owner for digital trust

A named individual is accountable for the digital trust programme, with the authority and budget to direct it.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ◐ HIPAA ● GDPR ◐ EUAIACT ◐ AIRMF ●
GOV-02Governance and Accountability

Approved policy set

Policies covering the organization's obligations are approved, dated, owned and reviewed on a stated cycle.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ● GDPR ◐ EUAIACT ○ AIRMF ●
GOV-03Governance and Accountability

Roles and responsibilities defined

Security, privacy and compliance responsibilities are assigned and communicated to the people who hold them.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ● GDPR ◐ EUAIACT ◐ AIRMF ●
GOV-04Governance and Accountability

Code of conduct and ethics affirmation

Expected conduct is published and affirmed by staff on joining and annually.

SOC2 ● ISO27001 ◐ NISTCSF ◐ PCIDSS ◐ HIPAA ● GDPR ○ EUAIACT ◐ AIRMF ●
RSK-01Risk and Decisions

Risk assessment performed and repeated

Risks to objectives are identified and assessed on a defined cadence and on material change.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ● GDPR ◐ EUAIACT ● AIRMF ●
RSK-02Risk and Decisions

Risk register with owners and treatment

Risks are recorded with inherent and residual judgement, an owner, a treatment decision and a review date.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ◐ HIPAA ● GDPR ○ EUAIACT ● AIRMF ●
RSK-04Risk and Decisions

Appetite and indicators

Risk appetite is stated in terms someone can measure, with indicators and thresholds that trigger action.

SOC2 ◐ ISO27001 ◐ NISTCSF ● PCIDSS ○ HIPAA ○ GDPR ○ EUAIACT ◐ AIRMF ●
OBL-01Obligations and Compliance

Obligation inventory

Legal, regulatory and contractual obligations that apply are identified, owned and kept current.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ◐ HIPAA ◐ GDPR ◐ EUAIACT ◐ AIRMF ●
OBL-02Obligations and Compliance

Scope decided and documented

What is in scope for each framework or certification is decided, justified and recorded, including deliberate exclusions.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ◐ EUAIACT ◐ AIRMF ●
OBL-03Obligations and Compliance

Training and awareness

People receive role-relevant training on joining and at a defined cadence, and completion is evidenced.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ● GDPR ◐ EUAIACT ● AIRMF ●
DAT-01Data and Privacy

Data inventory and classification

Data held is inventoried, classified and assigned an owner.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ● EUAIACT ◐ AIRMF ●
OPS-03Secure Operations

Logging and monitoring

Security-relevant events are logged, retained and reviewed, with alerts that reach a person who acts.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ● GDPR ◐ EUAIACT ● AIRMF ●
TPR-01Third Parties and Supply Chain

Third-party inventory

Third parties with access to data or systems are inventoried with an owner and a criticality judgement.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ● GDPR ● EUAIACT ◐ AIRMF ●
TPR-02Third Parties and Supply Chain

Due diligence proportionate to risk

Third parties are assessed before onboarding and periodically thereafter, at a depth proportionate to what they touch.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ● EUAIACT ◐ AIRMF ●
RES-01Resilience and Response

Incident response plan and roles

An incident response plan exists, names roles, and is exercised.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ● GDPR ◐ EUAIACT ◐ AIRMF ●
AIG-01AI and Automated Decisions

AI system inventory

AI and automated decision systems in use are inventoried with purpose, owner, data and risk classification.

SOC2 ○ ISO27001 ○ NISTCSF ◐ PCIDSS ○ HIPAA ○ GDPR ◐ EUAIACT ● AIRMF ●
AIG-02AI and Automated Decisions

AI risk assessed before deployment

AI systems are assessed for harm, bias, robustness and transparency before use, and the assessment is revisited on change.

SOC2 ○ ISO27001 ○ NISTCSF ◐ PCIDSS ○ HIPAA ○ GDPR ◐ EUAIACT ● AIRMF ●
AIG-03AI and Automated Decisions

Human oversight and disclosure

People affected by automated decisions are told, and a competent person can intervene.

SOC2 ○ ISO27001 ○ NISTCSF ○ PCIDSS ○ HIPAA ○ GDPR ● EUAIACT ● AIRMF ●
ASR-01Assurance and Evidence

Controls have owners

Every control has one accountable owner and named performers for its tasks.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ○ EUAIACT ○ AIRMF ●
ASR-03Assurance and Evidence

Evidence is dated, attributable and retained

Evidence shows what was done, by whom and when, and is kept for the period the obligation requires.

SOC2 ● ISO27001 ● NISTCSF ◐ PCIDSS ● HIPAA ● GDPR ● EUAIACT ● AIRMF ●
ASR-04Assurance and Evidence

Independent testing and reporting

Controls are tested by someone other than the person who performs them, and results are reported without softening.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ● GDPR ◐ EUAIACT ◐ AIRMF ●
ASR-05Assurance and Evidence

Findings are closed with evidence

Findings carry an owner, a date, a remediation and evidence that the fix works.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ○ EUAIACT ◐ AIRMF ●

How DTCF is governed

First edition. Objectives are normalised statements of what an organization must achieve. Mappings are graded: full, partial, or a recorded absence with the reason it is absent. An empty cell is a finding about the framework, not about the objective.

  • authorAssociation of Digital Trust Practitioners Authors and maintains DTCF. The framework is published free under CC BY 4.0 and is not tied to any product.
  • sponsoring contributorA sponsoring contributor A sponsoring contributor to the 2026.1 edition contributed mapping research and review. Sponsors do not own or control DTCF; like any vendor they may state conformance to it.

Framework names and references are the property of their publishers. DTCF is an independent mapping and is not endorsed by them. Corrections are welcome through the contact form and are published in the edition changelog.