[{"data":1,"prerenderedAt":1733},["ShallowReactive",2],{"\u002Fblog\u002Fsecuringthepipeline":3,"blog-surround-securingthepipeline":267,"explore-glossary-none-\u002Fblog\u002Fsecuringthepipeline":276,"explore-topics-none-\u002Fblog\u002Fsecuringthepipeline":1010,"explore-hub-none":6,"explore-compare-vs-\u002Fblog\u002Fsecuringthepipeline":1011,"explore-compare-\u002Fblog\u002Fsecuringthepipeline":1302,"explore-blog-none-\u002Fblog\u002Fsecuringthepipeline":1460,"explore-industry-none":1648},{"id":4,"title":5,"api":6,"authors":7,"body":13,"category":255,"date":256,"description":257,"extension":258,"faq":6,"features":6,"fixes":6,"highlight":6,"image":259,"improvements":6,"meta":261,"navigation":262,"path":263,"seo":264,"stem":265,"__hash__":266},"posts\u002F3.blog\u002FSecuringthePipeline.md","Securing the Pipeline: Why CI\u002FCD Is the New Perimeter",null,[8],{"name":9,"to":10,"avatar":11},"Justin Leapline","https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fjustinleapline\u002F",{"src":12},"\u002Fimages\u002Fjustinleapline.png",{"type":14,"value":15,"toc":241},"minimark",[16,21,31,34,39,42,45,58,69,71,75,78,85,96,98,102,107,110,121,125,128,139,143,146,157,159,163,223,225,229,236],[17,18,20],"h1",{"id":19},"securing-the-pipeline","Securing the Pipeline",[22,23,24],"blockquote",{},[25,26,27],"p",{},[28,29,30],"em",{},"The fastest way to ship insecure code is to treat security as the last step instead of the first one.",[32,33],"hr",{},[35,36,38],"h2",{"id":37},"the-shift-nobody-can-ignore-anymore","The Shift Nobody Can Ignore Anymore",[25,40,41],{},"For years, security lived at the end of the software lifecycle — a gate right before release, staffed by a team most engineers only heard from when something broke.",[25,43,44],{},"That model made sense when releases happened quarterly. It makes no sense when:",[46,47,48,52,55],"ul",{},[49,50,51],"li",{},"Code deploys multiple times a day",[49,53,54],{},"Infrastructure is defined and destroyed in code",[49,56,57],{},"Third-party dependencies outnumber first-party code by 10 to 1",[25,59,60,68],{},[61,62,63,64,67],"strong",{},"The pipeline ",[28,65,66],{},"is"," the product now."," If it isn't secure, nothing downstream is either.",[32,70],{},[35,72,74],{"id":73},"why-shift-left-isnt-enough-on-its-own","Why \"Shift Left\" Isn't Enough on Its Own",[25,76,77],{},"\"Shift left\" became the industry's favorite phrase — move security earlier, catch issues before production. True, but incomplete.",[25,79,80,81,84],{},"Shifting left without rethinking ",[28,82,83],{},"how"," security shows up creates a new problem: security becomes another blocking gate, just earlier in the process. Developers route around blockers. Speed wins, security loses.",[25,86,87,88,91,92,95],{},"The real fix isn't just moving security earlier — it's making security ",[61,89,90],{},"invisible until it's needed",", and ",[61,93,94],{},"fast when it is",".",[32,97],{},[35,99,101],{"id":100},"three-pillars-of-a-secured-pipeline","Three Pillars of a Secured Pipeline",[103,104,106],"h3",{"id":105},"_1-automated-not-manual","1. Automated, Not Manual",[25,108,109],{},"If a control depends on someone remembering to run it, it will eventually not run.",[46,111,112,115,118],{},[49,113,114],{},"SAST\u002FDAST scanning triggered on every commit, not every release",[49,116,117],{},"Dependency and SBOM checks baked into CI, not a quarterly spreadsheet exercise",[49,119,120],{},"Secrets scanning as a pre-commit hook, not a post-incident discovery",[103,122,124],{"id":123},"_2-context-aware-not-one-size-fits-all","2. Context-Aware, Not One-Size-Fits-All",[25,126,127],{},"A vulnerability in an internal tool with no internet exposure is not the same risk as one in a customer-facing API.",[46,129,130,133,136],{},[49,131,132],{},"Risk scoring tied to actual exposure and data sensitivity",[49,134,135],{},"Policies that adapt to the service, not a blanket rule applied everywhere",[49,137,138],{},"Exceptions that are tracked and time-boxed, not silently ignored",[103,140,142],{"id":141},"_3-owned-by-engineering-guided-by-security","3. Owned by Engineering, Guided by Security",[25,144,145],{},"Security teams can't review every line of code at pipeline speed — and they shouldn't have to.",[46,147,148,151,154],{},[49,149,150],{},"Guardrails instead of gatekeeping: pre-approved libraries, hardened base images, policy-as-code",[49,152,153],{},"Security embedded in the tools engineers already use, not a separate portal they have to remember to check",[49,155,156],{},"Findings routed directly to the owning team, with context — not a generic ticket queue",[32,158],{},[35,160,162],{"id":161},"what-this-looks-like-in-practice","What This Looks Like in Practice",[164,165,166,179],"table",{},[167,168,169],"thead",{},[170,171,172,176],"tr",{},[173,174,175],"th",{},"Traditional Approach",[173,177,178],{},"Secured Pipeline Approach",[180,181,182,191,199,207,215],"tbody",{},[170,183,184,188],{},[185,186,187],"td",{},"Security review before release",[185,189,190],{},"Continuous checks on every commit",[170,192,193,196],{},[185,194,195],{},"Manual dependency audits",[185,197,198],{},"Automated SBOM + vulnerability scanning",[170,200,201,204],{},[185,202,203],{},"One policy for all services",[185,205,206],{},"Risk-based policy per service\u002Fdata sensitivity",[170,208,209,212],{},[185,210,211],{},"Security as blocker",[185,213,214],{},"Security as guardrail",[170,216,217,220],{},[185,218,219],{},"Findings in a spreadsheet",[185,221,222],{},"Findings routed to owning team in real time",[32,224],{},[35,226,228],{"id":227},"the-real-payoff","The Real Payoff",[25,230,231,232,235],{},"A secured pipeline doesn't just reduce breaches — it removes the friction that makes teams ",[28,233,234],{},"want"," to skip security in the first place. When the secure path is also the fastest path, compliance stops being a fight and starts being the default.",[25,237,238],{},[61,239,240],{},"Security that slows you down gets bypassed. Security that's built into the pipeline becomes invisible — and that's exactly the point.",{"title":242,"searchDepth":243,"depth":243,"links":244},"",2,[245,246,247,253,254],{"id":37,"depth":243,"text":38},{"id":73,"depth":243,"text":74},{"id":100,"depth":243,"text":101,"children":248},[249,251,252],{"id":105,"depth":250,"text":106},3,{"id":123,"depth":250,"text":124},{"id":141,"depth":250,"text":142},{"id":161,"depth":243,"text":162},{"id":227,"depth":243,"text":228},"practices","2026-07-22","How modern engineering teams are moving security into the pipeline itself — automated checks, risk-based policies, and guardrails that don't slow teams down.","md",{"src":260},"\u002Fimages\u002Fblog\u002Fpublic\u002Fimages\u002Fblog\u002Ftech.jpg",{},true,"\u002Fblog\u002Fsecuringthepipeline",{"title":5,"description":257},"3.blog\u002FSecuringthePipeline","HTdM7nBImEAhULy9smG1QGOdsKfkdn42Bbt3MRSffdc",[268,271],{"title":5,"path":269,"stem":270,"description":257,"children":-1},"\u002Fblog\u002Fpipeline","3.blog\u002FPipeline",{"title":272,"path":273,"stem":274,"description":275,"children":-1},"You're Not Ready for Risk Assessments","\u002Fblog\u002Fyourenotreadyforriskassessments","3.blog\u002FYoureNotReadyforRiskAssessments","Most companies run a risk assessment as a checkbox exercise — and get a document nobody uses. Here's what actually needs to be in place first for it to mean anything.",[277,850],{"id":278,"title":279,"body":280,"description":242,"extension":258,"lastUpdated":830,"meta":831,"navigation":262,"path":832,"relatedFrameworks":833,"relatedTerms":840,"seo":844,"slug":847,"stem":848,"term":285,"__hash__":849},"glossary\u002F8.glossary\u002Faccess-control.md","Access Control",{"type":14,"value":281,"toc":816},[282,286,289,293,296,322,326,332,338,344,350,354,357,363,380,386,400,406,417,421,424,482,486,489,503,507,510,533,537,540,590,594,597,711,714,717,746,750,756,759,796,799,802,805,809],[35,283,285],{"id":284},"what-is-access-control","What is Access Control?",[25,287,288],{},"Access control is the set of policies, procedures, and technical mechanisms that regulate who can access systems, data, and resources within an organization. It ensures that only authorized individuals can view, modify, or interact