[{"data":1,"prerenderedAt":10527},["ShallowReactive",2],{"\u002Fcompare\u002Farcher":3,"related-frameworks-all":196,"explore-glossary-none-\u002Fcompare\u002Farcher":8824,"explore-topics-none-\u002Fcompare\u002Farcher":9529,"explore-hub-none":9530,"explore-compare-vs-\u002Fcompare\u002Farcher":9531,"explore-compare-\u002Fcompare\u002Farcher":9814,"explore-blog-none-\u002Fcompare\u002Farcher":9971,"explore-industry-none":10446},{"id":4,"title":5,"advantages":6,"body":28,"comparison":99,"competitor":5,"cta":148,"description":93,"extension":151,"faq":152,"hero":170,"lastUpdated":186,"meta":187,"navigation":188,"path":189,"seo":190,"slug":193,"stem":194,"__hash__":195},"compare\u002F7.compare\u002Farcher.md","Archer",[7,14,21],{"title":8,"description":9,"bullets":10},"Start this afternoon, not next quarter","Archer's power comes from configurability, and configurability has to be configured. episki is opinionated on purpose — sensible defaults, self-serve onboarding, and an agent drafting your first policy in minutes.",[11,12,13],"Self-serve signup with no implementation project and no onboarding fee","34+ frameworks pre-built, adopted through a wizard rather than modeled by a consultant","Same-day setup, with a 14-day free trial and no credit card",{"title":15,"description":16,"bullets":17},"A program that advances without a risk department","Archer assumes a staffed risk function operating it. episki assumes you do not have one — the agents draft the work and a human approves it.",[18,19,20],"Agents draft policies, narratives, and questionnaire answers from your own evidence","Vendor reviews advance over email, with inbound attachments triaged and linked with provenance","AI authors deterministic recipes; the recipes then run without AI in the loop, so auditors can trust the output",{"title":22,"description":23,"bullets":24},"A verdict you can defend, not just a green check","episki evaluates the evidence it collects and writes an explicit verdict, closing the failure modes that let a check pass without proving anything.",[25,26,27],"Empty, undecodable, or partially collected evidence returns inconclusive and attests nothing","A failing check raises a finding with the offending records attached","An approved exception can satisfy a check for named records — but it needs an approver and it expires",{"type":29,"value":30,"toc":92},"minimark",[31,36,40,43,46,69,73,76,79,82,85,89],[32,33,35],"h2",{"id":34},"why-teams-evaluate-archer-alternatives","Why teams evaluate Archer alternatives",[37,38,39],"p",{},"Archer is one of the originals in integrated risk management, and at the top of the market it earns its position: operational risk, IT risk, third-party risk, and regulatory compliance modeled together, configurable to almost any taxonomy, deployable on-premises where that is mandatory.",[37,41,42],{},"That power has a shape. Deployments are configuration projects measured in months, frequently with a partner. Pricing is modular and custom, commonly reported from $75,000 into the hundreds of thousands per year. And reviewers consistently describe the interface as dated with a steep learning curve — which matters when the people who need to file evidence are engineers, not risk analysts.",[37,44,45],{},"Most teams evaluating Archer alongside episki are not choosing between equals. They are asking whether they need an enterprise IRM platform at all, or whether they need the compliance program to run itself.",[47,48,49,57,63],"ul",{},[50,51,52,56],"li",{},[53,54,55],"strong",{},"No implementation project"," — self-serve signup, sensible defaults, first policy drafted in minutes",[50,58,59,62],{},[53,60,61],{},"A published price"," — $7,500\u002Fyr for the platform, unlimited users and frameworks",[50,64,65,68],{},[53,66,67],{},"Agents that do the drafting"," — instead of workflows that route it to a person",[32,70,72],{"id":71},"where-episki-is-different","Where episki is different",[37,74,75],{},"episki does not try to be Archer. It makes the opposite bet: rather than configurability for a risk department, opinionated defaults plus agents that do the work.",[37,77,78],{},"Those agents draft policies, answer security questionnaires, map controls across frameworks, and advance vendor reviews over email between audits. The AI authors deterministic recipes — plain, inspectable procedures — that then run without a model in the loop, so an auditor reads how an artifact was gathered rather than trusting a generation.",[37,80,81],{},"And every control check produces a verdict. Each integration operation decodes its response, evaluates its assertions, and writes pass, fail, or inconclusive. Empty evidence attests nothing. An incomplete sync cannot mark a control clean. A failing check raises a finding with the offending records attached. An approved exception, bound to an approver and an expiry, can satisfy a check for named records without pretending the condition changed.",[37,83,84],{},"Boundaries are real: programs report against individual scopes with rules on cloud account, region, resource, and tag — enough to define a PCI cardholder data environment precisely, without modeling a taxonomy first.",[32,86,88],{"id":87},"when-archer-might-still-be-the-better-fit","When Archer might still be the better fit",[37,90,91],{},"If you are a large enterprise with a staffed risk function, need operational and regulatory risk modeled alongside IT risk, or have a hard on-premises requirement, Archer is the more capable platform and episki is not a substitute. The honest dividing line is whether you are buying a risk modeling system for a department, or an operator for a small team.",{"title":93,"searchDepth":94,"depth":94,"links":95},"",2,[96,97,98],{"id":34,"depth":94,"text":35},{"id":71,"depth":94,"text":72},{"id":87,"depth":94,"text":88},[100,104,108,112,116,120,124,128,132,136,140,144],{"feature":101,"episki":102,"competitor":103},"Approach","Autonomous GRC — agents run the program; humans approve the work that matters","Integrated risk management — a configurable enterprise platform spanning operational, IT, third-party, and regulatory risk",{"feature":105,"episki":106,"competitor":107},"Built for","Security and compliance teams from one person to a few hundred employees, who need the program to advance without headcount","Large enterprises with a staffed risk function and a multi-year GRC roadmap",{"feature":109,"episki":110,"competitor":111},"Pricing model","Published — platform $750\u002Fmo (or $7,500\u002Fyr) + optional modules; unlimited users and frameworks, with AI tokens the only metered resource","Custom enterprise licensing, modular by use case, commonly reported from $75,000 to $300,000+ per year depending on modules, users, and deployment",{"feature":113,"episki":114,"competitor":115},"Time to value","Same-day — self-serve signup, connect a cloud account, and an agent drafts your first policy in minutes","A configuration and implementation project, frequently measured in months and often involving a partner",{"feature":117,"episki":118,"competitor":119},"Deployment","Cloud, with optional regional data residency for US, EU, or Canada","On-premises or SaaS, which is a genuine advantage where on-prem is mandatory",{"feature":121,"episki":122,"competitor":123},"Who does the work","Agents draft policies, narratives, questionnaire answers, and control mappings; a human approves","Your risk and compliance team, inside highly configurable workflows",{"feature":125,"episki":126,"competitor":127},"Risk management","Risk module — qualitative and quantitative scoring, treatments, and acceptance wired to controls and evidence","The deepest integrated risk model in the category, connecting operational, IT, third-party, and regulatory risk in one framework",{"feature":129,"episki":130,"competitor":131},"Controls & evidence","Continuous controls that produce a verdict — every check evaluates the evidence it collected and writes pass, fail, or inconclusive, and a failing check raises a finding. Empty or undecodable evidence attests nothing","Control and assessment management, with automated technical evidence collection depending on configuration and add-ons",{"feature":133,"episki":134,"competitor":135},"AI capabilities","Agents draft, answer, and map — and the AI authors deterministic recipes that then run without a model in the loop, so output is reproducible","AI features layered onto an established enterprise platform",{"feature":137,"episki":138,"competitor":139},"Integrations","AWS (multi-account, multi-region, and Organizations), GitHub, Google, Microsoft, Slack, Teams, Jira, Linear, Supabase, Vercel, and Netlify — each writing evaluated control coverage out of the box","Extensive integration capability, typically realized through configuration and professional services",{"feature":141,"episki":142,"competitor":143},"User experience","Notion-like, keyboard-first editor, a global command palette, and a desktop app with tabs","A mature interface that reviewers consistently describe as dated, with a steep learning curve",{"feature":145,"episki":146,"competitor":147},"API & agent access","REST API, a published entity-ontology catalog with a drift checksum, and a hosted MCP server whose writes route through the same API as the UI","REST API and enterprise integration tooling",{"title":149,"description":150},"Enterprise-grade, without the enterprise project","Start a free trial and let an agent draft your first policy in under five minutes. No credit card required.","md",{"title":153,"items":154},"episki vs Archer — frequently asked questions",[155,158,161,164,167],{"label":156,"content":157},"Is episki a realistic alternative to Archer?","For a large enterprise running a mature, multi-domain integrated risk program, generally no — Archer's risk model is deeper and its configurability is the reason organizations buy it. For the far more common case of a security or compliance team that has been quoted six figures for capability they will not use, episki covers the compliance, risk, vendor, trust, and AI governance ground at a published $7,500\u002Fyr and requires no implementation project.",{"label":159,"content":160},"How different is the cost really?","Substantially. Archer deployments are commonly reported between $75,000 and $300,000+ per year depending on modules, users, and deployment model, before implementation services. episki's platform is $7,500\u002Fyr with unlimited users and unlimited frameworks, with optional modules published on the pricing page and no onboarding or implementation fee.",{"label":162,"content":163},"What does Archer do that episki does not?","Three things worth naming honestly. Archer's integrated risk model connects operational, IT, third-party, and regulatory risk more deeply than episki's Risk module. Archer supports on-premises deployment, which episki does not. And Archer's configurability lets a large organization model risk taxonomies and workflows that episki deliberately keeps opinionated.",{"label":165,"content":166},"What does episki do that Archer does not?","The work. episki's agents draft policies, answer security questionnaires, map controls across frameworks, and advance vendor reviews between audits, with humans approving what matters. Every control check evaluates its own evidence and writes an explicit pass, fail, or inconclusive verdict, and connectors for AWS, GitHub, Supabase, Vercel, Netlify, Jira, and Linear write evaluated control coverage out of the box rather than through configuration.",{"label":168,"content":169},"When is Archer the better choice?","When you are a large enterprise — typically financial services, healthcare, or critical infrastructure — with a staffed risk function, a requirement to model operational and regulatory risk alongside IT risk, or a hard on-premises deployment requirement. Those are real needs and Archer is built for them.",{"headline":171,"title":172,"description":173,"links":174},"episki vs Archer","Two different weight classes, and that is the point","Archer is deep integrated risk management for large enterprises, deployed over months and priced accordingly. episki is Autonomous GRC you can start this afternoon — agents run the program, and the price is on the website.",[175,180],{"label":176,"icon":177,"to":178,"target":179},"Book a demo","i-lucide-calendar","\u002Fdemo","_blank",{"label":181,"icon":182,"color":183,"variant":184,"to":185},"Start free trial","i-lucide-rocket","neutral","subtle","https:\u002F\u002Fapp.episki.com\u002Fauth\u002Fregister","2026-08-31",{},true,"\u002Fcompare\u002Farcher",{"title":191,"description":192},"episki vs Archer (2026): Autonomous GRC vs Enterprise Risk Management","episki vs Archer: flat $750\u002Fmo self-serve vs Archer's six-figure enterprise IRM deployments. Compare implementation, autonomy, and who each is actually built for.","archer","7.compare\u002Farcher","X-XyGkrH428bktnKyiu-R4eTwNtfC5e4fPwZSHDxMVo",[197,334,559,1079,1244,1432,1628,1835,2572,2736,2863,3058,3637,3763,3932,4428,4589,4731,4863,4988,5156,5319,5449,5570,5747,6380,6625,7150,7323,7488,7613,8213,8370,8505,8664],{"id":198,"title":199,"advantages":200,"body":222,"checklist":264,"cta":274,"description":93,"extension":151,"faq":277,"hero":293,"lastUpdated":186,"meta":301,"name":302,"navigation":188,"path":303,"resources":304,"seo":318,"slug":321,"stats":322,"stem":332,"__hash__":333},"frameworks\u002F5.frameworks\u002Fccpa.md","Ccpa",[201,208,215],{"title":202,"description":203,"bullets":204},"DSAR intake and fulfillment","Consumers submit requests through your trust portal; you fulfill them on the platform.",[205,206,207],"Right to know, delete, correct, opt-out, limit","Identity verification flows","45-day SLA timers with extension workflow",{"title":209,"description":210,"bullets":211},"Sale \u002F share \u002F SPI controls","CCPA opt-out of sale; CPRA opt-out of sharing for cross-context behavioral advertising; SPI use-limitation.",[212,213,214],"GPC signal honored","Do Not Sell or Share My Personal Information","Sensitive PI use-limitation log",{"title":216,"description":217,"bullets":218},"Mapped to GDPR and ISO 27701","Most CCPA\u002FCPRA obligations have GDPR analogues. Reuse the work.",[219,220,221],"DSAR types crosswalked to GDPR rights","SPI categories mapped to GDPR special-category data","ISO 27701 control mapping",{"type":29,"value":223,"toc":259},[224,228,231,234,238,241,245],[32,225,227],{"id":226},"what-is-ccpa-cpra","What is CCPA \u002F CPRA?",[37,229,230],{},"The California Consumer Privacy Act (CCPA) was the first comprehensive US state privacy law, taking effect January 1, 2020. It was substantially amended by the California Privacy Rights Act (CPRA) — passed by ballot initiative in 2020 and effective January 1, 2023 — which established the California Privacy Protection Agency (CPPA), created the new category of Sensitive Personal Information (SPI), added a right to correction, and broadened \"sale\" opt-outs to \"sale or share\" opt-outs.",[37,232,233],{},"The combined CCPA\u002FCPRA gives California consumers a set of rights resembling but not identical to GDPR: the right to know what personal information is collected, the right to delete it, the right to correct it, the right to opt out of sale or sharing, the right to limit the use of SPI, and the right to non-discrimination for exercising rights.",[32,235,237],{"id":236},"who-is-subject","Who is subject",[37,239,240],{},"For-profit businesses doing business in California that meet at least one threshold: $25M+ annual gross revenue, processing personal information of 100,000+ consumers or households, or deriving 50%+ of annual revenue from selling or sharing personal information. The law also creates obligations for service providers and contractors processing personal information on behalf of businesses.",[32,242,244],{"id":243},"how-episki-helps","How episki helps",[37,246,247,248,254,255,258],{},"episki tracks CCPA and CPRA obligations as structured records with owners and due dates — consumer requests, opt-out handling, and service provider agreements — alongside technical controls that are evaluated continuously. Service providers and their subprocessors live on vendor records with review cadences. ",[249,250,253],"a",{"href":185,"rel":251},[252],"nofollow","Start a free trial"," or ",[249,256,257],{"href":178},"book a demo",".",{"title":93,"searchDepth":94,"depth":94,"links":260},[261,262,263],{"id":226,"depth":94,"text":227},{"id":236,"depth":94,"text":237},{"id":243,"depth":94,"text":244},{"title":265,"description":266,"items":267},"CCPA \u002F CPRA readiness inside episki","From notice at collection to fulfilling the right to delete.",[268,269,270,271,272,273],"Personal Information inventory (categories collected, sources, purposes)","Notice at collection language and triggers","DSAR intake portal with verification","Opt-out of sale\u002Fshare workflows (including GPC)","Sensitive PI use-limitation requests","12-month look-back for \"right to know\" requests",{"title":275,"description":276},"Operationalize CCPA \u002F CPRA in episki","Add California to your privacy program without spinning up a parallel system.",{"title":278,"items":279},"CCPA \u002F CPRA frequently asked questions",[280,283,287,290],{"label":281,"content":282},"What's the difference between CCPA and CPRA?","CCPA (California Consumer Privacy Act) was the original 2018 law. CPRA (California Privacy Rights Act, effective 2023) substantially amended CCPA — establishing the California Privacy Protection Agency (CPPA), creating the category of Sensitive Personal Information (SPI), adding the right to correction, and replacing \"sale\" opt-outs with \"sale or share\" opt-outs.",{"label":284,"content":285},"Who is subject to CCPA\u002FCPRA?",{"For-profit businesses doing business in California that meet at least one of":286},"(a) $25M+ annual gross revenue, (b) process personal information of 100,000+ consumers or households, or (c) derive 50%+ of revenue from selling\u002Fsharing personal information. The CPRA also creates obligations for service providers and contractors.",{"label":288,"content":289},"What is the Global Privacy Control?","The Global Privacy Control (GPC) is a browser-level signal expressing the user's intent to opt out of the sale or sharing of their personal information. CPRA regulations require businesses to honor GPC as a valid opt-out request when received from a known consumer.",{"label":291,"content":292},"How fast must I respond to a DSAR?","45 days from receipt, with one 45-day extension available if reasonably necessary and the consumer is notified. Identity verification must be completed before substantive response.",{"headline":294,"title":295,"description":296,"links":297},"California privacy, operationalized","Meet CCPA and CPRA without a separate program","DSAR intake on your trust portal, GPC opt-out signal handling, sensitive personal information inventory, and use-limitation workflows — wired to the rest of your privacy program.",[298,299],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},"i-lucide-message-circle",{},"CCPA \u002F CPRA","\u002Fframeworks\u002Fccpa",{"headline":305,"title":306,"description":307,"items":308},"CCPA \u002F CPRA accelerators","California privacy accelerators","Stand up California compliance alongside your GDPR program.",[309,312,315],{"title":310,"description":311},"PI inventory template","Categories of PI, sources, purposes, and disclosures captured per processing activity.",{"title":313,"description":314},"DSAR fulfillment runbook","Step-by-step playbook for each consumer right.",{"title":316,"description":317},"GPC + opt-out implementation guide","Technical implementation guide for honoring GPC and surfacing the opt-out link.",{"title":319,"description":320},"CCPA \u002F CPRA Compliance Software","Operationalize California consumer-privacy obligations — DSAR fulfillment, opt-out signals (GPC), sensitive PI inventory, and CPRA workflows.","ccpa",[323,326,329],{"value":324,"description":325},"45-day","Standard DSAR fulfillment SLA tracked per request with extension workflow.",{"value":327,"description":328},"GPC","Global Privacy Control signal handling for opt-out of sale\u002Fsharing.",{"value":330,"description":331},"SPI","Sensitive Personal Information inventory and use-limitation tracking.","5.frameworks\u002Fccpa","L9Y2G2Jj7YW03ncBNUSa6P57MFwZyJ12DJb3dWmamag",{"id":335,"title":336,"advantages":337,"body":359,"checklist":494,"cta":504,"description":93,"extension":151,"faq":507,"hero":521,"lastUpdated":186,"meta":528,"name":529,"navigation":188,"path":530,"resources":531,"seo":545,"slug":548,"stats":549,"stem":557,"__hash__":558},"frameworks\u002F5.frameworks\u002Fcis-controls.md","Cis Controls",[338,345,352],{"title":339,"description":340,"bullets":341},"18 controls, 153 safeguards","The complete v8.1 catalog implemented as controls with mapped evidence.",[342,343,344],"Asset, software, and data management","Access control, MFA, and account management","Continuous vulnerability and log management",{"title":346,"description":347,"bullets":348},"Implementation Groups","Start with essential cyber hygiene and grow into deeper safeguards.",[349,350,351],"IG1 — 56 foundational safeguards","IG2 — added rigor for larger orgs","IG3 — mature, high-risk environments",{"title":353,"description":354,"bullets":355},"A baseline that maps everywhere","CIS safeguards cross-walk to your other frameworks for evidence reuse.",[356,357,358],"Crosswalk to NIST CSF 2.0","Crosswalk to ISO 27001 and SOC 2","A practical on-ramp to CMMC and PCI DSS",{"type":29,"value":360,"toc":487},[361,365,396,399,405,429,432,436,451,455,477,479],[32,362,364],{"id":363},"what-are-the-cis-controls","What are the CIS Controls?",[37,366,367,368,371,372,375,376,380,381,384,385,388,389,392,393,258],{},"The ",[53,369,370],{},"CIS Critical Security Controls"," are a prioritized, prescriptive set of cybersecurity best practices maintained by the ",[53,373,374],{},"Center for Internet Security (CIS)",". Where many frameworks tell you ",[377,378,379],"em",{},"what outcomes"," to achieve, the CIS Controls tell you ",[377,382,383],{},"what to do first"," — they are ordered by impact and grounded in real-world attack data from sources like MITRE ATT&CK and the Verizon Data Breach Investigations Report. The current version, ",[53,386,387],{},"CIS Controls v8.1 (released June 2024)",", defines ",[53,390,391],{},"18 controls"," and ",[53,394,395],{},"153 safeguards",[32,397,346],{"id":398},"implementation-groups",[37,400,401,402,404],{},"The CIS Controls are designed to be adopted incrementally through three ",[53,403,346],{},":",[47,406,407,417,423],{},[50,408,409,412,413,416],{},[53,410,411],{},"IG1"," — the ",[53,414,415],{},"56 foundational safeguards"," that constitute essential cyber hygiene. Every organization, regardless of size, should meet IG1 to defend against the most common attacks.",[50,418,419,422],{},[53,420,421],{},"IG2"," — additional safeguards for organizations that manage more sensitive data and operate more complex environments.",[50,424,425,428],{},[53,426,427],{},"IG3"," — the full set, for mature organizations in high-risk sectors facing sophisticated, targeted threats.",[37,430,431],{},"This tiering makes the CIS Controls one of the most practical starting points for a security program: a smaller organization can implement IG1 and demonstrably reduce risk without committing to a full enterprise framework on day one.",[32,433,435],{"id":434},"what-v81-changed","What v8.1 changed",[37,437,438,439,442,443,446,447,450],{},"Version 8.1 is a refinement rather than a rewrite. It adds alignment with ",[53,440,441],{},"NIST CSF 2.0"," — including the new ",[53,444,445],{},"Govern"," function — clarifies safeguard language, and refreshes mappings to other frameworks, all while keeping the familiar 18-control structure. (Note that the CIS Controls are distinct from the ",[53,448,449],{},"CIS Benchmarks",", which are system-specific configuration-hardening guides; the two are complementary.)",[32,452,454],{"id":453},"how-the-cis-controls-map-to-other-frameworks","How the CIS Controls map to other frameworks",[37,456,457,458,461,462,466,467,471,472,476],{},"Because the CIS Controls are prescriptive and well-mapped, they make an excellent ",[53,459,460],{},"baseline and crosswalk layer",". The safeguards align cleanly with ",[249,463,465],{"href":464},"\u002Fframeworks\u002Fnistcsf","NIST CSF",", ",[249,468,470],{"href":469},"\u002Fframeworks\u002Fiso27001","ISO 27001"," Annex A, and the ",[249,473,475],{"href":474},"\u002Fframeworks\u002Fsoc2","SOC 2"," Trust Services Criteria, and they provide a practical on-ramp toward more prescriptive regimes like PCI DSS and CMMC.",[32,478,244],{"id":243},[37,480,481,482,254,485,258],{},"episki maps the CIS Controls to checks that are evaluated rather than attested: asset inventory from AWS across accounts and regions, access posture from live identity evidence, and configuration hardening from your cloud and platform connectors. Implementation Groups are expressed as scope, and crosswalks to NIST CSF and ISO 27001 come from the SCF hub. ",[249,483,253],{"href":185,"rel":484},[252],[249,486,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":488},[489,490,491,492,493],{"id":363,"depth":94,"text":364},{"id":398,"depth":94,"text":346},{"id":434,"depth":94,"text":435},{"id":453,"depth":94,"text":454},{"id":243,"depth":94,"text":244},{"title":495,"description":496,"items":497},"CIS Controls readiness inside episki","What a prioritized security program needs in place.",[498,499,500,501,502,503],"Implementation Group selection (IG1 \u002F IG2 \u002F IG3)","Enterprise asset and software inventory (Controls 1-2)","Data protection and secure configuration (Controls 3-4)","Account and access control management (Controls 5-6)","Continuous vulnerability and audit log management (Controls 7-8)","Crosswalks to NIST CSF, ISO 27001, and SOC 2",{"title":505,"description":506},"Build a CIS Controls program in episki","Implement the 18 controls once and reuse the evidence across NIST CSF, ISO 27001, and SOC 2.",{"title":508,"items":509},"CIS Controls frequently asked questions",[510,512,515,518],{"label":364,"content":511},"The CIS Critical Security Controls are a prioritized, prescriptive set of cybersecurity best practices maintained by the Center for Internet Security. The current version, CIS Controls v8.1 (released June 2024), organizes 153 safeguards across 18 controls, grounded in real-world attack data from sources such as MITRE ATT&CK and the Verizon DBIR.",{"label":513,"content":514},"What are Implementation Groups?","Implementation Groups (IG1, IG2, and IG3) let organizations prioritize by size, resources, and risk. IG1 is the 56-safeguard set of essential cyber hygiene that every organization should meet; IG2 adds safeguards for organizations managing more sensitive data; IG3 covers mature, high-risk environments facing sophisticated threats.",{"label":516,"content":517},"What changed in v8.1?","CIS Controls v8.1 is a refinement of v8. It adds alignment with NIST CSF 2.0 — including the new Govern function — updates and clarifies safeguard language, and refreshes the mappings to other frameworks, all without changing the overall 18-control structure.",{"label":519,"content":520},"Are CIS Controls the same as CIS Benchmarks?","No. The CIS Controls are a prioritized set of security actions for an organization. CIS Benchmarks are detailed, system-specific configuration-hardening guides (for operating systems, cloud services, and applications). The two are complementary — Benchmarks help you implement parts of the Controls.",{"headline":522,"title":523,"description":524,"links":525},"Prioritized security, by the numbers","Implement the CIS Critical Security Controls","All 18 CIS Controls and 153 safeguards as a living control library, scoped by Implementation Group, and cross-mapped to NIST CSF, ISO 27001, and SOC 2.",[526,527],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"CIS Controls","\u002Fframeworks\u002Fcis-controls",{"headline":532,"title":533,"description":534,"items":535},"CIS Controls accelerators","CIS Controls program accelerators","Turn a prioritized list into an operating security program.",[536,539,542],{"title":537,"description":538},"Implementation Group selector","Pick the right safeguard set for your size, resources, and risk profile.",{"title":540,"description":541},"Safeguard tracker","Owners, evidence, and status for each of the 153 safeguards.",{"title":543,"description":544},"NIST CSF \u002F ISO 27001 crosswalk","Reuse CIS evidence across your other frameworks automatically.",{"title":546,"description":547},"CIS Controls v8.1 Compliance Software","Implement the CIS Critical Security Controls v8.1 — 18 controls and 153 safeguards across Implementation Groups IG1-IG3 — mapped to NIST CSF, ISO 27001, and SOC 2.","cis-controls",[550,552,554],{"value":391,"description":551},"The full CIS Controls v8.1 catalog implemented as living episki controls.",{"value":395,"description":553},"Every safeguard tracked with evidence, owners, and Implementation Group.",{"value":555,"description":556},"IG1 \u002F IG2 \u002F IG3","Scope to the Implementation Group that matches your size and risk.","5.frameworks\u002Fcis-controls","gaRyAaXBNCCifpPHQ4shp8GnGye1rXarE4ODI3ycKy8",{"id":560,"title":561,"advantages":562,"body":584,"checklist":1009,"cta":1018,"description":93,"extension":151,"faq":1021,"hero":1039,"lastUpdated":186,"meta":1047,"name":1048,"navigation":188,"path":1049,"resources":1050,"seo":1063,"slug":1066,"stats":1067,"stem":1077,"__hash__":1078},"frameworks\u002F5.frameworks\u002Fcmmc.md","Cmmc",[563,570,577],{"title":564,"description":565,"bullets":566},"NIST 800-171 control mapping","Every CMMC Level 2 practice is linked to its NIST SP 800-171 source requirement with pre-written narratives.",[567,568,569],"14 control families mapped to 110 security requirements","AI-drafted implementation narratives and testing procedures","Gap analysis highlights missing controls before your assessment",{"title":571,"description":572,"bullets":573},"Assessment preparation workspace","Whether you self-assess or engage a C3PAO, episki organizes evidence and scoring in one place.",[574,575,576],"POA&M tracking with 180-day close-out reminders","Scoring methodology aligned to DoD assessment guide","Assessor portal with scoped read-only access",{"title":578,"description":579,"bullets":580},"Cross-framework reuse","Controls mapped to CMMC automatically satisfy overlapping NIST CSF, ISO 27001, and FedRAMP requirements.",[581,582,583],"Unified control graph eliminates duplicate documentation","Evidence collected once, reused