All articles
ComplianceGovernance

The Overlap Dividend: How One Control Can Satisfy Five Frameworks

Here is the single most valuable idea in compliance, and most organizations leave it on the table: a large share of the work repeats. The same controls appear in law after law, which is why ENISA's own mapping table links NIS2 across ISO 27001, NIST CSF and ETSI EN 319 401. Do the work once, evidence it once, and claim it everywhere. That's the overlap dividend.

Ilke Tosunoğlu
Ilke TosunoğluJune 25, 20265 min readUpdated July 20, 2026
A single access-control requirement radiating out to GDPR, NIS2, DORA, ISO 27001 and SOC 2 badges under the banner map once, prove many.

Part of the pillar series Sovereignty You Can Actually Operate.

This is practical guidance for compliance teams, not legal advice. Current as of July 2026.

The insight: laws differ in object, not in work

Across this series we've looked at GDPR, NIS2, DORA, the AI Act, and the CRA one at a time. Line them up and a pattern jumps out: they govern different things, but they demand the same work. The obligations converge on about seven shared control domains.

Shared control domain Appears in
Governance & accountable ownership GDPR (Art. 5(2)), NIS2 (Art. 20), DORA (Art. 5), AI Act, ISO/NIST "Govern"
Asset / data / AI inventory & scoping GDPR, NIS2, AI Act, Data Act
Risk assessment & treatment NIS2, DORA, AI RMF, ISO 27001/27005/42001/22301
Secure development & lifecycle CRA, AI Act, IEC 62443
Third-party & supply-chain oversight DORA, NIS2, ISO/ISA supplier controls
Incident detection, reporting & response NIS2, DORA, CRA, GDPR (breach), ISO 22301
Documentation & audit evidence AI Act, GDPR (demonstrability), ISO, NIST

This is where the compliance-maze gets its punchline. Seven domains carry most of the obligations across the entire stack. That is not a coincidence: it's the structure of the maze, and it's the exit.

The dividend, made concrete

Take one control: access control (least privilege, MFA, reviewed permissions). Count where a single, well-evidenced implementation of it lands:

One control: Access controlMFA · least privilege · reviews
GDPRArt. 32
NIS2Art. 21
DORAPillar 1
ISO 27001Annex A
SOC 2Trust Services
NIST CSFProtect
Map once, prove many.

One control. Six frameworks satisfied. One set of evidence (the access logs, the MFA config, the quarterly review record) counted toward all six audits. The same is true of encryption, incident response, risk assessment, and supplier oversight. This is the difference between doing access control six times and doing it once.

This reuse is officially intended

You don't have to take a vendor's word that frameworks overlap. In June 2025, ENISA published guidance that maps each NIS2 Article 21 measure to ISO/IEC 27001:2022 and NIST CSF 2.0, an official statement that your ISO 27001 controls can serve as NIST- and NIS2-aligned evidence (ENISA). NIST's frameworks are built with "informative references" for exactly this cross-mapping. The regulators expect you to reuse, not rebuild.

The honest trade-off

To be fair to the alternative: a law-by-law program gives you crisp, single-thread traceability: this obligation, this project, this binder. The shared-control model costs more to design at the start; you have to build the mapping. But every law after the first is nearly free, because it reuses controls you already run. Given that EU digital law only accumulates, the shared-control model wins on total cost, and, more importantly, it stops the "conflicting versions of the truth" that sink audits when four separate repositories drift apart.

Where Soveryne fits

This post describes exactly what Command is built to do. It's the product embodiment of the overlap dividend. Enroll the frameworks that apply to you, and Command drafts controls mapped to every framework requirement each one satisfies, so a single evidenced control is automatically counted toward GDPR, NIS2, DORA, ISO 27001, and more. Its framework-comparison view shows you, for any two frameworks, precisely where they overlap, so you can see the dividend before you bank it. Evidence collected once counts toward every audit it's relevant to; that's the whole design.

Practically: run your ISO 27001 program in Command, and your NIS2 and DORA posture is largely already evidenced rather than a second and third project. The Growth plan makes this explicit: unlimited frameworks, so adding the next law is a mapping exercise, not a new program.

And when you're deciding whether two obligations really are the same control (does NIS2's cryptography measure map to ISO 27001 Annex A 8.24?), Counsel answers from the frameworks and the ENISA mapping, cited, so your crosswalk is grounded in the source.

FAQ

How much do compliance frameworks actually overlap? Substantially. Most obligations across GDPR, NIS2, DORA, ISO 27001, SOC 2 and NIST CSF fall into about seven shared control domains: governance, inventory, risk, secure development, third-party, incidents, and evidence.

Can one control satisfy multiple frameworks? Yes. A single well-evidenced control like access control or encryption maps to requirements in GDPR, NIS2, DORA, ISO 27001, SOC 2 and NIST CSF at once, so the evidence is reused across every audit.

Is cross-framework mapping officially recognized? Yes. ENISA's June 2025 NIS2 guidance maps Article 21 to ISO 27001 and NIST CSF 2.0, and NIST publishes informative references to support cross-mapping. Regulators expect reuse.

What's the downside of a shared-control model? It takes more effort to design the mapping up front than a single-law project. But it dramatically lowers the marginal cost of every subsequent framework and prevents evidence drift.


Do the work once, prove it everywhere. See where your frameworks overlap (and evidence controls once across all of them) with Command; ground your crosswalk with cited answers from Counsel.

Sources