with sensitive information and critical systems. Access control is one of the most fundamental and universally required security controls across every major compliance framework.",[103,290,292],{"id":291},"what-are-the-core-principles-of-access-control","What are the core principles of access control?",[25,294,295],{},"Access control is built on several foundational principles:",[46,297,298,304,310,316],{},[49,299,300,303],{},[61,301,302],{},"Least privilege"," — users are granted only the minimum access necessary to perform their job functions",[49,305,306,309],{},[61,307,308],{},"Separation of duties"," — critical tasks are divided among multiple individuals to prevent any single person from having unchecked authority",[49,311,312,315],{},[61,313,314],{},"Need to know"," — access to information is restricted to those who require it for a specific purpose",[49,317,318,321],{},[61,319,320],{},"Default deny"," — access is denied by default unless explicitly granted",[103,323,325],{"id":324},"what-are-the-types-of-access-control","What are the types of access control?",[25,327,328,331],{},[61,329,330],{},"Role-Based Access Control (RBAC)"," — access is determined by the user's role within the organization. Roles are defined with specific permissions, and users are assigned to roles. This is the most common model in enterprise environments.",[25,333,334,337],{},[61,335,336],{},"Attribute-Based Access Control (ABAC)"," — access decisions are based on attributes of the user, the resource, and the environment (e.g., department, location, time of day, device type).",[25,339,340,343],{},[61,341,342],{},"Discretionary Access Control (DAC)"," — resource owners decide who can access their resources. Common in file systems where owners set permissions.",[25,345,346,349],{},[61,347,348],{},"Mandatory Access Control (MAC)"," — access is controlled by the system based on security labels and clearance levels. Common in government and military environments.",[103,351,353],{"id":352},"what-are-access-control-components","What are access control components?",[25,355,356],{},"A complete access control program addresses:",[25,358,359,362],{},[61,360,361],{},"Authentication"," — verifying the identity of users:",[46,364,365,368,371,374,377],{},[49,366,367],{},"Passwords and passphrases",[49,369,370],{},"Multi-factor authentication (MFA)",[49,372,373],{},"Single sign-on (SSO)",[49,375,376],{},"Biometric authentication",[49,378,379],{},"Certificate-based authentication",[25,381,382,385],{},[61,383,384],{},"Authorization"," — determining what authenticated users can do:",[46,387,388,391,394,397],{},[49,389,390],{},"Permission assignments",[49,392,393],{},"Role definitions",[49,395,396],{},"Access control lists",[49,398,399],{},"Policy enforcement points",[25,401,402,405],{},[61,403,404],{},"Access lifecycle management"," — managing access throughout the user lifecycle:",[46,407,408,411,414],{},[49,409,410],{},"Provisioning (granting access when hired or role changes)",[49,412,413],{},"Review (periodic access certification)",[49,415,416],{},"Deprovisioning (revoking access upon termination or role change)",[103,418,420],{"id":419},"how-do-compliance-frameworks-address-access-control","How do compliance frameworks address access control?",[25,422,423],{},"Every major framework requires access control:",[46,425,426,436,450,464,473],{},[49,427,428,435],{},[61,429,430],{},[431,432,434],"a",{"href":433},"\u002Fframeworks\u002Fsoc2","SOC 2"," — CC6.1 through CC6.8 cover logical and physical access controls",[49,437,438,444,445,449],{},[61,439,440],{},[431,441,443],{"href":442},"\u002Fframeworks\u002Fiso27001","ISO 27001"," — ",[431,446,448],{"href":447},"\u002Fglossary\u002Fannex-a","Annex A"," controls A.5.15 through A.5.18 and A.8.2 through A.8.5 address access management",[49,451,452,458,459,463],{},[61,453,454],{},[431,455,457],{"href":456},"\u002Fframeworks\u002Fhipaa","HIPAA"," — the ",[431,460,462],{"href":461},"\u002Fframeworks\u002Fhipaa\u002Fsecurity-rule","Security Rule"," requires access controls for ePHI (45 CFR 164.312(a))",[49,465,466,472],{},[61,467,468],{},[431,469,471],{"href":470},"\u002Fframeworks\u002Fpci","PCI DSS"," — Requirements 7 and 8 address access restriction and user identification",[49,474,475,481],{},[61,476,477],{},[431,478,480],{"href":479},"\u002Fframeworks\u002Fnistcsf","NIST CSF"," — PR.AC covers identity management, authentication, and access control",[103,483,485],{"id":484},"what-are-access-reviews","What are access reviews?",[25,487,488],{},"Regular access reviews (also called access certifications) are a critical control:",[46,490,491,494,497,500],{},[49,492,493],{},"Review user access rights periodically (quarterly is common for sensitive systems)",[49,495,496],{},"Verify that access aligns with current job responsibilities",[49,498,499],{},"Identify and remove excessive or unnecessary access",[49,501,502],{},"Document review results and remediation actions",[103,504,506],{"id":505},"what-are-common-access-control-weaknesses","What are common access control weaknesses?",[25,508,509],{},"Even well-designed access control programs can degrade over time without ongoing attention. Watch for these common issues:",[46,511,512,515,518,521,524,527,530],{},[49,513,514],{},"Excessive permissions that accumulate over time (privilege creep)",[49,516,517],{},"Shared or generic accounts that prevent individual accountability",[49,519,520],{},"Delayed deprovisioning when employees leave or change roles",[49,522,523],{},"Lack of MFA on critical systems and remote access paths",[49,525,526],{},"Inconsistent access review processes with no documented remediation",[49,528,529],{},"Service accounts with standing privileged access and no rotation schedule",[49,531,532],{},"Lack of visibility into SaaS application access outside the corporate IdP",[103,534,536],{"id":535},"how-do-you-implement-access-control-in-practice","How do you implement access control in practice?",[25,538,539],{},"Effective access control programs start with planning and build toward automation. The following steps provide a practical roadmap for organizations at any maturity level:",[541,542,543,549,555,561,567,573,584],"ol",{},[49,544,545,548],{},[61,546,547],{},"Map your environment"," — inventory all systems, applications, and data repositories that require access controls. You cannot protect what you have not identified. Include SaaS applications, cloud infrastructure, on-premises servers, databases, file shares, and third-party integrations.",[49,550,551,554],{},[61,552,553],{},"Define roles based on job functions"," — create roles that reflect organizational responsibilities, not individual users. Align roles to the principle of least privilege so each role includes only the permissions required for that function. Review role definitions annually and whenever organizational structure changes.",[49,556,557,560],{},[61,558,559],{},"Centralize authentication with SSO"," — implement single sign-on using SAML 2.0 or OpenID Connect (OIDC) to unify identity across cloud and on-premises systems. Centralized authentication reduces password sprawl and gives security teams a single point of enforcement. Ensure all business-critical applications are integrated with your SSO provider before considering the rollout complete.",[49,562,563,566],{},[61,564,565],{},"Layer MFA on all critical systems"," — require multi-factor authentication for remote access, privileged accounts, email, cloud consoles, and any system that touches sensitive data. Phishing-resistant methods such as FIDO2 hardware keys are preferred over SMS-based codes. At a minimum, enforce MFA on identity providers, admin consoles, and VPN access.",[49,568,569,572],{},[61,570,571],{},"Automate provisioning and deprovisioning"," — connect your HR system to your identity provider (IdP) and use SCIM or directory sync to automate account creation, role assignment, and account removal. When an employee is terminated in the HR system, access should be revoked within minutes, not days. Automation eliminates the human error that leads to orphaned accounts and privilege creep.",[49,574,575,578,579,583],{},[61,576,577],{},"Build an access request and approval workflow"," — establish a formal