For GRC analysts, IS auditors, DPOs, and infosec managers

Compliance frameworks overlap more than they conflict.

ControlForge resolves the overlap into one audit-defensible specification per operational concern — the strictest applicable clause across every framework that addresses it, with full source attribution.

Frameworks merging into one compliant specification Six framework boxes on the left pulse and feed into a central cluster node. From the cluster, a green checkmark and a list of compliant items emerge on the right. ISO 27001 SOC 2 PCI DSS DPDPA RBI CSF NIST CSF CLUSTER cl-backup COMPLIANT Backup architecture Restoration testing Immutability proof Air-gap evidence Satisfies all 6 frameworks
38
Frameworks
1,932
Controls
106
Syntheses
29
Guides
9
Tools
PILLAR 03 · CADENCE

What changed. What's coming.

Regulatory frameworks move. ControlForge tracks the deltas — what shifted in the last month, what circulars dropped, and the dates you should have on your calendar already.

⚑ Dates to watch

2026-08-02EU
EU AI Act high-risk obligations originally due (deferred under Omnibus political agreement of 7 May 2026)
2026-11-13India
DPDPA Consent Manager framework (Rule 4) activates
2026-12-02EU
EU AI Act content-marking obligations (Article 50.2)
2027-05-13India
DPDPA full operational enforcement — penalties up to ₹250 crore
2027-12-02EU
EU AI Act Annex III high-risk obligations (Omnibus-deferred deadline)

✎ Recent updates

2026-05-12
vuln
Microsoft Patch Tuesday ships 137 CVEs across Windows, Office, SharePoint, Azure — first month with zero zero-days since June 2024. Notable critical: CVE-2026-41089 Windows Netlogon RCE (CVSS 9.8), CVE-2026-41096 Windows DNS Client RCE.
2026-05-07
regulatory
EU Council and Parliament reach provisional agreement on AI Act simplification. National regulatory sandboxes deadline postponed to 2 Aug 2027; transparency grace period for synthetically generated content reduced from 6 to 3 months — new deadline 2 December 2026.
2026-05-06
advisory
SEBI AI Advisory adds 10 Annexure-A items to CSCRF. Regulated entities' existing VAPT scope must now formally include AI vulnerability assessment tooling, AI-augmented attacker scenarios in the risk register, and a documented IT-committee discussion of the advisory.
2026-04-29
regulatory
RBI's expanded cybersecurity expectations under the IT Governance Master Directions (2024) now span direct circulars, thematic guidance on cyber resilience and IT outsourcing, and operational expectations baked into supervisory exams. VAPT cycle moves from "did you do a scan" to "manual pen test, remediated, re-tested".
2026-04-28
vuln
CVE-2026-41940 (cPanel/WHM authentication bypass, CVSS 9.8) disclosed — mass exploitation underway. Same day: CISA adds CVE-2026-32202 (Windows NTLM zero-click hash leak) to Known Exploited Vulnerabilities catalog with federal patching deadline 12 May 2026.
2026-04-24
breach
ADT confirms unauthorized access affecting 5.5 million people per Have I Been Pwned (ShinyHunters claimed 10M+). Exposed: names, phone numbers, addresses; some DOB and last-4 of SSN/tax-ID. Payment data and security systems not impacted.
2026-04-21
vuln
Oracle April Critical Patch Update releases security fixes across Database Server, Eclipse RDF4J adapter, Autonomous Health Framework, and Blockchain Platform. Many vulnerabilities remotely exploitable without authentication.
2026-04-07
regulatory
RBI Cyber Security and IT Risk Group issues data-protection advisory aligning with DPDPA. All regulated entities directed to prioritise customer data protection; audit processes must now include third-party cybersecurity and data-protection reviews.
2026-04-01
regulatory
RBI's Digital Payment Authentication Framework takes effect. Banks transition away from SMS-based OTP toward biometric authentication or app-based tokens. Follows the 1 January 2026 Digital Banking Channels Authorisation Directions which require GAICA reports certified by CERT-In empanelled auditors.
2026-03-31
breach
Cisco discloses development environment breach. Attackers used stolen credentials from the Trivy supply chain compromise to access internal systems.
Subscribe to the RSS feed →
PILLAR 04 · MICRO UTILITIES

Single-purpose tools for the small jobs that come up every week.

Focused utilities for the compliance grunt work — multi-regulator incident timeline calculation, SDF designation self-check, cross-border flow analysis, vendor materiality classification. Each one solves one job well.

⌬ THE BACKBONE

Strictest-clause synthesis. NIST IR 8477 methodology. Five operational dimensions per cluster.

For any group of framework controls that address the same operational concern, there exists a strictest articulation across five dimensions: scope, threshold, method, frequency, and evidence. The strictest version of each dimension — often drawn from different contributing frameworks — becomes the audit-defensible target. One implementation, every framework satisfied.

Read the methodology in full →