across every framework","Framework coverage dashboard shows gaps at a glance",{"type":29,"value":585,"toc":990},[586,590,593,596,601,608,619,630,634,642,674,677,681,693,704,708,711,728,741,744,748,751,762,769,773,787,790,794,802,828,832,859,863,871,875,883,887,895,899,902,941,945,977,980,982],[32,587,589],{"id":588},"what-is-cmmc","What is CMMC?",[37,591,592],{},"The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense's verification program for ensuring that every organization in the defense industrial base adequately protects sensitive federal information. CMMC takes the cybersecurity standards the DoD has required for years and turns them into a verifiable certification that contractors must hold before a contract can be awarded.",[37,594,595],{},"Before CMMC, defense contractors were expected to comply with DFARS clause 252.204-7012 and the 110 security requirements in NIST SP 800-171 on the honor system. They self-attested. A 2018 DoD Inspector General report and the 2019 MITRE \"Deliver Uncompromised\" study both found the self-attestation model was failing — contractors claimed compliance they had not achieved, and nation-state adversaries were quietly stealing terabytes of Controlled Unclassified Information (CUI) from the supply chain. CMMC is the DoD's response: instead of trust, the Pentagon now requires verification.",[597,598,600],"h3",{"id":599},"cmmc-10-to-cmmc-20","CMMC 1.0 to CMMC 2.0",[37,602,603,604,607],{},"The first version of CMMC — sometimes called CMMC 1.0 — was announced in January 2020. It had ",[53,605,606],{},"five maturity levels",", added its own unique practices and maturity processes on top of NIST SP 800-171, and would have required third-party assessment for almost everyone in the defense supply chain. Industry pushback was substantial. Small businesses said the compliance burden was unaffordable. Cybersecurity teams argued that the custom CMMC practices and \"maturity processes\" diverged from established standards without clear security benefit.",[37,609,610,611,614,615,618],{},"In November 2021 the DoD announced ",[53,612,613],{},"CMMC 2.0",", a streamlined successor. CMMC 2.0 collapsed the five levels into ",[53,616,617],{},"three",", eliminated the custom CMMC practices, and aligned Level 2 directly with NIST SP 800-171 so there is no daylight between the two. It also re-introduced self-assessment as a compliant path for many contracts — a concession to cost that CMMC 1.0 did not allow.",[37,620,621,622,625,626,629],{},"The CMMC 2.0 program rule (32 CFR Part 170) was published in the Federal Register on October 15, 2024, and took effect on ",[53,623,624],{},"December 16, 2024",". The companion DFARS rule (48 CFR) was published on September 10, 2025, and took effect on ",[53,627,628],{},"November 10, 2025"," — the moment CMMC moved from a program on paper to an enforceable contract requirement. When we talk about \"CMMC\" today, we mean CMMC 2.0 as enforced through DFARS.",[597,631,633],{"id":632},"the-three-cmmc-levels","The three CMMC levels",[37,635,636,637,641],{},"CMMC uses a tiered model so that a small contractor handling a bill of materials gets a proportionate requirement, while a prime contractor engineering a weapons system gets a much heavier one. Each CMMC level builds on the one below it. ",[249,638,640],{"href":639},"\u002Fframeworks\u002Fcmmc\u002Flevels","See the full breakdown of CMMC levels"," for control counts, assessment types, and scoping rules.",[47,643,644,654,664],{},[50,645,646,649,650,653],{},[53,647,648],{},"Level 1 — Foundational."," Covers the basic safeguarding of Federal Contract Information (FCI). It requires 17 practices drawn directly from FAR 52.204-21. Any organization that processes FCI under a DoD contract must meet Level 1. It is verified through an ",[53,651,652],{},"annual self-assessment"," with a senior official affirming the results in the Supplier Performance Risk System (SPRS).",[50,655,656,659,660,663],{},[53,657,658],{},"Level 2 — Advanced."," Protects Controlled Unclassified Information (CUI). It requires all ",[53,661,662],{},"110 security requirements"," from NIST SP 800-171 Rev 2 across 14 control families. Level 2 has two assessment paths — self-assessment for less sensitive CUI, and third-party C3PAO assessment for more sensitive CUI or critical programs. Level 2 is where most defense contractors will land.",[50,665,666,669,670,673],{},[53,667,668],{},"Level 3 — Expert."," Reserved for the most sensitive DoD programs where advanced persistent threats are a credible risk. It includes every Level 2 requirement ",[53,671,672],{},"plus 24 enhanced requirements"," selected from NIST SP 800-172. Level 3 is verified through a government-led DIBCAC assessment and requires a valid Level 2 C3PAO certification as a prerequisite.",[37,675,676],{},"The CMMC level you need is determined by the specific solicitation or contract — not by company size or industry. A small engineering firm with a CUI-sensitive subcontract may need Level 2 C3PAO, while a larger prime on a less sensitive contract may only need Level 1.",[597,678,680],{"id":679},"nist-sp-800-171-is-the-heart-of-cmmc","NIST SP 800-171 is the heart of CMMC",[37,682,683,684,687,688,692],{},"CMMC Level 2 is a ",[53,685,686],{},"direct one-to-one mapping"," to NIST SP 800-171 Rev 2. There are no extra practices, no CMMC-specific maturity processes, no layered-on requirements. Every CMMC Level 2 practice corresponds to a single NIST SP 800-171 security requirement. This alignment was intentional: it made CMMC easier to implement and easier to audit, and it meant organizations that had been working toward ",[249,689,691],{"href":690},"\u002Fglossary\u002Fnist","NIST"," SP 800-171 compliance since 2017 did not have to start over.",[37,694,695,696,700,701,703],{},"The 110 requirements are organized into 14 control families including Access Control, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, System and Communications Protection, and System and Information Integrity. CMMC Level 3 layers 24 additional enhanced requirements on top, drawn from NIST SP 800-172. ",[249,697,699],{"href":698},"\u002Fframeworks\u002Fcmmc\u002Fnist-800-171-mapping","See the detailed NIST SP 800-171 mapping"," for the full control family breakdown and cross-framework overlap with ",[249,702,465],{"href":464}," and ISO 27001.",[597,705,707],{"id":706},"who-needs-cmmc","Who needs CMMC?",[37,709,710],{},"Any organization that processes, stores, or transmits FCI or CUI as part of a DoD contract or subcontract will need CMMC certification. That is a much broader population than \"defense contractors\" in the traditional sense. CMMC applies to:",[47,712,713,716,719,722,725],{},[50,714,715],{},"Prime contractors holding contracts directly with the DoD",[50,717,718],{},"Subcontractors at every tier in the supply chain",[50,720,721],{},"Cloud service providers hosting DoD contractor data",[50,723,724],{},"Managed service providers and IT vendors with access to FCI or CUI",[50,726,727],{},"Foreign suppliers in the defense industrial base handling covered information",[37,729,730,731,735,736,740],{},"CMMC flow-down is one of the most important operational realities. If a prime contractor shares CUI with a subcontractor, that subcontractor must hold the same CMMC level. If that subcontractor further shares CUI with a tier-three supplier, the tier-three supplier must also be certified. CMMC's reach extends deep into the supply chain. ",[249,732,734],{"href":733},"\u002Fframeworks\u002Fcmmc\u002Fwho-needs-cmmc","See who needs CMMC"," for detailed scoping guidance, and our ",[249,737,739],{"href":738},"\u002Findustry\u002Fgovernment","government industry page"," for broader public-sector compliance context.",[37,742,743],{},"Roughly 80,000 organizations are expected to pursue CMMC Level 2, and a few thousand the most stringent CMMC Level 3 — numbers from the DoD's own economic analysis of the CMMC rule.",[597,745,747],{"id":746},"the-cmmc-assessment-process","The CMMC assessment process",[37,749,750],{},"CMMC assessments come in three flavors that align to the three CMMC levels: self-assessment, C3PAO third-party assessment, and DIBCAC government-led assessment. Regardless of type, the assessment methodology is the same — scoring is based on the DoD Assessment Methodology and NIST SP 800-171A objectives.",[37,752,753,754,757,758,761],{},"A CMMC Level 2 C3PAO assessment typically runs through five stages: scoping, readiness review, evidence collection and review, on-site or virtual assessment, and scoring with any final findings. A Level 2 assessment starts with a score of 110 and subtracts points for each unmet objective. A score of 110 yields full certification. A score of ",[53,755,756],{},"88 or above"," with remaining gaps documented in a Plan of Action and Milestones (POA&M) yields a ",[53,759,760],{},"conditional"," certification with a 180-day remediation window. A score below 88 yields no certification at all.",[37,763,764,768],{},[249,765,767],{"href":766},"\u002Fframeworks\u002Fcmmc\u002Fassessment-process","See the full CMMC assessment process"," for scoring details, POA&M rules, and what you can and cannot defer.",[597,770,772],{"id":771},"c3paos-and-certified-assessors","C3PAOs and certified assessors",[37,774,775,776,779,780,392,783,786],{},"Third-party CMMC assessments are conducted by ",[53,777,778],{},"CMMC Third-Party Assessment Organizations (C3PAOs)"," accredited by the Cyber AB (the Cyber Accreditation Body, formerly the CMMC Accreditation Body). C3PAOs employ ",[53,781,782],{},"Certified CMMC Assessors (CCAs)",[53,784,785],{},"Certified CMMC Professionals (CCPs)"," who conduct the actual assessment work. CCAs must pass a certification exam administered by the Cyber AB and complete ongoing professional development.",[37,788,789],{},"The pool of accredited C3PAOs is deliberately limited — growing from just a handful at the start of 2024 to several dozen by early 2026. That scarcity matters. As CMMC Phase 2 enforcement begins in November 2026 and more contracts require C3PAO assessment, assessor availability will tighten. Organizations that wait to begin CMMC preparation until a contract requires it will likely find assessment slots booked six to twelve months out.",[597,791,793],{"id":792},"cmmc-implementation-timeline","CMMC implementation timeline",[37,795,796,797,801],{},"CMMC enforcement follows a four-phase rollout under the DFARS rule. The rollout gradually expands CMMC requirements over four years so the assessor ecosystem can scale and contractors have time to prepare. ",[249,798,800],{"href":799},"\u002Fframeworks\u002Fcmmc\u002Fimplementation-timeline","See the full CMMC implementation timeline"," for dates and milestones.",[47,803,804,810,816,822],{},[50,805,806,809],{},[53,807,808],{},"Phase 1 (November 2025 – November 2026)."," Active now. CMMC Level 1 and Level 2 self-assessments appear as conditions of award in select solicitations. A limited number of contracts require Level 2 C3PAO assessments at DoD discretion.",[50,811,812,815],{},[53,813,814],{},"Phase 2 (November 2026 – November 2027)."," CMMC Level 2 C3PAO certification requirements expand significantly. Level 3 requirements begin appearing in select solicitations.",[50,817,818,821],{},[53,819,820],{},"Phase 3 (November 2027 – November 2028)."," CMMC Level 2 and Level 3 requirements appear broadly across applicable DoD contracts.",[50,823,824,827],{},[53,825,826],{},"Phase 4 (November 2028 onward)."," All DoD contracts requiring FCI or CUI handling include the appropriate CMMC level as a condition of award. Full CMMC enforcement.",[597,829,831],{"id":830},"cmmc-and-dfars","CMMC and DFARS",[37,833,834,835,838,839,392,842,845,846,849,850,854,855,258],{},"CMMC is the certification. DFARS is the contractual mechanism that makes the certification binding. ",[53,836,837],{},"DFARS 252.204-7012"," has required safeguarding of covered defense information and rapid incident reporting since 2017. ",[53,840,841],{},"DFARS 252.204-7019",[53,843,844],{},"-7020"," added the requirement to post NIST SP 800-171 assessment scores to SPRS. ",[53,847,848],{},"DFARS 252.204-7021",", effective November 10, 2025, added the requirement to hold the specific CMMC level called out in the solicitation before contract award. ",[249,851,853],{"href":852},"\u002Fframeworks\u002Fcmmc\u002Fdfars-relationship","See how CMMC and DFARS relate"," for the full clause-by-clause picture. For blog-length coverage of DFARS and CMMC in context, see our ",[249,856,858],{"href":857},"\u002Fblog\u002Fcompliance-framework-comparison","compliance framework comparison",[597,860,862],{"id":861},"self-assessment-vs-third-party-assessment","Self-assessment vs third-party assessment",[37,864,865,866,870],{},"Not every CMMC obligation requires bringing in a C3PAO. CMMC Level 1 is always a self-assessment. CMMC Level 2 splits — some contracts accept self-assessment, and some require C3PAO certification. CMMC Level 3 is always government-led by DIBCAC. Self-assessment is cheaper and faster, but it comes with False Claims Act exposure if the attestation misrepresents your posture. Third-party CMMC assessment is more expensive but produces a defensible certification. ",[249,867,869],{"href":868},"\u002Fframeworks\u002Fcmmc\u002Fself-assessment-vs-third-party","Compare CMMC self-assessment vs third-party"," to decide which applies to you and how to budget.",[597,872,874],{"id":873},"handling-cui-the-cmmc-way","Handling CUI the CMMC way",[37,876,877,878,882],{},"Controlled Unclassified Information sits at the center of CMMC Level 2 and CMMC Level 3. Identifying CUI in your environment, marking it correctly, applying the right access controls, and documenting the CUI boundary are all preconditions for a successful CMMC assessment. FCI and CUI are not the same thing, and the differences drive which CMMC level you need. ",[249,879,881],{"href":880},"\u002Fframeworks\u002Fcmmc\u002Fcui-handling","See CUI handling under CMMC"," for marking rules, scoping guidance, and common mistakes.",[597,884,886],{"id":885},"subcontractor-requirements","Subcontractor requirements",[37,888,889,890,894],{},"CMMC flow-down affects nearly every defense prime. If you share FCI or CUI with a subcontractor, the subcontractor must hold the required CMMC level before you share the data. That means primes need to track subcontractor CMMC status across their supply chain, verify SPRS entries, and plan for the long tail of small suppliers that may not have started their CMMC journey. ",[249,891,893],{"href":892},"\u002Fframeworks\u002Fcmmc\u002Fsubcontractor-requirements","See CMMC subcontractor requirements"," for the full flow-down model and how to reduce the burden.",[597,896,898],{"id":897},"getting-cmmc-ready","Getting CMMC ready",[37,900,901],{},"CMMC readiness is not a last-mile sprint. Most organizations need 6 to 18 months to close gaps across all 110 NIST SP 800-171 requirements and prepare for CMMC Level 2. The high-leverage moves to start today:",[903,904,905,911,917,923,929,935],"ol",{},[50,906,907,910],{},[53,908,909],{},"Scope your CMMC environment."," Map where FCI and CUI enter, flow through, and are stored in your systems. Your CMMC assessment boundary is only as good as your scoping work.",[50,912,913,916],{},[53,914,915],{},"Complete your SSP."," A System Security Plan that documents every NIST SP 800-171 requirement — implementation status, responsible party, and evidence reference — is the backbone of any CMMC assessment.",[50,918,919,922],{},[53,920,921],{},"Submit a SPRS score."," Even before any contract requires CMMC, a current SPRS score demonstrates good faith and exposes gaps early. DoD agencies increasingly reference SPRS scores in source selection.",[50,924,925,928],{},[53,926,927],{},"Stand up a POA&M register."," Track every gap with an owner, a remediation plan, and a 180-day countdown. CMMC conditional certification lives or dies on POA&M closure.",[50,930,931,934],{},[53,932,933],{},"Review your flow-down."," Inventory every subcontractor, cloud service provider, and managed service provider that touches FCI or CUI. Confirm they are on their own CMMC path.",[50,936,937,940],{},[53,938,939],{},"Schedule a readiness review."," A mock CMMC assessment — internal or with a consultant or C3PAO — surfaces problems while there is still time to fix them.",[597,942,944],{"id":943},"common-cmmc-challenges","Common CMMC challenges",[47,946,947,953,959,965,971],{},[50,948,949,952],{},[53,950,951],{},"Scoping complexity."," Determining which systems, people, and processes handle CUI is often the hardest first step and the source of the most CMMC assessment rework.",[50,954,955,958],{},[53,956,957],{},"NIST SP 800-171 gaps."," Many contractors self-attested NIST SP 800-171 compliance for years but never closed all 110 requirements. CMMC exposes that gap.",[50,960,961,964],{},[53,962,963],{},"POA&M management."," Tracking remediation across teams within a 180-day window is hard without tooling. CMMC conditional certifications are revoked when POA&Ms go stale.",[50,966,967,970],{},[53,968,969],{},"Subcontractor flow-down."," Primes must verify subcontractor CMMC status continuously, not once at onboarding.",[50,972,973,976],{},[53,974,975],{},"Evidence organization."," A CMMC assessment can touch hundreds of evidence artifacts. Without a single source of truth, assessors burn billable hours chasing documents.",[37,978,979],{},"A structured approach that maps controls to NIST SP 800-171, reuses evidence across CMMC and other frameworks, tracks POA&M progress, and monitors the assessment timeline removes most of this friction — and that is exactly what the episki CMMC workspace is designed for.",[32,981,244],{"id":243},[37,983,984,985,254,988,258],{},"episki supports CMMC assessments at each level as first-class records with an in-app report and export, scoped to a program so the assessment inherits the controls and evidence your NIST 800-171 work already produced. The CUI enclave is an enforceable boundary with rules on cloud account, region, resource, and tag, POA&M items are findings with owners that sync into your engineers' tracker, and subcontractor flow-down runs through the TPRM module with review cadences that advance on accepted evidence. ",[249,986,253],{"href":185,"rel":987},[252],[249,989,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":991},[992,1008],{"id":588,"depth":94,"text":589,"children":993},[994,996,997,998,999,1000,1001,1002,1003,1004,1005,1006,1007],{"id":599,"depth":995,"text":600},3,{"id":632,"depth":995,"text":633},{"id":679,"depth":995,"text":680},{"id":706,"depth":995,"text":707},{"id":746,"depth":995,"text":747},{"id":771,"depth":995,"text":772},{"id":792,"depth":995,"text":793},{"id":830,"depth":995,"text":831},{"id":861,"depth":995,"text":862},{"id":873,"depth":995,"text":874},{"id":885,"depth":995,"text":886},{"id":897,"depth":995,"text":898},{"id":943,"depth":995,"text":944},{"id":243,"depth":94,"text":244},{"title":1010,"description":1011,"items":1012},"CMMC readiness checklist inside episki","Everything is preloaded in your free trial so you can start scoping your assessment and closing gaps immediately.",[1013,1014,1015,1016,1017],"NIST SP 800-171 control library with mapped CMMC practices","Level 1, 2, and 3 scoping guidance and practice sets","POA&M register with risk-ranked remediation priorities","System Security Plan (SSP) template with AI drafting","Evidence library organized by control family",{"title":1019,"description":1020},"Launch your CMMC workspace today","Import your NIST 800-171 controls, map them to CMMC levels, and start closing gaps before your next assessment.",{"title":1022,"items":1023},"CMMC frequently asked questions",[1024,1027,1030,1033,1036],{"label":1025,"content":1026},"What is CMMC 2.0?","CMMC 2.0 (Cybersecurity Maturity Model Certification) is the Department of Defense's program for verifying that defense contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The final program rule took effect December 16, 2024, and DFARS contract enforcement began November 10, 2025.",{"label":1028,"content":1029},"What are the three CMMC levels?","Level 1 requires 17 basic safeguarding practices for FCI based on FAR 52.204-21. Level 2 requires 110 security practices aligned to NIST SP 800-171 Rev 2 for CUI. Level 3 adds 24 enhanced practices from NIST SP 800-172 for the most sensitive programs. Each level builds on the one below it.",{"label":1031,"content":1032},"How much does CMMC certification cost?","Costs vary by level and organization size. Level 1 requires only an annual self-assessment. Level 2 self-assessments are free but require significant preparation effort. Level 2 C3PAO assessments typically range from $50,000 to $150,000+ depending on scope. episki reduces preparation costs by automating evidence collection and control documentation.",{"label":1034,"content":1035},"When will CMMC be required in contracts?","CMMC is being phased into DoD contracts over four phases. Phase 1 began November 10, 2025, requiring Level 1 and Level 2 self-assessments in select solicitations. Phase 2 (November 2026) expands Level 2 C3PAO requirements. Phase 3 (November 2027) adds Level 3. By Phase 4 (November 2028), all applicable DoD contracts will require the appropriate CMMC level.",{"label":1037,"content":1038},"Who needs CMMC certification?","Any organization that processes, stores, or transmits FCI or CUI as part of a DoD contract or subcontract needs CMMC certification. This includes prime contractors, subcontractors at all tiers, and cloud service providers hosting DoD data. The required level depends on the sensitivity of information handled.",{"headline":1040,"title":1041,"description":1042,"links":1043},"CMMC without the guesswork","Get assessment-ready for CMMC without rebuilding your security program","episki maps NIST SP 800-171 and 800-172 controls to CMMC levels, automates evidence collection, and keeps your POA&M current so your team can focus on winning contracts.",[1044,1046],{"label":1045,"icon":182,"to":185},"Start CMMC trial",{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"CMMC","\u002Fframeworks\u002Fcmmc",{"headline":1051,"title":1051,"description":1052,"items":1053},"CMMC acceleration resources","Give leadership and contracting officers visibility into your cybersecurity posture at every stage.",[1054,1057,1060],{"title":1055,"description":1056},"Executive scorecard","Translate control work into CMMC readiness percentages and contract eligibility status.",{"title":1058,"description":1059},"Assessment readiness kit","Pre-assessment checklist, evidence package review, and mock scoring aligned to DIBCAC methodology.",{"title":1061,"description":1062},"Subcontractor flow-down tracker","Monitor which subcontractors need their own CMMC certification and track their progress.",{"title":1064,"description":1065},"CMMC Compliance Software","Prepare for CMMC Level 1, 2, and 3 assessments with pre-mapped NIST 800-171 controls, automated evidence collection, and C3PAO-ready workspaces. Start your free 14-day trial.","cmmc",[1068,1071,1074],{"value":1069,"description":1070},"3 maturity levels","Pre-mapped practices for Level 1, Level 2, and Level 3 with assessment-type guidance for each.",{"value":1072,"description":1073},"110 practices","Full NIST SP 800-171 Rev 2 control set mapped to CMMC Level 2 objectives out of the box.",{"value":1075,"description":1076},"Phase 1 live now","DFARS enforcement began November 2025. Level 1 and Level 2 self-assessments already required in select solicitations.","5.frameworks\u002Fcmmc","gMD5paAoXE_aZOmHJZEWrJS_-CZIEA8loWsQdRDKX-M",{"id":1080,"title":1081,"advantages":1082,"body":1104,"checklist":1180,"cta":1190,"description":93,"extension":151,"faq":1193,"hero":1207,"lastUpdated":186,"meta":1214,"name":1114,"navigation":188,"path":1215,"resources":1216,"seo":1230,"slug":1233,"stats":1234,"stem":1242,"__hash__":1243},"frameworks\u002F5.frameworks\u002Fcsa-star.md","Csa Star",[1083,1090,1097],{"title":1084,"description":1085,"bullets":1086},"CCM v4 control library","The Cloud Controls Matrix implemented as living episki controls.",[1087,1088,1089],"17 domains of cloud security control objectives","Shared-responsibility model captured per control","Built-in mappings to ISO 27001, SOC 2, and more",{"title":1091,"description":1092,"bullets":1093},"CAIQ, answered from evidence","Complete the Consensus Assessment Initiative Questionnaire from real controls.",[1094,1095,1096],"CAIQ v4 responses generated from your controls","Consistent answers across customer questionnaires","Publish to the CSA STAR registry",{"title":1098,"description":1099,"bullets":1100},"One effort, many programs","CCM is a meta-framework — its controls map almost everywhere.",[1101,1102,1103],"Crosswalk to ISO 27001 \u002F 27017 \u002F 27018","Crosswalk to SOC 2 and NIST CSF","Reuse for PCI DSS and GDPR mapping",{"type":29,"value":1105,"toc":1174},[1106,1110,1127,1131,1146,1150,1164,1166],[32,1107,1109],{"id":1108},"what-is-csa-star","What is CSA STAR?",[37,1111,1112,1115,1116,1119,1120,1123,1124,258],{},[53,1113,1114],{},"CSA STAR"," — Security, Trust, Assurance and Risk — is the ",[53,1117,1118],{},"Cloud Security Alliance's"," cloud assurance program. It gives cloud providers a recognized way to document and publish their security posture, and gives cloud customers a public registry to evaluate them. STAR is built on two artifacts: the ",[53,1121,1122],{},"Cloud Controls Matrix (CCM)"," and the ",[53,1125,1126],{},"Consensus Assessment Initiative Questionnaire (CAIQ)",[32,1128,1130],{"id":1129},"ccm-v4-and-the-caiq","CCM v4 and the CAIQ",[37,1132,1133,1134,1137,1138,1141,1142,1145],{},"The current ",[53,1135,1136],{},"CCM v4"," organizes roughly ",[53,1139,1140],{},"197 control objectives across 17 domains"," of cloud security — identity and access management, data security and privacy, application security, supply-chain management, and more — with the shared-responsibility model built in. The ",[53,1143,1144],{},"CAIQ"," is the questionnaire form of the CCM: a standardized set of yes\u002Fno questions that maps to each control, designed to replace the endless bespoke security questionnaires that cloud buyers send.",[32,1147,1149],{"id":1148},"star-levels","STAR Levels",[47,1151,1152,1158],{},[50,1153,1154,1157],{},[53,1155,1156],{},"Level 1 — Self-Assessment."," Complete the CAIQ (or a CCM-based self-assessment) and publish it to the free, public CSA STAR registry.",[50,1159,1160,1163],{},[53,1161,1162],{},"Level 2 — Third-Party Assessment."," An accredited assessor verifies your controls, often as a STAR Certification (paired with ISO 27001) or STAR Attestation (paired with SOC 2).",[32,1165,244],{"id":243},[37,1167,1168,1169,254,1172,258],{},"episki ships the CAIQ v4.1 and CCM Lite questionnaires in its catalog, and the Trust module lets agents draft answers grounded in your own evidence with the excerpt each draft came from shown for review. CCM controls are evaluated continuously across your cloud estate and crosswalk to ISO 27001 and SOC 2 through the SCF hub. ",[249,1170,253],{"href":185,"rel":1171},[252],[249,1173,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":1175},[1176,1177,1178,1179],{"id":1108,"depth":94,"text":1109},{"id":1129,"depth":94,"text":1130},{"id":1148,"depth":94,"text":1149},{"id":243,"depth":94,"text":244},{"title":1181,"description":1182,"items":1183},"CSA STAR readiness inside episki","What a cloud provider needs to reach the STAR registry.",[1184,1185,1186,1187,1188,1189],"CCM v4 control library scoped to your services","Shared-responsibility documentation per control","CAIQ v4 questionnaire completed from evidence","STAR Level 1 self-assessment package","STAR Level 2 third-party certification readiness","Crosswalks to ISO 27001 and SOC 2",{"title":1191,"description":1192},"Reach the STAR registry from episki","Implement CCM v4 once, answer the CAIQ from evidence, and reuse it across ISO 27001 and SOC 2.",{"title":1194,"items":1195},"CSA STAR frequently asked questions",[1196,1198,1201,1204],{"label":1109,"content":1197},"CSA STAR (Security, Trust, Assurance and Risk) is a cloud assurance program from the Cloud Security Alliance. It is built on the Cloud Controls Matrix (CCM) — currently CCM v4, with around 197 control objectives across 17 domains — and the Consensus Assessment Initiative Questionnaire (CAIQ). Results are published on the public CSA STAR registry.",{"label":1199,"content":1200},"What are STAR Levels 1 and 2?","STAR Level 1 is a self-assessment in which an organization completes the CAIQ or a CCM-based self-assessment and publishes it to the registry. STAR Level 2 is a third-party assessment — a certification or attestation performed by an accredited assessor, often combined with an ISO 27001 or SOC 2 audit.",{"label":1202,"content":1203},"What is the Cloud Controls Matrix?","The CCM is a cybersecurity control framework for cloud computing, organized into domains covering areas such as identity and access management, data security, and supply-chain management. It is a meta-framework with built-in mappings to ISO 27001, ISO 27017\u002F27018, SOC 2, NIST CSF, PCI DSS, and more.",{"label":1205,"content":1206},"How does STAR relate to ISO 27001 and SOC 2?","STAR Level 2 is frequently pursued alongside ISO 27001 or SOC 2 because the CCM maps to both, letting a single body of evidence support multiple cloud-assurance outcomes at once.",{"headline":1208,"title":1209,"description":1210,"links":1211},"Cloud assurance, on the STAR registry","Run the CSA STAR program with CCM v4","The Cloud Controls Matrix v4 as a living control library and the CAIQ as a guided questionnaire — Level 1 self-assessment or Level 2 third-party assurance — mapped to ISO 27001 and SOC 2.",[1212,1213],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"\u002Fframeworks\u002Fcsa-star",{"headline":1217,"title":1218,"description":1219,"items":1220},"CSA STAR accelerators","Cloud assurance accelerators","Get listed on the STAR registry and stop re-answering the same questionnaires.",[1221,1224,1227],{"title":1222,"description":1223},"CAIQ builder","Generate consistent CAIQ v4 answers from your live controls.",{"title":1225,"description":1226},"CCM crosswalk","Map CCM controls to ISO 27001, SOC 2, and NIST CSF automatically.",{"title":1228,"description":1229},"STAR submission pack","Assemble the Level 1 or Level 2 package for the STAR registry.",{"title":1231,"description":1232},"CSA STAR \u002F CCM Compliance Software","Complete the CSA STAR program with the Cloud Controls Matrix v4 (CCM) and CAIQ — Level 1 self-assessment or Level 2 certification — cross-mapped to ISO 27001 and SOC 