[{"data":1,"prerenderedAt":1864},["ShallowReactive",2],{"\u002Fblog\u002F2026-09-14-pci-vulnerabilities":3,"blog-surround-2026-09-14-pci-vulnerabilities":334,"explore-glossary-none-\u002Fblog\u002F2026-09-14-pci-vulnerabilities":345,"explore-topics-none-\u002Fblog\u002F2026-09-14-pci-vulnerabilities":1086,"explore-hub-none":6,"explore-compare-vs-\u002Fblog\u002F2026-09-14-pci-vulnerabilities":1087,"explore-compare-\u002Fblog\u002F2026-09-14-pci-vulnerabilities":1381,"explore-blog-none-\u002Fblog\u002F2026-09-14-pci-vulnerabilities":1554,"explore-industry-none":1779},{"id":4,"title":5,"api":6,"authors":7,"body":13,"category":322,"date":323,"description":324,"extension":325,"faq":6,"features":6,"fixes":6,"highlight":6,"image":326,"improvements":6,"meta":328,"navigation":329,"path":330,"seo":331,"stem":332,"__hash__":333},"posts\u002F3.blog\u002F2026-09-14-pci-vulnerabilities.md","PCI Vulnerabilities: Finding Them Is Easy — Proving You Fixed Them Is the Hard Part",null,[8],{"name":9,"to":10,"avatar":11},"Justin Leapline","https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fjustinleapline\u002F",{"src":12},"\u002Fimages\u002Fjustinleapline.png",{"type":14,"value":15,"toc":303},"minimark",[16,20,23,26,31,34,63,66,70,76,82,88,94,100,106,110,115,118,122,125,148,151,155,158,162,165,169,176,180,183,200,203,207,210,213,217,220,237,240,244,247,250,254,271,274,279,290,297],[17,18,19],"p",{},"PCI vulnerability requirements look simple on a slide: scan, fix, rescans until clean.",[17,21,22],{},"In practice, teams drown in CVEs, argue about false positives, lose track of which hosts are in CDE scope, and scramble for evidence the week the QSA arrives. The scanners worked. The program didn't.",[17,24,25],{},"Vulnerability management for PCI is less about discovering more issues and more about running a closed loop: inventory → scan → triage → remediate → verify → evidence — with scope that matches reality.",[27,28,30],"h2",{"id":29},"what-pci-actually-expects-in-plain-language","What PCI actually expects (in plain language)",[17,32,33],{},"Depending on your SAQ or ROC path, you are generally expected to:",[35,36,37,46,53,60],"ul",{},[38,39,40,41,45],"li",{},"Run ",[42,43,44],"strong",{},"internal and external"," vulnerability scanning on a defined cadence.",[38,47,48,49,52],{},"Use an ",[42,50,51],{},"Approved Scanning Vendor (ASV)"," for external scans where required.",[38,54,55,56,59],{},"Address ",[42,57,58],{},"high-risk \u002F critical"," issues on a timeline that matches the standard and your policies.",[38,61,62],{},"Keep proof: scan reports, exceptions with rationale, remediation tickets, and clean rescans.",[17,64,65],{},"The standard does not reward the largest backlog. It rewards a program that can show the environment was assessed, risk was handled, and verification happened.",[27,67,69],{"id":68},"where-programs-break","Where programs break",[17,71,72,75],{},[42,73,74],{},"Scope fog."," If you can't say which systems are in scope for PCI, every scan result is debatable. Shadow assets and \"temporary\" cloud projects quietly become reportable gaps.",[17,77,78,81],{},[42,79,80],{},"Scan ≠ program."," Exporting a PDF from the ASV portal is not vulnerability management. Without owners, SLAs, and verification, it's a screenshot collection.",[17,83,84,87],{},[42,85,86],{},"Severity theater."," Treating every CVSS 9.8 as equal — including issues on non-exploitable paths or out-of-scope segments — burns the team and trains leadership to ignore the queue.",[17,89,90,93],{},[42,91,92],{},"Exception limbo."," Risk acceptances without expiry, owner, or compensating control become permanent holes that still look \"managed\" in a spreadsheet.",[17,95,96,99],{},[42,97,98],{},"Rescan amnesia."," Fixed in prod, never rescanned, still open in the auditor's eyes. If it isn't verified, it isn't closed.",[17,101,102,105],{},[42,103,104],{},"Tool sprawl."," Cloud provider findings, container scanners, ASV output, and endpoint agents all speak different languages. Nobody consolidates into one remediation spine.",[27,107,109],{"id":108},"build-a-pci-ready-vuln-loop","Build a PCI-ready vuln loop",[111,112,114],"h3",{"id":113},"_1-freeze-a-living-inventory","1. Freeze a living inventory",[17,116,117],{},"Maintain an authoritative list of in-scope assets: hosts, URLs, APIs, containers, and shared services that touch account data or segment the CDE. Inventory drift is the root cause of most \"surprise\" ASV failures.",[111,119,121],{"id":120},"_2-separate-discovery-from-duty","2. Separate discovery from duty",[17,123,124],{},"Let scanners find everything they're good at finding. Then map each finding to:",[35,126,127,132,137,142],{},[38,128,129],{},[42,130,131],{},"In scope or not",[38,133,134],{},[42,135,136],{},"Exploitability in your environment",[38,138,139],{},[42,140,141],{},"Owner and due date",[38,143,144,147],{},[42,145,146],{},"Fix, mitigate, or accept"," (with expiry)",[17,149,150],{},"PCI cares that in-scope, relevant risk is handled — not that you personally remediated every informational finding on a marketing microsite.",[111,152,154],{"id":153},"_3-triage-with-a-written-rulebook","3. Triage with a written rulebook",[17,156,157],{},"Write down how you promote or demote severity: network exposure, auth boundaries, compensating controls, asset criticality. When the QSA asks why a CVSS critical was treated as medium, you answer with policy — not improvisation.",[111,159,161],{"id":160},"_4-remediate-through-the-same-system-engineering-already-uses","4. Remediate through the same system engineering already uses",[17,163,164],{},"If fixes live only in the scanner UI, they die there. Ticket the work in Jira\u002FLinear (or equivalent), link the CVE and asset, and require a verification note on close.",[111,166,168],{"id":167},"_5-rescan-like-its-part-of-the-fix","5. Rescan like it's part of the fix",[17,170,171,172,175],{},"Closing a ticket should mean: change deployed ",[42,173,174],{},"and"," scanner\u002FASV no longer reports the issue (or an approved exception is on file). Build rescans into the definition of done.",[111,177,179],{"id":178},"_6-keep-evidence-boring-and-complete","6. Keep evidence boring and complete",[17,181,182],{},"For each cycle, retain:",[35,184,185,188,191,194,197],{},[38,186,187],{},"Scope list used for the scan",[38,189,190],{},"Raw and attested reports (ASV and internal)",[38,192,193],{},"Ticket exports for highs\u002Fcriticals",[38,195,196],{},"Exceptions with approver and expiry",[38,198,199],{},"Final clean \u002F residual-risk summary",[17,201,202],{},"Boring evidence is good evidence. Creative storytelling is what happens when the loop was broken.",[27,204,206],{"id":205},"asv-specific-reality-checks","ASV-specific reality checks",[17,208,209],{},"External ASVs will fail you for issues that feel \"not our app\" — shared hosting headers, mail servers, forgotten subdomains. Treat DNS and attack-surface hygiene as part of PCI prep, not a last-minute surprise.",[17,211,212],{},"Schedule ASV runs early enough to allow remediation + rescan before deadlines. A first scan three days before card-brand reporting is a self-inflicted incident.",[27,214,216],{"id":215},"exceptions-without-self-owning","Exceptions without self-owning",[17,218,219],{},"Some findings can't die on the PCI timeline (vendor dependency, platform limitation). An acceptable exception includes:",[35,221,222,225,228,231,234],{},[38,223,224],{},"Precise finding and asset",[38,226,227],{},"Business rationale",[38,229,230],{},"Compensating control",[38,232,233],{},"Named approver",[38,235,236],{},"Expiry and revisit date",[17,238,239],{},"An exception without an ending date is just an open vulnerability with better formatting.",[27,241,243],{"id":242},"what-good-looks-like-to-a-qsa","What \"good\" looks like to a QSA",[17,245,246],{},"You can explain scope. You can show cadence. You can show that highs were fixed or formally accepted. You can show rescans. You aren't discovering brand-new in-scope subnets in the interview.",[17,248,249],{},"That bar is operational excellence, not heroics.",[27,251,253],{"id":252},"start-this-sprint","Start this sprint",[35,255,256,259,262,265,268],{},[38,257,258],{},"Reconcile ASV targets with your current DNS and inventory.",[38,260,261],{},"Define SLA by severity for in-scope assets only.",[38,263,264],{},"Require rescan proof on ticket close.",[38,266,267],{},"Expire every standing exception older than 90 days — renew deliberately or fix.",[38,269,270],{},"Assign a single owner for the vuln loop (not \"the security team\").",[17,272,273],{},"Do those five and the next ROC\u002FSAQ conversation gets shorter — because the story is already true in the tooling.",[17,275,276],{},[42,277,278],{},"Need vulnerability management that stays audit-ready between ASV runs?",[17,280,281,282,289],{},"At ",[283,284,288],"a",{"href":285,"rel":286},"https:\u002F\u002Fepiski.com",[287],"nofollow","Episki",", we help teams connect scanning, ownership, and evidence so PCI requirements show up as an operated program — not a quarterly fire drill.",[17,291,292],{},[283,293,296],{"href":294,"rel":295},"https:\u002F\u002Fepiski.com\u002Fcontact",[287],"Let's talk →",[17,298,299],{},[300,301,302],"em",{},"Scanners find vulnerabilities. Programs close them — and can prove