DTCF

One objective. Many frameworks. Honest gaps.

DTCF normalises what an organization must achieve into 10 objectives across 10 families, then maps each to the frameworks practitioners face. Mappings are graded: fully addressed, partially addressed, or deliberately absent with the reason recorded. An empty cell is a finding about the framework, not a gap in your programme.

DTCF 2026.1 · published 10 Sep 2026 · CC BY 4.0 · free to use with attribution

10Objectives
312Graded mappings
49Deliberate absences
8Frameworks
OBL-01Obligations and Compliance

Obligation inventory

Legal, regulatory and contractual obligations that apply are identified, owned and kept current.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ◐ HIPAA ◐ GDPR ◐ EUAIACT ◐ AIRMF ●
OBL-02Obligations and Compliance

Scope decided and documented

What is in scope for each framework or certification is decided, justified and recorded, including deliberate exclusions.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ◐ EUAIACT ◐ AIRMF ●
DAT-01Data and Privacy

Data inventory and classification

Data held is inventoried, classified and assigned an owner.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ● EUAIACT ◐ AIRMF ●
ACC-03Identity and Access

Strong authentication

Authentication is proportionate to risk, with multi-factor authentication on administrative and remote access.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ◐ EUAIACT ○ AIRMF ○
ACC-04Identity and Access

Privileged access controlled

Administrative access is limited, separately approved, monitored and time-bound where possible.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ○ EUAIACT ○ AIRMF ○
OPS-01Secure Operations

Change management

Changes to production are requested, reviewed, tested and recorded, with emergency changes reconciled afterwards.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ○ EUAIACT ◐ AIRMF ◐
OPS-02Secure Operations

Vulnerability management

Vulnerabilities are discovered, prioritised by risk and remediated within stated timeframes, with exceptions recorded.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ◐ EUAIACT ◐ AIRMF ◐
TPR-02Third Parties and Supply Chain

Due diligence proportionate to risk

Third parties are assessed before onboarding and periodically thereafter, at a depth proportionate to what they touch.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ● EUAIACT ◐ AIRMF ●
ASR-01Assurance and Evidence

Controls have owners

Every control has one accountable owner and named performers for its tasks.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ○ EUAIACT ○ AIRMF ●
ASR-05Assurance and Evidence

Findings are closed with evidence

Findings carry an owner, a date, a remediation and evidence that the fix works.

SOC2 ● ISO27001 ● NISTCSF ● PCIDSS ● HIPAA ◐ GDPR ○ EUAIACT ◐ AIRMF ●

How DTCF is governed

First edition. Objectives are normalised statements of what an organization must achieve. Mappings are graded: full, partial, or a recorded absence with the reason it is absent. An empty cell is a finding about the framework, not about the objective.

  • authorAssociation of Digital Trust Practitioners Authors and maintains DTCF. The framework is published free under CC BY 4.0 and is not tied to any product.
  • sponsoring contributorA sponsoring contributor A sponsoring contributor to the 2026.1 edition contributed mapping research and review. Sponsors do not own or control DTCF; like any vendor they may state conformance to it.

Framework names and references are the property of their publishers. DTCF is an independent mapping and is not endorsed by them. Corrections are welcome through the contact form and are published in the edition changelog.