Skip to main content

Supported Frameworks

The compliance engine is built on the Secure Controls Framework (SCF) as a common-control backbone: you implement a control once, and it maps out to every framework that references it. That's why evidence collected for one framework automatically advances the others.

Framework catalog

Frameworks mapped through the SCF backbone:

FrameworkDomain
SOC 2 (AICPA Trust Services Criteria)Service-organization trust
ISO/IEC 27001:2022Information security management
ISO/IEC 27002:2022Security controls
ISO/IEC 27701Privacy information management
ISO/IEC 42001:2023AI management systems
PCI DSS 4.0.1Payment-card security
NIST CSF 2.0Cybersecurity framework
NIST SP 800-53 Rev 5Security & privacy controls
NIST SP 800-171 Rev 2 / Rev 3Controlled unclassified information
NIST Privacy FrameworkPrivacy
CIS Controls v8.1Baseline cyber hygiene
OWASP Top 10 (2021)Application security
EU GDPREU data protection
HIPAAUS healthcare privacy & security

Additional frameworks with dedicated assessment modules:

FrameworkWhere
India DPDP Act, 2023DPDP Act (India) Privacy — readiness, DPIA, SDF, vendor due diligence, breach workflow
EU AI Act & NIST AI RMFAI Governance — risk-tier classification, FRIA, assessments
OWASP ASVS 5.0Application security verification assessments
OWASP API Security Top 10API security assessments
NIST SSDFSecure software development
OWASP SAMMSoftware assurance maturity
DevSecOps maturityPipeline & practice maturity
Insider threatInsider-risk program assessment

How mappings work in practice

  • One control, many frameworks. Marking an SCF control implemented updates the posture of every mapped framework at once — the compliance dashboard shows the per-framework effect.
  • Evidence reuse. Evidence attached in the Evidence Hub is control-mapped, so a single artifact (say, your access-review export) counts toward SOC 2, ISO 27001, and NIST CSF simultaneously.
  • Scan findings map to controls. Cloud, code, container, and Kubernetes findings link to the controls they affect, so technical drift shows up as compliance drift.
Start with one anchor framework

Pick the framework your customers or regulators actually ask for (commonly SOC 2 or ISO 27001), get it green, and let the SCF mappings pull the others along — rather than assessing everything at once.