it.",{"title":304,"searchDepth":305,"depth":305,"links":306},"",2,[307,308,309,318,319,320,321],{"id":29,"depth":305,"text":30},{"id":68,"depth":305,"text":69},{"id":108,"depth":305,"text":109,"children":310},[311,313,314,315,316,317],{"id":113,"depth":312,"text":114},3,{"id":120,"depth":312,"text":121},{"id":153,"depth":312,"text":154},{"id":160,"depth":312,"text":161},{"id":167,"depth":312,"text":168},{"id":178,"depth":312,"text":179},{"id":205,"depth":305,"text":206},{"id":215,"depth":305,"text":216},{"id":242,"depth":305,"text":243},{"id":252,"depth":305,"text":253},"security","2026-09-14","ASV scans and internal vuln programs generate noise by default. Here's how to run PCI vulnerability management so findings become remediation, evidence stays audit-ready, and scope doesn't quietly expand.","md",{"src":327},"\u002Fimages\u002Fblog\u002Fautonomous-grc.webp",{},true,"\u002Fblog\u002F2026-09-14-pci-vulnerabilities",{"title":5,"description":324},"3.blog\u002F2026-09-14-pci-vulnerabilities","3jhqGZFjYoofS7xYLdlwXh6hJOHgzR-JZPVvKSXrVDk",[335,340],{"title":336,"path":337,"stem":338,"description":339,"children":-1},"Securing the Pipeline: Why DevSecOps Belongs on Your GRC Roadmap","\u002Fblog\u002F2026-09-08-risk-assessments","3.blog\u002F2026-09-08-risk assessments","CI\u002FCD pipelines hold privileged access to your code, secrets, and production environment. Here's what secure pipeline practices actually look like, and why they matter for compliance.",{"title":341,"path":342,"stem":343,"description":344,"children":-1},"Agent-first GRC: what changes when AI runs the program","\u002Fblog\u002Fagent-first-grc","3.blog\u002Fagent-first-grc","Most GRC tools added AI as a feature. Agent-first GRC treats agents as the operator — drafting policies, answering questionnaires, and running the program with humans approving the work that matters.",[346,925],{"id":347,"title":348,"body":349,"description":304,"extension":325,"lastUpdated":905,"meta":906,"navigation":329,"path":907,"relatedFrameworks":908,"relatedTerms":915,"seo":919,"slug":922,"stem":923,"term":354,"__hash__":924},"glossary\u002F8.glossary\u002Faccess-control.md","Access Control",{"type":14,"value":350,"toc":891},[351,355,358,362,365,391,395,401,407,413,419,423,426,432,449,455,469,475,486,490,493,550,554,557,571,575,578,601,605,608,658,662,665,785,788,791,820,824,831,834,871,874,877,880,884],[27,352,354],{"id":353},"what-is-access-control","What is Access Control?",[17,356,357],{},"Access control is the set of policies, procedures, and technical mechanisms that regulate who can access systems, data, and resources within an organization. It ensures that only authorized individuals can view, modify, or interact with sensitive information and critical systems. Access control is one of the most fundamental and universally required security controls across every major compliance framework.",[111,359,361],{"id":360},"what-are-the-core-principles-of-access-control","What are the core principles of access control?",[17,363,364],{},"Access control is built on several foundational principles:",[35,366,367,373,379,385],{},[38,368,369,372],{},[42,370,371],{},"Least privilege"," — users are granted only the minimum access necessary to perform their job functions",[38,374,375,378],{},[42,376,377],{},"Separation of duties"," — critical tasks are divided among multiple individuals to prevent any single person from having unchecked authority",[38,380,381,384],{},[42,382,383],{},"Need to know"," — access to information is restricted to those who require it for a specific purpose",[38,386,387,390],{},[42,388,389],{},"Default deny"," — access is denied by default unless explicitly granted",[111,392,394],{"id":393},"what-are-the-types-of-access-control","What are the types of access control?",[17,396,397,400],{},[42,398,399],{},"Role-Based Access Control (RBAC)"," — access is determined by the user's role within the organization. Roles are defined with specific permissions, and users are assigned to roles. This is the most common model in enterprise environments.",[17,402,403,406],{},[42,404,405],{},"Attribute-Based Access Control (ABAC)"," — access decisions are based on attributes of the user, the resource, and the environment (e.g., department, location, time of day, device type).",[17,408,409,412],{},[42,410,411],{},"Discretionary Access Control (DAC)"," — resource owners decide who can access their resources. Common in file systems where owners set permissions.",[17,414,415,418],{},[42,416,417],{},"Mandatory Access Control (MAC)"," — access is controlled by the system based on security labels and clearance levels. Common in government and military environments.",[111,420,422],{"id":421},"what-are-access-control-components","What are access control components?",[17,424,425],{},"A complete access control program addresses:",[17,427,428,431],{},[42,429,430],{},"Authentication"," — verifying the identity of users:",[35,433,434,437,440,443,446],{},[38,435,436],{},"Passwords and passphrases",[38,438,439],{},"Multi-factor authentication (MFA)",[38,441,442],{},"Single sign-on (SSO)",[38,444,445],{},"Biometric authentication",[38,447,448],{},"Certificate-based authentication",[17,450,451,454],{},[42,452,453],{},"Authorization"," — determining what authenticated users can do:",[35,456,457,460,463,466],{},[38,458,459],{},"Permission assignments",[38,461,462],{},"Role definitions",[38,464,465],{},"Access control lists",[38,467,468],{},"Policy enforcement points",[17,470,471,474],{},[42,472,473],{},"Access lifecycle management"," — managing access throughout the user lifecycle:",[35,476,477,480,483],{},[38,478,479],{},"Provisioning (granting access when hired or role changes)",[38,481,482],{},"Review (periodic access certification)",[38,484,485],{},"Deprovisioning (revoking access upon termination or role change)",[111,487,489],{"id":488},"how-do-compliance-frameworks-address-access-control","How do compliance frameworks address access control?",[17,491,492],{},"Every major framework requires access control:",[35,494,495,504,518,532,541],{},[38,496,497,503],{},[42,498,499],{},[283,500,502],{"href":501},"\u002Fframeworks\u002Fsoc2","SOC 2"," — CC6.1 through CC6.8 cover logical and physical access controls",[38,505,506,512,513,517],{},[42,507,508],{},[283,509,511],{"href":510},"\u002Fframeworks\u002Fiso27001","ISO 27001"," — ",[283,514,516],{"href":515},"\u002Fglossary\u002Fannex-a","Annex A"," controls A.5.15 through A.5.18 and A.8.2 through A.8.5 address access management",[38,519,520,526,527,531],{},[42,521,522],{},[283,523,525],{"href":524},"\u002Fframeworks\u002Fhipaa","HIPAA"," — the ",[283,528,530],{"href":529},"\u002Fframeworks\u002Fhipaa\u002Fsecurity-rule","Security Rule"," requires access controls for ePHI (45 CFR 164.312(a))",[38,533,534,540],{},[42,535,536],{},[283,537,539],{"href":538},"\u002Fframeworks\u002Fpci","PCI DSS"," — Requirements 7 and 8 address access restriction and user identification",[38,542,543,549],{},[42,544,545],{},[283,546,548],{"href":547},"\u002Fframeworks\u002Fnistcsf","NIST CSF"," — PR.AC covers identity management, authentication, and access control",[111,551,553],{"id":552},"what-are-access-reviews","What are access reviews?",[17,555,556],{},"Regular access reviews (also called access certifications) are a critical control:",[35,558,559,562,565,568],{},[38,560,561],{},"Review user access rights periodically (quarterly is common for sensitive systems)",[38,563,564],{},"Verify that access aligns with current job responsibilities",[38,566,567],{},"Identify and remove excessive or unnecessary access",[38,569,570],{},"Document review results and remediation actions",[111,572,574],{"id":573},"what-are-common-access-control-weaknesses","What are common access control weaknesses?",[17,576,577],{},"Even well-designed access control programs can degrade over time without ongoing attention. Watch for these common issues:",[35,579,580,583,586,589,592,595,598],{},[38,581,582],{},"Excessive permissions that accumulate over time (privilege creep)",[38,584,585],{},"Shared or generic accounts that prevent individual accountability",[38,587,588],{},"Delayed deprovisioning when employees leave or change roles",[38,590,591],{},"Lack of MFA on critical systems and remote access paths",[38,593,594],{},"Inconsistent access review processes with no documented remediation",[38,596,597],{},"Service accounts with standing privileged access and no rotation schedule",[38,599,600],{},"Lack of visibility into SaaS application access outside the corporate IdP",[111,602,604],{"id":603},"how-do-you-implement-access-control-in-practice","How do you implement access control in practice?",[17,606,607],{},"Effective access control programs start with planning and build toward automation. The following steps provide a practical roadmap for organizations at any maturity level:",[609,610,611,617,623,629,635,641,652],"ol",{},[38,612,613,616],{},[42,614,615],{},"Map your environment"," — inventory all systems, applications, and data repositories that require access controls. You cannot protect what you have not identified. Include SaaS applications, cloud infrastructure, on-premises servers, databases, file shares, and third-party integrations.",[38,618,619,622],{},[42,620,621],{},"Define roles based on job functions"," — create roles that reflect organizational responsibilities, not individual users. Align roles to the principle of least privilege so each role includes only the permissions required for that function. Review role definitions annually and whenever organizational structure changes.",[38,624,625,628],{},[42,626,627],{},"Centralize authentication with SSO"," — implement single sign-on using SAML 2.0 or OpenID Connect (OIDC) to unify