Frameworks
Readiness across every framework mapped in this workspace.
SOC 2
Trust Services Criteria
68%
In scope
Security, availability, confidentiality, processing integrity and privacy criteria for service organizations.
ISO 27001
Annex A controls
54%
Not in scope
Information security management system requirements, including risk treatment and Annex A controls.
GDPR
EU data protection
61%
Not in scope
Lawful basis, data subject rights, processor agreements and cross-border transfer safeguards.
HIPAA
Security & privacy rules
39%
Not in scope
Administrative, physical and technical safeguards for protected health information.
PCI DSS
Cardholder data security
27%
Not in scope
Requirements for protecting cardholder data across networks, applications and operations.