One control set, many frameworks
We meet you at the framework you’re being asked for.
Behind the scenes we build a single, unified control set and map it to each framework you’re accountable to. Pursue one today; add the next without starting over.
SOC 2
SOC 2 Type I & Type II
The AICPA Trust Services Criteria report your customers ask for when they trust you with their data.
- Trust Services Criteria scoping (Security, Availability, Confidentiality, Processing Integrity, Privacy)
- System description and control matrix
- Type I readiness, then Type II operating-period support
- CPA firm coordination through fieldwork
Best for: SaaS, cloud, and service providers selling to enterprises
PCI DSS
PCI DSS v4.0.1
The payment card industry’s data security standard for anyone who stores, processes, or transmits cardholder data.
- Cardholder data environment scoping and scope reduction
- SAQ selection and completion, or ROC readiness
- Targeted risk analyses and customized approach support
- Segmentation and quarterly scan coordination
Best for: merchants, payment processors, and service providers
ISO 27001
ISO/IEC 27001:2022
The international standard for an Information Security Management System (ISMS) — certifiable and recognized worldwide.
- ISMS scope, context, and leadership commitments
- Risk treatment plan and Statement of Applicability
- Annex A control implementation
- Internal audit and management review ahead of certification
Best for: organizations with international customers or partners
NIST
NIST CSF 2.0, SP 800-53 & SP 800-171
The U.S. government’s security frameworks — a flexible foundation for any program and a requirement for many federal contracts.
- CSF 2.0 current and target profiles (Govern, Identify, Protect, Detect, Respond, Recover)
- 800-53 control baselines for federal and regulated workloads
- 800-171 System Security Plan and POA&M for CUI
- Maturity scoring leadership can track over time
Best for: federal contractors, critical infrastructure, and anyone wanting a strong baseline
HIPAA
HIPAA Security Rule
Administrative, physical, and technical safeguards for electronic protected health information (ePHI).
- HIPAA security risk analysis, as the rule requires
- Safeguard implementation and documentation
- Business Associate Agreement review
- Breach response and workforce training programs
Best for: covered entities, business associates, and health tech
HITRUST
HITRUST CSF — e1, i1 & r2
A certifiable framework that harmonizes HIPAA, NIST, ISO, PCI, and more — increasingly required across healthcare.
- Choosing the right assessment: e1, i1, or risk-based r2
- Readiness assessment and scoping in MyCSF
- Policy, procedure, and implementation maturity guidance
- Validated assessment services delivered with the independence HITRUST requires
Best for: healthcare organizations and their technology vendors
Unified control framework
Why mapping once saves you a year later.
The same core disciplines — access control, change management, logging, vulnerability management, vendor risk, incident response, training — show up in every framework above. We implement each discipline once, document it in a way every auditor can follow, and keep a crosswalk that shows which requirement each control satisfies.
The result: when a new customer asks for ISO after you’ve finished SOC 2, you’re closing a short list of gaps rather than starting a new program.
Disciplines we map across frameworks
- Governance, policy, and risk management
- Identity and access management
- Asset, configuration, and change management
- Logging, monitoring, and incident response
- Vulnerability and patch management
- Vendor and third-party risk
- Business continuity and disaster recovery
- Security awareness and onboarding
Juggling more than one framework?
Tell us which ones are on your plate and we’ll show you how much overlap you can take advantage of.