identity across cloud and on-premises systems. Centralized authentication reduces password sprawl and gives security teams a single point of enforcement. Ensure all business-critical applications are integrated with your SSO provider before considering the rollout complete.",[38,630,631,634],{},[42,632,633],{},"Layer MFA on all critical systems"," — require multi-factor authentication for remote access, privileged accounts, email, cloud consoles, and any system that touches sensitive data. Phishing-resistant methods such as FIDO2 hardware keys are preferred over SMS-based codes. At a minimum, enforce MFA on identity providers, admin consoles, and VPN access.",[38,636,637,640],{},[42,638,639],{},"Automate provisioning and deprovisioning"," — connect your HR system to your identity provider (IdP) and use SCIM or directory sync to automate account creation, role assignment, and account removal. When an employee is terminated in the HR system, access should be revoked within minutes, not days. Automation eliminates the human error that leads to orphaned accounts and privilege creep.",[38,642,643,646,647,651],{},[42,644,645],{},"Build an access request and approval workflow"," — establish a formal process where users request access with documented business justification, managers approve, and the request is logged for audit. This creates an ",[283,648,650],{"href":649},"\u002Fglossary\u002Faudit-trail","audit trail"," that satisfies compliance requirements.",[38,653,654,657],{},[42,655,656],{},"Monitor and log access events"," — collect authentication and authorization logs centrally. Monitor for anomalies such as failed login attempts, access from unusual locations, and privilege escalation. Logs are essential for incident response and audit evidence.",[111,659,661],{"id":660},"what-are-the-access-control-requirements","What are the access control requirements?",[17,663,664],{},"Different frameworks address the same access control concepts with different control references. The table below maps common requirements to their framework-specific identifiers:",[666,667,668,688],"table",{},[669,670,671],"thead",{},[672,673,674,678,680,682,684,686],"tr",{},[675,676,677],"th",{},"Requirement",[675,679,502],{},[675,681,511],{},[675,683,525],{},[675,685,539],{},[675,687,548],{},[689,690,691,712,731,751,768],"tbody",{},[672,692,693,697,700,703,706,709],{},[694,695,696],"td",{},"Unique user IDs",[694,698,699],{},"CC6.1",[694,701,702],{},"A.5.16",[694,704,705],{},"§164.312(a)(2)(i)",[694,707,708],{},"Req 8.2.1",[694,710,711],{},"PR.AC-1",[672,713,714,717,719,722,725,728],{},[694,715,716],{},"MFA",[694,718,699],{},[694,720,721],{},"A.8.5",[694,723,724],{},"Addressable",[694,726,727],{},"Req 8.4",[694,729,730],{},"PR.AC-7",[672,732,733,736,739,742,745,748],{},[694,734,735],{},"Access reviews",[694,737,738],{},"CC6.2",[694,740,741],{},"A.5.18",[694,743,744],{},"§164.312(a)(1)",[694,746,747],{},"Req 7.2",[694,749,750],{},"PR.AC-4",[672,752,753,755,758,761,763,766],{},[694,754,371],{},[694,756,757],{},"CC6.3",[694,759,760],{},"A.5.15",[694,762,744],{},[694,764,765],{},"Req 7.1",[694,767,750],{},[672,769,770,773,775,777,780,783],{},[694,771,772],{},"Deprovisioning",[694,774,738],{},[694,776,741],{},[694,778,779],{},"§164.312(a)(2)(ii)",[694,781,782],{},"Req 8.2.6",[694,784,711],{},[17,786,787],{},"Organizations subject to multiple frameworks can use this mapping to build a unified access control program that satisfies overlapping requirements without duplicating effort.",[17,789,790],{},"A few notes on framework-specific nuances:",[35,792,793,798,806,813],{},[38,794,795,797],{},[42,796,525],{}," treats MFA as an \"addressable\" implementation specification, meaning covered entities must implement it or document why an equivalent alternative is reasonable. In practice, most organizations implement MFA because the risk of not doing so is difficult to justify.",[38,799,800,805],{},[42,801,802,804],{},[283,803,539],{"href":538}," v4.0"," expanded MFA requirements (Req 8.4) to include all access into the cardholder data environment, not just remote access. Organizations processing card data should verify their MFA coverage meets the updated scope.",[38,807,808,812],{},[42,809,810],{},[283,811,502],{"href":501}," does not prescribe specific technologies but evaluates whether the controls in place are suitably designed and operating effectively. Auditors will look for evidence that access control policies are enforced consistently.",[38,814,815,819],{},[42,816,817],{},[283,818,548],{"href":547}," provides a flexible, risk-based approach. The PR.AC subcategory identifiers map to more detailed controls in NIST SP 800-53, which organizations can reference for implementation guidance.",[111,821,823],{"id":822},"how-does-zero-trust-relate-to-access-control","How does zero trust relate to access control?",[17,825,826,827,830],{},"Traditional access control models assume that users inside the network perimeter can be trusted. Zero trust architecture rejects that assumption entirely: ",[42,828,829],{},"never trust, always verify",".",[17,832,833],{},"In a zero trust model, every access request is authenticated, authorized, and encrypted regardless of where it originates. Key principles include:",[35,835,836,842,848,859,865],{},[38,837,838,841],{},[42,839,840],{},"Continuous verification"," — access decisions are re-evaluated throughout a session, not just at login. Changes in user behavior, location, or risk score can trigger step-up authentication or session termination.",[38,843,844,847],{},[42,845,846],{},"Micro-segmentation"," — network resources are divided into small, isolated zones so that compromising one segment does not grant lateral access to others.",[38,849,850,853,854,858],{},[42,851,852],{},"Device posture checks"," — the security state of the connecting device (patch level, endpoint protection status, disk ",[283,855,857],{"href":856},"\u002Fglossary\u002Fencryption","encryption",") is evaluated before access is granted.",[38,860,861,864],{},[42,862,863],{},"Identity-centric perimeter"," — the network perimeter is replaced by identity as the primary security boundary. Every user, device, and workload must prove its identity before accessing any resource.",[38,866,867,870],{},[42,868,869],{},"Least privilege enforcement at the session level"," — access grants are scoped to the specific resource and action needed, and they expire when the session ends or conditions change.",[17,872,873],{},"NIST SP 800-207 defines the zero trust architecture and provides guidance on implementation. Many compliance frameworks are increasingly aligning their access control requirements with zero trust principles, making it a forward-looking strategy for organizations building or modernizing their access control programs.",[17,875,876],{},"Zero trust is not a single product but an architectural approach that spans identity, network, endpoints, and data.",[17,878,879],{},"Adopting zero trust does not require replacing your existing access control infrastructure overnight. Most organizations begin by enforcing MFA universally, segmenting their most sensitive assets, and adding device posture checks to their conditional access policies. Over time, these incremental improvements compound into a mature zero trust posture.",[111,881,883],{"id":882},"how-does-episki-help-with-access-control","How does episki help with access control?",[17,885,886,887,830],{},"episki evaluates access rather than inventorying it. Identity evidence from Google, Microsoft, and AWS IAM across multiple accounts is collected and then checked, writing pass, fail, or inconclusive against the control — and a check that finds over-broad access raises a finding naming the specific principals. An unreadable or empty response returns inconclusive rather than passing, so an access control is never attested by a collection that failed. Learn more on our ",[283,888,890],{"href":889},"\u002Fframeworks","compliance platform",{"title":304,"searchDepth":305,"depth":305,"links":892},[893],{"id":353,"depth":305,"text":354,"children":894},[895,896,897,898,899,900,901,902,903,904],{"id":360,"depth":312,"text":361},{"id":393,"depth":312,"text":394},{"id":421,"depth":312,"text":422},{"id":488,"depth":312,"text":489},{"id":552,"depth":312,"text":553},{"id":573,"depth":312,"text":574},{"id":603,"depth":312,"text":604},{"id":660,"depth":312,"text":661},{"id":822,"depth":312,"text":823},{"id":882,"depth":312,"text":883},"2026-08-31",{},"\u002Fglossary\u002Faccess-control",[909,910,911,912,913,914],"cmmc","soc2","iso27001","hipaa","pci","nistcsf",[916,917,857,918],"minimum-necessary-rule","audit-trail","user-entity-controls",{"title":920,"description":921},"Access Control in Compliance: RBAC, MFA & Least Privilege","Access control restricts system and data access to authorized users. Learn RBAC, MFA, least privilege, and requirements across SOC 2, ISO 27001, HIPAA, and PCI DSS.","access-control","8.glossary\u002Faccess-control","9s8m0GbTkTfzK-1ANXSdpQhsVk3cqHqMcU4xDE8iDn0",{"id":926,"title":516,"body":927,"description":304,"extension":325,"lastUpdated":905,"meta":1073,"navigation":329,"path":515,"relatedFrameworks":1074,"relatedTerms":1075,"seo":1080,"slug":1083,"stem":1084,"term":932,"__hash__":1085},"glossary\u002F8.glossary\u002Fannex-a.md",{"type":14,"value":928,"toc":1063},[929,933,944,948,951,977,981,984,1001,1004,1008,1011,1015,1018,1032,1035,1039,1052,1056],[27,930,932],{"id":931},"what-is-iso-27001-annex-a","What is ISO 27001 Annex