Custom Frameworks

Jamie Kandola
Jamie Kandola
  • Updated

About Custom Frameworks

Custom Frameworks lets you build your own compliance frameworks in ControlMap — beyond the standard ones it ships (NIST, SOC 2, CMMC, ISO) — for when a client needs a regional standard, an industry-specific regime, or a proprietary framework that isn't already in the library.

  • Build a framework once in your MSP portal, then publish it.
  • Publishing makes it available for your clients to import.
  • Once imported, it behaves like any other framework in the client's environment.

Where to find it

Custom Frameworks lives under the Frameworks item in the top navigation of your MSP portal.

The Frameworks list

The Frameworks page lists every custom framework you've built.

The Frameworks list in the MSP portal

Each row shows:

  • Logo, Title, and Description
  • # of Objectives
  • Created On, Last Published On, and Last Published By
  • Status — Draft until you first publish it, then Published

Each row's actions:

  • Publish (or Republish)
  • Edit framework details
  • Download objectives — exports the structure
  • Delete

Use Add Framework at the top of the list to create a new one.

Creating a framework

Click Add Framework to open the Create Framework panel and set:

  • Title (required)
  • Description (optional)
  • Framework Logo (optional — PNG, JPG, or BMP, max 2 MB)

Once created, you're taken straight into the builder to add structure.

The Create Framework panel

Building the framework structure

The builder defines the framework as a three-level hierarchy: Domains contain Levels, and Levels contain Objectives.

The framework builder — domain, level, objective, and scope

  • Click Add to insert a domain, then add levels and objectives within it.
  • Everything is editable inline, and you can drag items to reorder.
  • Numbering is suggested automatically (Domain 1, Level L1, Objective 1.1.1) and is editable.
  • Switch the objectives between Card and Table views.

Each objective has three things:

  • Description — free text describing the objective.
  • Scope — a label for what part of the client's environment the objective applies to, so related objectives can be grouped and configured together (for example Organization, Systems, or a specific process). Pick a value from the searchable Search scope picker or add your own; give it an optional description that explains the scope to clients; and mark it Required if clients must always include it. The description and Required setting belong to the scope value itself, so every objective that uses the same scope shares them.
  • Mapped Assessment Questions — the questions used to assess the objective (see below).

Importing objectives from a spreadsheet

Instead of building objectives by hand, you can bulk-import them from a spreadsheet:

  • Use Download Template at the top of the Frameworks list to get the CSV format (a sample file is also available inside the import wizard).
  • Create the framework first with Add Framework — it appears in the list as a Draft.
  • On the draft framework's row, choose Upload objectives to open the import wizard, which has three steps:
  • Upload File — choose your CSV (max 10 MB) and set the delimiter.
  • Map Fields — match each spreadsheet column to its ControlMap field, then Validate. Domain ID, Domain, Level ID, Level Name, Objective ID, Objective Name, and Scope are required; Objective Description and Scope Description are optional. (If you start from Download Template, the columns already line up.)
  • Import — once the file validates, Start Import adds the objectives to the framework.

The Import objectives wizard — Upload File, Map Fields, Import

Mapping assessment questions to an objective

Open an objective's Mapped Assessment Questions to choose the questions used to assess it.

Searching the assessment-question library to map questions

  • Search Assessment Questions — search the question library and select the questions to map.
  • Mapped Assessment Questions — the running list of what you've mapped, with a count and a per-item remove.

Click Save to keep your changes. The number of mapped questions shows on the objective in the builder.

Publishing a framework to your clients

When the framework is ready, click Publish and confirm — it becomes available for all of your clients to import.

The publish confirmation

When you edit a published framework and publish again, you choose how the update reaches clients:

  • Overwrite — replace the current version; the change is applied immediately to every client copy that imported it.
  • New Version — publish alongside the existing version; clients keep their current version and adopt the new one at their own pace.

Choosing Overwrite or New Version when republishing

Deleting a framework

Deleting a framework:

  • Permanently removes it and all of its objectives.
  • Retires it from new client imports.
  • Leaves clients that already imported it with their own copies.

Because it can't be undone, you type "delete" to confirm.

What your clients see

When you publish a custom framework, your clients find it in their New Framework screen (Frameworks → New Framework). A search box sits at the top, and the frameworks are organized into tabs:

  • All — every framework the client can import, standard and custom, in one list.
  • ControlMap — ControlMap's standard framework library (NIST, SOC 2, CMMC, ISO, and more).
  • Custom — the custom frameworks the client's MSP has published to them; your published frameworks appear here.
  • Imported — frameworks the client has already imported.

The client's New Framework screen — All view with search

The client imports it like any standard framework, choosing scope and — optionally — enabling a maturity assessment during import.

Importing the custom framework — scope and maturity assessment options

Once imported, it appears in the client's My Frameworks list with a "Managed in the MSP Admin Portal" marker, and its requirements appear under the framework's Objectives.

If you mapped assessment questions to the framework before publishing, the client's imported framework also shows an Assessment quick-link (and an Assessment tab) for completing that assessment. Frameworks published without mapped questions don't show it.

The imported custom framework in the client's My Frameworks list

If you republish as a New Version, the previous version stays in place and the new one is published alongside it. Clients already on the framework see an Update Available control; selecting it takes them to their New Framework screen to adopt the newer version when they're ready.

Update Available on a client's imported custom framework

Import Content imports the framework. Once it has more than one published version, Import Content first shows a Versions list so the client can choose which version to import — each version has its own Import Content, and versions they've already imported show as Already Setup.

The Versions list — clients choose which published version to import

Common questions

Where do I build custom frameworks?

In your MSP portal, under the Frameworks item in the top navigation.

How do my clients get a custom framework?

Publish it from the MSP portal. It then appears in each client's New Framework screen (on the All and Custom tabs) for them to import.

I changed a framework after publishing — how do my clients get the update?

Publish again, and choose:

  • Overwrite — apply the change to every client immediately, or
  • New Version — let clients keep their current version and adopt the update when they're ready (they'll see an Update Available control).

What happens if I delete a framework?

  • It's permanently removed, along with all of its objectives.
  • It's retired from new client imports.
  • Clients that already imported it keep their own copies.
  • It can't be undone, so you type "delete" to confirm.

Was this article helpful?

Yes! No