Part of Practice Engine
Applicability Matrix

Know exactly what applies, where.

Define which requirements apply to which entities, assets and data — so scope is explicit and you're never proving controls that don't apply or missing ones that do.

What it does

How Applicability Matrix works in GRAC

Scope by entity, asset and data type

draw the boundary clearly.

Mark requirements mandatory, optional or out of scope

with rationale captured.

Drive practices and audits from real applicability

no wasted effort on out-of-scope controls.

What you get

Outcomes

  • Defensible scope decisions, documented.
  • No wasted effort on out-of-scope controls.
  • A clear answer to "does this apply to us?"

See Applicability Matrix in action.