A?",[17,934,935,936,938,939,943],{},"ISO 27001 Annex A is the normative annex to the ",[283,937,511],{"href":510}," standard that provides a reference list of information security controls. Organizations use Annex A as a checklist to ensure their ",[283,940,942],{"href":941},"\u002Fframeworks\u002Fiso27001\u002Fisms-implementation","Information Security Management System (ISMS)"," addresses a comprehensive range of security topics. As of the 2022 revision, Annex A contains 93 controls organized into four themes.",[111,945,947],{"id":946},"what-are-the-four-themes","What are the four themes?",[17,949,950],{},"The 2022 revision reorganized controls from the previous 14 categories into four themes:",[35,952,953,959,965,971],{},[38,954,955,958],{},[42,956,957],{},"Organizational controls (37 controls)"," — policies, roles and responsibilities, threat intelligence, information security in project management, supplier relationships, and more",[38,960,961,964],{},[42,962,963],{},"People controls (8 controls)"," — screening, terms and conditions of employment, security awareness training, disciplinary processes, and responsibilities after termination",[38,966,967,970],{},[42,968,969],{},"Physical controls (14 controls)"," — physical security perimeters, entry controls, securing offices and facilities, equipment protection, and clear desk policies",[38,972,973,976],{},[42,974,975],{},"Technological controls (34 controls)"," — user endpoint devices, privileged access management, access restrictions, secure authentication, malware protection, logging, encryption, and secure development",[111,978,980],{"id":979},"how-does-annex-a-fit-into-iso-27001","How does Annex A fit into ISO 27001?",[17,982,983],{},"Annex A is not a standalone list of mandatory controls. Instead, it works in conjunction with the risk assessment process defined in clauses 6 and 8 of ISO 27001:",[609,985,986,989,992,995,998],{},[38,987,988],{},"The organization performs a risk assessment to identify information security risks",[38,990,991],{},"The organization determines how to treat each risk (mitigate, accept, transfer, or avoid)",[38,993,994],{},"For risks being mitigated, the organization selects appropriate controls",[38,996,997],{},"The organization compares selected controls against Annex A to ensure nothing has been overlooked",[38,999,1000],{},"The results are documented in the Statement of Applicability",[17,1002,1003],{},"This approach ensures that control selection is risk-driven rather than checkbox-driven. An organization may determine that certain Annex A controls are not applicable based on their specific risk profile, and this is acceptable as long as the justification is documented.",[111,1005,1007],{"id":1006},"how-does-annex-a-relate-to-iso-27002","How does Annex A relate to ISO 27002?",[17,1009,1010],{},"ISO 27002 provides detailed implementation guidance for each Annex A control. While Annex A lists the controls with brief descriptions, ISO 27002 explains the purpose, guidance, and other information for each control. Think of Annex A as the \"what\" and ISO 27002 as the \"how.\"",[111,1012,1014],{"id":1013},"what-changed-in-the-2022-revision-of-annex-a","What changed in the 2022 revision of Annex A?",[17,1016,1017],{},"The 2022 update introduced several changes from the 2013 version:",[35,1019,1020,1023,1026,1029],{},[38,1021,1022],{},"Controls were consolidated from 114 to 93",[38,1024,1025],{},"The 14 categories were replaced with 4 themes",[38,1027,1028],{},"11 new controls were added, including threat intelligence, information security for cloud services, ICT readiness for business continuity, and data masking",[38,1030,1031],{},"Each control now includes attributes (control type, cybersecurity concept, operational capability, and security domain) to aid in filtering and mapping",[17,1033,1034],{},"Organizations certified under the 2013 version had a transition period to update their ISMS to align with the 2022 revision.",[111,1036,1038],{"id":1037},"what-is-the-statement-of-applicability","What is the Statement of Applicability?",[17,1040,1041,1042,1046,1047,1051],{},"The ",[283,1043,1045],{"href":1044},"\u002Fframeworks\u002Fiso27001\u002Fstatement-of-applicability","Statement of Applicability (SoA)"," is the document where an organization records which Annex A controls are applicable, which are not, and the justification for each decision. The SoA is a mandatory document for ",[283,1048,1050],{"href":1049},"\u002Fframeworks\u002Fiso27001\u002Fcertification-process","ISO 27001 certification"," and is a key artifact reviewed during certification audits.",[111,1053,1055],{"id":1054},"how-does-episki-help-with-annex-a","How does episki help with Annex A?",[17,1057,1058,1059,830],{},"episki maps Annex A to controls evaluated on every sync across your connected estate, with evidence reused by every other framework that claims the same control. A check whose evidence comes back empty or unreadable returns inconclusive and attests nothing, so an Annex A control is never marked satisfied by a collection that silently failed. Learn more about the ",[283,1060,1062],{"href":1061},"\u002Fframeworks\u002Fiso27001\u002Fannex-a-controls","Annex A controls",{"title":304,"searchDepth":305,"depth":305,"links":1064},[1065],{"id":931,"depth":305,"text":932,"children":1066},[1067,1068,1069,1070,1071,1072],{"id":946,"depth":312,"text":947},{"id":979,"depth":312,"text":980},{"id":1006,"depth":312,"text":1007},{"id":1013,"depth":312,"text":1014},{"id":1037,"depth":312,"text":1038},{"id":1054,"depth":312,"text":1055},{},[911],[911,1076,1077,1078,1079],"statement-of-applicability","iso-27002","control-objectives","isms",{"title":1081,"description":1082},"ISO 27001 Annex A: All 93 Controls Explained (2022)","ISO 27001 Annex A lists 93 security controls in 4 themes. Learn each control category, how they map to your Statement of Applicability, and implementation tips.","annex-a","8.glossary\u002Fannex-a","ninWoLuGbIvkJx3djy7wTT090WPcFjANjfzM_i_lOn4",[],{"id":1088,"title":1089,"body":1090,"comparison":1282,"competitorA":1183,"competitorB":1195,"cta":1330,"description":304,"extension":325,"faq":1333,"hero":1351,"lastUpdated":905,"meta":1367,"navigation":329,"path":1368,"seo":1369,"slug":1372,"slugA":1373,"slugB":1374,"stem":1375,"verdict":1376,"__hash__":1380},"compareVs\u002F7.compare\u002Fvs\u002Fdrata-vs-secureframe.md","Drata Vs Secureframe",{"type":14,"value":1091,"toc":1272},[1092,1096,1099,1103,1106,1112,1115,1119,1122,1125,1128,1132,1135,1138,1142,1145,1217,1220,1223,1227,1230,1233,1237,1240,1243,1246],[27,1093,1095],{"id":1094},"drata-vs-secureframe-the-closest-comparison-in-compliance","Drata vs Secureframe: the closest comparison in compliance",[17,1097,1098],{},"If Vanta is the 800-pound gorilla, Drata and Secureframe are the two challengers most often compared against each other. They target similar buyers, cover similar frameworks, and offer similar automation. The differences are real but subtle — and they matter most in how your team experiences the platform day to day.",[111,1100,1102],{"id":1101},"feature-parity-with-different-emphasis","Feature parity with different emphasis",[17,1104,1105],{},"On paper, Drata and Secureframe look nearly identical. Both automate evidence collection, monitor your compliance posture continuously, support 15+ frameworks, and provide auditor-facing portals. The overlap is so significant that choosing between them often comes down to three factors: onboarding style, dashboard experience, and pricing.",[17,1107,1108,1111],{},[42,1109,1110],{},"Onboarding style"," is the clearest differentiator. Drata leans toward self-serve. The platform guides you through integration setup, control mapping, and evidence configuration with in-app workflows. For teams with compliance experience, this speed is an advantage — you can be operational in 1–2 weeks without waiting for a human to walk you through every step.",[17,1113,1114],{},"Secureframe takes the opposite approach. Every customer gets access to dedicated compliance managers who help interpret requirements, map controls to your environment, and prepare for audit. This white-glove model adds a week or two to implementation but dramatically reduces the learning curve for first-time audit teams.",[111,1116,1118],{"id":1117},"the-dashboard-question","The dashboard question",[17,1120,1121],{},"Drata's compliance dashboard is one of its signature features. The real-time posture view shows passing and failing controls across every framework, with compliance percentages and trend data. For compliance leads who report to a CISO or board, this visual layer simplifies status updates and makes it easy to demonstrate progress.",[17,1123,1124],{},"Secureframe also provides dashboards, but they feel more functional than visual. The platform surfaces actionable items — controls that need attention, evidence that's expiring, gaps to remediate — in a task-oriented format. It's effective, but it doesn't deliver the same at-a-glance executive view that Drata provides.",[17,1126,1127],{},"For teams that need board-ready compliance reporting, Drata has the edge. For teams that care more about daily workflow and task management, Secureframe's approach may feel more productive.",[111,1129,1131],{"id":1130},"integration-depth","Integration depth",[17,1133,1134],{},"Secureframe holds a slight advantage in integration count, with 150+ connections compared to Drata's 100+. The extra integrations primarily cover developer tools, identity providers, and security