BlogProduct updates
September 28, 2026

Introducing the Vanta Control Framework: One lens for every framework

Written by
Spencer Caton
Sr. Product Manager
Reviewed by
No items found.

Accelerating security solutions for small businesses 
‍

Tagore offers strategic services to small businesses. 

A partnership that can scale 
‍

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors
‍

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Sometimes, growth can feel like a gift and a curse. As you scale, compliance gets harder. Standard and custom frameworks add up, spreadsheets multiply, and it becomes difficult to answer what you’ve committed to, what’s actually implemented, and whether you’re covered across all frameworks. Teams end up rebuilding the same mapping in spreadsheets, running gap analysis framework by framework, and stitching together posture updates before every leadership conversation.

‍

Many GRC leaders turn to common control frameworks (CCFs)—unified libraries of security and compliance rules that satisfy many laws and standards at once—to reduce duplicate work, establish a single source of truth, and run cleaner audits. But CCFs often require organizations to restructure their programs and abandon the framework-specific structures they already work in. 

‍

Enter the Vanta Control Framework (VCF).

‍

The VCF gives GRC teams one place to manage standard and custom controls across every framework. But unlike with a CCF, the VCF doesn’t require you to restructure your entire program. Instead, the VCF is a layer that sits on top of your framework controls, grouping what your frameworks have in common so you can put controls in place and report on your posture anytime, without losing the details specific to each framework underneath.  

‍

How the Vanta Control Framework works

The VCF is a set of common control objectives, pre-mapped to 14 frameworks. 

‍

The VCF is not a replacement control set that overrides your framework or custom controls. Instead, think of the VCF as a lens for viewing all your controls from a single source that also lets you run workflows across all your controls. 

‍

Framework controls map to common controls via many-to-many, not a forced collapse into one generic control—so you keep the nuance where it matters and aggregate where it helps. This way, you can operationalize shared controls consistently, focus on what's unique to each framework, and maintain a single source of truth for audit readiness and executive reporting. With the VCF, you not only get the consolidation of your controls, but also the Vanta tests, policies, and evidence mappings that go within a single organized view rolled by a common control layer.

‍

Here’s what else you need to know about the VCF:

‍

It’s built by practitioners, for practitioners. Vanta’s in-house GRC experts designed the common control library, which means it reflects how programs are actually run.

‍

Works for every framework, whether standard or custom. The VCF offers Vanta’s most popular out-of-the-box frameworks pre-mapped by our in-house experts, such as SOC 2, ISO 27001, HIPAA, and GDPR. The Vanta Agent maps all other controls, including custom controls, so you can extend coverage to the frameworks unique to your company. 

‍

Adapts to and grows with your program. As you add frameworks to your program, VCF-supported frameworks get pre-designed mappings and unsupported frameworks get agentic recommendations. That way, nothing lives outside the program. Plus, as we continue to add framework support to the VCF, you'll see more and more coverage.   

‍

What you can do with the VCF today

The VCF is available today. Here’s how you can use it to start seeing impacts on your program:

 

  • Eliminate duplicate work: The VCF consolidates overlapping framework controls into one view of your objectives and current posture. Where several controls map to the same security area, it surfaces whether to broaden, consolidate, or create—a built-in check on program hygiene.
  • Report on posture: No more stitching together updates from five frameworks before every leadership conversation—the VCF provides status updates by domain and function, so you’re sharing a consistent, up-to-date narrative.
  • Improve audit readiness: View controls, evidence, risks, and issues automatically consolidated in the common control layer, making it easier to identify potential coverage gaps before an audit.

‍

What’s next: From the reporting layer to the operating layer

This is phase one. In Public Preview, the VCF already gives you a unified lens across your program—grouping overlapping controls, consolidating related evidence, risks, and issues, surfacing potential audit gaps, and reporting on posture across frameworks.

‍

Early next year, the VCF will go deeper by becoming the layer your program operates on. Teams will be able to define one or more implementations within a common control and map evidence directly to specific requirements and common controls.

‍

For example, ISO 27001 and HIPAA may share the same common control objective but require different implementations or evidence. With the VCF, teams will manage those differences within one common structure—and ensure auditors see the implementation context and evidence relevant to their specific framework.

‍

The VCF will also help teams evaluate evidence coverage by assessing a control’s objective and current evidence mappings, identifying where coverage may be incomplete, and recommending additional evidence. This will make it easier to address potential gaps without manually reviewing and mapping evidence in spreadsheets.

‍

And for organizations that already operate from their own common control framework, the VCF will provide a path to bring that CCF into the common-control layer in Vanta, so they can build on the program they already have rather than start over.

‍

Together, these capabilities move VCF beyond showing how a program is performing to helping teams operate controls, strengthen evidence coverage, and prepare for audits from one connected structure.

‍

See how the VCF could impact your program. Request a demo.

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.