2.","csa-star",[1235,1237,1239],{"value":1136,"description":1236},"~197 control objectives across 17 cloud security domains.",{"value":1144,"description":1238},"The Consensus Assessment Initiative Questionnaire, answered from live controls.",{"value":1240,"description":1241},"STAR L1 \u002F L2","Self-assessment or third-party certification on the public STAR registry.","5.frameworks\u002Fcsa-star","V88mMucyVPOzqD6W9gV4Fx35Z68NJFTCiisCHY0mJCI",{"id":1245,"title":1246,"advantages":1247,"body":1269,"checklist":1367,"cta":1377,"description":93,"extension":151,"faq":1380,"hero":1394,"lastUpdated":186,"meta":1401,"name":1246,"navigation":188,"path":1402,"resources":1403,"seo":1416,"slug":1419,"stats":1420,"stem":1430,"__hash__":1431},"frameworks\u002F5.frameworks\u002Fcyber-essentials.md","Cyber Essentials",[1248,1255,1262],{"title":1249,"description":1250,"bullets":1251},"The five technical controls","The complete Cyber Essentials control set, implemented and evidenced.",[1252,1253,1254],"Firewalls and secure configuration","User access control with MFA","Malware protection and update management",{"title":1256,"description":1257,"bullets":1258},"CE and CE Plus ready","Self-assessment for CE, and a clean evidence trail for the CE Plus audit.",[1259,1260,1261],"Self-assessment questionnaire support","Asset and device scoping","Evidence ready for the CE Plus technical audit",{"title":1263,"description":1264,"bullets":1265},"A UK on-ramp that maps up","Cyber Essentials controls feed your larger frameworks.",[1266,1267,1268],"Crosswalk to ISO 27001 and NIST CSF","Reuse evidence across SOC 2","Government-recognized baseline",{"type":29,"value":1270,"toc":1361},[1271,1275,1292,1295,1330,1334,1351,1353],[32,1272,1274],{"id":1273},"what-is-cyber-essentials","What is Cyber Essentials?",[37,1276,1277,1279,1280,1283,1284,1287,1288,1291],{},[53,1278,1246],{}," is a UK government-backed certification scheme — owned by the ",[53,1281,1282],{},"National Cyber Security Centre (NCSC)"," and delivered by the ",[53,1285,1286],{},"IASME Consortium"," — designed to protect organizations against the most common internet-based cyber attacks. It is deliberately simple: the entire scheme rests on ",[53,1289,1290],{},"five technical controls",", which makes it an excellent baseline and a frequent requirement for UK public-sector contracts.",[32,1293,1249],{"id":1294},"the-five-technical-controls",[903,1296,1297,1303,1309,1318,1324],{},[50,1298,1299,1302],{},[53,1300,1301],{},"Firewalls"," — boundary and host firewalls configured to block untrusted traffic.",[50,1304,1305,1308],{},[53,1306,1307],{},"Secure configuration"," — remove or disable unnecessary functionality and change default credentials.",[50,1310,1311,1314,1315,258],{},[53,1312,1313],{},"User access control"," — least-privilege accounts, with ",[53,1316,1317],{},"multi-factor authentication required for cloud services",[50,1319,1320,1323],{},[53,1321,1322],{},"Malware protection"," — anti-malware, allow-listing, or sandboxing across in-scope devices.",[50,1325,1326,1329],{},[53,1327,1328],{},"Security update management"," — keep software supported and patched within required windows.",[32,1331,1333],{"id":1332},"cyber-essentials-vs-cyber-essentials-plus","Cyber Essentials vs Cyber Essentials Plus",[37,1335,1336,1338,1339,1342,1343,1346,1347,1350],{},[53,1337,1246],{}," is a verified self-assessment against the five controls. ",[53,1340,1341],{},"Cyber Essentials Plus"," assesses the same controls but adds a hands-on ",[53,1344,1345],{},"technical audit"," — vulnerability scans and tests of a sample of in-scope devices — for a higher level of assurance. NCSC and IASME ",[53,1348,1349],{},"update the technical requirements annually",", so recent revisions have tightened expectations (for example, mandatory MFA for cloud services and stricter marking of critical controls).",[32,1352,244],{"id":243},[37,1354,1355,1356,254,1359,258],{},"episki evaluates the five Cyber Essentials technical controls from the systems that implement them — firewall and boundary configuration, secure configuration, access control, malware protection, and patch posture — writing an explicit verdict for each rather than collecting a screenshot. Failing checks raise findings with owners so remediation happens before assessment. ",[249,1357,253],{"href":185,"rel":1358},[252],[249,1360,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":1362},[1363,1364,1365,1366],{"id":1273,"depth":94,"text":1274},{"id":1294,"depth":94,"text":1249},{"id":1332,"depth":94,"text":1333},{"id":243,"depth":94,"text":244},{"title":1368,"description":1369,"items":1370},"Cyber Essentials readiness inside episki","What a UK organization needs in place.",[1371,1372,1373,1374,1375,1376],"Scope definition (devices, users, cloud services)","Firewalls and boundary controls","Secure configuration and removal of defaults","User access control with MFA on cloud services","Malware protection across in-scope devices","Security update management within required windows",{"title":1378,"description":1379},"Certify to Cyber Essentials in episki","Implement the five controls once and reuse the evidence toward ISO 27001 and SOC 2.",{"title":1381,"items":1382},"Cyber Essentials frequently asked questions",[1383,1385,1388,1391],{"label":1274,"content":1384},"Cyber Essentials is a UK government-backed certification scheme, run by the National Cyber Security Centre (NCSC) and delivered by the IASME Consortium, that helps organizations protect against the most common cyber attacks. It is built on five technical controls: firewalls, secure configuration, user access control, malware protection, and security update management.",{"label":1386,"content":1387},"What's the difference between CE and CE Plus?","Cyber Essentials is a verified self-assessment. Cyber Essentials Plus covers the same five controls but adds a hands-on technical audit by an assessor, including vulnerability scans and tests of in-scope devices, providing a higher level of assurance.",{"label":1389,"content":1390},"Is multi-factor authentication required?","Yes. The current Cyber Essentials requirements make multi-factor authentication mandatory for cloud services where it is available, alongside stricter marking of critical controls such as timely security updates. NCSC and IASME refresh the technical requirements annually, so the question set evolves each year.",{"label":1392,"content":1393},"Who needs Cyber Essentials?","Any UK organization that wants a recognized cybersecurity baseline — and notably, it is required for many UK central-government contracts that involve handling certain sensitive or personal information.",{"headline":1395,"title":1396,"description":1397,"links":1398},"UK Cyber Essentials, made simple","Certify to Cyber Essentials and CE Plus","The five Cyber Essentials technical controls — firewalls, secure configuration, access control, malware protection, and update management — implemented, evidenced, and ready for assessment.",[1399,1400],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"\u002Fframeworks\u002Fcyber-essentials",{"headline":1404,"title":1404,"description":1405,"items":1406},"Cyber Essentials accelerators","Pass the assessment and keep the certificate current year over year.",[1407,1410,1413],{"title":1408,"description":1409},"Scope builder","Define the devices, users, and cloud services in assessment scope.",{"title":1411,"description":1412},"Control evidence tracker","Owners and evidence for each of the five technical controls.",{"title":1414,"description":1415},"ISO 27001 crosswalk","Reuse Cyber Essentials work toward ISO 27001 and SOC 2.",{"title":1417,"description":1418},"Cyber Essentials Compliance Software","Achieve UK Cyber Essentials and Cyber Essentials Plus — the five technical controls, including mandatory MFA for cloud services — managed and evidenced in one workspace.","cyber-essentials",[1421,1424,1427],{"value":1422,"description":1423},"5 controls","Firewalls, secure configuration, access control, malware protection, and updates.",{"value":1425,"description":1426},"CE + CE Plus","Self-assessed Cyber Essentials and hands-on-verified Cyber Essentials Plus.",{"value":1428,"description":1429},"MFA required","Multi-factor authentication for cloud services per the current requirements.","5.frameworks\u002Fcyber-essentials","MesGk7_I4IdHjNl47Kcy-RGGSPYx-vfIV0zgBNZf2Y4",{"id":1433,"title":1434,"advantages":1435,"body":1457,"checklist":1561,"cta":1571,"description":93,"extension":151,"faq":1574,"hero":1588,"lastUpdated":186,"meta":1595,"name":1596,"navigation":188,"path":1597,"resources":1598,"seo":1612,"slug":1615,"stats":1616,"stem":1626,"__hash__":1627},"frameworks\u002F5.frameworks\u002Fdora.md","Dora",[1436,1443,1450],{"title":1437,"description":1438,"bullets":1439},"ICT risk management framework","The governance, controls, and continuity expected of an in-scope financial entity.",[1440,1441,1442],"ICT risk register tied to control treatments","Business continuity and ICT response plans","Management-body accountability and oversight",{"title":1444,"description":1445,"bullets":1446},"Incident reporting and testing","Classify ICT incidents, hit the reporting windows, and track resilience testing.",[1447,1448,1449],"Incident classification and reporting timers","Major-incident notifications to the competent authority","Resilience testing, including TLPT where required",{"title":1451,"description":1452,"bullets":1453},"ICT third-party risk","The Register of Information and contractual controls DORA requires.",[1454,1455,1456],"Register of Information on ICT providers","Contractual requirements and concentration risk","Reuse of vendor evidence across frameworks",{"type":29,"value":1458,"toc":1554},[1459,1463,1473,1477,1488,1492,1528,1532,1544,1546],[32,1460,1462],{"id":1461},"what-is-dora","What is DORA?",[37,1464,367,1465,1468,1469,1472],{},[53,1466,1467],{},"Digital Operational Resilience Act — Regulation (EU) 2022\u002F2554"," — is an EU regulation that harmonizes how financial entities manage the resilience of the information and communication technology (ICT) they depend on. It has been ",[53,1470,1471],{},"directly applicable across the EU since January 17, 2025",", and because it is a regulation rather than a directive, it applies as written with no national transposition. 2026 marks the first genuine supervisory enforcement cycle, with regulators signaling they will act on incident-reporting failures and gaps in the Register of Information.",[32,1474,1476],{"id":1475},"who-must-comply","Who must comply",[37,1478,1479,1480,1483,1484,1487],{},"DORA covers roughly ",[53,1481,1482],{},"20 types of financial entities"," — banks, insurers and reinsurers, investment firms, payment and electronic-money institutions, crypto-asset service providers, trading venues, and fund managers among them. Critically, it also reaches ",[53,1485,1486],{},"critical ICT third-party service providers"," (such as major cloud and software vendors), which the European Supervisory Authorities can oversee directly.",[32,1489,1491],{"id":1490},"the-five-pillars","The five pillars",[903,1493,1494,1500,1506,1512,1522],{},[50,1495,1496,1499],{},[53,1497,1498],{},"ICT risk management"," — a governance framework, controls, and continuity capabilities owned and overseen by the management body.",[50,1501,1502,1505],{},[53,1503,1504],{},"ICT-related incident management"," — classify ICT incidents by severity and report major incidents to the competent authority within defined windows (initial, intermediate, and final reports).",[50,1507,1508,1511],{},[53,1509,1510],{},"Digital operational resilience testing"," — a testing program that, for significant entities, includes threat-led penetration testing (TLPT).",[50,1513,1514,1517,1518,1521],{},[53,1515,1516],{},"ICT third-party risk management"," — maintain a ",[53,1519,1520],{},"Register of Information"," on all ICT third-party arrangements, impose contractual requirements, and manage concentration risk.",[50,1523,1524,1527],{},[53,1525,1526],{},"Information and intelligence sharing"," — voluntary arrangements to share cyber threat information among financial entities.",[32,1529,1531],{"id":1530},"how-dora-relates-to-nis2","How DORA relates to NIS2",[37,1533,1534,1535,1538,1539,1543],{},"For financial entities, DORA is ",[53,1536,1537],{},"lex specialis",": where DORA and the broader ",[249,1540,1542],{"href":1541},"\u002Fframeworks\u002Fnis2","NIS2"," Directive overlap, DORA's ICT-specific requirements take precedence. In practice, in-scope financial firms run their ICT resilience program to DORA.",[32,1545,244],{"id":243},[37,1547,1548,1549,254,1552,258],{},"episki maps DORA's ICT risk management, incident reporting, resilience testing, and third-party risk pillars onto structures it already runs: controls evaluated on every sync, findings with owners and reporting clocks, penetration and resilience test records linked to the controls they validate, and critical ICT providers tracked as vendor records with consolidated subprocessors and advancing review cadences. ",[249,1550,253],{"href":185,"rel":1551},[252],[249,1553,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":1555},[1556,1557,1558,1559,1560],{"id":1461,"depth":94,"text":1462},{"id":1475,"depth":94,"text":1476},{"id":1490,"depth":94,"text":1491},{"id":1530,"depth":94,"text":1531},{"id":243,"depth":94,"text":244},{"title":1562,"description":1563,"items":1564},"DORA readiness inside episki","What an in-scope financial entity needs in place.",[1565,1566,1567,1568,1569,1570],"ICT risk management framework and policies","ICT asset and dependency inventory","Incident classification and reporting workflow","Register of Information on ICT third-party arrangements","Digital operational resilience testing program (incl. TLPT)","Business continuity and ICT response and recovery plans",{"title":1572,"description":1573},"Build a DORA program in episki","Stand up ICT risk, incident reporting, and the Register of Information — and reuse the evidence across ISO 27001 and SOC 2.",{"title":1575,"items":1576},"DORA frequently asked questions",[1577,1579,1582,1585],{"label":1462,"content":1578},"The Digital Operational Resilience Act (Regulation (EU) 2022\u002F2554) is an EU regulation that sets uniform requirements for the security and operational resilience of the information and communication technology (ICT) that financial entities rely on. It has applied directly across all EU Member States since January 17, 2025 — as a regulation, it needs no national transposition.",{"label":1580,"content":1581},"Who must comply?","DORA applies to around 20 types of financial entities — banks, insurers and reinsurers, investment firms, payment and electronic-money institutions, crypto-asset service providers, fund managers, and more — as well as to critical ICT third-party service providers, which fall under direct oversight by the European Supervisory Authorities.",{"label":1583,"content":1584},"What are the five pillars?","DORA is organized into five areas: ICT risk management; ICT-related incident management, classification, and reporting; digital operational resilience testing (including threat-led penetration testing for significant entities); ICT third-party risk management (including the Register of Information); and information- and intelligence-sharing arrangements.",{"label":1586,"content":1587},"How does DORA relate to NIS2?","For financial entities, DORA acts as lex specialis — it takes precedence over the more general NIS2 Directive in the areas it specifically regulates, so in-scope financial firms generally follow DORA's ICT requirements rather than NIS2's.",{"headline":1589,"title":1590,"description":1591,"links":1592},"Digital operational resilience, in one place","Comply with the EU DORA regulation","ICT risk management, incident classification and reporting timers, the Register of Information, and ICT third-party risk — implemented as living controls for financial entities and their ICT providers.",[1593,1594],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"DORA","\u002Fframeworks\u002Fdora",{"headline":1599,"title":1600,"description":1601,"items":1602},"DORA accelerators","DORA readiness accelerators","Stand up a defensible resilience program and survive the first supervisory cycle.",[1603,1606,1609],{"title":1604,"description":1605},"Register of Information builder","Maintain the DORA Register of Information on your ICT third-party arrangements.",{"title":1607,"description":1608},"Incident reporting timers","Classify ICT incidents and track the initial, intermediate, and final report windows.",{"title":1610,"description":1611},"Third-party risk crosswalk","Reuse vendor due-diligence evidence across DORA, ISO 27001, and SOC 2.",{"title":1613,"description":1614},"DORA Compliance Software","Meet the EU Digital Operational Resilience Act (Regulation 2022\u002F2554) — ICT risk management, incident reporting, resilience testing, the Register of Information, and third-party risk in one workspace.","dora",[1617,1620,1623],{"value":1618,"description":1619},"5 pillars","ICT risk, incident reporting, resilience testing, third-party risk, and info sharing.",{"value":1621,"description":1622},"Register of Info","A maintained Register of Information on ICT third-party arrangements.",{"value":1624,"description":1625},"In force","Directly applicable across the EU since January 17, 2025 — no transposition needed.","5.frameworks\u002Fdora","wmV_ZuoFqupe9gprnIL4K-qRyuQt8Fp8Q-o8hQcdSsQ",{"id":1629,"title":1630,"advantages":1631,"body":1653,"checklist":1768,"cta":1778,"description":93,"extension":151,"faq":1781,"hero":1795,"lastUpdated":186,"meta":1802,"name":1803,"navigation":188,"path":1804,"resources":1805,"seo":1819,"slug":1822,"stats":1823,"stem":1833,"__hash__":1834},"frameworks\u002F5.frameworks\u002Feu-ai-act.md","Eu Ai Act",[1632,1639,1646],{"title":1633,"description":1634,"bullets":1635},"Risk classification, done right","Classify each AI system into the Act's risk tiers and apply the right obligations.",[1636,1637,1638],"Prohibited-practice screening","High-risk (Annex III \u002F Annex I) determination","Transparency duties for limited-risk systems",{"title":1640,"description":1641,"bullets":1642},"High-risk obligations as controls","The Annex III obligations implemented and evidenced, not described.",[1643,1644,1645],"Risk management system and data governance","Technical documentation, logging, and transparency","Human oversight, accuracy, robustness, and cybersecurity",{"title":1647,"description":1648,"bullets":1649},"One AI program, many frameworks","AI Act work reuses your ISO 42001 and NIST AI RMF evidence.",[1650,1651,1652],"Crosswalk to ISO 42001 (AIMS)","Crosswalk to the NIST AI RMF","GPAI \u002F foundation-model tracking",{"type":29,"value":1654,"toc":1761},[1655,1659,1669,1673,1676,1702,1709,1713,1744,1748,1751,1753],[32,1656,1658],{"id":1657},"what-is-the-eu-ai-act","What is the EU AI Act?",[37,1660,367,1661,1664,1665,1668],{},[53,1662,1663],{},"EU AI Act — Regulation (EU) 2024\u002F1689"," — is the world's first comprehensive law governing artificial intelligence. It ",[53,1666,1667],{},"entered into force on August 1, 2024"," and regulates AI based on the risk it poses rather than the technology itself. Like the GDPR, it applies extraterritorially: it reaches providers and deployers outside the EU whenever an AI system's output is used within the Union.",[32,1670,1672],{"id":1671},"the-risk-based-tiers","The risk-based tiers",[37,1674,1675],{},"The Act sorts AI into four tiers:",[47,1677,1678,1684,1690,1696],{},[50,1679,1680,1683],{},[53,1681,1682],{},"Unacceptable risk"," — a short list of prohibited practices (for example, social scoring and certain manipulative or biometric-categorization uses). These have been banned since February 2, 2025.",[50,1685,1686,1689],{},[53,1687,1688],{},"High risk"," — AI used as a safety component of regulated products (Annex I) or in listed sensitive domains (Annex III) such as employment, education, essential services, law enforcement, and biometrics. High-risk systems carry the full weight of the Act's obligations.",[50,1691,1692,1695],{},[53,1693,1694],{},"Limited risk"," — systems such as chatbots and generative content tools that carry transparency duties (users must know they are interacting with AI; synthetic content must be marked).",[50,1697,1698,1701],{},[53,1699,1700],{},"Minimal risk"," — everything else, which is largely unregulated.",[37,1703,1704,1705,1708],{},"Separately, ",[53,1706,1707],{},"general-purpose AI (GPAI) models"," carry their own obligations, which began applying on August 2, 2025.",[32,1710,1712],{"id":1711},"the-timeline-and-the-digital-omnibus","The timeline (and the Digital Omnibus)",[37,1714,1715,1716,1719,1720,1723,1724,1727,1728,1731,1732,1735,1736,1739,1740,1743],{},"The Act phases in over several years. Prohibited practices applied from ",[53,1717,1718],{},"February 2, 2025","; GPAI obligations from ",[53,1721,1722],{},"August 2, 2025","; and high-risk obligations were scheduled for ",[53,1725,1726],{},"August 2, 2026",". In 2026, EU institutions reached a provisional ",[53,1729,1730],{},"\"Digital Omnibus\""," agreement that would defer the high-risk obligations — Annex III use-based systems to ",[53,1733,1734],{},"December 2, 2027"," and Annex I product-embedded AI to ",[53,1737,1738],{},"August 2, 2028"," — along with targeted simplifications. That deferral only becomes law once formally adopted and published in the Official Journal; until then, ",[53,1741,1742],{},"August 2, 2026 remains the operative deadline",", so in-scope organizations should keep preparing.",[32,1745,1747],{"id":1746},"high-risk-obligations","High-risk obligations",[37,1749,1750],{},"Providers of high-risk AI must implement a risk management system, data and data-governance practices, technical documentation, automatic logging, transparency and instructions for use, human oversight, and appropriate accuracy, robustness, and cybersecurity — then pass a conformity assessment and maintain post-market monitoring. Deployers carry their own, lighter set of duties.",[32,1752,244],{"id":243},[37,1754,1755,1756,254,1759,258],{},"episki carries EU AI Act obligations in the AI Governance module: an AI system and use-case registry with risk classification, allowlists and safety floors, and treatments wired to controls and evidence. Crosswalks to ISO 42001 and the NIST AI RMF are derived through the SCF hub with recorded provenance, so one governance program serves all three. ",[249,1757,253],{"href":185,"rel":1758},[252],[249,1760,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":1762},[1763,1764,1765,1766,1767],{"id":1657,"depth":94,"text":1658},{"id":1671,"depth":94,"text":1672},{"id":1711,"depth":94,"text":1712},{"id":1746,"depth":94,"text":1747},{"id":243,"depth":94,"text":244},{"title":1769,"description":1770,"items":1771},"EU AI Act readiness inside episki","What an in-scope provider or deployer needs in place.",[1772,1773,1774,1775,1776,1777],"AI system inventory with provider\u002Fdeployer role per system","Risk-tier classification (prohibited, high, limited, minimal)","Risk management system for high-risk AI","Data governance and technical documentation","Logging, human oversight, and transparency measures","Conformity assessment and post-market monitoring evidence",{"title":1779,"description":1780},"Build EU AI Act readiness in episki","Classify your AI, stand up the high-risk obligations, and reuse the work for ISO 42001 and the NIST AI RMF.",{"title":1782,"items":1783},"EU AI Act frequently asked questions",[1784,1786,1789,1792],{"label":1658,"content":1785},"The EU AI Act (Regulation (EU) 2024\u002F1689) is the world's first comprehensive law regulating artificial intelligence. It entered into force on August 1, 2024 and takes a risk-based approach: it bans a small set of unacceptable-risk practices, imposes detailed obligations on high-risk AI systems, requires transparency for limited-risk systems, and leaves minimal-risk AI largely unregulated. It applies extraterritorially to providers and deployers whose AI output is used in the EU.",{"label":1787,"content":1788},"When do the obligations apply?","The Act phases in over time: prohibited practices applied from February 2, 2025 and general-purpose AI (GPAI) model obligations from August 2, 2025. High-risk obligations were set to apply from August 2, 2026. In 2026 the EU reached a provisional 'Digital Omnibus' agreement to defer high-risk obligations (Annex III use-cases to December 2, 2027 and Annex I product-embedded AI to August 2, 2028), but that change only takes effect once formally adopted and published — until then, August 2, 2026 remains the operative date. episki tracks the timeline as it is finalized.",{"label":1790,"content":1791},"What counts as high-risk?","High-risk AI includes systems used as safety components of regulated products (Annex I) and systems in listed sensitive use cases (Annex III) such as employment, education, essential services, law enforcement, and biometrics. High-risk systems carry the heaviest obligations — risk management, data governance, documentation, logging, human oversight, and a conformity assessment.",{"label":1793,"content":1794},"What are the penalties?","Penalties are tiered. Engaging in prohibited AI practices can draw fines up to €35 million or 7% of total worldwide annual turnover, whichever is higher; most other violations are capped at €15 million or 3%, and supplying incorrect information at €7.5 million or 1%.",{"headline":1796,"title":1797,"description":1798,"links":1799},"The EU AI Act, made operational","Classify and govern AI under the EU AI Act","Inventory your AI systems, classify them by risk tier, and stand up the high-risk obligations — risk management, data governance, logging, human oversight — mapped to ISO 42001 and the NIST AI RMF.",[1800,1801],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"EU AI Act","\u002Fframeworks\u002Feu-ai-act",{"headline":1806,"title":1807,"description":1808,"items":1809},"EU AI Act accelerators","AI Act readiness accelerators","Move from \"are we in scope?