platforms. For teams running complex stacks with multiple CI\u002FCD pipelines, vulnerability scanners, and endpoint management tools, Secureframe's broader integration library means less manual evidence collection.",[17,1136,1137],{},"Drata's integrations, while fewer in number, tend to offer deeper configuration options for the platforms they do support. If your stack is standard — AWS or GCP, Okta or Google Workspace, GitHub, and a common HR tool — both platforms will serve you equally well.",[111,1139,1141],{"id":1140},"pricing-opacity","Pricing opacity",[17,1143,1144],{},"Neither Drata nor Secureframe publishes pricing. Both require a sales conversation to get a quote, and both scale based on team size, framework count, and contract terms. Here's how the major platforms compare on 2026 pricing, based on market data:",[666,1146,1147,1163],{},[669,1148,1149],{},[672,1150,1151,1154,1157,1160],{},[675,1152,1153],{},"Platform",[675,1155,1156],{},"Typical entry price (2026)",[675,1158,1159],{},"Pricing model",[675,1161,1162],{},"Published?",[689,1164,1165,1179,1191,1203],{},[672,1166,1167,1170,1173,1176],{},[694,1168,1169],{},"Vanta",[694,1171,1172],{},"~$11,000–$15,000\u002Fyr",[694,1174,1175],{},"Per-seat + framework, custom quote",[694,1177,1178],{},"No",[672,1180,1181,1184,1187,1189],{},[694,1182,1183],{},"Drata",[694,1185,1186],{},"~$10,000–$15,000\u002Fyr",[694,1188,1175],{},[694,1190,1178],{},[672,1192,1193,1196,1199,1201],{},[694,1194,1195],{},"Secureframe",[694,1197,1198],{},"~$8,000–$12,000\u002Fyr",[694,1200,1175],{},[694,1202,1178],{},[672,1204,1205,1208,1211,1214],{},[694,1206,1207],{},"episki",[694,1209,1210],{},"$750\u002Fmo ($7,500\u002Fyr)",[694,1212,1213],{},"Flat platform + modules, unlimited seats",[694,1215,1216],{},"Yes",[17,1218,1219],{},"At scale, Vanta, Drata, and Secureframe all reach $30,000–$50,000\u002Fyr for larger organizations. Secureframe usually starts slightly cheaper than Drata at the entry tier, but because both scale on seats and frameworks, the gap narrows quickly as your team grows.",[17,1221,1222],{},"This pricing opacity creates a frustrating buying experience. You can't model costs internally before engaging sales. You can't easily compare options. And renewal conversations often involve price increases that are hard to predict at the time of initial purchase.",[111,1224,1226],{"id":1225},"where-both-platforms-struggle","Where both platforms struggle",[17,1228,1229],{},"The irony of comparing Drata and Secureframe is that their most significant limitations are shared. Both use pricing models that punish team growth. Both rely on templated control libraries that resist customization. Both treat policy documentation as a secondary concern — something generated through forms rather than crafted through a proper writing experience.",[17,1231,1232],{},"And both lock you into their workflow assumptions. If your compliance program doesn't map cleanly to their templates — if you run hybrid frameworks, need custom controls, or want to structure programs differently than the default — you'll spend time working around the platform instead of working within it.",[111,1234,1236],{"id":1235},"the-case-for-a-different-approach","The case for a different approach",[17,1238,1239],{},"When two products are this similar, the deciding factor often isn't which one is better — it's whether either one is the right category of tool for your needs. If you want maximum automation and are comfortable with enterprise pricing, Drata and Secureframe both deliver.",[17,1241,1242],{},"But if you want GRC that runs itself, episki offers something neither Drata nor Secureframe provides. Where legacy GRC automates evidence, episki automates the program: agents draft policies, answer security questionnaires, map controls, manage vendors, and keep evidence evergreen — while your team approves the work that matters. The AI authors deterministic recipes that then run without AI in the loop, so output is reproducible and auditor-acceptable. A dedicated AI Governance module (agent and use-case registry, ISO 42001, NIST AI RMF, EU AI Act) covers the governance work neither competitor was built for.",[17,1244,1245],{},"It comes with flat pricing at $750\u002Fmo plus optional modules, unlimited seats, and a Notion-like editor for the documentation your team owns. No per-seat scaling. No opaque quotes. No templated policies that read like every other company's — just a program that runs itself, at a price that doesn't make your CFO wince.",[17,1247,1248,1251,1252,1256,1257,1261,1262,1266,1267,1271],{},[42,1249,1250],{},"Related reading:"," dig deeper into each platform's competitors in our ",[283,1253,1255],{"href":1254},"\u002Fblog\u002Fdrata-alternatives","Drata alternatives"," and ",[283,1258,1260],{"href":1259},"\u002Fblog\u002Fsecureframe-alternatives","Secureframe alternatives"," guides, see where both rank in the ",[283,1263,1265],{"href":1264},"\u002Fblog\u002Fbest-grc-tools-2026","best GRC tools of 2026",", or compare ",[283,1268,1270],{"href":1269},"\u002Fcompare\u002Fvs\u002Fvanta-vs-drata","Vanta vs Drata"," if Vanta is also on your shortlist.",{"title":304,"searchDepth":305,"depth":305,"links":1273},[1274],{"id":1094,"depth":305,"text":1095,"children":1275},[1276,1277,1278,1279,1280,1281],{"id":1101,"depth":312,"text":1102},{"id":1117,"depth":312,"text":1118},{"id":1130,"depth":312,"text":1131},{"id":1140,"depth":312,"text":1141},{"id":1225,"depth":312,"text":1226},{"id":1235,"depth":312,"text":1236},[1283,1287,1291,1296,1301,1305,1310,1315,1320,1325],{"feature":1159,"competitorA":1284,"competitorB":1285,"episki":1286},"Custom pricing, typically starting around $10,000–$15,000\u002Fyr","Custom pricing, typically starting around $8,000–$12,000\u002Fyr","Flat $750\u002Fmo ($7,500\u002Fyr) platform + optional modules; unlimited users, frameworks, and vendors",{"feature":1288,"competitorA":1289,"competitorB":1289,"episki":1290},"Framework coverage","SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and 15+ frameworks","34+ pre-built frameworks (SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, CMMC, FedRAMP, ISO 42001) plus custom",{"feature":1292,"competitorA":1293,"competitorB":1294,"episki":1295},"Automation depth","Automated evidence collection with real-time compliance dashboards","Automated monitoring with continuous evidence collection and alerts","Autonomous GRC — agents draft, answer, and map across the program; humans approve",{"feature":1297,"competitorA":1298,"competitorB":1299,"episki":1300},"Integration count","100+ integrations covering major cloud and SaaS platforms","150+ integrations covering cloud, identity, HR, and developer tools","AWS (multi-account and Organizations), GitHub, Google, Microsoft, Slack, Teams, Jira, Linear, Supabase, Vercel, Netlify — each writing evaluated control coverage",{"feature":1302,"competitorA":1303,"competitorB":1303,"episki":1304},"Control verdicts","Continuous monitoring with pass\u002Ffail tests on a posture dashboard","Every check writes pass, fail, or inconclusive against the control and raises a finding when it fails — empty or unreadable evidence attests nothing, and an approved exception that expires can satisfy a check for named records",{"feature":1306,"competitorA":1307,"competitorB":1308,"episki":1309},"Auditor collaboration","Auditor-facing portal with read-only access and evidence downloads","Auditor-ready evidence rooms with structured access controls","Built-in auditor portal with scoped access and Q&A threads",{"feature":1311,"competitorA":1312,"competitorB":1313,"episki":1314},"AI features","AI-assisted control mapping and compliance recommendations","AI-driven compliance recommendations and automated risk scoring","Agents draft policies, answer questionnaires, map controls, and recommend tasks — AI authors deterministic recipes auditors can accept",{"feature":1316,"competitorA":1317,"competitorB":1318,"episki":1319},"Implementation time","1–3 weeks with self-serve setup and optional guided onboarding","2–3 weeks with guided onboarding and compliance expertise","Same-day setup with self-serve onboarding and optional demo",{"feature":1321,"competitorA":1322,"competitorB":1323,"episki":1324},"Support model","In-app chat, email support, and dedicated CSM for larger accounts","Dedicated compliance managers, email, and in-app support","Self-serve by design, in-app chat, plus vetted Operator Partners (vCISO\u002FvGRC) for advisory",{"feature":1326,"competitorA":1327,"competitorB":1328,"episki":1329},"Free trial","Demo-based sales process, limited free trial availability","Demo-based sales process, no public free trial","14-day free trial with full access, no credit card required",{"title":1331,"description":1332},"Skip the comparison. Try episki free.","14-day trial with full access. No credit card required.",{"title":1334,"items":1335},"Drata vs Secureframe pricing FAQ (2026)",[1336,1339,1342,1345,1348],{"label":1337,"content":1338},"How much does Drata cost in 2026?","Drata does not publish pricing. Based on 2026 market data, plans typically start around $10,000–$15,000\u002Fyr and scale with team size and framework count, reaching $30,000–$50,000\u002Fyr for larger organizations. You need a sales conversation to get a firm quote.",{"label":1340,"content":1341},"How much does Secureframe cost in 2026?","Secureframe also keeps pricing private. In 2026 it typically starts slightly lower than Drata, around $8,000–$12,000\u002Fyr, and scales with seats and frameworks. Expect $30,000–$50,000\u002Fyr at enterprise scale.",{"label":1343,"content":1344},"How do Vanta, Drata, and Secureframe pricing compare in 2026?","All three use custom, per-seat-plus-framework pricing and none publish rates. Rough 2026 entry points: Vanta ~$11,000–$15,000\u002Fyr, Drata ~$10,000–$15,000\u002Fyr, Secureframe ~$8,000–$12,000\u002Fyr. The common thread is that costs rise as your team grows. episki is the outlier at a flat $750\u002Fmo ($7,500\u002Fyr) for the platform plus optional modules, with unlimited seats and published pricing.",{"label":1346,"content":1347},"Which is cheaper, Drata or Secureframe?","At the entry tier, Secureframe is usually slightly cheaper than Drata. But both scale on seats and frameworks, so the gap narrows or reverses depending on your team size and contract. Neither is predictable without a quote — which is why some teams choose a flat-priced platform instead.",{"label":1349,"content":1350},"Do Drata or Secureframe offer a free trial?","Neither offers a true public free trial — both run a demo-led sales process. If you want to evaluate hands-on before committing, episki offers a 14-day free trial with full access and no credit card.",{"headline":1352,"title":1353,"description":1354,"links":1355},"Drata vs Secureframe","Similar features, different approaches to compliance automation","Compare Drata and Secureframe across pricing, onboarding, and compliance workflows. Two closely matched platforms with subtle but important differences for your team.",[1356,1361],{"label":1357,"icon":1358,"to":1359,"target":1360},"Book a demo","i-lucide-calendar","\u002Fdemo","_blank",{"label":1362,"icon":1363,"color":1364,"variant":1365,"to":1366},"Try episki free","i-lucide-rocket","neutral","subtle","https:\u002F\u002Fapp.episki.com\u002Fauth\u002Fregister",{},"\u002Fcompare\u002Fvs\u002Fdrata-vs-secureframe",{"title":1370,"description":1371},"Drata vs Secureframe (2026): Pricing, Features & Honest Comparison","Drata vs Secureframe compared on pricing, onboarding, framework coverage, and compliance automation. See which platform fits your team — or if neither does.","drata-vs-secureframe","drata","secureframe","7.compare\u002Fvs\u002Fdrata-vs-secureframe",{"chooseA":1377,"chooseB":1378,"chooseEpiski":1379},"Choose Drata if you value self-serve speed and visual compliance dashboards. Drata gets you operational faster and provides the clearest real-time view of your compliance posture — ideal for teams with in-house compliance knowledge.","Choose Secureframe if you want more hands-on guidance from dedicated compliance managers. Secureframe's human-led onboarding is better for teams running their first audit without experienced GRC staff.","Choose episki if you want GRC that runs itself — agents draft policies, answer questionnaires, and keep evidence evergreen while your team approves the work that matters. You get transparent flat pricing ($750\u002Fmo plus optional modules, unlimited seats) and a dedicated AI Governance module.","ZFhZug7YeFTwHWW7ofP4DEaTqpwuaS47YBVKAJnxU-U",{"id":1382,"title":1383,"advantages":1384,"body":1406,"comparison":1469,"competitor":1383,"cta":1517,"description":304,"extension":325,"faq":1520,"hero":1538,"lastUpdated":905,"meta":1546,"navigation":329,"path":1547,"seo":1548,"slug":1551,"stem":1552,"__hash__":1553},"compare\u002F7.compare\u002Farcher.md","Archer",[1385,1392,1399],{"title":1386,"description":1387,"bullets":1388},"Start this afternoon, not next quarter","Archer's power comes from configurability, and configurability has to be configured. episki is opinionated on purpose — sensible defaults, self-serve onboarding, and an agent drafting your first policy in minutes.",[1389,1390,1391],"Self-serve signup with no implementation project and no onboarding fee","34+ frameworks pre-built, adopted through a wizard rather than modeled by a consultant","Same-day setup, with a 14-day free trial and no credit card",{"title":1393,"description":1394,"bullets":1395},"A program that advances without a risk department","Archer assumes a staffed risk function operating it. episki assumes you do not have one — the agents draft the work and a human approves it.",[1396,1397,1398],"Agents draft policies, narratives, and questionnaire answers from your own evidence","Vendor reviews advance over email, with inbound attachments triaged and linked with provenance","AI authors deterministic recipes; the recipes then run without AI in the loop, so auditors can trust the output",{"title":1400,"description":1401,"bullets":1402},"A verdict you can defend, not just a green check","episki evaluates the evidence it collects and writes an explicit verdict, closing the failure modes that let a check pass without proving anything.",[1403,1404,1405],"Empty, undecodable, or partially collected evidence returns inconclusive and attests nothing","A failing check raises a finding with the offending records attached","An approved exception can satisfy a check for named records — but it needs an approver and it expires",{"type":14,"value":1407,"toc":1464},[1408,1412,1415,1418,1421,1441,1445,1448,1451,1454,1457,1461],[27,1409,1411],{"id":1410},"why-teams-evaluate-archer-alternatives","Why teams evaluate Archer alternatives",[17,1413,1414],{},"Archer is one of the originals in integrated risk management, and at the top of the market it earns its position: operational risk, IT risk, third-party risk, and regulatory compliance modeled together, configurable to almost any taxonomy, deployable on-premises where that is mandatory.",[17,1416,1417],{},"That power has a shape. Deployments are configuration projects measured in months, frequently with a partner. Pricing is modular and custom, commonly reported from $75,000 into the hundreds of thousands per year. And reviewers consistently describe the interface as dated with a steep learning curve — which matters when the people who need to file evidence are engineers, not risk analysts.",[17,1419,1420],{},"Most teams evaluating Archer alongside episki are not choosing between equals. They are asking whether they need an enterprise IRM platform at all, or whether they need the compliance program to run itself.",[35,1422,1423,1429,1435],{},[38,1424,1425,1428],{},[42,1426,1427],{},"No implementation project"," — self-serve signup, sensible defaults, first policy drafted in minutes",[38,1430,1431,1434],{},[42,1432,1433],{},"A published price"," — $7,500\u002Fyr for the platform, unlimited users and frameworks",[38,1436,1437,1440],{},[42,1438,1439],{},"Agents that do the drafting"," — instead of workflows that route it to a person",[27,1442,1444],{"id":1443},"where-episki-is-different","Where episki is different",[17,1446,1447],{},"episki does not try to be Archer. It makes the opposite bet: rather than configurability for a risk department, opinionated defaults plus agents that do the work.",[17,1449,1450],{},"Those agents draft policies, answer security questionnaires, map controls across frameworks, and advance vendor reviews over email between audits. The AI authors deterministic recipes — plain, inspectable procedures — that then run without a model in the loop, so an auditor reads how an artifact was gathered rather than trusting a generation.",[17,1452,1453],{},"And every control check produces a verdict. Each integration operation decodes its response, evaluates its assertions, and writes pass, fail, or inconclusive. Empty evidence attests nothing. An incomplete sync cannot mark a control clean. A failing check raises a finding with the offending records attached. An approved exception, bound to an approver and an expiry, can satisfy a check for named records without pretending the condition changed.",[17,1455,1456],{},"Boundaries are real: programs report against individual scopes with rules on cloud account, region, resource, and tag — enough to define a PCI cardholder data environment precisely, without modeling a taxonomy first.",[27,1458,1460],{"id":1459},"when-archer-might-still-be-the-better-fit","When Archer might still be the better fit",[17,1462,1463],{},"If you are a large enterprise with a staffed risk function, need operational and regulatory risk modeled alongside IT risk, or have a hard on-premises requirement, Archer is the more capable platform and episki is not a substitute. The honest dividing line is whether you are buying a risk modeling system for a department, or an operator for a small team.",{"title":304,"searchDepth":305,"depth":305,"links":1465},[1466,1467,1468],{"id":1410,"depth":305,"text":1411},{"id":1443,"depth":305,"text":1444},{"id":1459,"depth":305,"text":1460},[1470,1474,1478,1481,1485,1489,1493,1497,1501,1505,1509,1513],{"feature":1471,"episki":1472,"competitor":1473},"Approach","Autonomous GRC — agents run the program; humans approve the work that matters","Integrated risk management — a configurable enterprise platform spanning operational, IT, third-party, and regulatory risk",{"feature":1475,"episki":1476,"competitor":1477},"Built for","Security and compliance teams from one person to a few hundred employees, who need the program to advance without headcount","Large enterprises with a staffed risk function and a multi-year GRC roadmap",{"feature":1159,"episki":1479,"competitor":1480},"Published — platform $750\u002Fmo (or $7,500\u002Fyr) + optional modules; unlimited users and frameworks, with AI tokens the only metered resource","Custom enterprise licensing, modular by use case, commonly reported from $75,000 to $300,000+ per year depending on modules, users, and