How frameworks work
A framework tells Vendorica which obligations to hold you to, which registers to keep, and what to ask for at each step.
A framework is a body of obligations you are working to — DORA, NIS2, ISO 27001, and so on. Enabling one in Vendorica changes three things:
- What you are held to. The framework’s requirements appear as controls you can assign, evidence and evidence gaps.
- Which registers you keep. Some regimes require a specific artefact in a specific shape — DORA’s Register of Information is the clearest example.
- What you are asked at each step. Classifying a vendor under DORA asks different questions from classifying one under ISO 27001, because the two regimes care about different things.
One control, several frameworks
Section titled “One control, several frameworks”Most organizations are working to more than one regime at once, and the obligations overlap heavily — a supplier due-diligence control is doing work for DORA, ISO 27001 and your own policy simultaneously.
Vendorica models that overlap directly: a control can satisfy requirements in several frameworks at the same time. You maintain the control once, and it counts everywhere it applies. Adding a second framework to an organization that already has one is therefore usually far less work than the first — much of the evidence you need is already there and simply needs mapping.
Turning a framework off
Section titled “Turning a framework off”Disabling a framework stops holding you to its requirements. It does not delete the controls, evidence or assessments you built while it was on — those belong to your organization, not to the framework, and a control mapped to two regimes keeps doing its job for the other one.