One control to satisfy them all?
We measured the Secure Controls Framework against its own set theory.
Last updated: 20 August 2026 13:14 UTC
All numbers reproducible from SCF’s public 2026.2 downloads. SCF content used with attribution under CC BY-ND 4.0; we compute statistics from it and redistribute none of it.
If you answer to more than one security framework, you have heard the pitch: map everything to one common control set, and each control you implement satisfies requirements across dozens of frameworks at once. Products built on this idea are called meta-frameworks. The most credible free one is the Secure Controls Framework, which maps 252 laws, regulations and frameworks onto 1,534 common controls, and anyone can download it.
We measured what that pitch is worth, using SCF’s own published data and SCF’s own chosen logic. The short answer: for 74 to 96 percent of the cross-framework connections the design implies, SCF’s own mapping logic supports no conclusion at all.
What SCF gets right
This is a measurement, not a takedown. SCF earned the ability to be measured, which most of this industry has not. Since 2024, SCF labels every mapping using set theory, the approach NIST IR 8477 recommends: a framework requirement is equal to an SCF control, a subset of it, intersecting it, or unrelated to it. Most crosswalks just say “maps to.” Because SCF committed to labels with real logical meaning, and published everything free, its architecture can be checked. The paid alternative cannot be checked at all, as the companion piece explains.
SCF is also genuinely good at one thing: NIST 800-53. Its 810 mapped 800-53 requirements land on a median of one SCF control each. If 800-53 is your world, SCF keeps your structure intact and adds free implementation guidance by business size.
How merged the controls really are
The typical SCF control maps to 10 frameworks. The average is 20. One control maps to 142. Three out of four SCF controls merge requirements from three or more frameworks.
The merging is not even-handed. While 800-53 maps nearly one-to-one, each ISO 27002 control spreads across a median of 5 SCF controls, and one (5.18, access rights) spreads across 24. CSF 2.0 subcategories spread across a median of 4, worst case 18. In structure, the hub is an 800-53 derivative that other frameworks get projected onto. If you live in ISO or CSF, your controls break apart on arrival.
The mapping labels show the same bias. 800-53 requirements are marked “Functional Equal” 32 percent of the time. CSF 2.0 gets “Equal” 1.8 percent of the time, and “Intersects With” 88 percent.
The measurement
Here is the core of the meta-framework promise. Requirement A from one framework maps to an SCF control. Requirement B from another framework maps to the same control. The promise is that implementing the control satisfies both.
Set theory says exactly when that reasoning holds. If A equals the control and B is a subset of it, the conclusion is valid. But if A intersects the control and B intersects the control, which is by far the most common case, A and B may share nothing. Two circles that each overlap a third circle do not have to overlap each other. In that case there is no weak conclusion. There is no conclusion.
We computed every cross-framework requirement pair the hub implies, for three framework pairs, and asked SCF’s own logic whether each pair is supported. Where several shared controls connect a pair, we credited the most favorable one:
| Framework pair | Implied pairs | No conclusion | Overlap only | Equal, subset or superset |
|---|---|---|---|---|
| CSF 2.0 and 800-53 R5 | 888 | 78.8% | 19.1% | 2.0% |
| CSF 2.0 and ISO 27002 | 553 | 95.8% | 3.1% | 1.1% |
| ISO 27002 and 800-53 R5 | 615 | 74.1% | 24.2% | 1.6% |
Read the last column first, because that is what compliance runs on. Claims an auditor can use, this requirement equals that one or is contained in it, survive the trip through the hub for 1 to 2 percent of pairs. About a fifth survive as “these overlap somehow,” which tells you where to look and nothing more. The rest, 74 to 96 percent, get no support from SCF’s own logic.
This is not a data-entry problem. It is what merging does. A control built to touch many requirements gets touched by many requirements, and “both touch the same thing” proves nothing about the two things.
One smaller finding: SCF also publishes a “Strength of Relationship” score, described as a 3 to 10 scale. In the documents we measured it is really just the mapping label restated as a number, almost always 0, 5 or 10.
What to do with this
Use SCF for what it is good at. As a free 800-53 companion it is excellent. As an index that tells you which frameworks probably say something about a topic, the “intersects” label is honestly useful.
Do not use hub co-mapping as compliance evidence. If an auditor asks whether your ISO 27002 conformance covers a CSF 2.0 requirement, the answer must come from comparing those two requirements directly, because for 96 percent of such pairs the hub cannot answer, and “they overlap” was never the answer the auditor needed. Cross-framework claims need direct mappings, made pair by pair, with the relationship and its direction stated. That is more work. It is also the only version whose conclusions actually follow.
Full disclosure: this site already builds its crosswalks that way, directly per pair, with derived mappings banned. We ran this measurement partly to check whether that ban was too strict. It is not.
Method and limits
How each claim is sourced. Every figure in this piece is confirmed: each is computed by us directly from SCF’s published material, not taken from a third party or estimated. That covers the 252 frameworks and 1,534 controls, the 810 mapped 800-53 requirements landing on a median of one control, the spread medians for ISO (5, worst case 24) and CSF (4, worst case 18), the label shares (32 percent “Functional Equal” for 800-53 against 1.8 percent for CSF and 88 percent “Intersects With”), every row of the table above, and the Strength of Relationship finding. Nothing here is corroborated-only, which is why no claim carries a separate inline label.
Inputs: the SCF 2026.2 workbook and the published STRM documents for NIST 800-53 R5, ISO 27002:2022 and NIST CSF 2.0. We indexed every requirement-to-control relation, composed every implied requirement pair through every shared control, and classified each result by standard set algebra, crediting the strongest path per pair. All statistics are computed from SCF’s material, used with attribution under CC BY-ND 4.0; none of it is redistributed. Limits: we measured three of the 252 frameworks, the three this site maintains hand-reviewed direct mappings for; a follow-up will score the hub-derived pairs against those reviewed mappings. One oddity in the workbook, the 800-82 column appearing to duplicate the 800-53 column, is still being verified and nothing above depends on it.
Companion piece: the Unified Compliance Framework, the paid and patented elder of this category, and why it cannot be audited this way at all.