process where users request access with documented business justification, managers approve, and the request is logged for audit. This creates an ",[431,580,582],{"href":581},"\u002Fglossary\u002Faudit-trail","audit trail"," that satisfies compliance requirements.",[49,585,586,589],{},[61,587,588],{},"Monitor and log access events"," — collect authentication and authorization logs centrally. Monitor for anomalies such as failed login attempts, access from unusual locations, and privilege escalation. Logs are essential for incident response and audit evidence.",[103,591,593],{"id":592},"what-are-the-access-control-requirements","What are the access control requirements?",[25,595,596],{},"Different frameworks address the same access control concepts with different control references. The table below maps common requirements to their framework-specific identifiers:",[164,598,599,616],{},[167,600,601],{},[170,602,603,606,608,610,612,614],{},[173,604,605],{},"Requirement",[173,607,434],{},[173,609,443],{},[173,611,457],{},[173,613,471],{},[173,615,480],{},[180,617,618,638,657,677,694],{},[170,619,620,623,626,629,632,635],{},[185,621,622],{},"Unique user IDs",[185,624,625],{},"CC6.1",[185,627,628],{},"A.5.16",[185,630,631],{},"§164.312(a)(2)(i)",[185,633,634],{},"Req 8.2.1",[185,636,637],{},"PR.AC-1",[170,639,640,643,645,648,651,654],{},[185,641,642],{},"MFA",[185,644,625],{},[185,646,647],{},"A.8.5",[185,649,650],{},"Addressable",[185,652,653],{},"Req 8.4",[185,655,656],{},"PR.AC-7",[170,658,659,662,665,668,671,674],{},[185,660,661],{},"Access reviews",[185,663,664],{},"CC6.2",[185,666,667],{},"A.5.18",[185,669,670],{},"§164.312(a)(1)",[185,672,673],{},"Req 7.2",[185,675,676],{},"PR.AC-4",[170,678,679,681,684,687,689,692],{},[185,680,302],{},[185,682,683],{},"CC6.3",[185,685,686],{},"A.5.15",[185,688,670],{},[185,690,691],{},"Req 7.1",[185,693,676],{},[170,695,696,699,701,703,706,709],{},[185,697,698],{},"Deprovisioning",[185,700,664],{},[185,702,667],{},[185,704,705],{},"§164.312(a)(2)(ii)",[185,707,708],{},"Req 8.2.6",[185,710,637],{},[25,712,713],{},"Organizations subject to multiple frameworks can use this mapping to build a unified access control program that satisfies overlapping requirements without duplicating effort.",[25,715,716],{},"A few notes on framework-specific nuances:",[46,718,719,724,732,739],{},[49,720,721,723],{},[61,722,457],{}," treats MFA as an \"addressable\" implementation specification, meaning covered entities must implement it or document why an equivalent alternative is reasonable. In practice, most organizations implement MFA because the risk of not doing so is difficult to justify.",[49,725,726,731],{},[61,727,728,730],{},[431,729,471],{"href":470}," v4.0"," expanded MFA requirements (Req 8.4) to include all access into the cardholder data environment, not just remote access. Organizations processing card data should verify their MFA coverage meets the updated scope.",[49,733,734,738],{},[61,735,736],{},[431,737,434],{"href":433}," does not prescribe specific technologies but evaluates whether the controls in place are suitably designed and operating effectively. Auditors will look for evidence that access control policies are enforced consistently.",[49,740,741,745],{},[61,742,743],{},[431,744,480],{"href":479}," provides a flexible, risk-based approach. The PR.AC subcategory identifiers map to more detailed controls in NIST SP 800-53, which organizations can reference for implementation guidance.",[103,747,749],{"id":748},"how-does-zero-trust-relate-to-access-control","How does zero trust relate to access control?",[25,751,752,753,95],{},"Traditional access control models assume that users inside the network perimeter can be trusted. Zero trust architecture rejects that assumption entirely: ",[61,754,755],{},"never trust, always verify",[25,757,758],{},"In a zero trust model, every access request is authenticated, authorized, and encrypted regardless of where it originates. Key principles include:",[46,760,761,767,773,784,790],{},[49,762,763,766],{},[61,764,765],{},"Continuous verification"," — access decisions are re-evaluated throughout a session, not just at login. Changes in user behavior, location, or risk score can trigger step-up authentication or session termination.",[49,768,769,772],{},[61,770,771],{},"Micro-segmentation"," — network resources are divided into small, isolated zones so that compromising one segment does not grant lateral access to others.",[49,774,775,778,779,783],{},[61,776,777],{},"Device posture checks"," — the security state of the connecting device (patch level, endpoint protection status, disk ",[431,780,782],{"href":781},"\u002Fglossary\u002Fencryption","encryption",") is evaluated before access is granted.",[49,785,786,789],{},[61,787,788],{},"Identity-centric perimeter"," — the network perimeter is replaced by identity as the primary security boundary. Every user, device, and workload must prove its identity before accessing any resource.",[49,791,792,795],{},[61,793,794],{},"Least privilege enforcement at the session level"," — access grants are scoped to the specific resource and action needed, and they expire when the session ends or conditions change.",[25,797,798],{},"NIST SP 800-207 defines the zero trust architecture and provides guidance on implementation. Many compliance frameworks are increasingly aligning their access control requirements with zero trust principles, making it a forward-looking strategy for organizations building or modernizing their access control programs.",[25,800,801],{},"Zero trust is not a single product but an architectural approach that spans identity, network, endpoints, and data.",[25,803,804],{},"Adopting zero trust does not require replacing your existing access control infrastructure overnight. Most organizations begin by enforcing MFA universally, segmenting their most sensitive assets, and adding device posture checks to their conditional access policies. Over time, these incremental improvements compound into a mature zero trust posture.",[103,806,808],{"id":807},"how-does-episki-help-with-access-control","How does episki help with access control?",[25,810,811,812,95],{},"episki tracks access control policies, monitors review schedules, and documents access provisioning and deprovisioning activities. The platform sends reminders for periodic access reviews and maintains evidence for auditors. Learn more on our ",[431,813,815],{"href":814},"\u002Fframeworks","compliance platform",{"title":242,"searchDepth":243,"depth":243,"links":817},[818],{"id":284,"depth":243,"text":285,"children":819},[820,821,822,823,824,825,826,827,828,829],{"id":291,"depth":250,"text":292},{"id":324,"depth":250,"text":325},{"id":352,"depth":250,"text":353},{"id":419,"depth":250,"text":420},{"id":484,"depth":250,"text":485},{"id":505,"depth":250,"text":506},{"id":535,"depth":250,"text":536},{"id":592,"depth":250,"text":593},{"id":748,"depth":250,"text":749},{"id":807,"depth":250,"text":808},"2026-04-16",{},"\u002Fglossary\u002Faccess-control",[834,835,836,837,838,839],"cmmc","soc2","iso27001","hipaa","pci","nistcsf",[841,842,782,843],"minimum-necessary-rule","audit-trail","user-entity-controls",{"title":845,"description":846},"Access Control in Compliance: RBAC, MFA & Least Privilege","Access control restricts system and data access to authorized users. Learn RBAC, MFA, least privilege, and requirements across SOC 2, ISO 27001, HIPAA, and PCI DSS.","access-control","8.glossary\u002Faccess-control","06FHtOe5hEs65vhNnMjZcNgPP9NXCQTnLD9llz_jEjM",{"id":851,"title":448,"body":852,"description":242,"extension":258,"lastUpdated":830,"meta":997,"navigation":262,"path":447,"relatedFrameworks":998,"relatedTerms":999,"seo":1004,"slug":1007,"stem":1008,"term":857,"__hash__":1009},"glossary\u002F8.glossary\u002Fannex-a.md",{"type":14,"value":853,"toc":987},[854,858,869,873,876,902,906,909,926,929,933,936,940,943,957,960,964,977,981],[35,855,857],{"id":856},"what-is-iso-27001-annex-a","What is ISO 27001 Annex A?",[25,859,860,861,863,864,868],{},"ISO 27001 Annex A is the normative annex to the ",[431,862,443],{"href":442}," standard that provides a reference list of information security controls. Organizations use Annex A as a checklist