Dataset · Framework ladder
Adding compliance frameworks: the framework ladder for six AI compliance platforms
By the Signal Desk, AI Compliance Compare · Reviewed 2026-09-29
Short answer
Three entry plans are published with a one-framework scope (Scytale Build Starter, Vanta Essentials, Drata Foundation, which also caps at 50 FTEs). Sprinto’s Foundation plan states 25+ frameworks automated out of the box. Scytale and Sprinto are the two vendors that describe reusing controls across frameworks. Comp AI quotes per framework; Delve publishes no plans.
What does each entry plan cover?
| Platform | Entry plan | Entry framework scope | How you add more | Cross-mapping | Stated total | Source |
|---|---|---|---|---|---|---|
| Scytale | Build Starter | 1 framework | Add-ons; Scale plan adds custom frameworks | Stated: control cross-mapping | 80+ | Source: Scytale: pricing, Scytale: all frameworks · Read 2026-09-29 |
| Vanta | Essentials | One framework | Higher plans (Plus, Professional, Enterprise); custom frameworks available | Not stated on pages reviewed | 35+ | Source: Vanta: pricing, Vanta: additional frameworks · Read 2026-09-29 |
| Sprinto | Foundation | 25+ frameworks automated out of the box | 200+ digitized frameworks; Growth adds programmable monitors and custom workflows | Stated: common control framework (set up once, reuse) | 200+ | Source: Sprinto: pricing, Sprinto: frameworks · Read 2026-09-29 |
| Comp AI | No named plans | Quoted per framework | Frameworks are a stated pricing factor | Not stated on pages reviewed | 12 named | Source: Comp AI: pricing · Read 2026-09-29 |
| Drata | Compliance Automation Foundation | 1 pre-mapped framework (SOC 2, ISO 27001, Cyber Essentials, HIPAA or GDPR), up to 50 FTEs | Additional frameworks as add-ons; GRC Advanced allows any framework | Not stated on pages reviewed | 30+ | Source: Drata: plans, Drata: frameworks · Read 2026-09-29 |
| Delve | No plans published | Not published | Not published | Not stated on homepage | 7 named | Source: Delve homepage · Read 2026-09-29 |
Which frameworks does each platform name?
| Framework | Scytale | Vanta | Sprinto | Comp AI | Drata | Delve |
|---|---|---|---|---|---|---|
| SOC 2 | Named | Named | Count only | Named | Named | Named |
| SOC 1 | Named | Not named | Count only | Named | Not named | Not named |
| ISO 27001 | Named | Named | Count only | Named | Named | Named |
| ISO 42001 | Named | Named | Count only | Named | Named | Named |
| HIPAA | Named | Named | Count only | Named | Named | Named |
| GDPR | Named | Named | Count only | Named | Named | Named |
| PCI DSS | Named | Named | Count only | Named | Named | Named |
| CCPA | Named | Not named | Count only | Named | Named | Not named |
| FedRAMP | Not named | Named | Count only | Named | Named | Named |
| CMMC | Named | Named | Count only | Not named | Named | Not named |
| HITRUST | Not named | Named | Count only | Not named | Named | Not named |
| NIS2 | Not named | Named | Count only | Not named | Named | Not named |
| DORA | Checklist page | Named | Count only | Not named | Named | Not named |
| EU AI Act | Named | Named | Count only | Not named | Not named | Not named |
| NIST CSF 2.0 | Not named | Named | Count only | Not named | Not named | Not named |
| NIST AI RMF | Not named | Named | Count only | Not named | Named | Not named |
| ISO 9001 | Named | Not named | Count only | Named | Not named | Not named |
| Cyber Essentials | Named | Not named | Count only | Not named | Named | Not named |
| Essential Eight | Not named | Named | Count only | Not named | Not named | Not named |
| CPS 234 | Not named | Named | Count only | Not named | Not named | Not named |
Sprinto states 200+ frameworks digitized and 25+ automated out of the box, but the pages reviewed did not list them by name.
Not named does not mean unsupported. Scytale names Cyber Essentials as Cyber Essentials Plus, and publishes a DORA checklist page rather than listing DORA as covered.
What should you ask before buying for framework one?
- Which frameworks are in the entry plan, and what does framework two cost as an add-on?
- Are controls mapped once and reused, or rebuilt per framework?
- Does a second framework mean a second auditor, and who arranges it?
- Which evidence requests overlap between your first and second framework, and does the platform show the overlap?
- Is there a headcount cap on the entry plan (Drata Foundation publishes up to 50 FTEs)?
Questions about adding frameworks
Which platform states the most frameworks?
Sprinto states 200+ digitized frameworks, Scytale 80+, Vanta 35+ and Drata 30+. Comp AI names 12 on its pricing page and Delve names 7 on its homepage.
What is control cross-mapping?
Mapping one internal control to the matching requirements in several frameworks, so a single piece of evidence can satisfy all of them. Scytale states cross-mapping; Sprinto describes a common control framework.
Which entry plans cover only one framework?
Scytale Build Starter, Vanta Essentials and Drata Compliance Automation Foundation each list one framework.
Keep reading
- Ranking
Framework depth is 16% of the weighted total.
- Agents vs humans
Who does the extra work a second framework creates.
- Platform profiles
Plans, frameworks and expert models per vendor.
- Stack builder
Weight framework depth higher and re-rank.
- Scoring
How framework claims are scored.
Editorial assessment. Desk research from public vendor material, last reviewed 2026-09-29.