\" to a defensible high-risk program.",[1810,1813,1816],{"title":1811,"description":1812},"Risk-tier classifier","Walk each AI system through the Act's tiers and surface the applicable obligations.",{"title":1814,"description":1815},"High-risk obligation tracker","Owners, evidence, and status for each Annex III requirement.",{"title":1817,"description":1818},"ISO 42001 \u002F NIST AI RMF crosswalk","Reuse your AI management system evidence against AI Act obligations.",{"title":1820,"description":1821},"EU AI Act Compliance Software","Get ready for the EU AI Act (Regulation 2024\u002F1689) — AI system inventory, risk classification, high-risk obligations, and crosswalks to ISO 42001 and the NIST AI RMF.","eu-ai-act",[1824,1827,1830],{"value":1825,"description":1826},"4 risk tiers","Unacceptable, high, limited, and minimal risk classified per AI system.",{"value":1828,"description":1829},"High-risk ready","Annex III obligations implemented as controls with evidence and owners.",{"value":1831,"description":1832},"42001 mapped","AI Act obligations cross-walked to ISO 42001 and the NIST AI RMF.","5.frameworks\u002Feu-ai-act","ZNMJ60nzbxtmfYmCIInPICCtaQRDgmWVNeyb5gCcvWQ",{"id":1836,"title":1837,"advantages":1838,"body":1860,"checklist":2506,"cta":2516,"description":93,"extension":151,"faq":2519,"hero":2533,"lastUpdated":186,"meta":2540,"name":2241,"navigation":188,"path":2541,"resources":2542,"seo":2556,"slug":2559,"stats":2560,"stem":2570,"__hash__":2571},"frameworks\u002F5.frameworks\u002Ffedramp.md","Fedramp",[1839,1846,1853],{"title":1840,"description":1841,"bullets":1842},"800-53 baselines, pre-mapped","Every Low, Moderate, and High control implemented as an episki control with mapped evidence and testing procedures.",[1843,1844,1845],"All 20 control families ready to scope","Tailoring decisions captured in-platform","Overlays for FedRAMP, DoD IL2\u002F4\u002F5, and StateRAMP",{"title":1847,"description":1848,"bullets":1849},"SSP, SAR, POA&M workflows","Generate authorization documents from live data instead of maintaining parallel binders.",[1850,1851,1852],"SSP exports populated from control evidence","POA&M items tracked to closure with milestones","3PAO collaboration via scoped portal",{"title":1854,"description":1855,"bullets":1856},"Continuous monitoring","Monthly ConMon deliverables produced as a side effect of your normal operations.",[1857,1858,1859],"Vulnerability scan ingestion and triage","Deviation requests with approval workflow","Significant change notifications",{"type":29,"value":1861,"toc":2485},[1862,1866,1869,1877,1881,1884,1891,1911,1914,1918,1928,1936,1940,1946,2020,2029,2033,2040,2044,2047,2079,2082,2086,2092,2096,2103,2107,2110,2130,2137,2141,2149,2175,2178,2182,2185,2188,2208,2211,2215,2218,2294,2313,2317,2324,2327,2347,2354,2358,2368,2388,2391,2395,2398,2424,2427,2431,2434,2472,2475,2477],[32,1863,1865],{"id":1864},"what-is-fedramp","What is FedRAMP?",[37,1867,1868],{},"The Federal Risk and Authorization Management Program (FedRAMP) is a US government program that standardizes the security assessment, authorization, and continuous monitoring of cloud products used by federal agencies. Established in 2011 and operated by GSA in partnership with NIST, FedRAMP allows a cloud service to be authorized once and reused by any agency, dramatically reducing duplicate work.",[37,1870,1871,1872,1876],{},"FedRAMP is built on the ",[249,1873,1875],{"href":1874},"\u002Fframeworks\u002Fnist-800-53","NIST 800-53"," control catalog, with specific baselines for Low, Moderate, and High impact levels. Assessments are performed by accredited Third-Party Assessment Organizations (3PAOs), and authorizations are issued by a sponsoring federal agency as an Authority to Operate (ATO). The Joint Authorization Board (JAB) provisional-authorization path has been retired — FedRAMP now uses a single \"FedRAMP Authorized\" designation, and the 2025 FedRAMP 20x initiative is modernizing assessment and continuous monitoring with greater automation and reuse of commercial security evidence.",[32,1878,1880],{"id":1879},"a-brief-history-of-fedramp","A brief history of FedRAMP",[37,1882,1883],{},"FedRAMP launched in 2011, operated by GSA under Office of Management and Budget policy. For its first decade the program ran on policy memos rather than statute — it existed because agencies kept re-assessing the same cloud services, and a \"do it once, reuse it everywhere\" model promised to end that duplication.",[37,1885,1886,1887,1890],{},"That changed in December 2022, when Congress passed the ",[53,1888,1889],{},"FedRAMP Authorization Act"," as Section 5921 of the FY2023 National Defense Authorization Act — codifying FedRAMP into law for the first time. Three provisions are worth knowing:",[47,1892,1893,1899,1905],{},[50,1894,1895,1898],{},[53,1896,1897],{},"Presumption of adequacy."," An agency must presume that a cloud service already authorized by another agency has adequate security, making it far easier to reuse an existing authorization instead of starting over.",[50,1900,1901,1904],{},[53,1902,1903],{},"A FedRAMP Board"," of senior government officials was established to oversee and accelerate authorizations, replacing the Joint Authorization Board (JAB) and its provisional-authorization path.",[50,1906,1907,1910],{},[53,1908,1909],{},"A Federal Secure Cloud Advisory Committee"," was created to bring industry and agency input into improving the process.",[37,1912,1913],{},"Together these moves pushed FedRAMP toward its founding promise — authorize once, reuse everywhere — and set up the automation-first direction now playing out in FedRAMP 20x.",[32,1915,1917],{"id":1916},"fedramp-and-nist-800-53","FedRAMP and NIST 800-53",[37,1919,1920,1921,1923,1924,1927],{},"FedRAMP doesn't invent its own controls — it's built directly on ",[249,1922,1875],{"href":1874},", the federal catalog of security and privacy controls. Each FedRAMP baseline is a ",[377,1925,1926],{},"tailored selection"," from that catalog: a defined subset of controls, plus FedRAMP-specific parameter values and a small number of additional controls layered on top. When you implement a FedRAMP baseline, you're implementing 800-53 controls with FedRAMP's parameters and assignments filled in — not a separate standard.",[37,1929,1930,1931,1935],{},"That relationship matters for two reasons. First, work you've already done toward 800-53 — or frameworks that map to it — carries over directly. Second, it connects FedRAMP to the broader federal control family: contractors handling Controlled Unclassified Information (CUI) for the Department of Defense work from ",[249,1932,1934],{"href":1933},"\u002Fframeworks\u002Fnist-800-171","NIST 800-171",", a CUI-focused derivative of the same catalog. Understand 800-53 and you understand the backbone of FedRAMP.",[32,1937,1939],{"id":1938},"the-impact-levels-low-moderate-high","The impact levels: Low, Moderate, High",[37,1941,1942,1943,1945],{},"FedRAMP defines three baselines, set by the potential impact of a confidentiality, integrity, or availability breach on the data the system handles (the FIPS 199 categorization). The control count grows with the level — each baseline is a tailored selection from the ",[249,1944,1875],{"href":1874}," Rev 5 catalog, plus a handful of FedRAMP-specific additions:",[1947,1948,1949,1968],"table",{},[1950,1951,1952],"thead",{},[1953,1954,1955,1959,1962,1965],"tr",{},[1956,1957,1958],"th",{},"Level",[1956,1960,1961],{},"Breach impact",[1956,1963,1964],{},"Controls (Rev 5)",[1956,1966,1967],{},"Common fit",[1969,1970,1971,1988,2004],"tbody",{},[1953,1972,1973,1979,1982,1985],{},[1974,1975,1976],"td",{},[53,1977,1978],{},"Low",[1974,1980,1981],{},"Limited",[1974,1983,1984],{},"156 (+1 over NIST)",[1974,1986,1987],{},"Public-facing, low-sensitivity services",[1953,1989,1990,1995,1998,2001],{},[1974,1991,1992],{},[53,1993,1994],{},"Moderate",[1974,1996,1997],{},"Serious",[1974,1999,2000],{},"323 (+17 over NIST)",[1974,2002,2003],{},"Most commercial SaaS selling to agencies",[1953,2005,2006,2011,2014,2017],{},[1974,2007,2008],{},[53,2009,2010],{},"High",[1974,2012,2013],{},"Severe \u002F catastrophic",[1974,2015,2016],{},"410 (+22 over NIST)",[1974,2018,2019],{},"Law enforcement, financial, and health data",[37,2021,2022,2023,2025,2026,2028],{},"The large majority of commercial SaaS targets ",[53,2024,1994],{}," — it's the level most agency buyers expect. ",[53,2027,2010],{}," is reserved for the most sensitive non-classified federal data and carries a substantially heavier engineering and evidence burden.",[597,2030,2032],{"id":2031},"fedramp-tailored-li-saas","FedRAMP Tailored (Li-SaaS)",[37,2034,2035,2036,2039],{},"For low-impact, low-risk SaaS — collaboration tools, productivity apps, and similar — FedRAMP offers a tailored Low path known as ",[53,2037,2038],{},"Li-SaaS",". It covers the same 156 Low controls, but splits how they're validated: roughly 66 are independently tested by a 3PAO, while the remaining 90 are satisfied through documented CSP attestation. It's a lighter lift for services that genuinely qualify, without dropping the underlying control set.",[32,2041,2043],{"id":2042},"the-fedramp-authorization-process","The FedRAMP authorization process",[37,2045,2046],{},"FedRAMP authorization follows a defined arc, and the order matters:",[903,2048,2049,2055,2061,2067,2073],{},[50,2050,2051,2054],{},[53,2052,2053],{},"Secure an agency sponsor."," This is the gating step. Since the JAB provisional path was retired, an Authority to Operate (ATO) comes from a federal agency willing to sponsor and authorize your service. No sponsor, no authorization — and many CSPs underestimate how long building that relationship takes.",[50,2056,2057,2060],{},[53,2058,2059],{},"Prepare and document."," Categorize your system's impact level, define the authorization boundary, and document how each control is implemented in your System Security Plan (SSP).",[50,2062,2063,2066],{},[53,2064,2065],{},"Assessment."," An accredited Third-Party Assessment Organization (3PAO) independently tests your controls and produces a Security Assessment Report (SAR).",[50,2068,2069,2072],{},[53,2070,2071],{},"Authorization decision."," The sponsoring agency reviews the full package — SSP, SAR, and POA&M — and, if satisfied, issues the ATO.",[50,2074,2075,2078],{},[53,2076,2077],{},"Continuous monitoring."," The ATO is not the finish line; you move into ongoing ConMon to keep the authorization in good standing.",[37,2080,2081],{},"The pattern to internalize: a clean boundary and a solid SSP come first, independent assessment second, the agency decision third, and then continuous operation. Rushing the boundary or the SSP is the most common way to add months to the back half.",[597,2083,2085],{"id":2084},"readiness-assessment-report-rar","Readiness Assessment Report (RAR)",[37,2087,2088,2089,2091],{},"Before the full assessment, mature CSPs commission a ",[53,2090,2085],{}," — a lighter-weight evaluation by a 3PAO of whether your service is genuinely ready for authorization. A positive RAR signals to potential agency sponsors that you're a credible candidate, which makes sponsorship conversations far easier. It also surfaces gaps while they're still cheap to fix, before the formal SAR locks them in as findings. A RAR isn't mandatory on every path, but jumping straight to a full assessment when you aren't ready is an expensive way to learn what a RAR would have told you.",[597,2093,2095],{"id":2094},"the-role-of-the-3pao","The role of the 3PAO",[37,2097,2098,2099,2102],{},"A ",[53,2100,2101],{},"Third-Party Assessment Organization (3PAO)"," is the independent assessor that tests whether your controls actually work the way your SSP claims. They examine evidence, interview your team, and run technical checks, then document the results in the SAR. The independence is the whole point: an agency relies on the 3PAO's testing rather than re-verifying everything itself, which is what makes the \"authorize once, reuse everywhere\" model possible. Choosing a 3PAO with real experience in your type of service — and engaging them early enough to shape your readiness — tends to make the assessment far smoother than treating it as a final exam you cram for.",[32,2104,2106],{"id":2105},"authorization-artifacts-ssp-sar-poam","Authorization artifacts: SSP, SAR, POA&M",[37,2108,2109],{},"Three documents carry a FedRAMP authorization, and they build on each other:",[47,2111,2112,2118,2124],{},[50,2113,2114,2117],{},[53,2115,2116],{},"System Security Plan (SSP)."," The foundational document — it describes your system, its boundary, and exactly how each control in your baseline is implemented. The SSP is what the assessor tests against and what the agency reads to understand your posture.",[50,2119,2120,2123],{},[53,2121,2122],{},"Security Assessment Report (SAR)."," The 3PAO's findings after testing your implementation against the SSP. It documents what works, what doesn't, and the risk of any gaps.",[50,2125,2126,2129],{},[53,2127,2128],{},"Plan of Action & Milestones (POA&M)."," The living tracker of open findings — each with an owner, a remediation plan, and a target date. Agencies expect the POA&M to shrink over time, not sit static.",[37,2131,2132,2133,2136],{},"The trap most teams fall into is treating these as one-time Word documents maintained separately from how the system actually runs. The moment your environment changes, those binders drift out of date — and the next assessment surfaces the gap. The healthier model treats the SSP, SAR inputs, and POA&M as ",[53,2134,2135],{},"live artifacts driven by real control evidence",", so the documentation reflects the system as it is, not as it was at submission.",[32,2138,2140],{"id":2139},"continuous-monitoring-conmon","Continuous Monitoring (ConMon)",[37,2142,2143,2144,2148],{},"An ATO is the start of your obligations, not the end. FedRAMP requires ongoing ",[249,2145,2147],{"href":2146},"\u002Fglossary\u002Fcontinuous-monitoring","continuous monitoring"," (ConMon) to keep an authorization in good standing, and it runs on a monthly cadence:",[47,2150,2151,2157,2163,2169],{},[50,2152,2153,2156],{},[53,2154,2155],{},"Vulnerability scanning"," of your infrastructure, web applications, and databases, with results reported and tracked.",[50,2158,2159,2162],{},[53,2160,2161],{},"POA&M updates"," showing progress on open findings and any new ones.",[50,2164,2165,2168],{},[53,2166,2167],{},"Deviation requests"," when you need to document a risk-based exception to how a finding is expected to be handled.",[50,2170,2171,2174],{},[53,2172,2173],{},"Significant Change Requests (SCRs)"," before you make material changes to the authorized system, so the agency can assess the security impact first.",[37,2176,2177],{},"ConMon is where many CSPs underestimate the sustaining effort. Authorization is a sprint with a clear finish; ConMon is the standing operational load that follows for as long as you hold the ATO. Teams that build it into normal engineering and security operations — rather than treating it as a separate monthly fire drill — keep their authorizations far more cheaply than those who scramble each cycle.",[32,2179,2181],{"id":2180},"who-needs-fedramp","Who needs FedRAMP",[37,2183,2184],{},"Any cloud service offered to a federal agency typically requires FedRAMP authorization at the appropriate impact level. Authorization is also increasingly used as a procurement filter by state and local governments, defense primes, and international public-sector buyers.",[37,2186,2187],{},"In practice, that pulls in several kinds of cloud service provider:",[47,2189,2190,2196,2202],{},[50,2191,2192,2195],{},[53,2193,2194],{},"SaaS selling directly to a federal agency"," — the clearest case; the agency typically can't buy without authorization at the right impact level.",[50,2197,2198,2201],{},[53,2199,2200],{},"Services embedded in a larger federal system"," — if your product runs inside another vendor's authorized boundary, you inherit obligations through them.",[50,2203,2204,2207],{},[53,2205,2206],{},"Vendors whose enterprise buyers serve the government"," — increasingly, commercial customers with public-sector business push FedRAMP-aligned requirements down to their own suppliers.",[37,2209,2210],{},"If any of these describe where your revenue is heading, FedRAMP stops being optional — and the adjacent programs below may apply too.",[32,2212,2214],{"id":2213},"fedramp-vs-stateramp-vs-dod-impact-levels","FedRAMP vs StateRAMP vs DoD Impact Levels",[37,2216,2217],{},"FedRAMP sits among several programs that are easy to confuse:",[1947,2219,2220,2233],{},[1950,2221,2222],{},[1953,2223,2224,2227,2230],{},[1956,2225,2226],{},"Program",[1956,2228,2229],{},"Who it's for",[1956,2231,2232],{},"Relationship to FedRAMP",[1969,2234,2235,2248,2264,2277],{},[1953,2236,2237,2242,2245],{},[1974,2238,2239],{},[53,2240,2241],{},"FedRAMP",[1974,2243,2244],{},"Federal civilian agencies",[1974,2246,2247],{},"The baseline program",[1953,2249,2250,2258,2261],{},[1974,2251,2252],{},[53,2253,2254],{},[249,2255,2257],{"href":2256},"\u002Fframeworks\u002Fstateramp","StateRAMP",[1974,2259,2260],{},"State & local government",[1974,2262,2263],{},"Modeled closely on FedRAMP; separate authorization",[1953,2265,2266,2271,2274],{},[1974,2267,2268],{},[53,2269,2270],{},"DoD Impact Levels (IL2\u002F4\u002F5\u002F6)",[1974,2272,2273],{},"Department of Defense workloads",[1974,2275,2276],{},"A DoD overlay layered on top of FedRAMP",[1953,2278,2279,2288,2291],{},[1974,2280,2281],{},[53,2282,2283,2285,2286],{},[249,2284,1048],{"href":1049}," \u002F ",[249,2287,1934],{"href":1933},[1974,2289,2290],{},"Defense contractors handling CUI",[1974,2292,2293],{},"Different track — protects CUI in contractor systems",[37,2295,2296,2297,2299,2300,2302,2303,2306,2307,2309,2310,2312],{},"The short version: ",[53,2298,2241],{}," authorizes cloud services for federal civilian agencies. ",[53,2301,2257],{}," applies the same idea to state and local government, with its own process. The ",[53,2304,2305],{},"DoD Impact Levels"," build on a FedRAMP authorization and add controls based on how sensitive the defense data is — IL2 for public-facing data up through IL5\u002FIL6 for the most sensitive. And ",[53,2308,1048],{},", which draws on ",[53,2311,1934],{},", is a separate requirement aimed at contractors that handle Controlled Unclassified Information in their own environments — related in spirit, but not a substitute for FedRAMP. Knowing which program your buyers actually require keeps you from over-scoping toward the wrong one.",[32,2314,2316],{"id":2315},"fedramp-20x-and-whats-changing","FedRAMP 20x and what's changing",[37,2318,2319,2320,2323],{},"FedRAMP 20x is the program's 2025–2026 modernization effort, and it changes how authorization works. Instead of static annual assessments and lengthy written narratives, 20x is built around ",[53,2321,2322],{},"Key Security Indicators (KSIs)"," — machine-readable summaries of a cloud service's security capabilities, mapped to NIST 800-53 controls and validated through automation in near real time. The goal is continuous assurance rather than a once-a-year snapshot, with greater reuse of the commercial security evidence CSPs already produce.",[37,2325,2326],{},"It's rolling out in phases:",[47,2328,2329,2335,2341],{},[50,2330,2331,2334],{},[53,2332,2333],{},"Phase 1 — 20x Low pilot"," (FY25 Q3–Q4, ~Apr–Sep 2025): a proof of concept built on 56 KSIs for the Low baseline. FedRAMP received 26 submission packages and granted the first pilot authorizations in under two months — far faster than the traditional path.",[50,2336,2337,2340],{},[53,2338,2339],{},"Phase 2 — 20x Moderate pilot"," (FY26 Q1–Q2): extended the model to Moderate (61 KSIs) with a limited group of CSPs from the Low pilot.",[50,2342,2343,2346],{},[53,2344,2345],{},"Phase 3 — wide-scale adoption"," (FY26 Q3–Q4): currently underway — formalizing the Low and Moderate requirements and training agencies for broad adoption.",[37,2348,2349,2350,2353],{},"As of mid-2026, 20x Low and Moderate are ",[53,2351,2352],{},"not yet fully generally available"," to all CSPs — Phase 3 is still in progress. But the direction is unmistakable: faster authorizations, continuous validation, and automation in place of binders.",[32,2355,2357],{"id":2356},"timeline","Timeline",[37,2359,2360,2361,2363,2364,2367],{},"A typical FedRAMP ",[53,2362,1994],{}," authorization takes ",[53,2365,2366],{},"12–18 months"," from kickoff to ATO. What moves you within — or beyond — that range:",[47,2369,2370,2376,2382],{},[50,2371,2372,2375],{},[53,2373,2374],{},"Sponsorship timing."," The time spent finding and onboarding an agency sponsor often dominates the schedule and is the least predictable part.",[50,2377,2378,2381],{},[53,2379,2380],{},"Boundary size and complexity."," A tightly scoped, cloud-native system assesses faster than a sprawling one with many components and inherited services.",[50,2383,2384,2387],{},[53,2385,2386],{},"Engineering remediation."," Gaps found during readiness or assessment have to be fixed and re-evidenced, which adds months if the starting posture is weak.",[37,2389,2390],{},"FedRAMP 20x aims to compress this materially — pilot authorizations were granted in under two months — but for the traditional path, plan for a year-plus.",[32,2392,2394],{"id":2393},"common-fedramp-challenges","Common FedRAMP challenges",[37,2396,2397],{},"FedRAMP is achievable, but a few things reliably make it hard:",[47,2399,2400,2406,2412,2418],{},[50,2401,2402,2405],{},[53,2403,2404],{},"Finding an agency sponsor."," With the JAB path gone, no sponsor means no authorization. Building a relationship with an agency that has both the need and the bandwidth to sponsor you is often the single longest pole.",[50,2407,2408,2411],{},[53,2409,2410],{},"Scoping the authorization boundary."," Draw it too wide and you balloon the control and evidence burden; too narrow and you create findings or miss real data flows. Getting the boundary right is genuinely difficult — and expensive to change late.",[50,2413,2414,2417],{},[53,2415,2416],{},"Sustaining ConMon."," The monthly cadence is a standing operational commitment. Teams that treat it as an afterthought burn out or fall out of compliance.",[50,2419,2420,2423],{},[53,2421,2422],{},"The engineering lift of Moderate."," 323 controls is a serious investment, and many are operational rather than one-time — they require evidence that you do something consistently, month after month.",[37,2425,2426],{},"None of these are reasons to avoid FedRAMP if your market needs it. But they're why it's a program-level commitment rather than a checkbox — and why starting with a realistic picture of the effort beats discovering it mid-assessment.",[32,2428,2430],{"id":2429},"getting-fedramp-ready","Getting FedRAMP ready",[37,2432,2433],{},"If FedRAMP is on your roadmap, a sensible order of operations:",[903,2435,2436,2442,2448,2454,2460,2466],{},[50,2437,2438,2441],{},[53,2439,2440],{},"Pick your impact level."," Let your target agencies and the sensitivity of their data decide Low, Moderate, or High — don't over-scope.",[50,2443,2444,2447],{},[53,2445,2446],{},"Adopt the 800-53 baseline"," for that level as your working control set, with FedRAMP's parameters applied.",[50,2449,2450,2453],{},[53,2451,2452],{},"Build the SSP from real evidence."," Document how each control is actually implemented, drawn from how your system runs — not aspirational policy.",[50,2455,2456,2459],{},[53,2457,2458],{},"Run a readiness assessment."," Use a RAR to find gaps while they're cheap and to strengthen your pitch to potential sponsors.",[50,2461,2462,2465],{},[53,2463,2464],{},"Line up sponsorship and a 3PAO."," Start the sponsor conversation early — it's the long pole — and engage an experienced 3PAO to shape readiness, not just to grade it.",[50,2467,2468,2471],{},[53,2469,2470],{},"Stand up ConMon from day one."," Build the monthly cadence into operations before the ATO, so continuous monitoring is a habit rather than a scramble.",[37,2473,2474],{},"The teams that do well treat FedRAMP as an engineering and operations program with a compliance output — not a document exercise bolted on at the end.",[32,2476,244],{"id":243},[37,2478,2479,2480,254,2483,258],{},"episki holds FedRAMP control baselines with continuous evaluation, boundary definition through scope rules on cloud account, region, resource, and tag, and POA&M items generated as findings with owners and due dates that sync into your engineers' tracker. Evidence carries provenance showing the deterministic recipe that gathered it, which is what an assessor needs to trace a control to its proof. ",[249,2481,253],{"href":185,"rel":2482},[252],[249,2484,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":2486},[2487,2488,2489,2490,2493,2497,2498,2499,2500,2501,2502,2503,2504,2505],{"id":1864,"depth":94,"text":1865},{"id":1879,"depth":94,"text":1880},{"id":1916,"depth":94,"text":1917},{"id":1938,"depth":94,"text":1939,"children":2491},[2492],{"id":2031,"depth":995,"text":2032},{"id":2042,"depth":94,"text":2043,"children":2494},[2495,2496],{"id":2084,"depth":995,"text":2085},{"id":2094,"depth":995,"text":2095},{"id":2105,"depth":94,"text":2106},{"id":2139,"depth":94,"text":2140},{"id":2180,"depth":94,"text":2181},{"id":2213,"depth":94,"text":2214},{"id":2315,"depth":94,"text":2316},{"id":2356,"depth":94,"text":2357},{"id":2393,"depth":94,"text":2394},{"id":2429,"depth":94,"text":2430},{"id":243,"depth":94,"text":244},{"title":2507,"description":2508,"items":2509},"FedRAMP readiness inside episki","From SSP to ConMon — what you need preloaded in the workspace.",[2510,2511,2512,2513,2514,2515],"NIST 800-53 baseline aligned to your impact level","SSP narrative generation from control evidence","3PAO assessment workspace and POA&M tracking","Continuous monitoring cadences and reporting templates","Significant Change Request workflow","Authorization-package artifact library",{"title":2517,"description":2518},"Build toward FedRAMP without the binders","Start in episki with the right baseline and an SSP that updates with your environment.",{"title":2520,"items":2521},"FedRAMP frequently asked questions",[2522,2524,2527,2530],{"label":1865,"content":2523},"The Federal Risk and Authorization Management Program is a US government program that standardizes security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. FedRAMP-authorized services can be procured by any agency without each agency re-assessing them.",{"label":2525,"content":2526},"What's the difference between Low, Moderate, and High?","The three impact levels reflect the potential damage of a confidentiality, integrity, or availability breach to the data being processed. Most commercial SaaS pursues Moderate. High is reserved for systems handling the most sensitive non-classified federal data.",{"label":2528,"content":2529},"Do I need an agency sponsor?","Yes. Since the Joint Authorization Board (JAB) provisional-authorization path was retired and FedRAMP consolidated to a single \"FedRAMP Authorized\" designation, agency authorization is the path to an ATO — you partner with a sponsoring federal agency. The FedRAMP 20x initiative announced in 2025 is streamlining assessment and continuous monitoring with more automation.",{"label":2531,"content":2532},"How long does FedRAMP authorization take?","A typical FedRAMP Moderate authorization takes 12–18 months from kickoff to ATO. Mature security programs and dedicated FedRAMP teams can compress this, but it's a major engineering and compliance investment.",{"headline":2534,"title":2535,"description":2536,"links":2537},"FedRAMP without the binders","Authorize your cloud service for the US government","NIST 800-53 baselines pre-mapped, System Security Plan and POA&M workflows in-platform, continuous monitoring evidence cadences that hold up to ConMon audits.",[2538,2539],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"\u002Fframeworks\u002Ffedramp",{"headline":2543,"title":2544,"description":2545,"items":2546},"FedRAMP accelerators","FedRAMP authorization accelerators","Move from \"we want FedRAMP\" to a credible 3PAO engagement faster.",[2547,2550,2553],{"title":2548,"description":2549},"SSP generator","Compose your System Security Plan from live control data — no parallel Word doc.",{"title":2551,"description":2552},"3PAO collaboration room","Scoped portal for your assessor with evidence rooms and walkthrough scheduling.",{"title":2554,"description":2555},"ConMon dashboard","A single view of your monthly ConMon obligations and their status.",{"title":2557,"description":2558},"FedRAMP Compliance Software","Build toward FedRAMP Low, Moderate, or High authorization with NIST 800-53 baselines, SSP\u002FSAR\u002FPOA&M workflows, and continuous monitoring artifacts.","fedramp",[2561,2564,2567],{"value":2562,"description":2563},"3 baselines","Low, Moderate, and High control sets ready to scope into your environment.",{"value":2565,"description":2566},"SSP-ready","System Security Plan generated from your control evidence, not the other way around.",{"value":2568,"description":2569},"ConMon","Monthly continuous-monitoring cadences with deviation and POA&M tracking built in.","5.frameworks\u002Ffedramp","GrD277tendPIr6Di0VF1L621dbJrvP_Oglf-c-oKnyw",{"id":2573,"title":2574,"advantages":2575,"body":2597,"checklist":2671,"cta":2680,"description":93,"extension":151,"faq":2683,"hero":2697,"lastUpdated":186,"meta":2704,"name":2705,"navigation":188,"path":2706,"resources":2707,"seo":2721,"slug":2724,"stats":2725,"stem":2734,"__hash__":2735},"frameworks\u002F5.frameworks\u002Fffiec.md","Ffiec",[2576,2583,2590],{"title":2577,"description":2578,"bullets":2579},"A clean CAT replacement","Move off the retired CAT onto a maintained, examiner-recognized framework.",[2580,2581,2582],"NIST CSF 2.0 mapping out of the box","CRI Profile for financial-sector depth","CIS Controls and CISA CPGs as options",{"title":2584,"description":2585,"bullets":2586},"Examination readiness","Organize controls and evidence to the FFIEC IT Examination Handbook.",[2587,2588,2589],"Control-to-handbook mapping","Examiner-ready evidence library","Risk assessment and board reporting",{"title":2591,"description":2592,"bullets":2593},"One program, every regulator","Reuse the same controls across overlapping financial obligations.",[2594,2595,2596],"Crosswalk to GLBA Safeguards","Crosswalk to NY DFS Part 500","Reuse SOC 2 and ISO 27001 evidence",{"type":29,"value":2598,"toc":2666},[2599,2603,2613,2617,2628,2649,2656,2658],[32,2600,2602],{"id":2601},"what-is-the-ffiec","What is the FFIEC?",[37,2604,367,2605,2608,2609,2612],{},[53,2606,2607],{},"Federal Financial Institutions Examination Council (FFIEC)"," is the US interagency body that prescribes uniform principles, standards, and report forms for the federal examination of financial institutions. Its ",[53,2610,2611],{},"IT Examination Handbook"," is the reference examiners use to evaluate an institution's information security, business continuity, and IT risk management.",[32,2614,2616],{"id":2615},"the-cat-sunset","The CAT sunset",[37,2618,2619,2620,2623,2624,2627],{},"From 2015, many institutions used the ",[53,2621,2622],{},"FFIEC Cybersecurity Assessment Tool (CAT)"," to self-assess their cyber maturity. The FFIEC ",[53,2625,2626],{},"retired the CAT on August 31, 2025",", having decided not to update it to reflect newer government resources. Institutions are expected to transition to standardized, actively maintained frameworks instead:",[47,2629,2630,2635,2641],{},[50,2631,2632,2634],{},[53,2633,441],{}," — by far the most common replacement.",[50,2636,2637,2640],{},[53,2638,2639],{},"CRI Profile"," — the Cyber Risk Institute's financial-sector tailoring of NIST CSF, which maps to FFIEC handbooks, NY DFS Part 500, and other supervisory regimes.",[50,2642,2643,1123,2645,2648],{},[53,2644,529],{},[53,2646,2647],{},"CISA Cybersecurity Performance Goals"," — additional options.",[37,2650,2651,2652,2655],{},"Importantly, the ",[53,2653,2654],{},"IT Examination Handbook and the examination program itself remain in force"," — only the voluntary CAT tool went away.",[32,2657,244],{"id":243},[37,2659,2660,2661,254,2664,258],{},"episki carries FFIEC expectations as evaluated controls rather than a maturity questionnaire: access, change, resilience, and vendor management checks that write explicit verdicts, with findings routed to owners and crosswalks to NIST CSF and ISO 27001 derived through the SCF hub. ",[249,2662,253],{"href":185,"rel":2663},[252],[249,2665,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":2667},[2668,2669,2670],{"id":2601,"depth":94,"text":2602},{"id":2615,"depth":94,"text":2616},{"id":243,"depth":94,"text":244},{"title":2672,"description":2673,"items":2674},"FFIEC readiness inside episki","What an examined institution needs in place after the CAT sunset.",[2675,2676,2677,2678,2679,2588],"Successor framework selected (NIST CSF 2.0 or CRI Profile)","Control library mapped to the FFIEC IT Examination Handbook","Cybersecurity risk assessment kept current","Board and management reporting","Third-party \u002F vendor risk management",{"title":2681,"description":2682},"Stay FFIEC exam-ready in episki","Map to NIST CSF 2.0 or the CRI Profile and keep evidence ready across GLBA and NY DFS.",{"title":2684,"items":2685},"FFIEC frequently asked questions",[2686,2688,2691,2694],{"label":2602,"content":2687},"The Federal Financial Institutions Examination Council (FFIEC) is a US interagency body that sets uniform principles and standards for the examination of financial institutions. Its IT Examination Handbook defines the expectations examiners use to assess an institution's information security and IT risk management.",{"label":2689,"content":2690},"What happened to the FFIEC CAT?","The FFIEC Cybersecurity Assessment Tool (CAT) was sunset on August 31, 2025. The FFIEC decided not to update it to reflect newer resources such as NIST Cybersecurity Framework 2.0 and the CISA Cybersecurity Performance Goals, and instead points institutions to those standardized, maintained frameworks.",{"label":2692,"content":2693},"What should replace the CAT?","Institutions are moving to maintained frameworks — most commonly NIST CSF 2.0, followed by the CIS Controls, the Cyber Risk Institute (CRI) Profile (a financial-sector tailoring of NIST CSF), and the CISA Cybersecurity Performance Goals. episki supports mapping your program to any of these while preserving your prior CAT work.",{"label":2695,"content":2696},"Is the FFIEC handbook still in effect?","Yes. The CAT was a voluntary assessment tool; the FFIEC IT Examination Handbook and the underlying examination program remain in force. Institutions still need to demonstrate sound cybersecurity and IT risk management to their examiners.",{"headline":2698,"title":2699,"description":2700,"links":2701},"FFIEC exams, after the CAT","Stay FFIEC examination-ready","With the FFIEC Cybersecurity Assessment Tool retired, map your program to NIST CSF 2.0 or the CRI Profile, manage the controls examiners expect, and keep evidence exam-ready.",[2702,2703],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"FFIEC","\u002Fframeworks\u002Fffiec",{"headline":2708,"title":2709,"description":2710,"items":2711},"FFIEC