to ensure their ",[431,865,867],{"href":866},"\u002Fframeworks\u002Fiso27001\u002Fisms-implementation","Information Security Management System (ISMS)"," addresses a comprehensive range of security topics. As of the 2022 revision, Annex A contains 93 controls organized into four themes.",[103,870,872],{"id":871},"what-are-the-four-themes","What are the four themes?",[25,874,875],{},"The 2022 revision reorganized controls from the previous 14 categories into four themes:",[46,877,878,884,890,896],{},[49,879,880,883],{},[61,881,882],{},"Organizational controls (37 controls)"," — policies, roles and responsibilities, threat intelligence, information security in project management, supplier relationships, and more",[49,885,886,889],{},[61,887,888],{},"People controls (8 controls)"," — screening, terms and conditions of employment, security awareness training, disciplinary processes, and responsibilities after termination",[49,891,892,895],{},[61,893,894],{},"Physical controls (14 controls)"," — physical security perimeters, entry controls, securing offices and facilities, equipment protection, and clear desk policies",[49,897,898,901],{},[61,899,900],{},"Technological controls (34 controls)"," — user endpoint devices, privileged access management, access restrictions, secure authentication, malware protection, logging, encryption, and secure development",[103,903,905],{"id":904},"how-does-annex-a-fit-into-iso-27001","How does Annex A fit into ISO 27001?",[25,907,908],{},"Annex A is not a standalone list of mandatory controls. Instead, it works in conjunction with the risk assessment process defined in clauses 6 and 8 of ISO 27001:",[541,910,911,914,917,920,923],{},[49,912,913],{},"The organization performs a risk assessment to identify information security risks",[49,915,916],{},"The organization determines how to treat each risk (mitigate, accept, transfer, or avoid)",[49,918,919],{},"For risks being mitigated, the organization selects appropriate controls",[49,921,922],{},"The organization compares selected controls against Annex A to ensure nothing has been overlooked",[49,924,925],{},"The results are documented in the Statement of Applicability",[25,927,928],{},"This approach ensures that control selection is risk-driven rather than checkbox-driven. An organization may determine that certain Annex A controls are not applicable based on their specific risk profile, and this is acceptable as long as the justification is documented.",[103,930,932],{"id":931},"how-does-annex-a-relate-to-iso-27002","How does Annex A relate to ISO 27002?",[25,934,935],{},"ISO 27002 provides detailed implementation guidance for each Annex A control. While Annex A lists the controls with brief descriptions, ISO 27002 explains the purpose, guidance, and other information for each control. Think of Annex A as the \"what\" and ISO 27002 as the \"how.\"",[103,937,939],{"id":938},"what-changed-in-the-2022-revision-of-annex-a","What changed in the 2022 revision of Annex A?",[25,941,942],{},"The 2022 update introduced several changes from the 2013 version:",[46,944,945,948,951,954],{},[49,946,947],{},"Controls were consolidated from 114 to 93",[49,949,950],{},"The 14 categories were replaced with 4 themes",[49,952,953],{},"11 new controls were added, including threat intelligence, information security for cloud services, ICT readiness for business continuity, and data masking",[49,955,956],{},"Each control now includes attributes (control type, cybersecurity concept, operational capability, and security domain) to aid in filtering and mapping",[25,958,959],{},"Organizations certified under the 2013 version had a transition period to update their ISMS to align with the 2022 revision.",[103,961,963],{"id":962},"what-is-the-statement-of-applicability","What is the Statement of Applicability?",[25,965,966,967,971,972,976],{},"The ",[431,968,970],{"href":969},"\u002Fframeworks\u002Fiso27001\u002Fstatement-of-applicability","Statement of Applicability (SoA)"," is the document where an organization records which Annex A controls are applicable, which are not, and the justification for each decision. The SoA is a mandatory document for ",[431,973,975],{"href":974},"\u002Fframeworks\u002Fiso27001\u002Fcertification-process","ISO 27001 certification"," and is a key artifact reviewed during certification audits.",[103,978,980],{"id":979},"how-does-episki-help-with-annex-a","How does episki help with Annex A?",[25,982,983,984,95],{},"episki includes all 93 Annex A controls with mappings to your risk treatment plan and Statement of Applicability. The platform helps you track implementation status, assign ownership, and collect evidence for each applicable control. Learn more on our ",[431,985,986],{"href":442},"ISO 27001 compliance page",{"title":242,"searchDepth":243,"depth":243,"links":988},[989],{"id":856,"depth":243,"text":857,"children":990},[991,992,993,994,995,996],{"id":871,"depth":250,"text":872},{"id":904,"depth":250,"text":905},{"id":931,"depth":250,"text":932},{"id":938,"depth":250,"text":939},{"id":962,"depth":250,"text":963},{"id":979,"depth":250,"text":980},{},[836],[836,1000,1001,1002,1003],"statement-of-applicability","iso-27002","control-objectives","isms",{"title":1005,"description":1006},"ISO 27001 Annex A: All 93 Controls Explained (2022)","ISO 27001 Annex A lists 93 security controls in 4 themes. Learn each control category, how they map to your Statement of Applicability, and implementation tips.","annex-a","8.glossary\u002Fannex-a","7UuJknizYAej4wh0vgz3iQYe-_A9-r5bjizs222-Avw",[],{"id":1012,"title":1013,"body":1014,"comparison":1206,"competitorA":1107,"competitorB":1119,"cta":1250,"description":242,"extension":258,"faq":1253,"hero":1271,"lastUpdated":1287,"meta":1288,"navigation":262,"path":1289,"seo":1290,"slug":1293,"slugA":1294,"slugB":1295,"stem":1296,"verdict":1297,"__hash__":1301},"compareVs\u002F7.compare\u002Fvs\u002Fdrata-vs-secureframe.md","Drata Vs Secureframe",{"type":14,"value":1015,"toc":1196},[1016,1020,1023,1027,1030,1036,1039,1043,1046,1049,1052,1056,1059,1062,1066,1069,1141,1144,1147,1151,1154,1157,1161,1164,1167,1170],[35,1017,1019],{"id":1018},"drata-vs-secureframe-the-closest-comparison-in-compliance","Drata vs Secureframe: the closest comparison in compliance",[25,1021,1022],{},"If Vanta is the 800-pound gorilla, Drata and Secureframe are the two challengers most often compared against each other. They target similar buyers, cover similar frameworks, and offer similar automation. The differences are real but subtle — and they matter most in how your team experiences the platform day to day.",[103,1024,1026],{"id":1025},"feature-parity-with-different-emphasis","Feature parity with different emphasis",[25,1028,1029],{},"On paper, Drata and Secureframe look nearly identical. Both automate evidence collection, monitor your compliance posture continuously, support 15+ frameworks, and provide auditor-facing portals. The overlap is so significant that choosing between them often comes down to three factors: onboarding style, dashboard experience, and pricing.",[25,1031,1032,1035],{},[61,1033,1034],{},"Onboarding style"," is the clearest differentiator. Drata leans toward self-serve. The platform guides you through integration setup, control mapping, and evidence configuration with in-app workflows. For teams with compliance experience, this speed is an advantage — you can be operational in 1–2 weeks without waiting for a human to walk you through every step.",[25,1037,1038],{},"Secureframe takes the opposite approach. Every customer gets access to dedicated compliance managers who help interpret requirements, map controls to your environment, and prepare for audit. This white-glove model adds a week or two to implementation but dramatically reduces the learning curve for first-time audit teams.",[103,1040,1042],{"id":1041},"the-dashboard-question","The dashboard question",[25,1044,1045],{},"Drata's compliance dashboard is one of its signature features. The real-time posture view shows passing and failing controls across every framework, with compliance percentages and trend data. For compliance leads who report to a CISO or board, this visual layer simplifies status updates and makes it easy to