Paste a carrier application. See the controls each question tests.
A carrier's cyber application is a set of control requirements in disguise. Cyber Application Crosswalk reads the questions and shows, for each one, the ISO 27001:2022 controls, the SOC 2 criterion and the NIST CSF 2.0 outcome it points at, with the evidence an applicant would hand the carrier. Paste the questions one per line, or pick a held carrier. Every mapped row carries the source question beside it, so nothing is asserted that the application does not ask. The questions are read in this browser: nothing is uploaded while you map, and nothing leaves until you save.
- Paste the application questions, or pick a carrier. A carrier's questionnaire, one question per line, or the held Coalition application from the picker. The questions are read in this browser.
- You get the controls each question tests. The ISO 27001:2022 control, the SOC 2 criterion and the NIST CSF 2.0 outcome a question reaches, and the framework each belongs to.
- You get the evidence list per control. The artefacts an applicant would hand the carrier for that control, so the submission is not held up.
- It never rules on you or your client. It maps questions to controls and quotes the source question. Whether cover is offered, and on what terms, is the carrier's underwriting decision, never this tool's.

Paste the questions, or pick a carrier
A carrier's cyber application, one question per line, or the held Coalition application from the picker. A whole questionnaire at once, or a single line.
See the controls each question tests
Each question is read against the standards' text we hold for ISO 27001:2022, SOC 2 and NIST CSF 2.0, and the controls it reaches are shown with the source question beside every row.
Carry it to the submission
The evidence list per control, the held carriers ranked by the controls they ask, a two-carrier comparison, and a CSV of control, evidence and source question you drop into the submission file.
Why map the application, and not read three PDFs
The question a broker answers every week is which controls a carrier's application is really asking for, in the terms the applicant's own security team can evidence. The application is a public document; the controls sit in the frameworks the applicant already reports against. Cyber Application Crosswalk reads the questions, shows the controls each one reaches, and gives the evidence to gather, so a submission is not held up by a question nobody translated.