accelerators","FFIEC readiness accelerators","Make the post-CAT transition without losing exam readiness.",[2712,2715,2718],{"title":2713,"description":2714},"CAT-to-CSF mapping","Carry your prior CAT work forward into NIST CSF 2.0 or the CRI Profile.",{"title":2716,"description":2717},"Exam evidence library","Organize artifacts to the IT Examination Handbook domains.",{"title":2719,"description":2720},"Financial-framework crosswalk","Reuse evidence across GLBA, NY DFS, SOC 2, and ISO 27001.",{"title":2722,"description":2723},"FFIEC Cybersecurity Compliance Software","Meet FFIEC IT examination expectations after the CAT sunset — map to NIST CSF 2.0 or the CRI Profile, manage controls and evidence, and stay exam-ready.","ffiec",[2726,2729,2731],{"value":2727,"description":2728},"CAT retired","The FFIEC CAT was sunset on August 31, 2025 — a successor mapping is needed.",{"value":441,"description":2730},"The most-adopted CAT replacement, fully supported in episki.",{"value":2732,"description":2733},"Exam-ready","IT Examination Handbook expectations tracked as living controls.","5.frameworks\u002Fffiec","lnfweMv_BvjX2B6BpTLASUaK8PVq-A-laWvLbLZmXMM",{"id":2737,"title":2738,"advantages":2739,"body":2761,"checklist":2795,"cta":2805,"description":93,"extension":151,"faq":2808,"hero":2823,"lastUpdated":186,"meta":2830,"name":2831,"navigation":188,"path":2832,"resources":2833,"seo":2847,"slug":2850,"stats":2851,"stem":2861,"__hash__":2862},"frameworks\u002F5.frameworks\u002Fgdpr.md","Gdpr",[2740,2747,2754],{"title":2741,"description":2742,"bullets":2743},"Records of Processing (Art. 30)","Keep a live inventory of every processing activity with lawful basis, categories of data, retention, and transfers.",[2744,2745,2746],"Controller and processor records side by side","Versioned changes auditors and DPAs can review","Cross-link to vendors (Art. 28 processors) via TPRM",{"title":2748,"description":2749,"bullets":2750},"DPIA workflows (Art. 35)","Run Data Protection Impact Assessments where they belong — next to the processing activity they assess.",[2751,2752,2753],"DPIA templates aligned to EDPB guidance","Risk treatment plans linked to controls","Stakeholder consultation captured in-platform",{"title":2755,"description":2756,"bullets":2757},"Data-subject rights (Arts. 12–22)","Intake, identity-verify, fulfill, and track DSARs without leaving the workspace.",[2758,2759,2760],"DSAR intake form on your trust center","SLA timers per right type","Audit trail of every response",{"type":29,"value":2762,"toc":2790},[2763,2767,2770,2773,2777,2780,2782],[32,2764,2766],{"id":2765},"what-is-gdpr","What is GDPR?",[37,2768,2769],{},"The General Data Protection Regulation (Regulation (EU) 2016\u002F679) is the EU's comprehensive data-protection law. It applies extraterritorially: any organization processing personal data of individuals in the EU\u002FEEA is in scope, regardless of where the organization is located.",[37,2771,2772],{},"GDPR replaces the patchwork of pre-2018 national laws with a single set of obligations and individual rights. It introduces formal records of processing, mandatory breach notification, a 72-hour clock on serious incidents, fines up to 4% of global annual turnover, and a structured set of rights for data subjects (access, rectification, erasure, portability, objection, restriction, automated-decision review).",[32,2774,2776],{"id":2775},"who-needs-to-comply","Who needs to comply",[37,2778,2779],{},"If your organization offers goods or services to people in the EU\u002FEEA, monitors their behavior, or processes their personal data in any capacity, GDPR applies to you. Most B2B SaaS companies fall in scope because their customers' employees or end users live in the EU. UK businesses are subject to a near-identical UK GDPR, and Switzerland's revised FADP follows similar principles.",[32,2781,244],{"id":243},[37,2783,2784,2785,254,2788,258],{},"episki holds GDPR obligations as structured records — processing activities, lawful bases, data subject requests, and transfer mechanisms — linked to the controls and evidence that support them. Processors and subprocessors are consolidated onto vendor records with review cadences that advance on accepted evidence, and technical measures are evaluated continuously rather than asserted in a policy. ",[249,2786,253],{"href":185,"rel":2787},[252],[249,2789,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":2791},[2792,2793,2794],{"id":2765,"depth":94,"text":2766},{"id":2775,"depth":94,"text":2776},{"id":243,"depth":94,"text":244},{"title":2796,"description":2797,"items":2798},"GDPR readiness checklist inside episki","Everything the EDPB expects, available in your trial.",[2799,2800,2801,2802,2803,2804],"Article 30 records for every processing activity","Standard Contractual Clauses for international transfers","DPIA templates with risk treatment workflows","DSAR intake portal with SLA tracking","Breach notification runbook with 72-hour timers","Lawful basis assessments per processing activity",{"title":2806,"description":2807},"Stand up GDPR in days, not quarters","Start the free trial to bring your records, DPIAs, and DSAR queue into one workspace.",{"title":2809,"items":2810},"GDPR frequently asked questions",[2811,2814,2817,2820],{"label":2812,"content":2813},"Who is subject to GDPR?","GDPR applies to any organization processing personal data of individuals in the EU\u002FEEA, regardless of where the organization is located. Most SaaS companies with any EU customers or users fall in scope.",{"label":2815,"content":2816},"What is the difference between a controller and a processor?","A controller determines the purposes and means of processing personal data. A processor processes personal data on behalf of a controller. SaaS companies are typically processors for their customers' data and controllers for their own employee, marketing, and account data.",{"label":2818,"content":2819},"When is a DPIA required?","A Data Protection Impact Assessment is required when processing is likely to result in a high risk to individuals — for example, large-scale processing of special-category data, systematic monitoring, or use of new technologies. Many DPOs run DPIAs more broadly as good practice.",{"label":2821,"content":2822},"How quickly must we report a breach?","Controllers must notify the supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals. High-risk breaches also require notifying affected individuals without undue delay.",{"headline":2824,"title":2825,"description":2826,"links":2827},"GDPR without the spreadsheet","Run your GDPR program in one workspace","Records of processing, DPIAs, lawful-basis tracking, data-subject requests, breach timers — wired together so your DPO and your engineers can move at the same speed.",[2828,2829],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"GDPR","\u002Fframeworks\u002Fgdpr",{"headline":2834,"title":2835,"description":2836,"items":2837},"GDPR accelerators","GDPR program accelerators","Move from \"we should do this\" to a running program in weeks, not quarters.",[2838,2841,2844],{"title":2839,"description":2840},"Records of Processing template","Pre-filled rows for common SaaS processing activities, ready to adapt.",{"title":2842,"description":2843},"Sub-processor list publisher","Publish your Article 28 sub-processors to your trust center with diff notifications.",{"title":2845,"description":2846},"Breach playbook","Step-by-step runbook for the first 72 hours of a notifiable breach.",{"title":2848,"description":2849},"GDPR Compliance Software","Operationalize the EU General Data Protection Regulation with records of processing, DPIAs, data-subject request workflows, and 72-hour breach timers.","gdpr",[2852,2855,2858],{"value":2853,"description":2854},"Article 30","Records of processing for controllers and processors, kept current as systems change.",{"value":2856,"description":2857},"72-hour","Breach notification timers and templated regulator\u002Fdata-subject comms.",{"value":2859,"description":2860},"0 spreadsheets","Lawful basis, retention, and cross-border transfers live in the platform.","5.frameworks\u002Fgdpr","YzQXebbM5q88ooEKj6ce4fPbSQ1pesEb_fsKr-Udc44",{"id":2864,"title":2865,"advantages":2866,"body":2888,"checklist":2994,"cta":3003,"description":93,"extension":151,"faq":3006,"hero":3020,"lastUpdated":186,"meta":3027,"name":3028,"navigation":188,"path":3029,"resources":3030,"seo":3043,"slug":3046,"stats":3047,"stem":3056,"__hash__":3057},"frameworks\u002F5.frameworks\u002Fglba.md","Glba",[2867,2874,2881],{"title":2868,"description":2869,"bullets":2870},"A written security program","The Safeguards Rule's required program, designed and evidenced.",[2871,2872,2873],"Designated Qualified Individual","Written risk assessment kept current","Board \u002F governing-body reporting",{"title":2875,"description":2876,"bullets":2877},"The required safeguards","The technical and administrative controls the Rule mandates.",[2878,2879,2880],"Access controls and MFA","Encryption of customer information","Logging, monitoring, and secure disposal",{"title":2882,"description":2883,"bullets":2884},"Breach notification ready","Detect, assess, and report qualifying events to the FTC on time.",[2885,2886,2887],"Incident response plan","30-day FTC notification workflow","Service-provider oversight",{"type":29,"value":2889,"toc":2988},[2890,2894,2912,2916,2923,2927,2960,2978,2980],[32,2891,2893],{"id":2892},"what-is-glba","What is GLBA?",[37,2895,367,2896,2899,2900,2903,2904,2907,2908,2911],{},[53,2897,2898],{},"Gramm-Leach-Bliley Act (GLBA)"," is a US federal law requiring financial institutions to protect the security and confidentiality of customers' ",[53,2901,2902],{},"nonpublic personal information",". Its information-security obligations are carried out through the FTC's ",[53,2905,2906],{},"Safeguards Rule (16 CFR Part 314)",", while the companion ",[53,2909,2910],{},"Privacy Rule"," governs how institutions disclose information-sharing practices and offer opt-outs.",[32,2913,2915],{"id":2914},"who-is-covered","Who is covered",[37,2917,2918,2919,2922],{},"The FTC interprets \"financial institution\" broadly. Beyond banks, the Safeguards Rule reaches mortgage lenders and brokers, payday lenders, auto dealers that arrange financing, tax preparers, collection agencies, investment advisers, and many ",[53,2920,2921],{},"fintechs"," — any business significantly engaged in providing financial products or services. A large number of organizations are in scope without realizing it.",[32,2924,2926],{"id":2925},"what-the-safeguards-rule-requires","What the Safeguards Rule requires",[37,2928,2929,2930,2933,2934,2937,2938,2941,2942,2945,2946,466,2949,2952,2953,2956,2957,258],{},"The amended Safeguards Rule (with most requirements effective ",[53,2931,2932],{},"June 9, 2023",") requires a ",[53,2935,2936],{},"written information security program"," led by a designated ",[53,2939,2940],{},"Qualified Individual",", supported by a documented ",[53,2943,2944],{},"risk assessment"," and a defined set of safeguards: access controls and ",[53,2947,2948],{},"multi-factor authentication",[53,2950,2951],{},"encryption"," of customer information at rest and in transit, secure disposal, change management, logging and monitoring, secure development practices, ",[53,2954,2955],{},"service-provider oversight",", an incident response plan, and periodic ",[53,2958,2959],{},"reporting to the board or governing body",[37,2961,2962,2963,2966,2967,2970,2971,2974,2975,258],{},"A subsequent amendment, effective ",[53,2964,2965],{},"May 13, 2024",", added a ",[53,2968,2969],{},"breach-notification requirement",": covered institutions must notify the FTC as soon as possible, and within ",[53,2972,2973],{},"30 days",", of discovering a breach involving the unencrypted information of ",[53,2976,2977],{},"500 or more consumers",[32,2979,244],{"id":243},[37,2981,2982,2983,254,2986,258],{},"episki maps the Safeguards Rule to controls evaluated continuously — access, encryption, monitoring, and disposal checks that write explicit verdicts from live evidence — with service providers tracked as vendor records carrying risk scores, review cadences, and consolidated subprocessors. Findings carry owners and due dates into your engineers' tracker. ",[249,2984,253],{"href":185,"rel":2985},[252],[249,2987,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":2989},[2990,2991,2992,2993],{"id":2892,"depth":94,"text":2893},{"id":2914,"depth":94,"text":2915},{"id":2925,"depth":94,"text":2926},{"id":243,"depth":94,"text":244},{"title":2995,"description":2996,"items":2997},"GLBA readiness inside episki","What a covered financial institution needs in place.",[2871,2998,2999,3000,3001,3002],"Written risk assessment","Access controls and multi-factor authentication","Encryption of customer information at rest and in transit","Service-provider security oversight","Incident response and 30-day FTC breach notification",{"title":3004,"description":3005},"Build a GLBA Safeguards program in episki","Implement the Safeguards Rule once and reuse the evidence across FFIEC, NY DFS, and SOC 2.",{"title":3007,"items":3008},"GLBA frequently asked questions",[3009,3011,3014,3017],{"label":2893,"content":3010},"The Gramm-Leach-Bliley Act (GLBA) is a US federal law that requires financial institutions to protect the security and confidentiality of customers' nonpublic personal information. Its security requirements are implemented through the FTC's Safeguards Rule (16 CFR Part 314), with a companion Privacy Rule governing how that information is shared.",{"label":3012,"content":3013},"Who must comply with the Safeguards Rule?","The FTC defines 'financial institution' broadly — it includes banks' nonbank competitors and many businesses 'significantly engaged' in financial activities, such as mortgage lenders, payday lenders, auto dealers that arrange financing, tax preparers, and fintechs. Many organizations are surprised to find they are in scope.",{"label":3015,"content":3016},"What does the updated Safeguards Rule require?","The Safeguards Rule, as amended (with key requirements effective June 2023), requires a written information security program led by a designated Qualified Individual, a risk assessment, access controls, encryption, multi-factor authentication, secure disposal, logging and monitoring, service-provider oversight, and periodic reporting to the board or governing body.",{"label":3018,"content":3019},"Is there a breach-notification requirement?","Yes. An amendment effective May 13, 2024 requires covered financial institutions to notify the FTC as soon as possible, and no later than 30 days, after discovering a security breach involving the unencrypted information of 500 or more consumers.",{"headline":3021,"title":3022,"description":3023,"links":3024},"GLBA Safeguards, operationalized","Comply with the GLBA Safeguards Rule","The FTC Safeguards Rule elements as living controls — risk assessment, access controls, encryption, MFA, and breach notification — for financial institutions of every size.",[3025,3026],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"GLBA","\u002Fframeworks\u002Fglba",{"headline":3031,"title":3032,"description":3033,"items":3034},"GLBA accelerators","GLBA Safeguards accelerators","Stand up a defensible Safeguards program and keep it current.",[3035,3038,3041],{"title":3036,"description":3037},"Safeguards control set","The Rule's required elements as living controls with owners.",{"title":3039,"description":3040},"Breach notification workflow","Assess qualifying events and track the FTC reporting window.",{"title":2719,"description":3042},"Reuse evidence across FFIEC, NY DFS, and SOC 2.",{"title":3044,"description":3045},"GLBA Safeguards Rule Compliance Software","Meet the GLBA Safeguards Rule — qualified individual, risk assessment, encryption, MFA, and the FTC breach-notification requirement — managed and evidenced in one workspace.","glba",[3048,3051,3054],{"value":3049,"description":3050},"Safeguards Rule","The FTC's information-security requirements implemented as controls.",{"value":3052,"description":3053},"30-day notice","FTC breach-notification timer for events affecting 500+ consumers.",{"value":2940,"description":3055},"A designated owner accountable for the information security program.","5.frameworks\u002Fglba","Cwr6pCktaj_mF03_OR4vdU-U2xcqI5GuI7mQXpm-3xI",{"id":3059,"title":3060,"advantages":3061,"body":3083,"checklist":3568,"cta":3577,"description":93,"extension":151,"faq":3580,"hero":3598,"lastUpdated":186,"meta":3606,"name":3459,"navigation":188,"path":3607,"resources":3608,"seo":3621,"slug":3624,"stats":3625,"stem":3635,"__hash__":3636},"frameworks\u002F5.frameworks\u002Fhipaa.md","Hipaa",[3062,3069,3076],{"title":3063,"description":3064,"bullets":3065},"Safeguards mapped to your stack","Every HIPAA standard comes with plain-language owners, SLAs, and tests.",[3066,3067,3068],"Assign compliance, engineering, and ops leads to each safeguard","Playbooks explain what “good” looks like for each requirement","Timeline view keeps renewals and reviews on schedule",{"title":3070,"description":3071,"bullets":3072},"PHI-aware evidence locker","Secure uploads, access controls, and audit trails keep regulators satisfied.",[3073,3074,3075],"Granular permissions for internal and external reviewers","Automated retention and deletion policies","Download tracking and access audit trails",{"title":3077,"description":3078,"bullets":3079},"Vendor & incident workflows","Track BAAs, vendor attestations, and incidents from discovery to closure.",[3080,3081,3082],"BAA repository tied to vendor risk levels","Incident response runbooks with reminders","Post-incident reports aligned to HIPAA timelines",{"type":29,"value":3084,"toc":3541},[3085,3089,3092,3105,3108,3112,3115,3158,3162,3165,3170,3174,3177,3181,3188,3208,3211,3215,3222,3230,3234,3237,3241,3244,3247,3260,3264,3267,3270,3274,3292,3296,3308,3312,3315,3323,3327,3330,3333,3340,3344,3351,3354,3358,3365,3368,3391,3395,3398,3401,3407,3411,3414,3440,3443,3446,3450,3453,3472,3475,3479,3485,3489,3492,3521,3529,3533],[32,3086,3088],{"id":3087},"what-is-hipaa","What is HIPAA?",[37,3090,3091],{},"HIPAA, the Health Insurance Portability and Accountability Act of 1996, is the cornerstone US federal law governing the privacy and security of patient health information. Signed into law by President Bill Clinton, the act was originally designed to improve the portability of health insurance coverage when workers changed jobs, combat fraud and waste in healthcare, and simplify the administration of health insurance through standardized electronic transactions. Over the decades since, HIPAA has evolved into the defining US regulation for how healthcare organizations and their partners handle sensitive patient data.",[37,3093,3094,3095,3099,3100,3104],{},"At its core, the law establishes national standards that protect sensitive patient information — known as ",[249,3096,3098],{"href":3097},"\u002Fglossary\u002Fphi","protected health information",", or PHI — from unauthorized use and disclosure. Any organization that creates, receives, maintains, or transmits PHI must comply, whether that organization is a hospital, a health plan, a billing clearinghouse, or a SaaS vendor providing services to healthcare customers. The ",[249,3101,3103],{"href":3102},"\u002Fglossary\u002Fhipaa","HIPAA glossary entry"," provides a concise definition, while this page walks through the full regulatory landscape so you understand how each HIPAA rule fits together.",[37,3106,3107],{},"Enforcement falls to the US Department of Health and Human Services (HHS) through its Office for Civil Rights (OCR). State attorneys general also have authority to bring enforcement actions under powers granted by the HITECH Act. The law applies across all 50 states and preempts weaker state privacy laws, though state laws that provide greater protection remain in force.",[32,3109,3111],{"id":3110},"a-brief-history-of-hipaa","A brief history of HIPAA",[37,3113,3114],{},"HIPAA was enacted in 1996, but its privacy and security requirements were not finalized overnight. The act directed HHS to develop implementing regulations, and the major rules were rolled out over more than a decade.",[47,3116,3117,3123,3129,3135,3146,3152],{},[50,3118,3119,3122],{},[53,3120,3121],{},"1996"," — Congress passes HIPAA, directing HHS to issue regulations on privacy, security, and electronic transactions.",[50,3124,3125,3128],{},[53,3126,3127],{},"2000"," — The HIPAA Privacy Rule is published; it takes full effect in 2003.",[50,3130,3131,3134],{},[53,3132,3133],{},"2003"," — The HIPAA Security Rule is finalized, with compliance required by 2005 for most entities.",[50,3136,3137,3140,3141,3145],{},[53,3138,3139],{},"2009"," — The Health Information Technology for Economic and Clinical Health Act (",[249,3142,3144],{"href":3143},"\u002Fframeworks\u002Fhipaa\u002Fhitech-and-omnibus","HITECH",") is signed into law as part of the American Recovery and Reinvestment Act, extending HIPAA obligations to business associates and introducing breach notification requirements.",[50,3147,3148,3151],{},[53,3149,3150],{},"2013"," — The HIPAA Omnibus Rule implements HITECH and further strengthens HIPAA enforcement, fines, and patient rights.",[50,3153,3154,3157],{},[53,3155,3156],{},"2024 and beyond"," — HHS continues to update HIPAA guidance, most recently around cybersecurity expectations, reproductive health privacy, and the proposed modernization of the HIPAA Security Rule to reflect modern threats.",[597,3159,3161],{"id":3160},"hitech-and-the-omnibus-rule","HITECH and the Omnibus Rule",[37,3163,3164],{},"The HITECH Act of 2009 was a watershed moment. Before HITECH, HIPAA obligations technically applied only to covered entities, and business associates were bound solely by contract. HITECH changed that by making business associates directly liable. It also introduced the federal Breach Notification Rule, increased civil monetary penalties, and funded the nationwide adoption of electronic health records — which dramatically expanded the volume of electronic PHI requiring protection.",[37,3166,3167,3168,258],{},"The 2013 Omnibus Rule then translated HITECH into binding regulation. It extended the Privacy and Security Rules to business associates and their subcontractors, tightened the definition of a breach, strengthened individual rights to access electronic health records, and aligned the law with the Genetic Information Nondiscrimination Act (GINA). For a deeper breakdown of what changed, read ",[249,3169,3161],{"href":3143},[32,3171,3173],{"id":3172},"who-hipaa-applies-to","Who HIPAA applies to",[37,3175,3176],{},"HIPAA applies to two broad categories of organizations: covered entities and business associates. Understanding which category your organization falls into is the first and most important step in any HIPAA compliance program.",[597,3178,3180],{"id":3179},"covered-entities","Covered entities",[37,3182,2098,3183,3187],{},[249,3184,3186],{"href":3185},"\u002Fglossary\u002Fcovered-entity","covered entity"," is any of the following:",[47,3189,3190,3196,3202],{},[50,3191,3192,3195],{},[53,3193,3194],{},"Health plans"," — health insurance companies, HMOs, employer-sponsored group health plans, government programs like Medicare and Medicaid, and long-term care insurers.",[50,3197,3198,3201],{},[53,3199,3200],{},"Healthcare providers"," — hospitals, clinics, physician practices, dentists, pharmacies, psychologists, and any other provider that transmits health information electronically for billing or eligibility purposes.",[50,3203,3204,3207],{},[53,3205,3206],{},"Healthcare clearinghouses"," — entities that process nonstandard health information into standard formats (or vice versa), such as billing services and repricing companies.",[37,3209,3210],{},"If your organization directly delivers healthcare or finances it, you are almost certainly a covered entity.",[597,3212,3214],{"id":3213},"business-associates","Business associates",[37,3216,2098,3217,3221],{},[249,3218,3220],{"href":3219},"\u002Fglossary\u002Fbusiness-associate","business associate"," is any person or organization that performs a function or activity on behalf of a covered entity that involves the use or disclosure of PHI. Typical business associates include cloud hosting providers, billing vendors, EHR vendors, IT service providers, analytics firms, legal counsel, accounting firms, transcription services, and SaaS platforms that process PHI on behalf of covered entities.",[37,3223,3224,3225,3229],{},"Most modern SaaS companies serving healthcare customers are business associates. If your product ingests, stores, processes, or transmits PHI for a covered entity, HIPAA applies to you directly — regardless of whether you consider yourself a \"healthcare company.\" Subcontractors of business associates are themselves business associates and are bound by the same obligations. Signing a ",[249,3226,3228],{"href":3227},"\u002Fglossary\u002Fbaa","business associate agreement"," with every upstream and downstream partner that touches PHI is non-negotiable.",[597,3231,3233],{"id":3232},"who-is-not-covered-by-hipaa","Who is not covered by HIPAA?",[37,3235,3236],{},"Not every organization that handles health information is subject to the law. Consumer wellness apps, fitness trackers, direct-to-consumer genetic testing services, employers (in their role as employers), life insurers, and schools generally fall outside its reach unless they act on behalf of a covered entity. That said, many of these organizations still face FTC oversight, state privacy laws, and customer expectations that mirror HIPAA protections.",[32,3238,3240],{"id":3239},"the-hipaa-privacy-rule","The HIPAA Privacy Rule",[37,3242,3243],{},"The HIPAA Privacy Rule sets national standards for the protection of PHI in all forms — electronic, paper, and oral. It establishes when PHI may be used and disclosed, defines patient rights over their own health data, and imposes the minimum necessary standard on most disclosures. The Privacy Rule applies to covered entities directly and to business associates through their BAAs.",[37,3245,3246],{},"Key Privacy Rule concepts include the Notice of Privacy Practices, patient access rights (including the right to an electronic copy of an electronic health record within 30 days), the right to request amendments and accounting of disclosures, the minimum necessary standard, permitted uses for treatment, payment, and operations, and the authorization requirements for marketing and sale of PHI.",[37,3248,3249,3250,3254,3255,3259],{},"For a comprehensive walkthrough of the HIPAA Privacy Rule, permitted disclosures, and patient rights, read the dedicated ",[249,3251,3253],{"href":3252},"\u002Fframeworks\u002Fhipaa\u002Fprivacy-rule","HIPAA Privacy Rule"," guide. For more on the narrowly tailored access principle that governs day-to-day PHI handling, see the ",[249,3256,3258],{"href":3257},"\u002Fframeworks\u002Fhipaa\u002Fminimum-necessary-rule","minimum necessary rule"," page.",[32,3261,3263],{"id":3262},"the-hipaa-security-rule","The HIPAA Security Rule",[37,3265,3266],{},"The HIPAA Security Rule establishes the national floor for protecting electronic PHI (ePHI). While the Privacy Rule covers every form of PHI, the Security Rule is scoped to electronic data — which, in 2026, is effectively every record of clinical or financial relevance inside a modern healthcare organization.",[37,3268,3269],{},"The Security Rule organizes its requirements into three categories of safeguards. Every covered entity and business associate must implement each category based on a documented HIPAA risk analysis.",[597,3271,3273],{"id":3272},"administrative-safeguards","Administrative safeguards",[37,3275,3276,3277,3281,3282,3286,3287,3291],{},"Administrative safeguards are the policies, procedures, and organizational measures that govern your HIPAA program. They include security management processes, a designated security official, ",[249,3278,3280],{"href":3279},"\u002Fframeworks\u002Fhipaa\u002Fworkforce-training","workforce training",", a ",[249,3283,3285],{"href":3284},"\u002Fframeworks\u002Fhipaa\u002Fsanctions-policy","sanctions policy"," for workforce violations, access management, ",[249,3288,3290],{"href":3289},"\u002Fframeworks\u002Fhipaa\u002Fcontingency-planning","contingency planning",", periodic evaluations, and BAAs with every downstream partner. These typically consume the most effort because they touch every corner of the business.",[597,3293,3295],{"id":3294},"physical-safeguards","Physical safeguards",[37,3297,3298,3299,466,3303,3307],{},"Physical safeguards protect the facilities, workstations, devices, and media that house ePHI. This category covers ",[249,3300,3302],{"href":3301},"\u002Fframeworks\u002Fhipaa\u002Ffacility-access-controls","facility access controls",[249,3304,3306],{"href":3305},"\u002Fframeworks\u002Fhipaa\u002Fworkstation-and-device-controls","workstation and device controls",", and media disposal. For cloud-first SaaS companies, physical safeguards increasingly translate into inherited controls from hyperscale cloud providers, but every regulated organization still needs defensible answers for the laptops, offices, and portable media its workforce uses.",[597,3309,3311],{"id":3310},"technical-safeguards","Technical safeguards",[37,3313,3314],{},"Technical safeguards are the technology controls that protect ePHI and govern access to it. They include unique user identification, automatic logoff, encryption and decryption of ePHI at rest and in transit, audit controls that log system activity, integrity controls that prevent improper alteration, and person or entity authentication.",[37,3316,3317,3318,3322],{},"For a deep dive into the complete Security Rule standards, required versus addressable implementation specifications, and how to pass an OCR audit of your ePHI safeguards, read the ",[249,3319,3321],{"href":3320},"\u002Fframeworks\u002Fhipaa\u002Fsecurity-rule","HIPAA Security Rule"," guide.",[32,3324,3326],{"id":3325},"the-hipaa-breach-notification-rule","The HIPAA Breach Notification Rule",[37,3328,3329],{},"The Breach Notification Rule, added by HITECH and finalized in the Omnibus Rule, requires covered entities and business associates to notify affected individuals, HHS, and in some cases the media when unsecured PHI is breached. A breach is presumed whenever PHI is used or disclosed in a way that is not permitted under the Privacy Rule, unless the organization can demonstrate through a four-factor risk assessment that there is a low probability the PHI has been