demonstrate progress.",[25,1047,1048],{},"Secureframe also provides dashboards, but they feel more functional than visual. The platform surfaces actionable items — controls that need attention, evidence that's expiring, gaps to remediate — in a task-oriented format. It's effective, but it doesn't deliver the same at-a-glance executive view that Drata provides.",[25,1050,1051],{},"For teams that need board-ready compliance reporting, Drata has the edge. For teams that care more about daily workflow and task management, Secureframe's approach may feel more productive.",[103,1053,1055],{"id":1054},"integration-depth","Integration depth",[25,1057,1058],{},"Secureframe holds a slight advantage in integration count, with 150+ connections compared to Drata's 100+. The extra integrations primarily cover developer tools, identity providers, and security platforms. For teams running complex stacks with multiple CI\u002FCD pipelines, vulnerability scanners, and endpoint management tools, Secureframe's broader integration library means less manual evidence collection.",[25,1060,1061],{},"Drata's integrations, while fewer in number, tend to offer deeper configuration options for the platforms they do support. If your stack is standard — AWS or GCP, Okta or Google Workspace, GitHub, and a common HR tool — both platforms will serve you equally well.",[103,1063,1065],{"id":1064},"pricing-opacity","Pricing opacity",[25,1067,1068],{},"Neither Drata nor Secureframe publishes pricing. Both require a sales conversation to get a quote, and both scale based on team size, framework count, and contract terms. Here's how the major platforms compare on 2026 pricing, based on market data:",[164,1070,1071,1087],{},[167,1072,1073],{},[170,1074,1075,1078,1081,1084],{},[173,1076,1077],{},"Platform",[173,1079,1080],{},"Typical entry price (2026)",[173,1082,1083],{},"Pricing model",[173,1085,1086],{},"Published?",[180,1088,1089,1103,1115,1127],{},[170,1090,1091,1094,1097,1100],{},[185,1092,1093],{},"Vanta",[185,1095,1096],{},"~$11,000–$15,000\u002Fyr",[185,1098,1099],{},"Per-seat + framework, custom quote",[185,1101,1102],{},"No",[170,1104,1105,1108,1111,1113],{},[185,1106,1107],{},"Drata",[185,1109,1110],{},"~$10,000–$15,000\u002Fyr",[185,1112,1099],{},[185,1114,1102],{},[170,1116,1117,1120,1123,1125],{},[185,1118,1119],{},"Secureframe",[185,1121,1122],{},"~$8,000–$12,000\u002Fyr",[185,1124,1099],{},[185,1126,1102],{},[170,1128,1129,1132,1135,1138],{},[185,1130,1131],{},"episki",[185,1133,1134],{},"$750\u002Fmo ($7,500\u002Fyr)",[185,1136,1137],{},"Flat platform + modules, unlimited seats",[185,1139,1140],{},"Yes",[25,1142,1143],{},"At scale, Vanta, Drata, and Secureframe all reach $30,000–$50,000\u002Fyr for larger organizations. Secureframe usually starts slightly cheaper than Drata at the entry tier, but because both scale on seats and frameworks, the gap narrows quickly as your team grows.",[25,1145,1146],{},"This pricing opacity creates a frustrating buying experience. You can't model costs internally before engaging sales. You can't easily compare options. And renewal conversations often involve price increases that are hard to predict at the time of initial purchase.",[103,1148,1150],{"id":1149},"where-both-platforms-struggle","Where both platforms struggle",[25,1152,1153],{},"The irony of comparing Drata and Secureframe is that their most significant limitations are shared. Both use pricing models that punish team growth. Both rely on templated control libraries that resist customization. Both treat policy documentation as a secondary concern — something generated through forms rather than crafted through a proper writing experience.",[25,1155,1156],{},"And both lock you into their workflow assumptions. If your compliance program doesn't map cleanly to their templates — if you run hybrid frameworks, need custom controls, or want to structure programs differently than the default — you'll spend time working around the platform instead of working within it.",[103,1158,1160],{"id":1159},"the-case-for-a-different-approach","The case for a different approach",[25,1162,1163],{},"When two products are this similar, the deciding factor often isn't which one is better — it's whether either one is the right category of tool for your needs. If you want maximum automation and are comfortable with enterprise pricing, Drata and Secureframe both deliver.",[25,1165,1166],{},"But if you want GRC that runs itself, episki offers something neither Drata nor Secureframe provides. Where legacy GRC automates evidence, episki automates the program: agents draft policies, answer security questionnaires, map controls, manage vendors, and keep evidence evergreen — while your team approves the work that matters. The AI authors deterministic recipes that then run without AI in the loop, so output is reproducible and auditor-acceptable. A dedicated AI Governance module (agent and use-case registry, ISO 42001, NIST AI RMF, EU AI Act) covers the governance work neither competitor was built for.",[25,1168,1169],{},"It comes with flat pricing at $750\u002Fmo plus optional modules, unlimited seats, and a Notion-like editor for the documentation your team owns. No per-seat scaling. No opaque quotes. No templated policies that read like every other company's — just a program that runs itself, at a price that doesn't make your CFO wince.",[25,1171,1172,1175,1176,1180,1181,1185,1186,1190,1191,1195],{},[61,1173,1174],{},"Related reading:"," dig deeper into each platform's competitors in our ",[431,1177,1179],{"href":1178},"\u002Fblog\u002Fdrata-alternatives","Drata alternatives"," and ",[431,1182,1184],{"href":1183},"\u002Fblog\u002Fsecureframe-alternatives","Secureframe alternatives"," guides, see where both rank in the ",[431,1187,1189],{"href":1188},"\u002Fblog\u002Fbest-grc-tools-2026","best GRC tools of 2026",", or compare ",[431,1192,1194],{"href":1193},"\u002Fcompare\u002Fvs\u002Fvanta-vs-drata","Vanta vs Drata"," if Vanta is also on your shortlist.",{"title":242,"searchDepth":243,"depth":243,"links":1197},[1198],{"id":1018,"depth":243,"text":1019,"children":1199},[1200,1201,1202,1203,1204,1205],{"id":1025,"depth":250,"text":1026},{"id":1041,"depth":250,"text":1042},{"id":1054,"depth":250,"text":1055},{"id":1064,"depth":250,"text":1065},{"id":1149,"depth":250,"text":1150},{"id":1159,"depth":250,"text":1160},[1207,1211,1215,1220,1225,1230,1235,1240,1245],{"feature":1083,"competitorA":1208,"competitorB":1209,"episki":1210},"Custom pricing, typically starting around $10,000–$15,000\u002Fyr","Custom pricing, typically starting around $8,000–$12,000\u002Fyr","Flat $750\u002Fmo ($7,500\u002Fyr) platform + optional modules; unlimited users, frameworks, and vendors",{"feature":1212,"competitorA":1213,"competitorB":1213,"episki":1214},"Framework coverage","SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and 15+ frameworks","34+ pre-built frameworks (SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, CMMC, FedRAMP, ISO 42001) plus custom",{"feature":1216,"competitorA":1217,"competitorB":1218,"episki":1219},"Automation depth","Automated evidence collection with real-time compliance dashboards","Automated monitoring with continuous evidence collection and alerts","Autonomous GRC — agents draft, answer, and map across the program; humans approve",{"feature":1221,"competitorA":1222,"competitorB":1223,"episki":1224},"Integration count","100+ integrations covering major cloud and SaaS platforms","150+ integrations covering cloud, identity, HR, and developer tools","Native cloud, identity, ticketing & chat integrations plus full MCP server support",{"feature":1226,"competitorA":1227,"competitorB":1228,"episki":1229},"Auditor collaboration","Auditor-facing portal with read-only access and evidence downloads","Auditor-ready evidence rooms with structured access controls","Built-in auditor portal with scoped access and Q&A threads",{"feature":1231,"competitorA":1232,"competitorB":1233,"episki":1234},"AI features","AI-assisted control mapping and compliance recommendations","AI-driven compliance recommendations and automated risk scoring","Agents draft policies, answer questionnaires, map controls, and recommend tasks — AI authors deterministic recipes auditors can