Skip to content
Frameworks and regulations

How frameworks work

A framework tells Vendorica which obligations to hold you to, which registers to keep, and what to ask for at each step.

Updated

A framework is a body of obligations you are working to — DORA, NIS2, ISO 27001, and so on. Enabling one in Vendorica changes three things:

  1. What you are held to. The framework’s requirements appear as controls you can assign, evidence and evidence gaps.
  2. Which registers you keep. Some regimes require a specific artefact in a specific shape — DORA’s Register of Information is the clearest example.
  3. What you are asked at each step. Classifying a vendor under DORA asks different questions from classifying one under ISO 27001, because the two regimes care about different things.

Most organizations are working to more than one regime at once, and the obligations overlap heavily — a supplier due-diligence control is doing work for DORA, ISO 27001 and your own policy simultaneously.

Vendorica models that overlap directly: a control can satisfy requirements in several frameworks at the same time. You maintain the control once, and it counts everywhere it applies. Adding a second framework to an organization that already has one is therefore usually far less work than the first — much of the evidence you need is already there and simply needs mapping.

Disabling a framework stops holding you to its requirements. It does not delete the controls, evidence or assessments you built while it was on — those belong to your organization, not to the framework, and a control mapped to two regimes keeps doing its job for the other one.

  1. DORA

    Who it binds, and what Vendorica keeps for you

  2. Registers of Information

    The Article 28(3) register, and how to produce one you can defend