| SOC 2 (TSC 2017) |
Type II |
Control monitoring for logical access, change management and system operations |
Continuous control status, exception register, evidence packets |
| ISO/IEC 27001:2022 |
Certified |
Annex A technical control coverage with automated gap reporting |
SoA mapping export, control effectiveness history |
| NIST CSF 2.0 |
Aligned |
Function-level scoring across Govern, Identify, Protect, Detect, Respond, Recover |
Maturity scorecard, trend over 24 months |
| NIST SP 800-53 Rev 5 |
FedRAMP High |
Control inheritance statements and a customer responsibility matrix |
Inheritance letter, POA&M extract |
| PCI DSS v4.0 |
Level 1 SP |
File integrity monitoring, log retention, segmentation validation evidence |
AoC, responsibility matrix, quarterly evidence pack |
| HIPAA Security Rule |
BAA offered |
PHI discovery, access monitoring and breach investigation timelines |
Access reports, disclosure accounting extracts |
| GDPR / UK GDPR |
Processor, DPF certified |
Data discovery, residency enforcement, subject request support |
DPA, TIA, records of processing extract |
| DORA (EU financial entities) |
Contractually aligned |
ICT incident classification, register of information fields, resilience testing |
Incident register export, subcontracting chain |
| NIS2 (EU essential entities) |
Contractually aligned |
24-hour early-warning workflow and supply chain risk reporting |
Notification timeline export |
| CMMC 2.0 Level 2 |
Supports assessment |
CUI marking, boundary monitoring and audit record protection |
Practice-level evidence mapping |
| APRA CPS 234 / CPS 230 |
Aligned |
Information asset classification and testing evidence for regulated entities |
Control testing register |
| CIS Critical Controls v8.1 |
Aligned |
Implementation group scoring across all 18 controls |
IG1–IG3 scorecard, per-safeguard status |