accept",{"feature":1236,"competitorA":1237,"competitorB":1238,"episki":1239},"Implementation time","1–3 weeks with self-serve setup and optional guided onboarding","2–3 weeks with guided onboarding and compliance expertise","Same-day setup with self-serve onboarding and optional demo",{"feature":1241,"competitorA":1242,"competitorB":1243,"episki":1244},"Support model","In-app chat, email support, and dedicated CSM for larger accounts","Dedicated compliance managers, email, and in-app support","Self-serve by design, in-app chat, plus vetted Operator Partners (vCISO\u002FvGRC) for advisory",{"feature":1246,"competitorA":1247,"competitorB":1248,"episki":1249},"Free trial","Demo-based sales process, limited free trial availability","Demo-based sales process, no public free trial","14-day free trial with full access, no credit card required",{"title":1251,"description":1252},"Skip the comparison. Try episki free.","14-day trial with full access. No credit card required.",{"title":1254,"items":1255},"Drata vs Secureframe pricing FAQ (2026)",[1256,1259,1262,1265,1268],{"label":1257,"content":1258},"How much does Drata cost in 2026?","Drata does not publish pricing. Based on 2026 market data, plans typically start around $10,000–$15,000\u002Fyr and scale with team size and framework count, reaching $30,000–$50,000\u002Fyr for larger organizations. You need a sales conversation to get a firm quote.",{"label":1260,"content":1261},"How much does Secureframe cost in 2026?","Secureframe also keeps pricing private. In 2026 it typically starts slightly lower than Drata, around $8,000–$12,000\u002Fyr, and scales with seats and frameworks. Expect $30,000–$50,000\u002Fyr at enterprise scale.",{"label":1263,"content":1264},"How do Vanta, Drata, and Secureframe pricing compare in 2026?","All three use custom, per-seat-plus-framework pricing and none publish rates. Rough 2026 entry points: Vanta ~$11,000–$15,000\u002Fyr, Drata ~$10,000–$15,000\u002Fyr, Secureframe ~$8,000–$12,000\u002Fyr. The common thread is that costs rise as your team grows. episki is the outlier at a flat $750\u002Fmo ($7,500\u002Fyr) for the platform plus optional modules, with unlimited seats and published pricing.",{"label":1266,"content":1267},"Which is cheaper, Drata or Secureframe?","At the entry tier, Secureframe is usually slightly cheaper than Drata. But both scale on seats and frameworks, so the gap narrows or reverses depending on your team size and contract. Neither is predictable without a quote — which is why some teams choose a flat-priced platform instead.",{"label":1269,"content":1270},"Do Drata or Secureframe offer a free trial?","Neither offers a true public free trial — both run a demo-led sales process. If you want to evaluate hands-on before committing, episki offers a 14-day free trial with full access and no credit card.",{"headline":1272,"title":1273,"description":1274,"links":1275},"Drata vs Secureframe","Similar features, different approaches to compliance automation","Compare Drata and Secureframe across pricing, onboarding, and compliance workflows. Two closely matched platforms with subtle but important differences for your team.",[1276,1281],{"label":1277,"icon":1278,"to":1279,"target":1280},"Book a demo","i-lucide-calendar","\u002Fdemo","_blank",{"label":1282,"icon":1283,"color":1284,"variant":1285,"to":1286},"Try episki free","i-lucide-rocket","neutral","subtle","https:\u002F\u002Fapp.episki.com\u002Fauth\u002Fregister","2026-06-26",{},"\u002Fcompare\u002Fvs\u002Fdrata-vs-secureframe",{"title":1291,"description":1292},"Drata vs Secureframe (2026): Pricing, Features & Honest Comparison","Drata vs Secureframe compared on pricing, onboarding, framework coverage, and compliance automation. See which platform fits your team — or if neither does.","drata-vs-secureframe","drata","secureframe","7.compare\u002Fvs\u002Fdrata-vs-secureframe",{"chooseA":1298,"chooseB":1299,"chooseEpiski":1300},"Choose Drata if you value self-serve speed and visual compliance dashboards. Drata gets you operational faster and provides the clearest real-time view of your compliance posture — ideal for teams with in-house compliance knowledge.","Choose Secureframe if you want more hands-on guidance from dedicated compliance managers. Secureframe's human-led onboarding is better for teams running their first audit without experienced GRC staff.","Choose episki if you want GRC that runs itself — agents draft policies, answer questionnaires, and keep evidence evergreen while your team approves the work that matters. You get transparent flat pricing ($750\u002Fmo plus optional modules, unlimited seats) and a dedicated AI Governance module.","sNccN3IjWTEx7y-g-BHuculQmXSrBCClPF03MGUzlbg",{"id":1303,"title":1107,"advantages":1304,"body":1326,"comparison":1392,"competitor":1107,"cta":1424,"description":242,"extension":258,"faq":1427,"hero":1445,"lastUpdated":1287,"meta":1453,"navigation":262,"path":1454,"seo":1455,"slug":1294,"stem":1458,"__hash__":1459},"compare\u002F7.compare\u002Fdrata.md",[1305,1312,1319],{"title":1306,"description":1307,"bullets":1308},"Automate the program, not just the monitoring","Drata is excellent at monitoring controls and showing you a dashboard. episki goes further — agents draft the policies, narratives, and questionnaire answers behind those controls, and a human approves. The work advances between audits, not just the status indicators.",[1309,1310,1311],"Agents draft policies, narratives, and questionnaire answers from your evidence","AI authors deterministic recipes; the recipes then run without AI in the loop, so auditors can trust the output","Continuous controls and evergreen evidence linked to programs, tasks, and risks",{"title":1313,"description":1314,"bullets":1315},"One flat platform price, expand by module","episki charges a flat $750\u002Fmo for the Compliance Platform with unlimited frameworks, users, and vendors. Add Risk, TPRM, Trust, or AI Governance only when you need them — no tier upgrade for adding your second or third framework.",[1316,1317,1318],"Adding a framework never triggers a higher pricing tier","Unlimited users and vendors; only AI tokens are metered","Annual prepay gives two months free; Operator Partner discounts for vCISO and MSP firms",{"title":1320,"description":1321,"bullets":1322},"Govern the AI, too","As your org adopts AI internally, episki ships a dedicated AI Governance module and governs its own agents the same way — an agent and use-case registry, AI risk treatments, and the newest frameworks mapped out of the box.",[1323,1324,1325],"Agent and AI use-case registry with allowlists and safety floors","AI risk treatments wired to controls and evidence","ISO 42001, NIST AI RMF, and the EU AI Act mapped from day one",{"type":14,"value":1327,"toc":1387},[1328,1332,1335,1346,1366,1370,1377,1380,1384],[35,1329,1331],{"id":1330},"why-teams-evaluate-drata-alternatives","Why teams evaluate Drata alternatives",[25,1333,1334],{},"Drata built a polished, real-time compliance dashboard on top of automated evidence collection. For teams that want continuous monitoring with a clean visual posture view, it works well — and its integration coverage across cloud and SaaS platforms is broad.",[25,1336,1337,1338,1341,1342,1345],{},"Teams look for alternatives when they want the program to ",[28,1339,1340],{},"run",", not just be ",[28,1343,1344],{},"watched",":",[46,1347,1348,1354,1360],{},[49,1349,1350,1353],{},[61,1351,1352],{},"Work that runs itself"," — a dashboard tells you a control is failing; episki's agents draft the policy, narrative, or remediation task to fix it, and a human approves.",[49,1355,1356,1359],{},[61,1357,1358],{},"Simpler, flat pricing"," — Drata's tiering by framework count and company size makes budgeting unpredictable. episki is a flat platform price with unlimited frameworks and users.",[49,1361,1362,1365],{},[61,1363,1364],{},"Built-in AI governance"," — episki ships a dedicated AI Governance module and maps ISO 42001, NIST AI RMF, and the EU AI Act out of the box.",[35,1367,1369],{"id":1368},"where-episki-is-different","Where episki is different",[25,1371,1372,1373,1376],{},"Legacy GRC automates evidence and renders it on a dashboard. episki automates the program. Agents