compromised.",[37,3331,3332],{},"Notifications must be made without unreasonable delay and in no case later than 60 calendar days after discovery. Business associates must notify their covered entity clients, who in turn notify affected individuals. Breaches involving 500 or more individuals must be reported to HHS within 60 days and listed on the public OCR \"Wall of Shame,\" while smaller breaches may be reported in an annual log.",[37,3334,3335,3336,3322],{},"For full details on timelines, content requirements, and documentation expectations, see the ",[249,3337,3339],{"href":3338},"\u002Fframeworks\u002Fhipaa\u002Fbreach-notification","HIPAA Breach Notification Rule",[32,3341,3343],{"id":3342},"business-associate-agreements","Business associate agreements",[37,3345,3346,3347,3350],{},"No PHI should ever leave a covered entity — or a business associate — without a properly executed BAA in place. A ",[249,3348,3228],{"href":3349},"\u002Fframeworks\u002Fhipaa\u002Fbusiness-associate-agreements"," is a legally binding contract that defines permitted uses and disclosures of PHI, requires implementation of appropriate safeguards, obligates breach notification, mandates BAA flow-down to subcontractors, and establishes termination rights when a business associate violates the agreement.",[37,3352,3353],{},"In practice, BAA management is one of the most common HIPAA failure modes for growing SaaS companies. Deals close, engineering ships, and PHI starts flowing before legal has countersigned the BAA — creating exposure for both sides. A disciplined BAA intake process, a BAA repository with renewal reminders, and clear ownership of vendor risk are table stakes for any serious compliance program.",[32,3355,3357],{"id":3356},"hipaa-compliance-checklist","HIPAA compliance checklist",[37,3359,3360,3361,3364],{},"Translating the regulatory language into day-to-day operations is where most programs struggle. The ",[249,3362,3357],{"href":3363},"\u002Fframeworks\u002Fhipaa\u002Fcompliance-checklist"," walks through every major obligation — from assigning a security official through finalizing your Notice of Privacy Practices — as a sequenced program of work.",[37,3366,3367],{},"At a high level, a complete HIPAA program includes:",[47,3369,3370,3373,3376,3379,3382,3385,3388],{},[50,3371,3372],{},"A current risk analysis and documented risk management plan.",[50,3374,3375],{},"Written policies and procedures covering Privacy, Security, and Breach Notification obligations.",[50,3377,3378],{},"A signed BAA with every vendor, subcontractor, and customer that exchanges PHI.",[50,3380,3381],{},"Workforce training at hire and at least annually thereafter, with documented completion.",[50,3383,3384],{},"Access control, audit logging, encryption, and contingency planning for every system that touches ePHI.",[50,3386,3387],{},"An incident response runbook aligned to the Breach Notification Rule.",[50,3389,3390],{},"Documentation retained for at least six years from creation or last effective date, whichever is later.",[32,3392,3394],{"id":3393},"hipaa-risk-analysis","HIPAA risk analysis",[37,3396,3397],{},"Every HIPAA Security Rule program begins with a risk analysis. Under 45 CFR §164.308(a)(1)(ii)(A), covered entities and business associates must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. HHS has repeatedly stated that a missing or superficial risk analysis is among the most common findings in OCR enforcement actions.",[37,3399,3400],{},"A defensible risk analysis inventories every system that creates, receives, maintains, or transmits ePHI, identifies threats and vulnerabilities affecting each system, measures the likelihood and impact of each risk, and feeds directly into the Security Management Process that prioritizes mitigation. Most mature programs align their methodology to NIST Special Publication 800-30, which OCR cites favorably.",[37,3402,3403,3404,3322],{},"For a full breakdown of methodology, documentation requirements, and common pitfalls, read the ",[249,3405,3394],{"href":3406},"\u002Fframeworks\u002Fhipaa\u002Frisk-analysis",[32,3408,3410],{"id":3409},"penalties-and-enforcement","Penalties and enforcement",[37,3412,3413],{},"Enforcement is administered by OCR, with parallel criminal enforcement authority held by the Department of Justice and civil enforcement authority held by state attorneys general. HIPAA penalties are tiered by culpability.",[47,3415,3416,3422,3428,3434],{},[50,3417,3418,3421],{},[53,3419,3420],{},"Tier 1 — Unknowing violation"," — $100 to $50,000 per violation; annual cap $25,000 for identical violations.",[50,3423,3424,3427],{},[53,3425,3426],{},"Tier 2 — Reasonable cause"," — $1,000 to $50,000 per violation; annual cap $100,000.",[50,3429,3430,3433],{},[53,3431,3432],{},"Tier 3 — Willful neglect, corrected"," — $10,000 to $50,000 per violation; annual cap $250,000.",[50,3435,3436,3439],{},[53,3437,3438],{},"Tier 4 — Willful neglect, uncorrected"," — $50,000 per violation; annual cap $1.5 million per violation category.",[37,3441,3442],{},"Penalty amounts are adjusted annually for inflation. Criminal penalties can reach $250,000 and 10 years of imprisonment for offenses involving intent to sell, transfer, or use PHI for commercial advantage, personal gain, or malicious harm.",[37,3444,3445],{},"OCR enforcement tends to cluster around predictable themes: missing or inadequate risk analyses, lost unencrypted devices, failure to terminate workforce access, insufficient BAAs, delayed breach notifications, and refusal to provide patient access to records. Organizations that can demonstrate a mature, well-documented program — with evidence of ongoing risk analysis, training, and monitoring — consistently receive more favorable resolutions.",[32,3447,3449],{"id":3448},"hipaa-vs-hitech-vs-hitrust","HIPAA vs HITECH vs HITRUST",[37,3451,3452],{},"These three acronyms sit close together in healthcare conversations and are often conflated. They are related but distinct.",[47,3454,3455,3461,3466],{},[50,3456,3457,3460],{},[53,3458,3459],{},"HIPAA"," is the underlying federal law and its implementing regulations (Privacy, Security, Breach Notification, and Enforcement Rules). HIPAA defines the legal obligations.",[50,3462,3463,3465],{},[53,3464,3144],{}," is a 2009 federal law that strengthened HIPAA — extending it to business associates, introducing breach notification, increasing penalties, and funding EHR adoption. HITECH is part of HIPAA's regulatory stack, not a separate framework.",[50,3467,3468,3471],{},[53,3469,3470],{},"HITRUST"," is a private-sector certification maintained by the HITRUST Alliance. The HITRUST CSF is a control framework that maps HIPAA, NIST, ISO 27001, PCI DSS, and other standards into a single certifiable set of controls. HITRUST is a common way to demonstrate HIPAA compliance to sophisticated healthcare customers, but HITRUST certification is not itself required by HIPAA.",[37,3473,3474],{},"A healthcare SaaS company might pursue HITRUST CSF certification as a commercial asset while its underlying legal obligation remains HIPAA compliance under HITECH-amended rules.",[597,3476,3478],{"id":3477},"hipaa-and-soc-2","HIPAA and SOC 2",[37,3480,3481,3482,3484],{},"Many SaaS companies pursue ",[249,3483,475],{"href":474}," alongside HIPAA. The two frameworks complement each other: SOC 2 evaluates security, availability, confidentiality, processing integrity, and privacy trust services criteria, while HIPAA is a statutory requirement for handling PHI. A well-designed control environment can satisfy both with substantial overlap.",[32,3486,3488],{"id":3487},"getting-hipaa-compliant","Getting HIPAA compliant",[37,3490,3491],{},"The most successful HIPAA programs treat compliance as a continuous operating rhythm rather than a once-a-year scramble. A typical rollout for a SaaS company serving healthcare customers looks like this.",[903,3493,3494,3497,3500,3503,3506,3509,3512,3515,3518],{},[50,3495,3496],{},"Confirm your status as a covered entity, business associate, or both, and inventory the PHI you handle today.",[50,3498,3499],{},"Appoint a security official and a privacy official (the same person may hold both roles at small companies).",[50,3501,3502],{},"Conduct a risk analysis scoped to every system that creates, receives, maintains, or transmits ePHI.",[50,3504,3505],{},"Implement the administrative, physical, and technical safeguards required by the Security Rule, informed by your risk analysis.",[50,3507,3508],{},"Draft and publish policies and procedures covering Privacy, Security, and Breach Notification obligations.",[50,3510,3511],{},"Execute BAAs with every vendor that touches PHI, and require a signed BAA before onboarding any new customer that qualifies as a covered entity.",[50,3513,3514],{},"Deliver workforce training at hire and annually thereafter, and document completion.",[50,3516,3517],{},"Stand up an incident response runbook aligned to the Breach Notification Rule.",[50,3519,3520],{},"Operate the program: review access quarterly, test contingency plans at least annually, refresh your risk analysis whenever material change occurs, and retain documentation for at least six years.",[37,3522,3523,3524,3528],{},"For companies operating in the broader ",[249,3525,3527],{"href":3526},"\u002Findustry\u002Fhealthcare","healthcare industry",", HIPAA is rarely the only regulation in scope. State privacy laws, the 21st Century Cures Act, FDA software-as-a-medical-device requirements, and payor-specific security reviews often run in parallel — which is why most compliance programs are built into a broader GRC operating model.",[32,3530,3532],{"id":3531},"how-episki-helps-with-hipaa-compliance","How episki helps with HIPAA compliance",[37,3534,3535,3536,254,3539,258],{},"episki maps the administrative, physical, and technical safeguards to controls evaluated continuously rather than attested annually. Identity and access evidence from Google, Microsoft, and AWS is checked rather than inventoried; contingency planning is proven from point-in-time recovery and multi-region backup posture; and business associates run through the TPRM module with BAAs, risk scores, consolidated subprocessors, and review cadences that advance when you accept evidence. Addressable specifications you decide not to implement are recorded as approved exceptions carrying the required rationale and an expiry date — precisely the documentation the rule asks for. ",[249,3537,253],{"href":185,"rel":3538},[252],[249,3540,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":3542},[3543,3544,3547,3552,3553,3558,3559,3560,3561,3562,3563,3566,3567],{"id":3087,"depth":94,"text":3088},{"id":3110,"depth":94,"text":3111,"children":3545},[3546],{"id":3160,"depth":995,"text":3161},{"id":3172,"depth":94,"text":3173,"children":3548},[3549,3550,3551],{"id":3179,"depth":995,"text":3180},{"id":3213,"depth":995,"text":3214},{"id":3232,"depth":995,"text":3233},{"id":3239,"depth":94,"text":3240},{"id":3262,"depth":94,"text":3263,"children":3554},[3555,3556,3557],{"id":3272,"depth":995,"text":3273},{"id":3294,"depth":995,"text":3295},{"id":3310,"depth":995,"text":3311},{"id":3325,"depth":94,"text":3326},{"id":3342,"depth":94,"text":3343},{"id":3356,"depth":94,"text":3357},{"id":3393,"depth":94,"text":3394},{"id":3409,"depth":94,"text":3410},{"id":3448,"depth":94,"text":3449,"children":3564},[3565],{"id":3477,"depth":995,"text":3478},{"id":3487,"depth":94,"text":3488},{"id":3531,"depth":94,"text":3532},{"title":3569,"description":3570,"items":3571},"HIPAA launch kit","Guided steps keep privacy, security, and ops in sync from day one.",[3572,3573,3574,3575,3576],"Safeguard library with ownership matrix","Evidence tracking for access logs and configs","BAA tracker with renewal reminders","Incident and breach response templates","Stakeholder portal with PHI redaction controls",{"title":3578,"description":3579},"Launch HIPAA monitoring in minutes","Kick off the free trial and invite stakeholders before your next diligence call.",{"title":3581,"items":3582},"HIPAA compliance frequently asked questions",[3583,3586,3589,3592,3595],{"label":3584,"content":3585},"Who needs to comply with HIPAA?","HIPAA applies to covered entities (health plans, healthcare providers, clearinghouses) and business associates — any vendor or subcontractor that creates, receives, maintains, or transmits protected health information (PHI). SaaS companies serving healthcare customers almost always qualify as business associates.",{"label":3587,"content":3588},"What is a Business Associate Agreement (BAA)?","A BAA is a legally required contract between a covered entity and a business associate that establishes permitted uses and disclosures of PHI, requires appropriate safeguards, and outlines breach notification responsibilities. No PHI should be shared with a vendor before a BAA is signed.",{"label":3590,"content":3591},"What are the penalties for HIPAA violations?","HIPAA penalties range from $100 to $50,000 per violation depending on the level of negligence, with annual maximums up to $1.5 million per violation category. Criminal penalties can include fines up to $250,000 and imprisonment. The HHS Office for Civil Rights enforces compliance.",{"label":3593,"content":3594},"Does HIPAA apply to SaaS companies?","Yes. Any SaaS company that handles, stores, or transmits PHI on behalf of a healthcare organization is considered a business associate under HIPAA and must comply with the Security Rule, Privacy Rule, and Breach Notification Rule.",{"label":3596,"content":3597},"What are the three HIPAA safeguard categories?","HIPAA requires administrative safeguards (policies, training, risk assessments), physical safeguards (facility access, workstation security), and technical safeguards (access controls, encryption, audit logging) to protect electronic PHI.",{"headline":3599,"title":3600,"description":3601,"links":3602},"HIPAA-ready cloud teams","Stay HIPAA compliant while shipping product weekly","episki maps administrative, physical, and technical safeguards to your systems and keeps PHI protections verifiable.",[3603,3605],{"label":3604,"icon":182,"to":185},"Start HIPAA trial",{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"\u002Fframeworks\u002Fhipaa",{"headline":3609,"title":3609,"description":3610,"items":3611},"HIPAA enablement","Keep leadership, customers, and partners aligned.",[3612,3615,3618],{"title":3613,"description":3614},"Board-ready posture report","Shows maturity score, risk trends, and upcoming audits.",{"title":3616,"description":3617},"Customer FAQ pack","Answers the most common HIPAA diligence questions.",{"title":3619,"description":3620},"Ops automation guide","Explains how to plug security tasks into existing tools.",{"title":3622,"description":3623},"HIPAA Compliance Management Software","Map HIPAA safeguards, track PHI evidence, and manage BAAs in one secure workspace. Get audit-ready in 30 days with episki's free trial.","hipaa",[3626,3629,3632],{"value":3627,"description":3628},"30-day rollout","Average time to production monitoring across safeguards.",{"value":3630,"description":3631},"PHI-safe sharing","Role-based portals keep sensitive documents organized and protected.",{"value":3633,"description":3634},"24\u002F7 alerts","Continuous monitoring for access, logging, and vendor risks.","5.frameworks\u002Fhipaa","Lqnz0buRwatd8W5eTg9CgEuGavo4WvKd7_wgEhumRqQ",{"id":3638,"title":3639,"advantages":3640,"body":3662,"checklist":3696,"cta":3705,"description":93,"extension":151,"faq":3708,"hero":3723,"lastUpdated":186,"meta":3730,"name":3731,"navigation":188,"path":3732,"resources":3733,"seo":3747,"slug":3750,"stats":3751,"stem":3761,"__hash__":3762},"frameworks\u002F5.frameworks\u002Fhitrust.md","Hitrust",[3641,3648,3655],{"title":3642,"description":3643,"bullets":3644},"e1, i1, r2 scoping","Pick the right assessment type and scope, with the right control selection guided by HITRUST's risk factors.",[3645,3646,3647],"HITRUST CSF library at the requirement level","Risk-factor-driven control selection","Inheritance from prior assessments",{"title":3649,"description":3650,"bullets":3651},"External assessor collaboration","HITRUST authorized External Assessors get a scoped workspace with the evidence and walkthroughs they need.",[3652,3653,3654],"Scoped portal per engagement","Evidence packets organized by requirement","MyCSF-style language in episki narratives",{"title":3656,"description":3657,"bullets":3658},"Cross-mapped to HIPAA, SOC 2, ISO 27001","Stop maintaining parallel programs. One control, many certifications.",[3659,3660,3661],"Evidence reuse across audits","Crosswalks visible per control","Map once, satisfy many",{"type":29,"value":3663,"toc":3691},[3664,3668,3671,3674,3678,3681,3683],[32,3665,3667],{"id":3666},"what-is-hitrust-csf","What is HITRUST CSF?",[37,3669,3670],{},"The HITRUST Common Security Framework is a certifiable, risk-based control framework originally developed for the healthcare industry and now used across regulated industries broadly. HITRUST integrates requirements from HIPAA, NIST, ISO 27001, PCI DSS, GDPR, and other authorities into a single, scalable control catalog.",[37,3672,3673],{},"The HITRUST organization offers three assessment types: e1 (essentials), i1 (intermediate), and r2 (the comprehensive, certifiable assessment). Each escalates the rigor of evidence and the breadth of controls. r2 is the most widely recognized in enterprise procurement.",[32,3675,3677],{"id":3676},"who-needs-hitrust","Who needs HITRUST",[37,3679,3680],{},"HITRUST CSF Certified status is increasingly expected — sometimes required — by major payers, hospitals, and pharma companies before doing business with a SaaS or technology vendor. Outside healthcare, financial services and government contractors are also adopting HITRUST as a comprehensive way to demonstrate a mature control environment.",[32,3682,244],{"id":243},[37,3684,3685,3686,254,3689,258],{},"episki maps HITRUST CSF requirements to controls evaluated continuously, with crosswalks to HIPAA, ISO 27001, and SOC 2 derived through the SCF hub so one piece of evidence satisfies every framework that claims the control. Each check writes an explicit verdict, and a formally accepted gap becomes an exception with a named approver and an expiry. ",[249,3687,253],{"href":185,"rel":3688},[252],[249,3690,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":3692},[3693,3694,3695],{"id":3666,"depth":94,"text":3667},{"id":3676,"depth":94,"text":3677},{"id":243,"depth":94,"text":244},{"title":3697,"description":3698,"items":3699},"HITRUST readiness inside episki","Everything you need to scope and prepare for assessment.",[3645,3700,3701,3702,3703,3704],"Risk-factor questionnaire driving control selection","Evidence library organized by HITRUST domain","Cross-walks to HIPAA, SOC 2, and ISO 27001","External Assessor collaboration workspace","Interim assessment workflow",{"title":3706,"description":3707},"Start your HITRUST program in episki","Pull in your existing controls, pick the right assessment type, and prep your assessor.",{"title":3709,"items":3710},"HITRUST frequently asked questions",[3711,3714,3717,3720],{"label":3712,"content":3713},"What's the difference between e1, i1, and r2?","e1 is a foundational essentials-based assessment with 44 controls. i1 is an intermediate-rigor assessment around 180 controls. r2 (formerly r2 CSF Certified) is the most rigorous, fully-tailored assessment with hundreds of controls and is what most enterprise healthcare buyers expect.",{"label":3715,"content":3716},"How does HITRUST relate to HIPAA?","HITRUST CSF is a comprehensive framework that incorporates HIPAA security and privacy requirements along with controls from NIST, ISO, PCI, and others. Many healthcare organizations pursue HITRUST as a way to demonstrate HIPAA compliance plus more.",{"label":3718,"content":3719},"Who performs HITRUST assessments?","HITRUST r2 and i1 assessments are performed by HITRUST Authorized External Assessors. e1 can be self-assessed or validated. The assessor uploads results to MyCSF for HITRUST's quality assurance review.",{"label":3721,"content":3722},"How long does a HITRUST r2 take?","A first-time r2 typically takes 9–18 months from kickoff to certification depending on scope and maturity. Programs that have an existing SOC 2 or ISO 27001 in episki can move significantly faster because evidence and controls already exist.",{"headline":3724,"title":3725,"description":3726,"links":3727},"HITRUST without the binder cart","Move from e1 to r2 without rebuilding your program","HITRUST CSF mapped to your existing controls, assessment-handler-friendly evidence packets, and cross-walks to HIPAA, SOC 2, and ISO 27001 so you stop running parallel programs.",[3728,3729],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"HITRUST CSF","\u002Fframeworks\u002Fhitrust",{"headline":3734,"title":3735,"description":3736,"items":3737},"HITRUST accelerators","HITRUST program accelerators","Stop running HITRUST as a separate animal.",[3738,3741,3744],{"title":3739,"description":3740},"Scoping wizard","Risk-factor-driven control selection so you don't over- or under-scope.",{"title":3742,"description":3743},"Evidence cross-walk","Reuse the same evidence across HIPAA, SOC 2, ISO 27001, and HITRUST.",{"title":3745,"description":3746},"Assessor handoff packet","Pre-organized evidence and narratives for your External Assessor.",{"title":3748,"description":3749},"HITRUST CSF Compliance Software","Run HITRUST e1, i1, or r2 assessments with the HITRUST CSF mapped to your existing controls and evidence. Cross-mapped to HIPAA, SOC 2, and ISO 27001.","hitrust",[3752,3755,3758],{"value":3753,"description":3754},"3 paths","e1, i1, and r2 assessment types supported with the right scoping.",{"value":3756,"description":3757},"100+ controls","HITRUST CSF requirements pre-mapped to your control library.",{"value":3759,"description":3760},"1 program","One evidence set serving HITRUST, HIPAA, SOC 2, ISO 27001 simultaneously.","5.frameworks\u002Fhitrust","eUDofIZbPaP3ykxX0crJh1jtU59FsSCbsk6na7IkF-k",{"id":3764,"title":3765,"advantages":3766,"body":3788,"checklist":3866,"cta":3876,"description":93,"extension":151,"faq":3879,"hero":3893,"lastUpdated":186,"meta":3900,"name":3901,"navigation":188,"path":3902,"resources":3903,"seo":3916,"slug":3919,"stats":3920,"stem":3930,"__hash__":3931},"frameworks\u002F5.frameworks\u002Fiso22301.md","Iso22301",[3767,3774,3781],{"title":3768,"description":3769,"bullets":3770},"A real BCMS, not a binder","The ISO 22301 management system implemented as living artifacts.",[3771,3772,3773],"Business impact analysis and risk assessment","Continuity strategies and solutions","Documented plans and recovery objectives",{"title":3775,"description":3776,"bullets":3777},"Tested and improved","Exercises, reviews, and corrective actions that satisfy auditors.",[3778,3779,3780],"Exercise and test scheduling","Post-incident and post-exercise reviews","Corrective actions tracked to closure",{"title":3782,"description":3783,"bullets":3784},"Reuse your ISMS","ISO 22301 shares the harmonized structure with ISO 27001.",[3785,3786,3787],"Shared clauses 4-10 with ISO 27001","One combined audit where scoped together","Crosswalk to SOC 2 availability criteria",{"type":29,"value":3789,"toc":3860},[3790,3794,3804,3808,3834,3838,3850,3852],[32,3791,3793],{"id":3792},"what-is-iso-22301","What is ISO 22301?",[37,3795,3796,3799,3800,3803],{},[53,3797,3798],{},"ISO 22301:2019"," is the international standard for a ",[53,3801,3802],{},"Business Continuity Management System (BCMS)",". It defines the requirements for a documented, repeatable system that helps an organization prepare for, respond to, and recover from disruptive incidents — from outages and natural disasters to supply-chain failures and cyber attacks. It is certifiable, and it follows the Plan-Do-Check-Act model common to ISO management-system standards.",[32,3805,3807],{"id":3806},"what-a-bcms-covers","What a BCMS covers",[37,3809,3810,3811,3814,3815,3817,3818,3821,3822,3825,3826,3829,3830,3833],{},"At its core, ISO 22301 is driven by a ",[53,3812,3813],{},"business impact analysis (BIA)"," and a ",[53,3816,2944],{}," that together identify an organization's critical activities, their dependencies, and the impact of disruption over time. From there, the organization defines ",[53,3819,3820],{},"continuity strategies",", sets ",[53,3823,3824],{},"recovery time and recovery point objectives (RTO\u002FRPO)",", documents ",[53,3827,3828],{},"continuity and incident-response plans",", and validates them through an ",[53,3831,3832],{},"exercise and testing program"," with reviews and corrective actions.",[32,3835,3837],{"id":3836},"how-it-relates-to-iso-27001","How it relates to ISO 27001",[37,3839,3840,3841,3844,3845,3847,3848,258],{},"ISO 22301 shares the ",[53,3842,3843],{},"ISO harmonized structure"," (clauses 4–10) with ",[249,3846,470],{"href":469},", so the leadership, risk-management, and continual-improvement processes overlap substantially. Many organizations run the two together and pursue a combined audit, and the BCMS also strengthens the availability story for ",[249,3849,475],{"href":474},[32,3851,244],{"id":243},[37,3853,3854,3855,254,3858,258],{},"episki proves continuity capability from the systems that provide it — point-in-time recovery, backup configuration, and multi-region posture evaluated on every sync, with an absent setting treated as unprotected rather than assumed fine. Business impact analyses, plans, and test records link to the controls they support, and gaps become findings with owners and due dates. ",[249,3856,253],{"href":185,"rel":3857},[252],[249,3859,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":3861},[3862,3863,3864,3865],{"id":3792,"depth":94,"text":3793},{"id":3806,"depth":94,"text":3807},{"id":3836,"depth":94,"text":3837},{"id":243,"depth":94,"text":244},{"title":3867,"description":3868,"items":3869},"ISO 22301 readiness inside episki","What a BCMS needs in place.",[3870,3871,3872,3873,3874,3875],"BCMS scope, policy, and objectives","Business impact analysis (BIA)","Risk assessment of disruption scenarios","Continuity strategies and recovery objectives (RTO \u002F RPO)","Business continuity and incident response plans","Exercise program, reviews, and corrective actions",{"title":3877,"description":3878},"Build a certifiable BCMS in episki","Stand up ISO 22301 alongside ISO 27001 and reuse the management-system work.",{"title":3880,"items":3881},"ISO 22301 frequently asked questions",[3882,3884,3887,3890],{"label":3793,"content":3883},"ISO 22301:2019 is the international standard for a Business Continuity Management System (BCMS). It specifies requirements to plan, establish, implement, operate, monitor, review, maintain, and continually improve a documented system that protects against, reduces the likelihood of, and ensures recovery from disruptive incidents.",{"label":3885,"content":3886},"Is the current version 2019?","Yes. ISO 22301:2019 is the current edition. As of 2026 it remains the in-force version, with no confirmed publication date for a revision.",{"label":3888,"content":3889},"How does it relate to ISO 27001?","ISO 22301 and ISO 27001 share the ISO harmonized (high-level) structure, so the management-system clauses (4-10) overlap heavily. Organizations frequently run them together and can pursue a combined audit, reusing leadership, risk, and improvement processes across both.",{"label":3891,"content":3892},"What is a business impact analysis?","A business impact analysis (BIA) identifies an organization's critical activities, their dependencies, and the impact of disruption over time. It drives the recovery time and recovery point objectives (RTO\u002FRPO) and the continuity strategies the BCMS puts in place.",{"headline":3894,"title":3895,"description":3896,"links":3897},"Business continuity, certifiable","Build a BCMS with ISO 22301","ISO 22301:2019 as a working program — business impact analysis, continuity strategies, plans, and exercises — that reuses your ISO 27001 management system.",[3898,3899],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"ISO 22301","\u002Fframeworks\u002Fiso22301",{"headline":3904,"title":3905,"description":3906,"items":3907},"ISO 22301 accelerators","Business continuity accelerators","Stand up a certifiable BCMS without a parallel project.",[3908,3911,3914],{"title":3909,"description":3910},"BIA builder","Capture critical activities, dependencies, and recovery objectives.",{"title":3912,"description":3913},"Continuity plan templates","Document plans tied to your BIA and recovery objectives.",{"title":1414,"description":3915},"Reuse your ISMS management-system evidence for the BCMS.",{"title":3917,"description":3918},"ISO 22301 Business Continuity Compliance Software","Build a certifiable Business Continuity Management System (BCMS) per ISO 22301:2019 — business impact analysis, continuity plans, and exercises — in one workspace.","iso22301",[3921,3924,3927],{"value":3922,"description":3923},":2019","The current edition of the international BCMS standard.",{"value":3925,"description":3926},"BIA-driven","Continuity priorities set by a documented business impact analysis.",{"value":3928,"description":3929},"27001 aligned","Shares the ISO harmonized structure with ISO 27001 for reuse.","5.frameworks\u002Fiso22301","zUUAtOcXc1BmjUWFEsaOYkVWlsn3hDlfhf6ZodijxFQ",{"id":3933,"title":3934,"advantages":3935,"body":3957,"checklist":4359,"cta":4370,"description":93,"extension":151,"faq":4373,"hero":4391,"lastUpdated":186,"meta":4399,"name":470,"navigation":188,"path":469,"resources":4400,"seo":4413,"slug":4416,"stats":4417,"stem":4426,"__hash__":4427},"frameworks\u002F5.frameworks\u002Fiso27001.md","Iso27001",[3936,3943,3950],{"title":3937,"description":3938,"bullets":3939},"Statement of Applicability in minutes","Generate and maintain your SoA directly from your control graph with justification notes for every inclusion and exclusion.",[3940,3941,3942],"Auto-populate applicability status from existing controls","Link each control to risk treatment decisions","Export auditor-ready SoA documents on demand",{"title":3944,"description":3945,"bullets":3946},"Risk-driven control management","Connect your risk register to Annex A controls so treatment plans and evidence stay aligned as threats evolve.",[3947,3948,3949],"Risk assessment templates following ISO 27005 guidance","Heat maps show residual risk by domain","Treatment plans tie directly to control tasks and owners",{"title":3951,"description":3952,"bullets":3953},"Surveillance audit confidence","Keep your ISMS current between certification cycles with continuous