deployment",{"feature":1482,"episki":1483,"competitor":1484},"Time to value","Same-day — self-serve signup, connect a cloud account, and an agent drafts your first policy in minutes","A configuration and implementation project, frequently measured in months and often involving a partner",{"feature":1486,"episki":1487,"competitor":1488},"Deployment","Cloud, with optional regional data residency for US, EU, or Canada","On-premises or SaaS, which is a genuine advantage where on-prem is mandatory",{"feature":1490,"episki":1491,"competitor":1492},"Who does the work","Agents draft policies, narratives, questionnaire answers, and control mappings; a human approves","Your risk and compliance team, inside highly configurable workflows",{"feature":1494,"episki":1495,"competitor":1496},"Risk management","Risk module — qualitative and quantitative scoring, treatments, and acceptance wired to controls and evidence","The deepest integrated risk model in the category, connecting operational, IT, third-party, and regulatory risk in one framework",{"feature":1498,"episki":1499,"competitor":1500},"Controls & evidence","Continuous controls that produce a verdict — every check evaluates the evidence it collected and writes pass, fail, or inconclusive, and a failing check raises a finding. Empty or undecodable evidence attests nothing","Control and assessment management, with automated technical evidence collection depending on configuration and add-ons",{"feature":1502,"episki":1503,"competitor":1504},"AI capabilities","Agents draft, answer, and map — and the AI authors deterministic recipes that then run without a model in the loop, so output is reproducible","AI features layered onto an established enterprise platform",{"feature":1506,"episki":1507,"competitor":1508},"Integrations","AWS (multi-account, multi-region, and Organizations), GitHub, Google, Microsoft, Slack, Teams, Jira, Linear, Supabase, Vercel, and Netlify — each writing evaluated control coverage out of the box","Extensive integration capability, typically realized through configuration and professional services",{"feature":1510,"episki":1511,"competitor":1512},"User experience","Notion-like, keyboard-first editor, a global command palette, and a desktop app with tabs","A mature interface that reviewers consistently describe as dated, with a steep learning curve",{"feature":1514,"episki":1515,"competitor":1516},"API & agent access","REST API, a published entity-ontology catalog with a drift checksum, and a hosted MCP server whose writes route through the same API as the UI","REST API and enterprise integration tooling",{"title":1518,"description":1519},"Enterprise-grade, without the enterprise project","Start a free trial and let an agent draft your first policy in under five minutes. No credit card required.",{"title":1521,"items":1522},"episki vs Archer — frequently asked questions",[1523,1526,1529,1532,1535],{"label":1524,"content":1525},"Is episki a realistic alternative to Archer?","For a large enterprise running a mature, multi-domain integrated risk program, generally no — Archer's risk model is deeper and its configurability is the reason organizations buy it. For the far more common case of a security or compliance team that has been quoted six figures for capability they will not use, episki covers the compliance, risk, vendor, trust, and AI governance ground at a published $7,500\u002Fyr and requires no implementation project.",{"label":1527,"content":1528},"How different is the cost really?","Substantially. Archer deployments are commonly reported between $75,000 and $300,000+ per year depending on modules, users, and deployment model, before implementation services. episki's platform is $7,500\u002Fyr with unlimited users and unlimited frameworks, with optional modules published on the pricing page and no onboarding or implementation fee.",{"label":1530,"content":1531},"What does Archer do that episki does not?","Three things worth naming honestly. Archer's integrated risk model connects operational, IT, third-party, and regulatory risk more deeply than episki's Risk module. Archer supports on-premises deployment, which episki does not. And Archer's configurability lets a large organization model risk taxonomies and workflows that episki deliberately keeps opinionated.",{"label":1533,"content":1534},"What does episki do that Archer does not?","The work. episki's agents draft policies, answer security questionnaires, map controls across frameworks, and advance vendor reviews between audits, with humans approving what matters. Every control check evaluates its own evidence and writes an explicit pass, fail, or inconclusive verdict, and connectors for AWS, GitHub, Supabase, Vercel, Netlify, Jira, and Linear write evaluated control coverage out of the box rather than through configuration.",{"label":1536,"content":1537},"When is Archer the better choice?","When you are a large enterprise — typically financial services, healthcare, or critical infrastructure — with a staffed risk function, a requirement to model operational and regulatory risk alongside IT risk, or a hard on-premises deployment requirement. Those are real needs and Archer is built for them.",{"headline":1539,"title":1540,"description":1541,"links":1542},"episki vs Archer","Two different weight classes, and that is the point","Archer is deep integrated risk management for large enterprises, deployed over months and priced accordingly. episki is Autonomous GRC you can start this afternoon — agents run the program, and the price is on the website.",[1543,1544],{"label":1357,"icon":1358,"to":1359,"target":1360},{"label":1545,"icon":1363,"color":1364,"variant":1365,"to":1366},"Start free trial",{},"\u002Fcompare\u002Farcher",{"title":1549,"description":1550},"episki vs Archer (2026): Autonomous GRC vs Enterprise Risk Management","episki vs Archer: flat $750\u002Fmo self-serve vs Archer's six-figure enterprise IRM deployments. Compare implementation, autonomy, and who each is actually built for.","archer","7.compare\u002Farcher","X-XyGkrH428bktnKyiu-R4eTwNtfC5e4fPwZSHDxMVo",{"id":1555,"title":1556,"api":6,"authors":1557,"body":1560,"category":1770,"date":323,"description":1771,"extension":325,"faq":6,"features":6,"fixes":6,"highlight":6,"image":1772,"improvements":6,"meta":1774,"navigation":329,"path":1775,"seo":1776,"stem":1777,"__hash__":1778},"posts\u002F3.blog\u002Fdealing.md","Dealing with Bad Auditors: How to Protect Your Program When the Process Breaks Down",[1558],{"name":9,"to":10,"avatar":1559},{"src":12},{"type":14,"value":1561,"toc":1762},[1562,1565,1568,1571,1574,1578,1581,1587,1593,1599,1605,1611,1614,1618,1621,1627,1633,1639,1645,1648,1652,1655,1661,1667,1673,1679,1685,1688,1692,1695,1698,1701,1704,1708,1711,1714,1728,1731,1735,1738,1741,1746,1752,1757],[17,1563,1564],{},"Every security leader eventually meets a bad auditor.",[17,1566,1567],{},"Not the tough one who asks hard questions — those people are useful. The bad one is different: vague scopes, shifting criteria, findings that don't map to the control, staff who rotate mid-engagement, and a final report that reads like it was written about someone else's environment. You leave the call more confused than when you started, and your team burns weeks chasing evidence that was never going to satisfy them.",[17,1569,1570],{},"This isn't rare. It's just rarely discussed in public, because nobody wants to look like they're \"fighting the audit.\" So programs absorb the friction, accept weak findings, and hope the next cycle is better.",[17,1572,1573],{},"Hope is not a strategy. Here's how to handle it.",[27,1575,1577],{"id":1576},"what-bad-actually-looks-like","What \"bad\" actually looks like",[17,1579,1580],{},"Before you escalate, name the pattern. Most difficult audit relationships fall into a few buckets:",[17,1582,1583,1586],{},[42,1584,1585],{},"Checklist without context."," They score the letter of a control and ignore how the business actually works. Your compensating control is invisible to them because it isn't on their template.",[17,1588,1589,1592],{},[42,1590,1591],{},"Moving goalposts."," What counted as evidence last week no longer counts. Requirements appear mid-engagement with no update to the scope letter.",[17,1594,1595,1598],{},[42,1596,1597],{},"Findings in search of a narrative."," Issues are written for drama — severity inflated, root cause guessed, remediation advice that doesn't fit your stack.",[17,1600,1601,1604],{},[42,1602,1603],{},"Engagement theater."," Junior staff collect screenshots; senior reviewers appear only at the end and rewrite the story. Continuity is gone, and so is accountability.",[17,1606,1607,1610],{},[42,1608,1609],{},"Weaponized ambiguity."," You ask \"what would good look like?\" and get \"we'll know it when we see it.