Trusted security · Built from London
Products
Module 06

Compliance.

Continuous evidence for twelve frameworks.

Every finding from every other module is mapped automatically to the controls that govern you. No more spreadsheet ping-pong with auditors.

At a glance
Module
06
Cadence
Hourly
Scoring axes
4
Compliance
SOC 2 · ISO · PCI
What we monitor

Inside the module.

SOC 2
CC and supplementary trust-services criteria.
ISO 27001 & ISO 27002
Annex A controls + control objectives.
PCI DSS 4.0
Requirements 1, 2, 3, 4, 6, 8, 11 with sub-requirement attribution.
NIST CSF 2.0
GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER.
NIST SP 800-53
AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PS, RA, SA, SC, SI control families.
HIPAA
Security Rule administrative, physical and technical safeguards.
GDPR
Articles 5, 25, 28, 32, 33, 34 technical and organisational measures.
DORA
ICT risk-management framework, third-party risk, incident reporting.
CIS Controls v8
Implementation Groups 1, 2, 3.
Cyber Essentials Plus
UK NCSC five technical control categories.
Scoring

How this module contributes to your rating.

Each factor below is a normalised sub-score (0–100). The module score is the asset-weighted geometric mean, a single missing header on your billing endpoint shouldn’t weigh the same as one on a marketing page.

Control pass rate
percentage of mapped controls passing across active frameworks
Cross-framework impact
findings ranked by number of frameworks they touch
Audit readiness
evidence currency, how stale the supporting scan is
Drift
controls that moved from passing to failing in the period

See Compliance on your domain.

Get your free rating