monitoring and internal audit workflows.",[3954,3955,3956],"Automated evidence refresh and expiration alerts","Internal audit scheduling with finding tracking","Management review templates with trend data",{"type":29,"value":3958,"toc":4341},[3959,3963,3974,3977,3980,3983,3987,3990,3993,3996,4000,4003,4016,4020,4023,4030,4033,4037,4045,4048,4056,4060,4067,4070,4078,4082,4085,4129,4137,4145,4149,4152,4155,4162,4166,4169,4172,4183,4187,4190,4198,4202,4205,4212,4216,4219,4245,4252,4256,4259,4267,4271,4274,4282,4286,4289,4310,4316,4320,4323,4335,4338],[32,3960,3962],{"id":3961},"what-is-iso-27001","What is ISO 27001?",[37,3964,3965,3968,3969,3973],{},[249,3966,470],{"href":3967},"\u002Fglossary\u002Fiso27001"," is the world's most widely adopted international standard for information security management. Formally titled ISO\u002FIEC 27001, it defines the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System, or ",[249,3970,3972],{"href":3971},"\u002Fglossary\u002Fisms","ISMS",". Organizations that align with ISO 27001 commit to a risk-based, process-driven approach to protecting the confidentiality, integrity, and availability of the information they hold on behalf of customers, employees, and business partners.",[37,3975,3976],{},"The standard is published jointly by two bodies. The International Organization for Standardization (ISO), headquartered in Geneva, develops consensus-based standards across nearly every industry. The International Electrotechnical Commission (IEC) is its counterpart for electrotechnical and information technology standards. Together, their joint technical committee ISO\u002FIEC JTC 1\u002FSC 27 maintains the ISO 27001 family, which includes supporting documents such as ISO 27002 (implementation guidance) and ISO 27005 (risk management guidance).",[37,3978,3979],{},"ISO 27001 was first released in 2005, revised in 2013, and most recently updated in October 2022. The 2022 revision is now the only version against which new ISO 27001 certifications are issued. Any discussion of ISO 27001 today should default to this edition, which reorganized the control set and introduced eleven new controls addressing modern risks like threat intelligence, data masking, and secure coding.",[37,3981,3982],{},"At the heart of ISO 27001 is the concept of an ISMS. An ISMS is not a product you can buy or a checklist you can run through once. It is the living combination of policies, processes, people, and technology that your organization uses to identify information security risks, decide how to treat them, implement controls, measure effectiveness, and continually improve. ISO 27001 provides the blueprint. Your ISMS is the thing you build from that blueprint.",[32,3984,3986],{"id":3985},"why-iso-27001-matters","Why ISO 27001 matters",[37,3988,3989],{},"ISO 27001 is recognized in more than 160 countries and frequently shows up as a procurement requirement for enterprise technology contracts, financial services partnerships, public sector work, and any organization selling into European or APAC markets. Unlike self-attested programs, ISO 27001 certification is issued by an independent accredited certification body, which gives customers and regulators external assurance that your security practices are real and not marketing.",[37,3991,3992],{},"Beyond procurement, ISO 27001 brings discipline. Many organizations treat security as a reactive function that only activates after an incident or failed audit. The ISO 27001 approach forces proactive risk identification, documented decisions, and measurable effectiveness. Even teams that never pursue certification often adopt the ISO 27001 framework as an internal operating model because it is mature, well-documented, and maps cleanly to other standards.",[37,3994,3995],{},"ISO 27001 also signals organizational maturity to investors. Due diligence for Series B and later funding rounds almost always includes a security review. Holding an ISO 27001 certificate short-circuits much of that review and accelerates close.",[32,3997,3999],{"id":3998},"the-iso-27001-certification-process","The ISO 27001 certification process",[37,4001,4002],{},"ISO 27001 certification follows a standardized two-stage audit model used worldwide. A Stage 1 audit reviews your ISMS documentation and readiness. A Stage 2 audit evaluates whether your ISMS is actually implemented and effective in practice. If there are no major nonconformities, the certification body recommends certification and a three-year certificate is issued. Annual surveillance audits follow, with full recertification every three years.",[37,4004,4005,4006,4010,4011,4015],{},"For a deep walkthrough of every phase of the journey, including timelines, auditor expectations, and common pitfalls, see the ",[249,4007,4009],{"href":4008},"\u002Fframeworks\u002Fiso27001\u002Fcertification-process","ISO 27001 certification process guide",". If you are still evaluating whether to pursue ISO 27001 at all, the ",[249,4012,4014],{"href":4013},"\u002Fblog\u002Fiso27001-certification-guide","ISO 27001 certification guide"," covers the business case and sequencing decisions.",[32,4017,4019],{"id":4018},"iso-270012022-what-changed","ISO 27001:2022 — What changed",[37,4021,4022],{},"The 2022 revision is the current version of the standard. Two changes matter most for teams implementing ISO 27001 today.",[37,4024,4025,4026,4029],{},"First, the control set was restructured. The 2013 edition had 114 controls across 14 domains. ISO 27001:2022 consolidates these into ",[53,4027,4028],{},"93 controls across four themes",": organizational (37 controls), people (8 controls), physical (14 controls), and technological (34 controls). Eleven entirely new controls were introduced, including threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.",[37,4031,4032],{},"Second, the clause-level requirements in sections 4 through 10 received targeted updates around planning, leadership commitment, and operational control. The Plan-Do-Check-Act structure remains, but the language is tighter and more aligned with other ISO management system standards such as ISO 9001 and ISO 14001. Organizations holding ISO 27001:2013 certificates were given a three-year transition window that closed on October 31, 2025; those certificates have now expired, and all certifications are issued and assessed exclusively against ISO 27001:2022.",[32,4034,4036],{"id":4035},"annex-a-controls","Annex A controls",[37,4038,4039,4040,4044],{},"Annex A of ISO 27001 is the reference control set. The ",[249,4041,4043],{"href":4042},"\u002Fglossary\u002Fannex-a","93 Annex A controls"," are organized under the four themes described above and represent the universe of possible safeguards your ISMS might apply. Every control must be evaluated for applicability and either implemented or formally excluded with justification.",[37,4046,4047],{},"Organizational controls cover governance, policy, third-party management, incident response, and business continuity. People controls address screening, training, responsibilities, and remote working. Physical controls protect buildings, equipment, and storage media. Technological controls handle access control, cryptography, logging, vulnerability management, secure development, and cloud security.",[37,4049,4050,4051,4055],{},"For a full breakdown of every theme, example controls in each, and how to prioritize implementation, see the ",[249,4052,4054],{"href":4053},"\u002Fframeworks\u002Fiso27001\u002Fannex-a-controls","ISO 27001 Annex A controls reference",". ISO 27002:2022 provides detailed implementation guidance for each control and is invaluable as a companion reference, though it is not mandatory to follow prescriptively.",[32,4057,4059],{"id":4058},"statement-of-applicability-soa","Statement of Applicability (SoA)",[37,4061,367,4062,4066],{},[249,4063,4065],{"href":4064},"\u002Fglossary\u002Fstatement-of-applicability","Statement of Applicability"," is arguably the single most important document in your ISO 27001 program. The SoA lists every Annex A control, records whether it is applicable to your ISMS, explains why, and summarizes how the control is implemented. It is the document auditors will open first, and it is the document customers may ask to see.",[37,4068,4069],{},"A well-built SoA ties directly to your risk assessment output. Controls are marked applicable because they treat identified risks, satisfy legal or contractual requirements, or reflect business decisions. Controls marked not applicable require a short but credible justification. Auditors routinely sample SoA entries during Stage 2 and ask for corresponding evidence.",[37,4071,4072,4073,4077],{},"See the dedicated guide on the ",[249,4074,4076],{"href":4075},"\u002Fframeworks\u002Fiso27001\u002Fstatement-of-applicability","ISO 27001 Statement of Applicability"," for format examples, justification patterns, and common SoA mistakes.",[32,4079,4081],{"id":4080},"building-your-isms","Building your ISMS",[37,4083,4084],{},"Implementing ISO 27001 is primarily an exercise in building a functioning ISMS. The standard walks through this in clauses 4 through 10:",[47,4086,4087,4093,4099,4105,4111,4117,4123],{},[50,4088,4089,4092],{},[53,4090,4091],{},"Clause 4 — Context of the organization."," Understand internal and external issues, interested parties, and define the ISMS scope.",[50,4094,4095,4098],{},[53,4096,4097],{},"Clause 5 — Leadership."," Top management must demonstrate commitment, approve the information security policy, and assign roles.",[50,4100,4101,4104],{},[53,4102,4103],{},"Clause 6 — Planning."," Identify risks and opportunities, set information security objectives, and plan how to achieve them.",[50,4106,4107,4110],{},[53,4108,4109],{},"Clause 7 — Support."," Provide resources, competence, awareness, communication, and documented information.",[50,4112,4113,4116],{},[53,4114,4115],{},"Clause 8 — Operation."," Execute the risk assessment and risk treatment process and operate the ISMS on an ongoing basis.",[50,4118,4119,4122],{},[53,4120,4121],{},"Clause 9 — Performance evaluation."," Monitor, measure, analyze, evaluate, conduct internal audits, and hold management reviews.",[50,4124,4125,4128],{},[53,4126,4127],{},"Clause 10 — Improvement."," Handle nonconformities and drive continual improvement.",[37,4130,4131,4132,4136],{},"Each clause has mandatory documented information and mandatory activities. The ",[249,4133,4135],{"href":4134},"\u002Fframeworks\u002Fiso27001\u002Fisms-implementation","ISO 27001 ISMS implementation guide"," breaks down exactly what to produce at each stage.",[37,4138,4139,4140,4144],{},"Scope definition deserves special attention. A scope that is too narrow can fail to satisfy customers. A scope that is too broad inflates audit cost and implementation effort. The ",[249,4141,4143],{"href":4142},"\u002Fframeworks\u002Fiso27001\u002Fisms-scope","ISMS scope"," guide walks through how to draw the right boundaries for your business.",[32,4146,4148],{"id":4147},"iso-27001-risk-assessment","ISO 27001 risk assessment",[37,4150,4151],{},"Risk assessment is the engine that drives control selection in ISO 27001. The standard requires a documented, repeatable methodology. Most organizations use a qualitative or semi-quantitative approach that evaluates likelihood and impact across confidentiality, integrity, and availability. ISO 27005 provides detailed guidance but is not mandatory.",[37,4153,4154],{},"Outputs of the risk assessment feed directly into the risk treatment plan, which in turn feeds the Statement of Applicability. This chain is why ISO 27001 auditors spend significant time tracing from a risk to a treatment decision to a control to evidence of operation. Break this chain and you create nonconformities.",[37,4156,4157,4158,258],{},"For methodology, risk register structure, treatment options, and residual risk handling, see the ",[249,4159,4161],{"href":4160},"\u002Fframeworks\u002Fiso27001\u002Frisk-assessment","ISO 27001 risk assessment guide",[32,4163,4165],{"id":4164},"internal-audits-and-management-review","Internal audits and management review",[37,4167,4168],{},"Two activities inside Clause 9 are frequent failure points for first-time ISO 27001 certifiers. Clause 9.2 requires internal audits of the ISMS at planned intervals. Clause 9.3 requires a formal management review with defined inputs and outputs. Both must be complete before your Stage 2 audit.",[37,4170,4171],{},"Internal audits must cover every clause of ISO 27001 and every applicable Annex A control across your audit cycle. Auditors must be objective and impartial, which typically means the person who built a control cannot audit it. Findings must be documented, communicated, and tracked to closure.",[37,4173,4174,4175,1123,4179,258],{},"Management reviews force leadership engagement. Inputs include audit results, risk changes, nonconformities, and stakeholder feedback. Outputs include decisions on resources, improvement opportunities, and changes to the ISMS. Detailed coverage lives in the ",[249,4176,4178],{"href":4177},"\u002Fframeworks\u002Fiso27001\u002Finternal-audit","internal audit guide",[249,4180,4182],{"href":4181},"\u002Fframeworks\u002Fiso27001\u002Fmanagement-review","management review guide",[32,4184,4186],{"id":4185},"nonconformities-and-corrective-action","Nonconformities and corrective action",[37,4188,4189],{},"When something in your ISMS does not meet ISO 27001 requirements, your own policies, or customer obligations, that is a nonconformity. Clauses 10.1 and 10.2 require you to react, contain the consequences, perform root cause analysis, implement corrective action, and verify effectiveness.",[37,4191,4192,4193,4197],{},"Mature organizations treat nonconformities as valuable signals rather than failures. The ",[249,4194,4196],{"href":4195},"\u002Fframeworks\u002Fiso27001\u002Fnonconformity-and-corrective-action","nonconformity and corrective action"," guide walks through the full CAPA workflow auditors expect to see.",[32,4199,4201],{"id":4200},"continual-improvement","Continual improvement",[37,4203,4204],{},"Clause 10.3 requires continual improvement of the suitability, adequacy, and effectiveness of the ISMS. This is not about constantly changing controls. It is about demonstrating measurable progress over time through metrics, KPIs, trend analysis, and lessons learned.",[37,4206,4207,4208,258],{},"Learn how to set ISMS metrics that auditors respect and leadership actually uses in the ",[249,4209,4211],{"href":4210},"\u002Fframeworks\u002Fiso27001\u002Fcontinual-improvement","continual improvement guide",[32,4213,4215],{"id":4214},"cost-and-timeline","Cost and timeline",[37,4217,4218],{},"ISO 27001 certification costs vary by scope, organization size, and maturity. A realistic budget range for a first-time certification at a small to mid-sized technology company looks like this:",[47,4220,4221,4227,4233,4239],{},[50,4222,4223,4226],{},[53,4224,4225],{},"Internal effort."," Six to twelve months of fractional time from an ISMS owner plus contributions from engineering, HR, legal, and IT. Equivalent fully loaded cost of $50,000 to $200,000.",[50,4228,4229,4232],{},[53,4230,4231],{},"External consulting (optional)."," Gap analysis and implementation support from a consultancy typically runs $20,000 to $100,000 depending on scope.",[50,4234,4235,4238],{},[53,4236,4237],{},"Certification body fees."," Stage 1 and Stage 2 audits combined usually cost $15,000 to $40,000. Annual surveillance audits run $8,000 to $20,000. Recertification in year three runs similar to the initial audit.",[50,4240,4241,4244],{},[53,4242,4243],{},"Platform and tooling."," GRC platforms like episki typically replace $30,000 or more in spreadsheet-driven consulting labor annually.",[37,4246,4247,4248,4251],{},"Total first-year ISO 27001 program cost for a 50 to 200 person company commonly lands between $60,000 and $150,000 all-in. Timeline from kickoff to certificate in hand is typically nine to fifteen months. See the ",[249,4249,4250],{"href":4008},"cost and timeline discussion in the certification process guide"," for more detail.",[32,4253,4255],{"id":4254},"choosing-a-certification-body","Choosing a certification body",[37,4257,4258],{},"Only an accredited certification body can issue a recognized ISO 27001 certificate. Accreditation is granted by national bodies such as UKAS in the United Kingdom, ANAB in the United States, and JAS-ANZ in Australia and New Zealand, all operating under the International Accreditation Forum (IAF). A certificate from a non-accredited body has little value with enterprise customers.",[37,4260,4261,4262,4266],{},"Selection criteria include accreditation scope, industry experience, auditor availability, geographic coverage, and cost transparency. The ",[249,4263,4265],{"href":4264},"\u002Fframeworks\u002Fiso27001\u002Fcertification-body-selection","certification body selection guide"," walks through the full evaluation.",[32,4268,4270],{"id":4269},"surveillance-audits-and-recertification","Surveillance audits and recertification",[37,4272,4273],{},"Once certified, your ISO 27001 certificate is valid for three years. Certification bodies conduct a lighter annual surveillance audit in years one and two to confirm the ISMS is still operating effectively. A full recertification audit occurs in year three. Nonconformities identified during surveillance can put your certificate at risk if not resolved within the specified timeframe.",[37,4275,4276,4277,4281],{},"See the ",[249,4278,4280],{"href":4279},"\u002Fframeworks\u002Fiso27001\u002Fsurveillance-audits","surveillance audits guide"," for preparation checklists and what auditors typically sample during year-one and year-two visits.",[32,4283,4285],{"id":4284},"iso-27001-vs-soc-2-vs-nist-csf","ISO 27001 vs SOC 2 vs NIST CSF",[37,4287,4288],{},"Customers and leadership teams frequently ask how ISO 27001 compares to other frameworks. The short version:",[47,4290,4291,4299],{},[50,4292,4293,4298],{},[53,4294,4295,4296,258],{},"ISO 27001 vs ",[249,4297,475],{"href":474}," ISO 27001 is an international certification of an ISMS. SOC 2 is a US-centric attestation of controls aligned with the AICPA Trust Services Criteria. SOC 2 produces a detailed report; ISO 27001 produces a certificate. SOC 2 is faster to complete and often preferred by US buyers. ISO 27001 is stronger for European customers and regulated industries. Many organizations run both, mapping controls once in a tool like episki.",[50,4300,4301,4304,4305,4309],{},[53,4302,4303],{},"ISO 27001 vs NIST CSF."," NIST CSF is a voluntary US framework structured around five functions: Identify, Protect, Detect, Respond, and Recover. It is not a certification. Organizations often use NIST CSF as a maturity assessment tool and ISO 27001 as the formal certification. The two map cleanly at the control level. See ",[249,4306,4308],{"href":4307},"\u002Fframeworks\u002Fnistcsf\u002Fmapping-to-other-frameworks","NIST CSF mapping to other frameworks"," for a side-by-side comparison.",[37,4311,4312,4313,4315],{},"If you are weighing which framework to pursue first, the ",[249,4314,4014],{"href":4013}," covers framework sequencing for growing companies.",[32,4317,4319],{"id":4318},"getting-certified-with-episki","Getting certified with episki",[37,4321,4322],{},"episki ships the full 93-control Annex A library pre-mapped, generates the Statement of Applicability from live control state, and ties a risk register to ISO 27005 treatment options. What changed most recently is what a control check means: every connected system decodes its own response, evaluates its assertions, and writes pass, fail, or inconclusive against the control — and evidence that comes back empty or unreadable attests nothing rather than passing. ISMS scope is enforceable, with boundaries carrying rules on cloud account, region, resource, and tag. Applicable controls you have formally accepted become exceptions with a named approver and an expiry date, so an exclusion is a dated decision rather than a permanent footnote.",[37,4324,4325,4326,392,4330,4334],{},"Customers regularly compare episki against more established vendors; see ",[249,4327,4329],{"href":4328},"\u002Fcompare\u002Fvanta","episki vs Vanta",[249,4331,4333],{"href":4332},"\u002Fcompare\u002Fdrata","episki vs Drata"," for honest side-by-side views.",[37,4336,4337],{},"Teams using episki arrive at Stage 2 with an evidence pack an auditor can trace: every control carries an explicit verdict, and every artifact records the deterministic recipe that gathered it.",[37,4339,4340],{},"Start a free trial, import your controls, and run your first ISO 27001 gap analysis in under an hour.",{"title":93,"searchDepth":94,"depth":94,"links":4342},[4343,4344,4345,4346,4347,4348,4349,4350,4351,4352,4353,4354,4355,4356,4357,4358],{"id":3961,"depth":94,"text":3962},{"id":3985,"depth":94,"text":3986},{"id":3998,"depth":94,"text":3999},{"id":4018,"depth":94,"text":4019},{"id":4035,"depth":94,"text":4036},{"id":4058,"depth":94,"text":4059},{"id":4080,"depth":94,"text":4081},{"id":4147,"depth":94,"text":4148},{"id":4164,"depth":94,"text":4165},{"id":4185,"depth":94,"text":4186},{"id":4200,"depth":94,"text":4201},{"id":4214,"depth":94,"text":4215},{"id":4254,"depth":94,"text":4255},{"id":4269,"depth":94,"text":4270},{"id":4284,"depth":94,"text":4285},{"id":4318,"depth":94,"text":4319},{"title":4360,"description":4361,"items":4362},"ISO 27001 certification checklist inside episki","Everything you need to scope, implement, and certify your ISMS is preloaded in your free trial.",[4363,4364,4365,4366,4367,4368,4369],"ISMS scope definition and context of the organization templates","Full Annex A control library with implementation guidance","Risk assessment and treatment plan workflows","Statement of Applicability generator","Internal audit programme with finding management","Management review agenda and output templates","Corrective action tracking with root cause analysis",{"title":4371,"description":4372},"Start your ISO 27001 journey today","Import your controls, define your ISMS scope, and generate your first Statement of Applicability in under an hour.",{"title":4374,"items":4375},"ISO 27001 frequently asked questions",[4376,4379,4382,4385,4388],{"label":4377,"content":4378},"How long does ISO 27001 certification take?","Most organizations achieve certification in 6-12 months depending on scope and existing maturity. The process includes a Stage 1 documentation review and a Stage 2 implementation audit. episki reduces preparation time by up to 60% with pre-mapped controls and automated evidence.",{"label":4380,"content":4381},"What is the difference between ISO 27001 and SOC 2?","ISO 27001 is an international certification standard focused on building a complete information security management system (ISMS). SOC 2 is a US-based attestation that evaluates specific Trust Services Criteria. Many companies pursue both, and episki lets you map controls once and reuse them across frameworks.",{"label":4383,"content":4384},"What is an ISMS?","An Information Security Management System (ISMS) is the set of policies, procedures, controls, and processes an organization uses to manage information security risk. ISO 27001 provides the framework for establishing, implementing, maintaining, and continually improving an ISMS.",{"label":4386,"content":4387},"How much does ISO 27001 certification cost?","Certification costs vary by organization size and scope but typically range from $30,000 to $80,000 including auditor fees, with ongoing surveillance audit costs annually. episki's flat-rate pricing keeps the platform cost predictable at $750\u002Fmonth.",{"label":4389,"content":4390},"How often are ISO 27001 surveillance audits?","After initial certification, surveillance audits occur annually to confirm your ISMS remains effective. A full recertification audit is required every three years. episki's continuous monitoring keeps evidence current between audits.",{"headline":4392,"title":4393,"description":4394,"links":4395},"ISO 27001 certification on your timeline","Build and maintain your ISMS without drowning in spreadsheets","episki maps Annex A controls, tracks your Statement of Applicability, and keeps risk treatment plans linked to real evidence so certification audits run smoothly.",[4396,4398],{"label":4397,"icon":182,"to":185},"Start ISO 27001 trial",{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},{"headline":4401,"title":4401,"description":4402,"items":4403},"ISO 27001 certification resources","Give leadership, auditors, and customers visibility into your ISMS maturity.",[4404,4407,4410],{"title":4405,"description":4406},"ISMS maturity dashboard","Visual progress across all Annex A domains with gap analysis and trending.",{"title":4408,"description":4409},"Auditor collaboration portal","Scoped access for certification bodies with evidence requests and Q&A threads.",{"title":4411,"description":4412},"Customer trust pack","Shareable ISO 27001 certification summary with scope details and control highlights.",{"title":4414,"description":4415},"ISO 27001 Compliance Platform","Build and certify your ISMS faster with episki. Annex A control mapping, SoA generation, and risk treatment plans in one workspace. Free 14-day trial.","iso27001",[4418,4420,4423],{"value":4043,"description":4419},"Pre-mapped to your control graph with owners, evidence, and review cadences.",{"value":4421,"description":4422},"60% less prep","Average reduction in Stage 2 audit preparation time with episki's automation.",{"value":4424,"description":4425},"Continuous compliance","Surveillance audits stay painless with always-current evidence and risk registers.","5.frameworks\u002Fiso27001","YAm3GouewtGya0YKY29shtlygl-AYSgj0aepu87SFQM",{"id":4429,"title":4430,"advantages":4431,"body":4453,"checklist":4523,"cta":4533,"description":93,"extension":151,"faq":4536,"hero":4550,"lastUpdated":186,"meta":4557,"name":4558,"navigation":188,"path":4559,"resources":4560,"seo":4573,"slug":4576,"stats":4577,"stem":4587,"__hash__":4588},"frameworks\u002F5.frameworks\u002Fiso27017.md","Iso27017",[4432,4439,4446],{"title":4433,"description":4434,"bullets":4435},"Cloud controls on your ISMS","ISO 27017 builds on ISO 27002 with cloud-specific implementation guidance.",[4436,4437,4438],"Cloud-specific guidance for relevant 27002 controls","Seven additional cloud-only controls","Assessed alongside ISO 27001",{"title":4440,"description":4441,"bullets":4442},"Shared responsibility, documented","Make the provider\u002Fcustomer split explicit for every cloud control.",[4443,4444,4445],"Provider vs. customer responsibility per control","Virtualization and segregation controls","Administrative operations and monitoring",{"title":4447,"description":4448,"bullets":4449},"Reuse your security evidence","27017 leans on the controls you already maintain for 27001 and SOC 2.",[4450,4451,4452],"Evidence shared with ISO 27001 \u002F 27018","Crosswalk to SOC 2 and CSA CCM","One audit, broader scope",{"type":29,"value":4454,"toc":4517},[4455,4459,4484,4488,4491,4495,4507,4509],[32,4456,4458],{"id":4457},"what-is-iso-27017","What is ISO 27017?",[37,4460,4461,4464,4465,4468,4469,4472,4473,4476,4477,392,4480,4483],{},[53,4462,4463],{},"ISO\u002FIEC 27017:2015"," is the international ",[53,4466,4467],{},"code of practice for cloud security",". It does not stand on its own — it supplements ",[53,4470,4471],{},"ISO\u002FIEC 27002"," by adding cloud-specific implementation guidance to existing controls and introducing ",[53,4474,4475],{},"seven additional controls"," that apply only to cloud computing. It is written for both ",[53,4478,4479],{},"cloud service providers",[53,4481,4482],{},"cloud service customers",", making the shared-responsibility model explicit.",[32,4485,4487],{"id":4486},"what-it-adds","What it adds",[37,4489,4490],{},"For many ISO 27002 controls, 27017 provides cloud-specific guidance — how the control applies when infrastructure, platform, or software is consumed as a service. On top of that, it adds cloud-only controls covering areas such as the shared roles and responsibilities between provider and customer, removal and return of customer assets at contract termination, segregation in virtualized environments, virtual machine hardening, and the monitoring of cloud administrative operations.",[32,4492,4494],{"id":4493},"how-its-assessed","How it's assessed",[37,4496,4497,4498,4501,4502,4506],{},"Because 27017 is an extension rather than a standalone standard, it is ",[53,4499,4500],{},"assessed as part of an ISO\u002FIEC 27001 audit",". Organizations add 27017 — and frequently ",[249,4503,4505],{"href":4504},"\u002Fframeworks\u002Fiso27018","ISO 27018"," for PII — to the scope of their existing ISMS, so a single certification effort covers information security and cloud-specific controls together.",[32,4508,244],{"id":243},[37,4510,4511,4512,254,4515,258],{},"episki evaluates cloud-specific controls directly from the estate they govern: AWS across multiple accounts, regions, and Organizations, plus Supabase, Vercel, and Netlify. Each check writes an explicit pass, fail, or inconclusive verdict, every record is stamped with the account and region it came from, and shared-responsibility boundaries are expressed as scope rules rather than prose. ",[249,4513,253],{"href":185,"rel":4514},[252],[249,4516,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":4518},[4519,4520,4521,4522],{"id":4457,"depth":94,"text":4458},{"id":4486,"depth":94,"text":4487},{"id":4493,"depth":94,"text":4494},{"id":243,"depth":94,"text":244},{"title":4524,"description":4525,"items":4526},"ISO 27017 readiness inside episki","What a cloud provider or customer needs in place.",[4527,4528,4529,4530,4531,4532],"ISO 27001 ISMS in place or in progress","Shared-responsibility matrix per cloud service","Cloud-specific control guidance applied","Virtualization segregation and hardening controls","Administrator operations logging and monitoring","Customer data return and removal on contract exit",{"title":4534,"description":4535},"Add ISO 27017 to your ISMS in episki","Extend your ISO 27001 program with cloud controls and reuse the evidence across SOC 2 and CSA CCM.",{"title":4537,"items":4538},"ISO 27017 frequently asked questions",[4539,4541,4544,4547],{"label":4458,"content":4540},"ISO\u002FIEC 27017:2015 is an international code of practice for information security controls for cloud services. It supplements ISO\u002FIEC 27002 with cloud-specific implementation guidance and adds seven controls unique to cloud computing, addressing both cloud service providers and cloud service customers.",{"label":4542,"content":4543},"Is ISO 27017 