Compliance Officer Journey
You own frameworks, assessments, evidence, and audit readiness. This path assumes the security team has already connected accounts and run scans (Days 1–2 of the First 7 Days) — compliance scores are computed from that scan data, so coverage comes first.
Typical role: Compliance Officer, with Auditor accounts for external reviewers (see Roles, Teams & API Keys).
Stage 1 — Choose your frameworks
- Supported Frameworks — the full catalog (ISO 27001:2022, SOC 2, PCI DSS 4.0.1, NIST CSF 2.0, GDPR, DPDP Act, SEBI CSCRF, and more), all mapped through the SCF common-control library.
- Compliance & GRC overview — how one control maps to many frameworks, and how statuses become scores.
- Activate the one or two frameworks you actually answer to. Every additional framework is mostly free later — the common-control model means evidence and control status carry across.
You can now: explain to an auditor which framework versions you track and where the control library comes from.
Stage 2 — Read your posture
- Compliance Posture Dashboard — scores, gap analysis, and drift detection.
- Autonomous Compliance — how control statuses are derived automatically from scan findings, what the score weightings are, and when manual overrides are appropriate.
You can now: name your top gaps per framework and distinguish "failing" from "not assessed."
Stage 3 — Assess what scans can't see
- Interactive Assessments — questionnaire-based assessments (ISO 27001, SOC 2 Type II, NIST CSF, OWASP ASVS/SAMM, and more) with Yes/Partially/No scoring and PDF export.
- Use auto-fill to draft answers from platform data, then review each one — auto-filled answers carry confidence levels and are yours to confirm or correct.
You can now: produce a scored self-assessment for your primary framework.
Stage 4 — Build the evidence trail
- Evidence Hub — auto-collected evidence with quality scores and validity windows (cloud and scan evidence stays valid 90 days; assessment answers and policy documents, 365), plus manual upload for policies and screenshots.
- Run Collect All, then work the review queue: approve what's right, reject what isn't, replace what's expired.
- Turn material gaps into governed risks in the Risk Register so they get owners, treatment plans, and SLAs instead of living in a spreadsheet.
You can now: show, for any control, why it has its status — with dated evidence behind it.
Stage 5 — India-specific obligations
Skip this stage if you have no Indian regulatory exposure.
- DPDP Act (India) Privacy — readiness assessment, DPIA lifecycle, vendor due diligence, and the breach workflow with dual DPB and CERT-In reporting tracks and deadline watchdog. (Consent management and data-principal request handling are on the roadmap, not in the module today.)
- India Regulatory Readiness — how RBI expectations, SEBI CSCRF, and CERT-In directions map to platform capabilities, and the recommended deployment shape for regulated entities. Note: CSCRF audits and VAPT remain with CERT-In-empanelled firms — the platform maintains your evidence and posture between audits; it doesn't replace the auditor.
You can now: run a DPDP readiness check and show CSCRF-relevant evidence continuity between audit cycles.
Stage 6 — Face the audit
- Export the audit package for your framework from the Evidence Hub — up to four layers of proof per control: policy, procedure, technical proof, attestation.
- Generate executive and audit reports in PDF/HTML — Reports & AI Assistance.
- Give your external auditor an Auditor account: read-only access to evidence and reports, with export rights — Roles, Teams & API Keys.
You can now: hand an auditor a package and an account instead of a shared drive of screenshots.
Ongoing rhythm
- Weekly: check the Compliance Dashboard for drift and newly failing controls.
- Monthly: review the Evidence Hub for expiring evidence (technical evidence ages out on its validity window by design — fresh scans refresh it automatically).
- Quarterly: re-run interactive assessments and update the Risk Register treatment plans.
- Continuously: let scheduled scans keep the technical evidence current — that's what makes this posture continuous rather than an annual scramble.