draft policies, answer questionnaires, map controls across frameworks, and recommend tasks — and the AI authors ",[28,1374,1375],{},"deterministic recipes"," that then run without AI in the loop, so the output is reproducible and defensible in front of an auditor. A human always approves the work that matters.",[25,1378,1379],{},"Everything is connected underneath: programs, assessments, controls, tasks, risks, and evidence link together, and a fast, keyboard-first editor makes the daily work of writing and reviewing feel like a modern tool.",[35,1381,1383],{"id":1382},"when-drata-might-still-be-the-better-fit","When Drata might still be the better fit",[25,1385,1386],{},"Drata is a strong choice for teams that prioritize a clean, real-time monitoring dashboard with broad automated evidence collection, operating primarily in a well-defined framework like SOC 2 or ISO 27001. If continuous visual posture monitoring is your single most important requirement, Drata's dashboard is mature and compelling.",{"title":242,"searchDepth":243,"depth":243,"links":1388},[1389,1390,1391],{"id":1330,"depth":243,"text":1331},{"id":1368,"depth":243,"text":1369},{"id":1382,"depth":243,"text":1383},[1393,1396,1399,1402,1406,1410,1414,1416,1420],{"feature":1394,"episki":1395,"competitor":1217},"Approach","Autonomous GRC — agents run the program; humans approve the work that matters",{"feature":1083,"episki":1397,"competitor":1398},"Platform $750\u002Fmo (or $7,500\u002Fyr) + optional modules; unlimited users, frameworks, and vendors","Tiered pricing based on framework count and company size",{"feature":1400,"episki":1234,"competitor":1401},"AI capabilities","AI-assisted control mapping and recommendations",{"feature":1403,"episki":1404,"competitor":1405},"Controls & evidence","Continuous controls with evergreen evidence; structured ownership and cross-framework reuse","Automated evidence collection with 100+ integrations",{"feature":1407,"episki":1408,"competitor":1409},"Risk management","Risk module — qualitative and quantitative scoring, treatments, and acceptance wired to controls and evidence","Built-in risk management with scoring and treatment plans",{"feature":1411,"episki":1412,"competitor":1413},"AI governance","Dedicated AI Governance module — agent and use-case registry, AI risk treatments, ISO 42001, NIST AI RMF, EU AI Act","Limited dedicated AI governance tooling",{"feature":1212,"episki":1415,"competitor":1213},"34+ pre-built frameworks (SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, CMMC, FedRAMP, ISO 42001) plus custom — all unlimited",{"feature":1417,"episki":1418,"competitor":1419},"Integrations","Native cloud, identity, ticketing, and chat integrations plus full MCP server support so agents can use any tool you bring","100+ integrations across major cloud and SaaS platforms",{"feature":1421,"episki":1422,"competitor":1423},"Editor experience","Notion-like, keyboard-first editor for policies, narratives, and responses","Structured forms and workflow-based interface",{"title":1425,"description":1426},"See Autonomous GRC for yourself","Start a free trial with the platform and any modules enabled. Import your controls and watch an agent get to work.",{"title":1428,"items":1429},"episki vs Drata — frequently asked questions",[1430,1433,1436,1439,1442],{"label":1431,"content":1432},"Is episki a good alternative to Drata?","Yes — especially for teams that want the program to run itself rather than just be monitored. episki's agents draft policies, answer questionnaires, map controls, and recommend tasks, with humans approving. It links programs, assessments, controls, tasks, risks, and evidence into one connected graph and adds a dedicated AI Governance module.",{"label":1434,"content":1435},"How does episki's pricing compare to Drata's?","episki uses one flat platform price — $750\u002Fmo (or $7,500\u002Fyr) — that includes unlimited frameworks, users, and vendors, plus optional modules you add only when you need them. Drata uses tiered pricing based on framework count and company size, which can make budgeting unpredictable as you add frameworks or grow.",{"label":1437,"content":1438},"Does episki do continuous monitoring like Drata?","episki runs continuous controls with evergreen evidence and ties them to programs, tasks, and risks. Where it differs is what happens next — instead of only surfacing a gap on a dashboard, agents draft the remediation, the policy, or the narrative to close it, and a human approves. Drata's real-time monitoring dashboard is mature and a genuine strength if a visual posture view is your primary need.",{"label":1440,"content":1441},"Does episki support the same frameworks as Drata?","episki ships 34+ pre-built frameworks (SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, CMMC, FedRAMP, ISO 42001, EU AI Act, and more) plus custom frameworks, all unlimited and with cross-framework control reuse. Adding a framework never triggers a higher pricing tier.",{"label":1443,"content":1444},"When is Drata the better choice?","Drata is a strong fit if a clean, real-time monitoring dashboard with broad automated evidence collection is your top priority and you operate primarily in a well-defined framework like SOC 2 or ISO 27001. Its visual posture view and integration coverage are mature.",{"headline":1446,"title":1447,"description":1448,"links":1449},"episki vs Drata","Autonomous GRC vs a continuous-monitoring dashboard","Drata monitors controls and renders a clean dashboard. episki automates the program itself — agents draft policies, answer security questionnaires, manage vendors, and keep your audit evergreen, with humans approving the work that matters.",[1450,1451],{"label":1277,"icon":1278,"to":1279,"target":1280},{"label":1452,"icon":1283,"color":1284,"variant":1285,"to":1286},"Start free trial",{},"\u002Fcompare\u002Fdrata",{"title":1456,"description":1457},"episki vs Drata (2026): Autonomous GRC vs Continuous Monitoring","Compare episki and Drata. episki is the Autonomous GRC platform — agents draft policies, answer questionnaires, and run the program — with transparent pricing.","7.compare\u002Fdrata","jHYZmO1FNZGQI9dexDGqjmueUBlCm4JVNapKY2d6Ui4",{"id":1461,"title":1462,"api":6,"authors":1463,"body":1466,"category":255,"date":256,"description":1640,"extension":258,"faq":6,"features":6,"fixes":6,"highlight":6,"image":1641,"improvements":6,"meta":1643,"navigation":262,"path":1644,"seo":1645,"stem":1646,"__hash__":1647},"posts\u002F3.blog\u002FFedRAMP.md","FedRAMP: What It Actually Takes",[1464],{"name":9,"to":10,"avatar":1465},{"src":12},{"type":14,"value":1467,"toc":1628},[1468,1471,1478,1480,1484,1487,1490,1492,1496,1499,1545,1551,1553,1557,1561,1564,1568,1571,1575,1578,1582,1585,1587,1591,1594,1601,1603,1607,1610,1615,1623],[17,1469,1462],{"id":1470},"fedramp-what-it-actually-takes",[22,1472,1473],{},[25,1474,1475],{},[28,1476,1477],{},"FedRAMP isn't a certification you add to a checklist. It's a multi-year commitment that reshapes how you build, document, and prove your security.",[32,1479],{},[35,1481,1483],{"id":1482},"why-companies-chase-it-anyway","Why Companies Chase It Anyway",[25,1485,1486],{},"FedRAMP (Federal Risk and Authorization Management Program) exists because the U.S. government needs a consistent way to trust cloud products before agencies can buy them. For a SaaS company, getting authorized is the key that unlocks federal contracts — often worth $500K to $50M or more.",[25,1488,1489],{},"That's the upside. The downside is what it takes to get there, and it's significant enough that plenty of companies start the process and don't finish it.",[32,1491],{},[35,1493,1495],{"id":1494},"the-real-timeline","The Real Timeline",[25,1497,1498],{},"Most teams underestimate this by a wide margin.",[164,1500,1501,1511],{},[167,1502,1503],{},[170,1504,1505,1508],{},[173,1506,1507],{},"Stage",[173,1509,1510],{},"Typical Duration",[180,1512,1513,1521,1529,1537],{},[170,1514,1515,1518],{},[185,1516,1517],{},"Readiness assessment & gap remediation",[185,1519,1520],{},"3–6 months",[170,1522,1523,1526],{},[185,1524,1525],{},"Full security package documentation",[185,1527,1528],{},"4–8 months",[170,1530,1531,1534],{},[185,1532,1533],{},"Third-party assessment (3PAO)",[185,1535,1536],{},"2–3 months",[170,1538,1539,1542],{},[185,1540,1541],{},"Agency or JAB review & authorization",[185,1543,1544],{},"3–12 months",[25,1546,1547,1550],{},[61,1548,1549],{},"Total: 12 to 36 months",", start to finish — and that's assuming no major findings force a restart of any stage.",[32,1552],{},[35,1554,1556],{"id":1555},"what-it-actually-involves","What It Actually Involves",[103,1558,1560],{"id":1559},"_1-a-sponsor-not-just-an-application","1. A Sponsor, Not Just an Application",[25,1562,1563],{},"You can't self-submit for FedRAMP. You need either a federal agency sponsor (Agency Authorization) or approval through the Joint Authorization Board (JAB) — and JAB slots are limited and competitive.",[103,1565,1567],{"id":1566},"_2-documentation-at-a-different-scale","2. Documentation at a Different Scale",[25,1569,1570],{},"A System Security Plan (SSP) for FedRAMP routinely runs several hundred pages, mapping controls across NIST 800-53 — often 300+ controls depending on your impact level (Low, Moderate, or High).",[103,1572,1574],{"id":1573},"_3-a-third-party-assessment-organization-3pao","3. A Third-Party Assessment Organization (3PAO)",[25,1576,1577],{},"An accredited 3PAO has to independently test your environment against every applicable control. This isn't a formality — it's where most gaps get found, and where remediation cycles eat the most time.",[103,1579,1581],{"id":1580},"_4-continuous-monitoring-forever","4. Continuous Monitoring, Forever",[25,1583,1584],{},"Authorization isn't a one-time event. FedRAMP requires monthly vulnerability scans, annual assessments, and ongoing evidence that controls are still operating — indefinitely, for as long as you hold the authorization.",[32,1586],{},[35,1588,1590],{"id":1589},"the-mistake-that-costs-the-most-time","The Mistake That Costs the Most Time",[25,1592,1593],{},"Companies that treat FedRAMP like SOC 2 — something you can retrofit onto an existing product in a few months — lose the most time. The architectures, logging, and access control decisions FedRAMP expects often need to be built in from early on, not bolted on right before assessment.",[25,1595,1596,1597,1600],{},"At episki, the conversations that go best start the same way: mapping the ",[28,1598,1599],{},"actual"," gap between current controls and FedRAMP requirements before committing a timeline or budget to leadership — not after.",[32,1602],{},[35,1604,1606],{"id":1605},"is-it-worth-it","Is It Worth It?",[25,1608,1609],{},"For a company with a confirmed federal pipeline, yes — the payback period is measured in single contracts, not years. For a company chasing it speculatively, without a sponsor or a pipeline already forming, it's usually the wrong first move. Pursue it when the demand is real, not when it looks impressive on a website.",[25,1611,1612],{},[61,1613,1614],{},"FedRAMP doesn't reward companies that move fast. It rewards companies that can prove, in detail, that they know exactly what they're doing — and keep proving it.",[25,1616,1617],{},[431,1618,1622],{"href":1619,"rel":1620},"https:\u002F\u002Fepiski.com\u002Fcontact",[1621],"nofollow","Let's talk →",[25,1624,1625],{},[28,1626,1627],{},"episki. Compliance, simplified.",{"title":242,"searchDepth":243,"depth":243,"links":1629},[1630,1631,1632,1638,1639],{"id":1482,"depth":243,"text":1483},{"id":1494,"depth":243,"text":1495},{"id":1555,"depth":243,"text":1556,"children":1633},[1634,1635,1636,1637],{"id":1559,"depth":250,"text":1560},{"id":1566,"depth":250,"text":1567},{"id":1573,"depth":250,"text":1574},{"id":1580,"depth":250,"text":1581},{"id":1589,"depth":243,"text":1590},{"id":1605,"depth":243,"text":1606},"FedRAMP authorization opens the door to federal contracts worth millions — but the path there is longer, costlier, and more demanding than most companies expect. Here's what it really involves.",{"src":1642},"\u002Fimages\u002Fblog\u002Ffedramp-what-it-takes.webp",{},"\u002Fblog\u002Ffedramp",{"title":1462,"description":1640},"3.blog\u002FFedRAMP","Idxza8Qc1OJcHUwK99KVRjYwxwbja64jH2Y0O1o4c9M",{"id":1649,"title":1650,"advantages":1651,"body":1673,"checklist":1680,"cta":1689,"description":1677,"extension":258,"faq":6,"hero":1692,"meta":1701,"name":1702,"navigation":262,"path":1703,"resources":1704,"seo":1717,"slug":1720,"stats":1721,"stem":1731,"__hash__":1732},"industries\u002F6.industry\u002F1.healthcare.md","Healthcare",[1652,1659,1666],{"title":1653,"description":1654,"bullets":1655},"PHI-aware control mapping","Map administrative, technical, and physical safeguards to your stack without rebuilding every audit.",[1656,1657,1658],"Track EHR, identity, and cloud evidence with structured ownership","Track segmentation, backups, and log retention against HIPAA safeguards","Map once for HIPAA and reuse for HITRUST or regional requirements",{"title":1660,"description":1661,"bullets":1662},"Clinician-friendly workflows","Keep nurses, clinicians, and ops aligned without burying them in tickets.",[1663,1664,1665],"Role-aware tasks routed to the right owner with due dates","Playbooks show “what good looks like” for PHI handling","Attestations and approvals captured inline for auditors",{"title":1667,"description":1668,"bullets":1669},"Auditor and partner collaboration","Give regulators, payers, and partners scoped access instead of email threads.",[1670,1671,1672],"Auditor portal with threaded Q&A per safeguard","Secure uploads with expirations and access controls","Exports for SOC 2, PCI, or privacy questionnaires",{"type":14,"value":1674,"toc":1678},[1675],[25,1676,1677],{},"Healthcare buyers move fast when they trust your safeguards. episki keeps PHI protections documented, monitored, and shareable without slowing product or patient care.",{"title":242,"searchDepth":243,"depth":243,"links":1679},[],{"title":1681,"description":1682,"items":1683},"Healthtech compliance checklist","Use this inside your trial to assign owners, attach evidence, and track renewals.",[1684,1685,1686,1687,1688],"HIPAA safeguard library mapped to your systems","BAA tracker with renewal reminders and risk scoring","Incident response runbooks with timelines and owners","Access, logging, and backup verification tasks","Third-party risk reviews tied to PHI data flows",{"title":1690,"description":1691},"Launch a healthtech-ready workspace","Connect your stack, invite stakeholders, and show PHI protections the same day.",{"headline":1693,"title":1694,"description":1695,"links":1696},"HIPAA-grade governance without slowing clinicians","Keep PHI protections provable across cloud apps, clinics, and vendors","episki maps safeguards, automates evidence, and gives auditors scoped access so healthtech teams can keep shipping.",[1697,1699],{"label":1698,"icon":1283,"to":1286},"Start healthtech trial",{"label":1277,"icon":1700,"color":1284,"variant":1285,"to":1279,"target":1280},"i-lucide-message-circle",{},"healthcare and healthtech","\u002Findustry\u002Fhealthcare",{"headline":1705,"title":1705,"description":1706,"items":1707},"Healthcare enablement kit","Keep leadership, clinicians, and auditors aligned on the same story.",[1708,1711,1714],{"title":1709,"description":1710},"PHI data flow deck","Share sanitized diagrams plus segmentation notes for customers and partners.",{"title":1712,"description":1713},"Board + payer brief","Summarize control health, incidents, and remediation in plain language.",{"title":1715,"description":1716},"Auditor-ready workspace","Prebuilt template for requests, evidence, and walkthrough scheduling.",{"title":1718,"description":1719},"Healthcare Compliance Software","HIPAA-ready GRC for healthtech teams. Map safeguards, track PHI evidence, and collaborate with auditors in one secure workspace. Start your free trial.","healthcare",[1722,1725,1728],{"value":1723,"description":1724},"30-day rollout","Move from baseline controls to monitored safeguards in under a month.",{"value":1726,"description":1727},"PHI-safe sharing","Role-based portals keep BAAs, policies, and diagrams organized and protected.",{"value":1729,"description":1730},"Continuous watch","Drift detection across access, logging, vendors, and incidents.","6.industry\u002F1.healthcare","sogOs7i6e0u8UvMv69Ec8JQjsLrinF-rfW1s2gd6sT0",1784927273841]