Skip to content
Foxx Cyberfoxxcyber/docs

Frameworks Catalog and Sources

The eight frameworks in Bedrock GRC's built-in catalog, the published sources each one is taken from, the crosswalks between them, and what is not included.

Bedrock GRC's framework catalog is built into the application and shared by every client. Each framework is taken from its official published source, and the requirement text is kept as published. This page lists the sources so you can check any control against the original.

The frameworks

FrameworkAssessableSource
NIST Cybersecurity Framework 2.0106 subcategories (6 functions, 22 categories)NIST CSWP 29, February 26, 2024. Guidance carries NIST's implementation examples from the CSF 2.0 Reference Tool. doi.org/10.6028/NIST.CSWP.29
CMMC 2.0 Level 115 practices, 59 objectivesDoD CIO, CMMC Assessment Guide, Level 1, version 2.13, September 2024. dodcio.defense.gov
CMMC 2.0 Level 2110 practices, 320 objectivesDoD CIO, CMMC Assessment Guide, Level 2, version 2.13, September 2024, with objectives as quoted from NIST SP 800-171A. SPRS weights from the DoD NIST SP 800-171 Assessment Methodology, version 1.2.1. dodcio.defense.gov
NIST SP 800-171 Rev. 397 requirements, 422 determination statements, 88 organization-defined parametersNIST SP 800-171 Rev. 3 and SP 800-171A Rev. 3, May 2024. Withdrawn requirements are left out. doi.org/10.6028/NIST.SP.800-171r3
NIST SP 800-53 Rev. 5 (release 5.2.0)1,014 (300 controls, 714 enhancements)NIST's OSCAL catalog for release 5.2.0. Withdrawn controls and enhancements are left out. doi.org/10.6028/NIST.SP.800-53r5
HIPAA Security Rule53 standards and implementation specifications (31 required, 22 addressable)45 CFR 164.308 to 164.316, from the eCFR as of September 24, 2026, each marked Required or Addressable. Guidance carries the key activities from NIST SP 800-66 Rev. 2. ecfr.gov
HIPAA Privacy Rule85 standards and implementation specifications45 CFR 164.502 to 164.530, from the eCFR as of September 24, 2026: uses and disclosures, individual rights and administrative requirements. ecfr.gov
HIPAA Breach Notification Rule13 standards and implementation specifications45 CFR 164.404 to 164.414, from the eCFR as of September 24, 2026: notification to individuals, the media and the Secretary, business associates, law enforcement delays and administrative requirements. ecfr.gov

A few notes on how they are laid out:

  • CMMC Level 1 has 15 practices, the 15 requirements of FAR 52.204-21(b)(1), as version 2.13 of the Assessment Guide defines it.
  • CMMC Level 2 stays on SP 800-171 Rev. 2, as 32 CFR Part 170 sets it. Clients that want Rev. 3 adopt it as its own framework; see Moving to NIST SP 800-171 Rev. 3.
  • NIST SP 800-53 baselines come from NIST SP 800-53B, release 5.2.0: Low 149, Moderate 287, High 370, and the additive Privacy baseline 96. See Frameworks and Baselines.
  • HIPAA Privacy and Breach Notification standards are not marked Required or Addressable. Those marks belong to the Security Rule (45 CFR 164.306(d)); every Privacy and Breach standard applies as written. NIST has published no guidance or crosswalk for these two rules, so their controls show the regulation text only.
  • The HIPAA Security Rule text is the current rule. HHS proposed a major revision in January 2025; it is not in the catalog unless and until a final rule takes effect.

Crosswalks

The catalog holds 1,618 crosswalk links:

FromToSourceRelationship
CMMC Level 1CMMC Level 2The Assessment Guides' references to the same NIST SP 800-171 requirementSubset
CMMC Level 2NIST SP 800-171 Rev. 3NIST's SP 800-171 Rev. 2 to Rev. 3 change analysisEquivalent where NIST found no significant or a minor change; related otherwise
NIST SP 800-171 Rev. 3NIST SP 800-53 Rev. 5The source controls NIST lists for each requirementRelated
NIST CSF 2.0NIST SP 800-171 Rev. 3 and SP 800-53 Rev. 5NIST's CSF 2.0 informative referencesRelated
HIPAA Security RuleNIST SP 800-53 Rev. 5NIST SP 800-66 Rev. 2, Appendix D crosswalkRelated

Only equivalent and subset links can fill in an answer; related links inform your answer on the control page but never fill one in. See Crosswalks: answer once.

Downloading the catalog

Frameworks in the sidebar shows a card for each framework with its publisher, version, number of assessable controls and a link to the source. Excel and CSV download the whole framework with its crosswalks.

Not in the catalog

  • SOC 2. The Trust Services Criteria are copyright of the AICPA, and reproducing them in software and client deliverables needs the AICPA's permission.
  • CMMC Level 3 (NIST SP 800-172) is not loaded yet.
  • Custom frameworks. There is no framework import; the catalog ships with the application.

NIST publications are works of the US Government and are not subject to copyright in the United States (17 U.S.C. 105). The CMMC Assessment Guides are DoD publications approved for public release with unlimited distribution. The Code of Federal Regulations is a work of the US Government. Only NIST's own mappings are used for crosswalks; third-party mappings are not.

Last updated October 9, 2026