Compliance management
From framework adoption to evidence — one record.
Adopt ISO 27001, NIS2, DORA — or any of the twelve frameworks in the library — as versioned, immutable packs. Decide applicability per requirement, map controls, collect evidence and track findings. Posture is derived from that record — never typed in.
| Requirement | Applicability | Status |
|---|---|---|
| Policies for information security | Applicable | Compliant |
| Management of technical vulnerabilities | Applicable · scoped | Partial |
| Information backup | Deferred → 2026-11 | Evidence due |
| Physical security monitoring | Not applicable | Documented |
| Supplier relationships | Applicable | Compliant |
Capabilities
What the module does
- 01
A twelve-framework library
ISO/IEC 27001, NIS2, DORA, GDPR, NIST CSF 2.0, NIST SP 800-53, SOC 2, PCI DSS, ISO/IEC 42001, the EU AI Act, the CRA and HIPAA — 833 requirements, published as immutable versions.
- 02
Version-pinned adoption
Frameworks are published as immutable versions. Your adoption is pinned to one and moves only by an explicit transfer; superseded adoptions stay as frozen history.
- 03
Applicability per requirement
Mark each requirement applicable or not, with a reason. Scope is explicit, reviewable and shows up in every posture number.
- 04
Your own requirements, same shape
Requirements you write yourself are stored exactly like a framework's — same applicability decision, same evidence rules, same findings, the same posture arithmetic. An ISMS is not a checklist of someone else's requirements.
- 05
Control library & templates
A tenant control library plus platform control templates you apply in bulk. Coverage of a requirement is an explicit, manual decision — never inferred from a file.
- 06
Evidence with recency rules
Attach files and records to controls and requirements. Recency rules flag evidence that needs revalidation before an auditor asks.
- 07
Findings & remediation
Raise findings against requirements, controls or assets; assign owners and due dates; drive them to closure with an audit trail.
- 08
Derived posture
Posture snapshots are frozen copies of derived state — adoption, applicability, coverage, evidence. Immutable once taken, explainable line by line; not a scoring engine.
One data model
How it connects to the rest of the workspace
CMDB →
Assets, IT services and business solutions are the compliance targets — no second inventory.
Risk →
Risks reference the same requirements and controls; a failed control shows up where the risk lives.
Governance →
Policies and procedures approved through review workflows are the documents your controls point to.
Questions we get asked
Can we adopt more than one framework?
Yes. Each framework has one active adoption per tenant; a tenant can run several frameworks side by side on the same assets and controls.
What happens when a framework version is updated?
Published versions are immutable. You move to the new version through an explicit transfer; the superseded adoption is kept as history, nothing is silently rewritten.
Can posture be edited by hand?
No. Posture is derived from the record. If a number looks wrong, the fix is in the adoption, applicability, control or evidence that produced it.
See it on your own frameworks
A walkthrough on a workspace set up for your sector. No trial sign-up, no credit card.