Nobody Complies With a PDF. Turn It Into Tasks.

You do not comply with a standard by reading it. You comply by doing the specific things it asks, one by one, with someone accountable for each. Extract those obligations into a to-do list the team can track.

Sorena AI TeamProduct and Strategy4 min read

A PDF is not compliance

A framework arrives as a document: a standard, a directive, or a customer requirement. Reading and filing it changes nothing on its own.

Compliance requires doing the specific things the framework asks and proving you did them. Extract each applicable obligation into a task with an owner.

Count the obligations, not the pages

ISO/IEC 27001 has 93 controls in Annex A of its 2022 edition. They are reference controls, not 93 automatic implementation tasks for every organization. Each organization evaluates them through risk treatment, selects those it needs, and documents inclusions and exclusions in the Statement of Applicability.

NIST publishes SP 800-53 supplemental mappings for comparison with ISO/IEC 27001 and warns that the mappings are not automatically one-to-one. A control theme can support more than one framework, but the mapping still needs judgment. Count the decisions, owners, and evidence. For a detailed crosswalk, see NIST 800-53 vs ISO 27001.

Regulation has the same shape

Regulations also need to be translated into work. The European Commission describes NIS2 as requiring essential and important entities to take appropriate cybersecurity risk-management measures. Article 21(2) lists 10 minimum measure areas, from risk analysis and incident handling to supply-chain security and business continuity.

Each area can require policies, controls, and evidence, with proportionality and sector context still mattering. The directive states what entities must address but does not assign the work inside your organization. Teams must make that translation and update it when the rules change. A live regulatory watch helps track those changes. ESG and sustainability rules need the same ownership.

Show the requirement becoming work

A useful requirement record has six fields. Source requirement, plain-language obligation, control or task, owner, due date, and evidence. Add status and reviewer, and the team can run the work from the record.

The extraction pipeline ingests the framework, splits obligations, maps controls, assigns owners, requests evidence, and produces an audit package. Each task should trace to the sentence it implements and each piece of evidence to the obligation it proves.

The translation is manual, and that is the tax

Somebody has to extract the requirements. The manual process is slow: read each requirement, decide what it means in context, assign an owner, set a deadline, and track it to completion. Multiply that by 93 ISO 27001 Annex A controls to evaluate, or 10 NIS2 Article 21 measure areas that expand into policies, controls, and evidence, across every framework you carry.

Teams spend weeks sorting the work. They reread the same clauses, argue over ownership, and lose track of which obligations are covered or still open. Rebuilding the translation for every assessment wastes that work.

Extract once and maintain the mapping

Structure the work when you first assess the framework, then maintain the mapping. Each applicable obligation or selected control gets a responsible person, a status, and attached evidence.

Sorena Assessment ingests a framework, standard, or questionnaire, extracts the requirements, maps them to your context, assigns actions, and tracks each one to completion. Teams can work through ISO 27001 Annex A as a set of owned decisions and tasks.

One source under every task

Tasks need a shared source. When obligations live in scattered spreadsheets and inboxes, versions diverge and answers go stale. A single control may be tracked three ways by three people, with no clear current record.

Each extracted obligation in Sorena is grounded in the Single Source of Truth: one canonical record of the requirement, owner, status, and evidence. The same control or evidence can support ISO 27001, NIS2, and other frameworks where their requirements overlap.

A framework that actually moves

Treat compliance as owned work. When obligations are extracted and tracked in one place, you can see what is done, what is open, and who is responsible.

Start with one framework. Extract its applicable obligations into tasks, assign the owners, and attach the evidence. People comply by finishing and proving the work the framework requires, not by filing the PDF.

Frequently asked questions

Why isn't reading and understanding a framework enough?+

Reading a framework does not implement its requirements. [ISO 27001:2022](/artifacts/global/iso-27001) has 93 Annex A reference controls to consider through risk treatment and the [Statement of Applicability](/artifacts/global/iso-27001/statement-of-applicability-evidence-workflow). [NIS2](/artifacts/eu/nis2-directive) [Article 21(2)](/artifacts/eu/nis2-directive/article-21-control-by-control-evidence) lists 10 minimum cybersecurity risk-management measure areas for covered entities. Assign each applicable requirement an owner, task, evidence expectation, and review date.

Do we have to redo this mapping for every framework?+

No. Sorena Assessment extracts requirements once and grounds them in the Single Source of Truth. Because the same control, evidence, or risk-management activity can often support [ISO 27001](/artifacts/global/iso-27001), [NIS2](/artifacts/eu/nis2-directive), and other frameworks, you map and answer it once, then reuse it where the overlap is real instead of rebuilding the work each time.

Who owns the tasks once a framework is extracted?+

People do. Sorena assigns each obligation to a responsible owner with a status and attached evidence. The system handles extraction, mapping, and tracking; humans make the decisions and close the items. Every task is traceable back to the exact requirement it satisfies.

Sources

Share

See Sorena do the work

Book a demo and watch one real compliance workflow go from question to audit-ready output.