The second framework is the most common reason a SOC 2 platform stops fitting. A customer asks for ISO 27001, a product team ships AI features and someone mentions ISO 42001 or the EU AI Act, or a European customer brings NIS2 or DORA. We checked which frameworks each platform names on the pages we read on 24 August 2026.
Which frameworks does each platform name?
| Framework | Scytale | Vanta | Drata | Secureframe | Sprinto | Thoropass | Scrut | Comp AI |
|---|---|---|---|---|---|---|---|---|
| SOC 2 | Named | Named | Named | Named | Count stated, names not recorded | Named | Count stated, names not recorded | Named |
| SOC 1 | Named | Not named on pages read | Not named on pages read | Not named on pages read | Count stated, names not recorded | Named | Count stated, names not recorded | Named |
| ISO 27001 | Named | Named | Named | Named | Count stated, names not recorded | Named | Count stated, names not recorded | Named |
| ISO 42001 | Named | Named | Named | Not named on pages read | Count stated, names not recorded | Not named on pages read | Count stated, names not recorded | Named |
| HIPAA | Named | Named | Named | Named | Count stated, names not recorded | Named | Count stated, names not recorded | Named |
| GDPR | Named | Named | Named | Named | Count stated, names not recorded | Named | Count stated, names not recorded | Named |
| PCI DSS | Named | Named | Named | Named | Count stated, names not recorded | Named | Count stated, names not recorded | Named |
| CCPA | Named | Not named on pages read | Named | Named | Count stated, names not recorded | Not named on pages read | Count stated, names not recorded | Named |
| CMMC | Named as CMMC 2.0 | Named | Named | Named | Count stated, names not recorded | Named as CMMC L1 | Count stated, names not recorded | Not named on pages read |
| FedRAMP | Not named on pages read | Named | Named | Named | Count stated, names not recorded | Not named on pages read | Count stated, names not recorded | Named |
| HITRUST | Not named on pages read | Named | Named | Not named on pages read | Count stated, names not recorded | Named | Count stated, names not recorded | Not named on pages read |
| NIS2 | Not named on pages read | Named | Named | Not named on pages read | Count stated, names not recorded | Not named on pages read | Count stated, names not recorded | Not named on pages read |
| DORA | Not named on pages read | Named | Named | Not named on pages read | Count stated, names not recorded | Not named on pages read | Count stated, names not recorded | Not named on pages read |
| EU AI Act | Named | Named | Not named on pages read | Not named on pages read | Count stated, names not recorded | Not named on pages read | Count stated, names not recorded | Not named on pages read |
| Essential Eight | Not named on pages read | Named | Not named on pages read | Not named on pages read | Count stated, names not recorded | Not named on pages read | Count stated, names not recorded | Not named on pages read |
| Cyber Essentials | Named as Cyber Essentials Plus | Not named on pages read | Named | Named | Count stated, names not recorded | Named | Count stated, names not recorded | Not named on pages read |
| NIST CSF 2.0 | Not named on pages read | Named | Not named on pages read | Not named on pages read | Count stated, names not recorded | Named | Count stated, names not recorded | Listed as NIST |
| TISAX | Not named on pages read | Not named on pages read | Named | Not named on pages read | Count stated, names not recorded | Not named on pages read | Count stated, names not recorded | Not named on pages read |
Not named on pages read does not mean unsupported. It means the framework did not appear on the vendor pages in our sources.
What do the stated counts say?
Counts as each vendor states them: Sprinto 200+ frameworks digitized and 25+ automated out of the box; Scytale 80+ with control cross-mapping (its framework library page lists 35 by name); Scrut 70+ on its homepage and 60+ on its startup page; Vanta 35+; Drata 30+ pre-built plus custom frameworks; Thoropass ten listed on its homepage; Comp AI twelve quoted on its pricing page; Secureframe no total. We did not count any library ourselves.
A large count helps when you expect several frameworks. It helps less if the one framework you need is missing, so always check by name.
Which AI frameworks are named?
ISO 42001 is named by Scytale, Vanta, Drata and Comp AI on the pages we read. The EU AI Act is named by Scytale on its AI agent page and by Vanta. NIST AI RMF is named by Vanta and Drata. Secureframe lists AI frameworks without naming them on the page we read.
Which European and regional frameworks are named?
NIS2 and DORA are named by Vanta and Drata. Cyber Essentials is named by Drata, Secureframe and Thoropass, and Scytale names Cyber Essentials Plus. Vanta names Essential Eight and CPS 234. Drata names TISAX. Comp AI names NEN 7510.
How does cross-mapping change the work?
The count matters less than whether controls are mapped once and reused. Scytale states cross-mapping across its library, Sprinto describes a common control framework, and Scrut a Unified Control Framework. In each case the promise is the same: evidence collected for SOC 2 counts toward the next framework. Ask the vendor to show the mapping for your existing controls in the demo.
What should you do before you switch for a framework?
- Name the framework and the date you need it.
- Check that your current vendor names it, and what plan it needs.
- Run the switch planner with that framework selected; it shows how many of your frameworks each platform names.
- Ask finalists to show your SOC 2 controls mapped to the new framework.
What if your framework is not named anywhere?
Ask each vendor directly and get the answer in writing, including whether the framework is pre-built or would be set up as a custom framework. A custom framework can work well, but it usually means more of the mapping lands on your team. Factor that work into the comparison alongside the plan price.