\" That phrase is a red flag.",[17,1612,1613],{},"A rigorous auditor challenges you. A bad auditor leaves you unable to predict what \"done\" means.",[27,1615,1617],{"id":1616},"protect-the-record-early","Protect the record early",[17,1619,1620],{},"Your first job is not to win an argument. It's to make the engagement legible.",[17,1622,1623,1626],{},[42,1624,1625],{},"Lock the scope in writing."," Framework, systems in scope, period under review, evidence standards, and how findings will be rated. If something changes, get the change in email — not in a hallway conversation.",[17,1628,1629,1632],{},[42,1630,1631],{},"Agree on samples and walkthroughs up front."," Ambiguity about \"how many\" and \"which systems\" is where weeks disappear.",[17,1634,1635,1638],{},[42,1636,1637],{},"Assign a single owner on your side."," One person tracks requests, due dates, and open questions. Parallel Slack threads are how things get lost.",[17,1640,1641,1644],{},[42,1642,1643],{},"Log every request and response."," Date, what was asked, what you delivered, and any follow-up. When a finding appears that ignores evidence you already sent, you need that trail.",[17,1646,1647],{},"This feels bureaucratic until the day a finding cites a control you already satisfied twice. Then it feels like insurance.",[27,1649,1651],{"id":1650},"push-back-without-becoming-the-problem","Push back without becoming the problem",[17,1653,1654],{},"You can disagree without looking obstructive. The difference is tone and specificity.",[17,1656,1657,1660],{},[42,1658,1659],{},"Ask for the requirement."," \"Which clause or control ID does this map to?\" If they can't point to one, the finding isn't ready.",[17,1662,1663,1666],{},[42,1664,1665],{},"Ask for the evidence gap."," \"What specifically is missing from what we provided?\" Force a concrete answer — file type, coverage period, system boundary — not \"more detail.\"",[17,1668,1669,1672],{},[42,1670,1671],{},"Offer an alternative that still meets the intent."," Compensating controls, system descriptions, and architecture diagrams often close the gap faster than arguing about the original ask.",[17,1674,1675,1678],{},[42,1676,1677],{},"Separate severity from existence."," You can accept that something is imperfect and still challenge \"critical\" when the exposure is limited, monitored, or already in remediation.",[17,1680,1681,1684],{},[42,1682,1683],{},"Keep leadership informed early."," Surprises in the closing meeting are how bad findings become permanent.",[17,1686,1687],{},"Documented, calm, specific pushback reads as professionalism. Vague resistance reads as avoidance.",[27,1689,1691],{"id":1690},"when-the-firm-is-the-problem","When the firm is the problem",[17,1693,1694],{},"Sometimes the individual isn't salvageable — or the firm won't staff the engagement properly. Then you escalate the relationship, not just the finding.",[17,1696,1697],{},"Talk to the engagement partner with a short brief: patterns you observed, examples with dates, impact on timeline and quality, and what you need changed (named senior reviewer, frozen criteria, revised draft findings).",[17,1699,1700],{},"If you're the customer, you have leverage. Use it to fix the process, not to bully a junior auditor who is following a bad playbook.",[17,1702,1703],{},"In regulated contexts (PCI QSA, SOC examiners, etc.), you may not get to \"fire\" the auditor mid-cycle — but you can still demand clarity, continuity, and a fair reading of your evidence. Use your internal compliance counsel or sponsor when the commercial relationship needs weight.",[27,1705,1707],{"id":1706},"dont-let-a-bad-audit-wreck-the-program","Don't let a bad audit wreck the program",[17,1709,1710],{},"The worst outcome isn't an awkward report. It's a team that starts building for the auditor instead of for risk.",[17,1712,1713],{},"Keep two tracks:",[609,1715,1716,1722],{},[38,1717,1718,1721],{},[42,1719,1720],{},"Satisfy the engagement"," with the cleanest evidence path you can.",[38,1723,1724,1727],{},[42,1725,1726],{},"Protect the real program"," — backlog, risk register, and engineering priorities stay driven by actual exposure, not by whoever shouted loudest in the findings meeting.",[17,1729,1730],{},"After the report lands, run a short internal retro: what was fair, what was noise, what process you'll change next time (earlier scoping, better sample packs, clearer system inventory). Capture it so the next cycle starts stronger.",[27,1732,1734],{"id":1733},"a-better-default","A better default",[17,1736,1737],{},"The goal isn't to \"beat\" auditors. It's to make good audits easy and bad audits contained.",[17,1739,1740],{},"Clear scope, tight evidence hygiene, specific pushback, and escalation when the firm drops the ball — that's how you protect the program without turning every engagement into a fight.",[17,1742,1743],{},[42,1744,1745],{},"Need a cleaner path from evidence to audit-ready?",[17,1747,281,1748,1751],{},[283,1749,288],{"href":285,"rel":1750},[287],", we help teams run compliance that holds up under scrutiny — with evidence, ownership, and reports that reflect how the business actually works.",[17,1753,1754],{},[283,1755,296],{"href":294,"rel":1756},[287],[17,1758,1759],{},[300,1760,1761],{},"A hard auditor makes you better. A bad one only makes you busier — unless you take the process back.",{"title":304,"searchDepth":305,"depth":305,"links":1763},[1764,1765,1766,1767,1768,1769],{"id":1576,"depth":305,"text":1577},{"id":1616,"depth":305,"text":1617},{"id":1650,"depth":305,"text":1651},{"id":1690,"depth":305,"text":1691},{"id":1706,"depth":305,"text":1707},{"id":1733,"depth":305,"text":1734},"craft","A bad auditor wastes time, muddies findings, and can put your program at risk. Here's a practical playbook for spotting the problem early, pushing back without burning bridges, and getting the engagement back on track.",{"src":1773},"\u002Fimages\u002Fblog\u002Fdealing.webp",{},"\u002Fblog\u002Fdealing",{"title":1556,"description":1771},"3.blog\u002Fdealing","0Ak4fKGICxfBpn45oBF3ChkCZJF4dOS8BexOo18N9Vo",{"id":1780,"title":1781,"advantages":1782,"body":1804,"checklist":1811,"cta":1820,"description":1808,"extension":325,"faq":6,"hero":1823,"lastUpdated":905,"meta":1832,"name":1833,"navigation":329,"path":1834,"resources":1835,"seo":1848,"slug":1851,"stats":1852,"stem":1862,"__hash__":1863},"industries\u002F6.industry\u002F1.healthcare.md","Healthcare",[1783,1790,1797],{"title":1784,"description":1785,"bullets":1786},"PHI-aware control mapping","Map administrative, technical, and physical safeguards to your stack without rebuilding every audit.",[1787,1788,1789],"Track EHR, identity, and cloud evidence with structured ownership","Track segmentation, backups, and log retention against HIPAA safeguards","Map once for HIPAA and reuse for HITRUST or regional requirements",{"title":1791,"description":1792,"bullets":1793},"Clinician-friendly workflows","Keep nurses, clinicians, and ops aligned without burying them in tickets.",[1794,1795,1796],"Role-aware tasks routed to the right owner with due dates","Playbooks show “what good looks like” for PHI handling","Attestations and approvals captured inline for auditors",{"title":1798,"description":1799,"bullets":1800},"Auditor and partner collaboration","Give regulators, payers, and partners scoped access instead of email threads.",[1801,1802,1803],"Auditor portal with threaded Q&A per safeguard","Secure uploads with expirations and access controls","Exports for SOC 2, PCI, or privacy questionnaires",{"type":14,"value":1805,"toc":1809},[1806],[17,1807,1808],{},"Healthcare buyers move fast when they trust your safeguards. episki keeps PHI protections documented, monitored, and shareable without slowing product or patient care.",{"title":304,"searchDepth":305,"depth":305,"links":1810},[],{"title":1812,"description":1813,"items":1814},"Healthtech compliance checklist","Use this inside your trial to assign owners, attach evidence, and track renewals.",[1815,1816,1817,1818,1819],"HIPAA safeguard library mapped to your systems","BAA tracker with renewal reminders and risk scoring","Incident response runbooks with timelines and owners","Access, logging, and backup verification tasks","Third-party risk reviews tied to PHI data flows",{"title":1821,"description":1822},"Launch a healthtech-ready workspace","Connect your stack, invite stakeholders, and show PHI protections the same day.",{"headline":1824,"title":1825,"description":1826,"links":1827},"HIPAA-grade governance without slowing clinicians","Keep PHI protections provable across cloud apps, clinics, and vendors","episki maps safeguards, automates evidence, and gives auditors scoped access so healthtech teams can keep shipping.",[1828,1830],{"label":1829,"icon":1363,"to":1366},"Start healthtech trial",{"label":1357,"icon":1831,"color":1364,"variant":1365,"to":1359,"target":1360},"i-lucide-message-circle",{},"healthcare and healthtech","\u002Findustry\u002Fhealthcare",{"headline":1836,"title":1836,"description":1837,"items":1838},"Healthcare enablement kit","Keep leadership, clinicians, and auditors aligned on the same story.",[1839,1842,1845],{"title":1840,"description":1841},"PHI data flow deck","Share sanitized diagrams plus segmentation notes for customers and partners.",{"title":1843,"description":1844},"Board + payer brief","Summarize control health, incidents, and remediation in plain language.",{"title":1846,"description":1847},"Auditor-ready workspace","Prebuilt template for requests, evidence, and walkthrough scheduling.",{"title":1849,"description":1850},"Healthcare Compliance Software","HIPAA-ready GRC for healthtech teams. Map safeguards, track PHI evidence, and collaborate with auditors in one secure workspace. Start your free trial.","healthcare",[1853,1856,1859],{"value":1854,"description":1855},"30-day rollout","Move from baseline controls to monitored safeguards in under a month.",{"value":1857,"description":1858},"PHI-safe sharing","Role-based portals keep BAAs, policies, and diagrams organized and protected.",{"value":1860,"description":1861},"Continuous watch","Drift detection across access, logging, vendors, and incidents.","6.industry\u002F1.healthcare","u08a7hidKILzMlQgEwXI8WBgv7i08HXpMKdsEpMA3Tw",1789422995750]