DTCF

One objective. Many frameworks. Honest gaps.

DTCF normalises what an organization must achieve into 10 objectives across 10 families, then maps each to the frameworks practitioners face. Mappings are graded: fully addressed, partially addressed, or deliberately absent with the reason recorded. An empty cell is a finding about the framework, not a gap in your programme.

DTCF 2026.1 · published 10 Sep 2026 · CC BY 4.0 · free to use with attribution

10Objectives
312Graded mappings
49Deliberate absences
8Frameworks
RSK-03Risk and Decisions

Acceptances expire

Accepted risks and control exceptions carry an accountable executive, a compensating control and an expiry date.

SOC2 ◐ ISO27001 ◐ NISTCSF ◐ PCIDSS ◐ HIPAA ○ GDPR ○ EUAIACT ○ AIRMF ◐
DAT-02Data and Privacy

Lawful, minimised processing

Personal data is processed on a stated basis, limited to what is needed and kept only as long as needed.

SOC2 ◐ ISO27001 ◐ NISTCSF ◐ PCIDSS ● HIPAA ● GDPR ● EUAIACT ◐ AIRMF ◐
DAT-03Data and Privacy

Deliberate data sharing

Data leaves the organization only through a decided channel, with a defined end and a record of what was shared.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ● GDPR ● EUAIACT ○ AIRMF ◐
ACC-01Identity and Access

Joiners, movers, leavers

Access is provisioned on a documented request, changed when a role changes and removed promptly on departure.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ● GDPR ◐ EUAIACT ○ AIRMF ◐
OPS-01Secure Operations

Change management

Changes to production are requested, reviewed, tested and recorded, with emergency changes reconciled afterwards.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ○ EUAIACT ◐ AIRMF ◐
OPS-02Secure Operations

Vulnerability management

Vulnerabilities are discovered, prioritised by risk and remediated within stated timeframes, with exceptions recorded.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ◐ EUAIACT ◐ AIRMF ◐
OPS-05Secure Operations

Secure development

Security requirements, review and testing are part of how software is built and released.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ○ GDPR ◐ EUAIACT ● AIRMF ◐
TPR-03Third Parties and Supply Chain

Contractual terms and offboarding

Contracts carry security, privacy and breach terms, and access and data are recovered when the relationship ends.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ● GDPR ● EUAIACT ◐ AIRMF ◐
RES-03Resilience and Response

Backups that restore

Backups exist, are protected from the same failure as production, and restoration is tested.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ◐ HIPAA ● GDPR ● EUAIACT ○ AIRMF ◐
RES-04Resilience and Response

Continuity and recovery objectives

Critical processes have recovery objectives, a continuity plan and a tested route back to service.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ○ HIPAA ● GDPR ◐ EUAIACT ○ AIRMF ◐

How DTCF is governed

First edition. Objectives are normalised statements of what an organization must achieve. Mappings are graded: full, partial, or a recorded absence with the reason it is absent. An empty cell is a finding about the framework, not about the objective.

  • authorAssociation of Digital Trust Practitioners Authors and maintains DTCF. The framework is published free under CC BY 4.0 and is not tied to any product.
  • sponsoring contributorA sponsoring contributor A sponsoring contributor to the 2026.1 edition contributed mapping research and review. Sponsors do not own or control DTCF; like any vendor they may state conformance to it.

Framework names and references are the property of their publishers. DTCF is an independent mapping and is not endorsed by them. Corrections are welcome through the contact form and are published in the edition changelog.