separately certifiable?","ISO 27017 is not a standalone management-system standard — it is assessed as an extension of an ISO\u002FIEC 27001 ISMS. Organizations typically add 27017 (and often 27018) to the scope of their ISO 27001 audit.",{"label":4545,"content":4546},"Who should adopt it?","Cloud service providers that want to demonstrate strong cloud security practices, and cloud customers that want a recognized framework for governing their use of cloud services. It is common alongside SOC 2 and the CSA STAR program.",{"label":4548,"content":4549},"How does it relate to ISO 27018?","ISO 27017 focuses on cloud security broadly, while ISO 27018 focuses specifically on protecting personally identifiable information (PII) in public clouds. Many organizations adopt both as extensions of the same ISO 27001 ISMS.",{"headline":4551,"title":4552,"description":4553,"links":4554},"Cloud security, ISO-aligned","Extend your ISMS with ISO 27017 cloud controls","ISO\u002FIEC 27017:2015 adds cloud-specific guidance on top of ISO 27002 — shared responsibility, virtualization, and admin operations — assessed alongside your ISO 27001 certificate.",[4555,4556],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"ISO 27017","\u002Fframeworks\u002Fiso27017",{"headline":4561,"title":4562,"description":4563,"items":4564},"ISO 27017 accelerators","Cloud control accelerators","Layer cloud controls onto your ISMS without a parallel project.",[4565,4568,4571],{"title":4566,"description":4567},"Shared-responsibility matrix","Document provider and customer duties for every cloud control.",{"title":4569,"description":4570},"Cloud control guidance","Cloud-specific implementation notes mapped to your ISO 27002 controls.",{"title":1414,"description":4572},"Reuse your ISMS evidence to satisfy the 27017 extension.",{"title":4574,"description":4575},"ISO 27017 Cloud Security Compliance Software","Add the ISO\u002FIEC 27017:2015 cloud security code of practice to your ISO 27001 ISMS — cloud-specific controls and provider\u002Fcustomer responsibilities in one workspace.","iso27017",[4578,4581,4584],{"value":4579,"description":4580},"37 + 7","ISO 27002 controls with cloud guidance, plus 7 cloud-specific controls.",{"value":4582,"description":4583},"Shared model","Provider and customer responsibilities documented per control.",{"value":4585,"description":4586},"27001 add-on","Assessed as an extension of your ISO 27001 ISMS, not a separate program.","5.frameworks\u002Fiso27017","Ly7vb0hx6iMCCD33CLaUGRduLEeak8lTGAFZymAX-o0",{"id":4590,"title":4591,"advantages":4592,"body":4614,"checklist":4669,"cta":4678,"description":93,"extension":151,"faq":4681,"hero":4694,"lastUpdated":186,"meta":4701,"name":4505,"navigation":188,"path":4504,"resources":4702,"seo":4716,"slug":4719,"stats":4720,"stem":4729,"__hash__":4730},"frameworks\u002F5.frameworks\u002Fiso27018.md","Iso27018",[4593,4600,4607],{"title":4594,"description":4595,"bullets":4596},"Cloud PII controls","ISO 27018 supplements ISO 27002 with controls for protecting PII in public clouds.",[4597,4598,4599],"Consent, choice, and purpose limitation","Transparency on subprocessors and data location","Return, transfer, and disposal of PII",{"title":4601,"description":4602,"bullets":4603},"Built for processors","Designed for public-cloud providers handling customer PII on their behalf.",[4604,4605,4606],"Customer-controller \u002F provider-processor split","No use of PII for advertising without consent","Breach notification support to the customer",{"title":4608,"description":4609,"bullets":4610},"Reuse privacy evidence","27018 dovetails with ISO 27701 and GDPR work you already do.",[4611,4612,4613],"Crosswalk to ISO 27701 (PIMS)","Crosswalk to GDPR articles","One audit alongside ISO 27001 \u002F 27017",{"type":29,"value":4615,"toc":4663},[4616,4620,4633,4635,4638,4640,4653,4655],[32,4617,4619],{"id":4618},"what-is-iso-27018","What is ISO 27018?",[37,4621,4622,4464,4625,4628,4629,4632],{},[53,4623,4624],{},"ISO\u002FIEC 27018:2019",[53,4626,4627],{},"code of practice for protecting personally identifiable information (PII) in public clouds",". It supplements ISO\u002FIEC 27002 with privacy-specific controls and guidance aimed at organizations that act as ",[53,4630,4631],{},"PII processors"," in a public-cloud setting. First published in 2014 and revised in 2019, it was the first international standard dedicated to cloud privacy.",[32,4634,4487],{"id":4486},[37,4636,4637],{},"ISO 27018 augments the ISMS with controls that address how a cloud provider handles its customers' PII: obtaining consent and respecting purpose limitation, being transparent about subprocessors and the geographic location of data, restricting the use of PII for marketing or advertising without consent, supporting the customer in meeting data-subject requests, and ensuring PII is returned, transferred, or securely disposed of at the end of the relationship.",[32,4639,4494],{"id":4493},[37,4641,4642,4643,4645,4646,4649,4650,4652],{},"Like ",[249,4644,4558],{"href":4559},", ISO 27018 is ",[53,4647,4648],{},"not a standalone certification"," — it is assessed as an extension to an ",[249,4651,470],{"href":469}," ISMS. Many cloud providers add both 27017 (cloud security) and 27018 (cloud privacy) to the same audit scope.",[32,4654,244],{"id":243},[37,4656,4657,4658,254,4661,258],{},"episki maps ISO 27018 alongside ISO 27001 and 27701, sharing controls and evidence between them. Cloud PII handling controls are evaluated continuously from the platforms that hold the data, and subprocessors are consolidated onto vendor records with review cadences that advance when you accept evidence. ",[249,4659,253],{"href":185,"rel":4660},[252],[249,4662,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":4664},[4665,4666,4667,4668],{"id":4618,"depth":94,"text":4619},{"id":4486,"depth":94,"text":4487},{"id":4493,"depth":94,"text":4494},{"id":243,"depth":94,"text":244},{"title":4670,"description":4671,"items":4672},"ISO 27018 readiness inside episki","What a public-cloud PII processor needs in place.",[4527,4673,4674,4675,4676,4677],"PII processing inventory for cloud services","Consent, choice, and purpose-limitation controls","Subprocessor disclosure and data-location transparency","PII return, transfer, and secure disposal procedures","Breach notification support to the customer-controller",{"title":4679,"description":4680},"Add ISO 27018 to your ISMS in episki","Extend your ISO 27001 program with cloud privacy controls and reuse the evidence across GDPR and ISO 27701.",{"title":4682,"items":4683},"ISO 27018 frequently asked questions",[4684,4686,4689,4692],{"label":4619,"content":4685},"ISO\u002FIEC 27018:2019 is an international code of practice for protecting personally identifiable information (PII) in public clouds that act as PII processors. It supplements ISO\u002FIEC 27002 and ISO\u002FIEC 27001 with privacy-specific controls and guidance, and was the first international standard focused on cloud privacy.",{"label":4687,"content":4688},"Is it separately certifiable?","Like ISO 27017, ISO 27018 is assessed as an extension of an ISO\u002FIEC 27001 ISMS rather than as a standalone certification. Organizations typically add it (often together with 27017) to their ISO 27001 audit scope.",{"label":4690,"content":4691},"How does it relate to GDPR?","ISO 27018 is not a substitute for GDPR, but its controls map closely to GDPR obligations for processors and provide recognized evidence of good-faith PII protection in the cloud. It pairs naturally with the certifiable ISO 27701 privacy management standard.",{"label":4545,"content":4693},"Public-cloud providers and SaaS companies that process personal data on behalf of their customers, and who want a recognized way to demonstrate responsible cloud PII handling to privacy-conscious buyers.",{"headline":4695,"title":4696,"description":4697,"links":4698},"PII protection for public clouds","Add ISO 27018 privacy controls to your ISMS","ISO\u002FIEC 27018:2019 is the code of practice for protecting personally identifiable information in public clouds acting as a PII processor — assessed alongside ISO 27001 and mapped to GDPR.",[4699,4700],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},{"headline":4703,"title":4704,"description":4705,"items":4706},"ISO 27018 accelerators","Cloud privacy accelerators","Demonstrate responsible PII handling without a separate privacy project.",[4707,4710,4713],{"title":4708,"description":4709},"Cloud PII inventory","Track the PII you process per cloud service and its location.",{"title":4711,"description":4712},"Subprocessor register","Disclose and manage subprocessors handling customer PII.",{"title":4714,"description":4715},"ISO 27701 \u002F GDPR crosswalk","Reuse your PIMS and GDPR evidence to satisfy 27018.",{"title":4717,"description":4718},"ISO 27018 Cloud Privacy Compliance Software","Protect PII in public clouds with the ISO\u002FIEC 27018:2019 code of practice — added to your ISO 27001 ISMS and cross-mapped to GDPR and ISO 27701.","iso27018",[4721,4724,4726],{"value":4722,"description":4723},"PII processor","Privacy controls for public-cloud providers acting as PII processors.",{"value":4585,"description":4725},"Assessed as an extension of your ISO 27001 ISMS.",{"value":4727,"description":4728},"GDPR mapped","Controls cross-walked to GDPR and ISO 27701 for evidence reuse.","5.frameworks\u002Fiso27018","CHIwLTRrtJx66hCY_-93WUH6dKZSDvT3BdLGQGBhnhU",{"id":4732,"title":4733,"advantages":4734,"body":4756,"checklist":4798,"cta":4808,"description":93,"extension":151,"faq":4811,"hero":4825,"lastUpdated":186,"meta":4832,"name":4833,"navigation":188,"path":4834,"resources":4835,"seo":4849,"slug":4852,"stats":4853,"stem":4861,"__hash__":4862},"frameworks\u002F5.frameworks\u002Fiso27701.md","Iso27701",[4735,4742,4749],{"title":4736,"description":4737,"bullets":4738},"Standalone — or paired with ISO 27001","ISO 27701:2025 can be certified on its own, and it still reuses your existing ISMS controls when you have them.",[4739,4740,4741],"Certify a PIMS with or without ISO 27001","27001 controls flagged with privacy applicability","Single combined audit when run alongside 27001",{"title":4743,"description":4744,"bullets":4745},"Controller and processor controls","Privacy controls scoped based on how you process PII for each activity.",[4746,4747,4748],"Controller-specific privacy controls","Processor-specific privacy controls","Shared controls for organizations with both roles",{"title":4750,"description":4751,"bullets":4752},"Mapped to GDPR, CCPA, and beyond","Cross-walks built in so your 27701 work feeds your other privacy program reporting.",[4753,4754,4755],"GDPR Article-level mapping","CCPA \u002F CPRA mapping","LGPD, PIPEDA, and emerging laws",{"type":29,"value":4757,"toc":4793},[4758,4762,4769,4776,4780,4783,4785],[32,4759,4761],{"id":4760},"what-is-iso-27701","What is ISO 27701?",[37,4763,4764,4765,4768],{},"ISO\u002FIEC 27701 is the international standard for a Privacy Information Management System (PIMS) — it adds privacy-specific requirements and controls to an information security management baseline. First published in 2019 as the first standard organizations could certify against for privacy management, it was substantially revised as ",[53,4766,4767],{},"ISO\u002FIEC 27701:2025"," (published October 2025), which is the current edition. Organizations certified to the 2019 version have until October 2028 to transition.",[37,4770,4771,4772,4775],{},"The standard provides privacy control sets for PII controllers and PII processors (split across Annex A and Annex B in the 2019 edition, and consolidated into a single set in the 2025 edition) and aligns its management clauses (4–10) with the ISO harmonized structure shared by ISO 27001 and ISO 42001. The biggest change in 2025: ISO 27701 is now ",[53,4773,4774],{},"standalone"," — you can certify a PIMS without holding ISO 27001, though the two still pair naturally because 27701 builds on the ISO 27002 security controls.",[32,4777,4779],{"id":4778},"who-pursues-iso-27701","Who pursues ISO 27701",[37,4781,4782],{},"Organizations that want a recognized, certifiable demonstration of privacy management — especially those processing personal data of EU\u002FEEA residents, but increasingly relevant for CCPA, LGPD, and similar regimes. SaaS companies acting as data processors for their customers frequently pursue 27701 alongside SOC 2 and 27001 as a comprehensive trust posture.",[32,4784,244],{"id":243},[37,4786,4787,4788,254,4791,258],{},"episki maps ISO 27701 onto the ISO 27001 ISMS you already run, sharing controls and evidence rather than duplicating them, with crosswalks derived through the SCF hub. Processing activities, lawful bases, and data subject requests are structured records, and processors and their subprocessors live on vendor records with review cadences that advance on accepted evidence. ",[249,4789,253],{"href":185,"rel":4790},[252],[249,4792,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":4794},[4795,4796,4797],{"id":4760,"depth":94,"text":4761},{"id":4778,"depth":94,"text":4779},{"id":243,"depth":94,"text":244},{"title":4799,"description":4800,"items":4801},"ISO 27701 readiness inside episki","Build the PIMS without rebuilding the ISMS.",[4802,4803,4804,4805,4806,4807],"PIMS scope definition (PII processing activities)","Controller \u002F processor role determination per activity","Annex A and Annex B applicable-controls list","Records of Processing (ROPA) integrated with controls","Data-subject rights (DSAR) workflow","Privacy training and awareness program",{"title":4809,"description":4810},"Build a certifiable PIMS in episki","Stand up ISO 27701 — alongside ISO 27001 or on its own — in the same workspace.",{"title":4812,"items":4813},"ISO 27701 frequently asked questions",[4814,4816,4819,4822],{"label":4761,"content":4815},"ISO\u002FIEC 27701 is the international standard for a Privacy Information Management System (PIMS) — it adds controller and processor privacy controls on top of an information security baseline. The 2025 revision (published October 2025, replacing the 2019 edition) made it a standalone standard you can certify against with or without ISO 27001.",{"label":4817,"content":4818},"How does 27701 relate to GDPR?","27701 was designed to provide an international standard organizations can demonstrate when claiming GDPR readiness. Many of its clauses map directly to GDPR Articles, and supervisory authorities increasingly recognize 27701 as evidence of good-faith compliance effort — though it doesn't substitute for GDPR.",{"label":4820,"content":4821},"Controller vs. processor controls?","A PIMS addresses two roles — controls for organizations acting as PII controllers and controls for those acting as PII processors. The 2019 edition split these into Annex A and Annex B; ISO 27701:2025 consolidated them into a single control set covering both roles. Organizations acting as both apply the relevant controls per processing activity.",{"label":4823,"content":4824},"Can we certify to 27701 without 27001?","Yes — as of ISO\u002FIEC 27701:2025 the standard is standalone, so you can certify a PIMS without holding ISO 27001. Many organizations still pursue the two together and run a combined audit, because 27701 reuses the ISO 27001\u002F27002 security baseline.",{"headline":4826,"title":4827,"description":4828,"links":4829},"Privacy management, certifiable","Build a Privacy Information Management System","ISO\u002FIEC 27701:2025 is now a standalone Privacy Information Management System standard — certify with or without ISO 27001. PII controller and processor controls, GDPR Article mapping, and one workspace for security + privacy.",[4830,4831],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"ISO 27701","\u002Fframeworks\u002Fiso27701",{"headline":4836,"title":4837,"description":4838,"items":4839},"ISO 27701 accelerators","PIMS program accelerators","Add a privacy layer to your ISMS without reinventing the wheel.",[4840,4843,4846],{"title":4841,"description":4842},"Role mapper","Determine controller, processor, or joint controller per processing activity.",{"title":4844,"description":4845},"Annex A \u002F B selector","Pick the right control set based on your role determinations.",{"title":4847,"description":4848},"GDPR Article crosswalk","See which ISO 27701 clauses satisfy which GDPR Articles.",{"title":4850,"description":4851},"ISO 27701 Privacy Information Management Software","Stand up a certifiable Privacy Information Management System (PIMS) under ISO\u002FIEC 27701:2025 — now a standalone standard. Mapped to GDPR, CCPA, and other privacy laws.","iso27701",[4854,4857,4859],{"value":4855,"description":4856},"PII controller","Privacy controls for organizations acting as PII controllers.",{"value":4722,"description":4858},"Privacy controls for organizations acting as PII processors.",{"value":4727,"description":4860},"Each ISO 27701 clause cross-walked to relevant GDPR Articles for evidence reuse.","5.frameworks\u002Fiso27701","728AscZSGnE3WME2KcjOBYUv2hJHSqAyTjXIzlF6ChQ",{"id":4864,"title":4865,"advantages":4866,"body":4887,"checklist":4921,"cta":4931,"description":93,"extension":151,"faq":4934,"hero":4948,"lastUpdated":186,"meta":4955,"name":4956,"navigation":188,"path":4957,"resources":4958,"seo":4972,"slug":4975,"stats":4976,"stem":4986,"__hash__":4987},"frameworks\u002F5.frameworks\u002Fiso42001.md","Iso42001",[4867,4874,4881],{"title":4868,"description":4869,"bullets":4870},"Agent registry and use-case inventory","Track every AI use case in your organization with risk classification, ownership, and lifecycle stage.",[4871,4872,4873],"Inventory across vendors, internal builds, and shadow AI","Risk tier per use case using ISO 42001 criteria","Lifecycle stage from concept to retirement",{"title":4875,"description":4876,"bullets":4877},"AI-specific risk treatments","Run AI risks (bias, hallucination, security, drift) through the same treatment workflows as your existing risk register.",[4878,4879,4880],"AI-specific risk taxonomy","Acceptance, mitigation, transfer, avoid paths","Tied to controls and ongoing monitoring",{"title":4036,"description":4882,"bullets":4883},"The 38 operational controls in ISO 42001 Annex A, ready to scope, implement, and evidence.",[4884,4885,4886],"Policies, leadership, resources, lifecycle controls","Data quality, fairness, interpretability","Third-party AI provider obligations",{"type":29,"value":4888,"toc":4916},[4889,4893,4896,4899,4903,4906,4908],[32,4890,4892],{"id":4891},"what-is-iso-42001","What is ISO 42001?",[37,4894,4895],{},"ISO\u002FIEC 42001:2023, published in December 2023, is the world's first international management-system standard for artificial intelligence. It defines requirements for establishing, implementing, maintaining, and continually improving an AI Management System (AIMS) — modeled on the pattern used by ISO 27001 for information security and ISO 9001 for quality.",[37,4897,4898],{},"The standard contains a set of management-system clauses (4–10) covering context, leadership, planning, support, operation, performance evaluation, and improvement, plus a normative Annex A with 38 controls covering the AI lifecycle from policies through third-party providers.",[32,4900,4902],{"id":4901},"who-needs-iso-42001","Who needs ISO 42001",[37,4904,4905],{},"Any organization developing, providing, or using AI systems at material scale. The standard is rapidly becoming the de facto demonstration of mature AI governance for enterprise buyers, regulated industries (financial services, healthcare, public sector), and as a readiness signal for the EU AI Act, which references ISO 42001 as evidence of due diligence.",[32,4907,244],{"id":243},[37,4909,4910,4911,254,4914,258],{},"episki ships ISO 42001 alongside a dedicated AI Governance module: an agent and AI use-case registry with allowlists and safety floors, AI-specific risk treatments wired to controls and evidence, and confidence-scored registry upkeep. episki governs its own agents through the same module — every model call is attributed to a surface and an operation, so the AIMS covers the platform you are running it on. Crosswalks to ISO 27001 and the NIST AI RMF are derived through the SCF hub. ",[249,4912,253],{"href":185,"rel":4913},[252],[249,4915,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":4917},[4918,4919,4920],{"id":4891,"depth":94,"text":4892},{"id":4901,"depth":94,"text":4902},{"id":243,"depth":94,"text":244},{"title":4922,"description":4923,"items":4924},"ISO 42001 readiness inside episki","Stand up an AIMS in days, not quarters.",[4925,4926,4927,4928,4929,4930],"AI use-case inventory and risk tiering","Annex A control selection per use case","AI ethics and acceptable use policy","AI risk register with treatment plans","Third-party AI provider (sub-processor) assessment","Ongoing AI performance and incident monitoring",{"title":4932,"description":4933},"Build a certifiable AIMS in episki","Inventory your AI, treat the risks, map to NIST and the EU AI Act — one workspace.",{"title":4935,"items":4936},"ISO 42001 frequently asked questions",[4937,4939,4942,4945],{"label":4892,"content":4938},"ISO\u002FIEC 42001:2023 is the first international standard for an AI Management System (AIMS). It defines requirements for establishing, implementing, maintaining, and continually improving an AIMS within the context of an organization that develops, provides, or uses AI systems. Modeled on ISO 27001's ISMS pattern.",{"label":4940,"content":4941},"Who needs ISO 42001?","Any organization developing, providing, or using AI at material scale benefits. It's increasingly being requested by enterprise buyers, regulated industries, and as readiness signal for the EU AI Act. SaaS companies that ship AI features (drafting, retrieval, agentic workflows) are prime candidates.",{"label":4943,"content":4944},"How does 42001 relate to the EU AI Act?","ISO 42001 is the leading control framework cited by EU AI Act guidance as evidence of due diligence for high-risk AI systems. Certification doesn't satisfy the AI Act on its own, but it materially reduces compliance burden by reusing artifacts and aligning to expected obligations.",{"label":4946,"content":4947},"How does 42001 relate to NIST AI RMF?","NIST AI RMF is a voluntary US framework with four functions (Govern, Map, Measure, Manage). ISO 42001 is the international management-system standard. They're complementary — 42001 provides certifiable management, AI RMF provides operational guidance. episki crosswalks the two.",{"headline":4949,"title":4950,"description":4951,"links":4952},"AI governance, certifiable","The world's first certifiable AI Management System","ISO 42001 is the new international standard for governing AI inside an organization. episki operationalizes it — agent registry, AI use-case inventory, risk treatments, and crosswalks to NIST AI RMF and the EU AI Act.",[4953,4954],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"ISO 42001","\u002Fframeworks\u002Fiso42001",{"headline":4959,"title":4960,"description":4961,"items":4962},"ISO 42001 accelerators","AI governance accelerators","Translate ISO 42001 from a 50-page PDF into a running program.",[4963,4966,4969],{"title":4964,"description":4965},"AI use-case scoping wizard","Determine which 42001 controls apply per use case based on risk classification.",{"title":4967,"description":4968},"NIST AI RMF crosswalk","Map 42001 controls to NIST AI RMF functions for reusable evidence.",{"title":4970,"description":4971},"EU AI Act readiness checklist","Prepare for high-risk and general-purpose AI obligations under the EU AI Act.",{"title":4973,"description":4974},"ISO 42001 AI Management System Software","Build a certifiable AI Management System (AIMS) per ISO\u002FIEC 42001. Agent registry, AI risk treatments, and controls mapped to NIST AI RMF and the EU AI Act.","iso42001",[4977,4980,4983],{"value":4978,"description":4979},"AIMS","A certifiable AI Management System modeled on the ISMS pattern from ISO 27001.",{"value":4981,"description":4982},"38 controls","Annex A operational controls covering the AI lifecycle.",{"value":4984,"description":4985},"NIST AI RMF","Cross-walked to NIST AI RMF and the EU AI Act for reusable evidence.","5.frameworks\u002Fiso42001","SXWTB-2JI5XMxbrMkB1c-LpaUjBHmDXDo9cqvBMx5AQ",{"id":4989,"title":4990,"advantages":4991,"body":5012,"checklist":5095,"cta":5104,"description":93,"extension":151,"faq":5107,"hero":5119,"lastUpdated":186,"meta":5126,"name":5127,"navigation":188,"path":5128,"resources":5129,"seo":5142,"slug":5145,"stats":5146,"stem":5154,"__hash__":5155},"frameworks\u002F5.frameworks\u002Flgpd.md","Lgpd",[4992,4999,5006],{"title":4993,"description":4994,"bullets":4995},"Lawful processing","Determine and document a legal basis for each activity.",[4996,4997,4998],"Ten LGPD legal bases supported","Records of processing maintained","Purpose and necessity documented",{"title":5000,"description":5001,"bullets":5002},"Rights and roles","Data-subject rights and the DPO role LGPD expects.",[5003,5004,5005],"Data-subject request workflow","Data Protection Officer (encarregado) duties","Controller \u002F operator role mapping",{"title":5007,"description":5008,"bullets":5009},"One privacy program","LGPD overlaps almost entirely with GDPR.",[4612,5010,5011],"Reuse ROPA and DPIA work","Aligns with CCPA and PIPEDA",{"type":29,"value":5013,"toc":5089},[5014,5018,5047,5051,5061,5065,5079,5081],[32,5015,5017],{"id":5016},"what-is-the-lgpd","What is the LGPD?",[37,5019,367,5020,5023,5024,5027,5028,5031,5032,5035,5036,5039,5040,5043,5044,258],{},[53,5021,5022],{},"Lei Geral de Proteção de Dados (LGPD)"," is ",[53,5025,5026],{},"Brazil's general data protection law",", in force since ",[53,5029,5030],{},"September 18, 2020",". It closely mirrors the EU's GDPR: it sets out ",[53,5033,5034],{},"lawful bases"," for processing personal data, grants individuals a set of ",[53,5037,5038],{},"data-subject rights",", distinguishes ",[53,5041,5042],{},"controllers and operators",", and is enforced by Brazil's national data protection authority, the ",[53,5045,5046],{},"ANPD",[32,5048,5050],{"id":5049},"who-it-applies-to-and-the-penalties","Who it applies to and the penalties",[37,5052,5053,5054,5056,5057,5060],{},"The LGPD reaches any organization that processes the personal data of people in Brazil or carries out processing in Brazil — including many companies based elsewhere that serve Brazilian customers. The ",[53,5055,5046],{}," can impose fines of up to ",[53,5058,5059],{},"2% of a company's revenue in Brazil, capped at R$50 million per violation",", alongside warnings, processing restrictions, and public disclosure.",[32,5062,5064],{"id":5063},"how-it-relates-to-gdpr","How it relates to GDPR",[37,5066,5067,5068,5070,5071,5074,5075,5078],{},"Because the LGPD is so closely aligned with the ",[249,5069,2831],{"href":2832},", most of a GDPR program transfers directly — records of processing, DPIAs, rights workflows, and the data protection officer role all carry over. In a significant ",[53,5072,5073],{},"2026"," development, ",[53,5076,5077],{},"Brazil and the EU adopted mutual adequacy decisions",", easing personal-data transfers between the two jurisdictions.",[32,5080,244],{"id":243},[37,5082,5083,5084,254,5087,258],{},"episki carries LGPD obligations as structured records — processing activities, legal bases, data subject requests, and international transfers — tied to controls that are evaluated rather than asserted, with processors and subprocessors consolidated onto vendor records carrying review cadences. ",[249,5085,253],{"href":185,"rel":5086},[252],[249,5088,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":5090},[5091,5092,5093,5094],{"id":5016,"depth":94,"text":5017},{"id":5049,"depth":94,"text":5050},{"id":5063,"depth":94,"text":5064},{"id":243,"depth":94,"text":244},{"title":5096,"description":5097,"items":5098},"LGPD readiness inside episki","What an organization processing Brazilian personal data needs.",[5099,5100,5003,5101,5102,5103],"Legal-basis determination per processing activity","Records of processing (ROPA)","Data Protection Officer (encarregado) designated","International-transfer safeguards","ANPD breach notification workflow",{"title":5105,"description":5106},"Build an LGPD program in episki","Implement lawful bases and data-subject rights once and reuse your GDPR work.",{"title":5108,"items":5109},"LGPD frequently asked questions",[5110,5112,5114,5116],{"label":5017,"content":5111},"The Lei Geral de Proteção de Dados (LGPD) is Brazil's general data protection law, in force since September 18, 2020. It closely mirrors the EU GDPR — defining lawful bases for processing, data-subject rights, controller and operator obligations, and a national authority (the ANPD) to enforce it.",{"label":1580,"content":5113},"The LGPD applies to any organization that processes the personal data of individuals in Brazil, or processes data in Brazil, regardless of where the organization is based — so it reaches many companies outside Brazil that serve Brazilian customers.",{"label":1793,"content":5115},"The ANPD can impose fines of up to 2% of a company's revenue in Brazil, capped at R$50 million per violation, along with warnings, data-processing restrictions, and public disclosure of the infraction.",{"label":5117,"content":5118},"How does LGPD relate to GDPR?","The LGPD is closely aligned with the GDPR, so most of a GDPR program transfers directly. In a notable 2026 development, Brazil and the EU adopted mutual adequacy decisions, easing personal-data transfers between the two jurisdictions.",{"headline":5120,"title":5121,"description":5122,"links":5123},"Brazilian privacy, operationalized","Comply with Brazil's LGPD","Legal bases, data-subject rights, a data protection officer, and ANPD breach handling — implemented as living controls and mapped to GDPR for reuse.",[5124,5125],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"LGPD","\u002Fframeworks\u002Flgpd",{"headline":5130,"title":5130,"description":5131,"items":5132},"LGPD accelerators","Stand up Brazilian privacy compliance and reuse it across regimes.",[5133,5136,5139],{"title":5134,"description":5135},"Legal-basis mapper","Assign and document a lawful basis for each processing activity.",{"title":5137,"description":5138},"DSAR workflow","Intake and fulfill data-subject requests within statutory timelines.",{"title":5140,"description":5141},"GDPR crosswalk","Reuse your GDPR records and DPIAs to satisfy the LGPD.",{"title":5143,"description":5144},"LGPD Compliance Software","Comply with Brazil's LGPD — legal bases, data-subject rights, DPO, and ANPD breach notification — with controls and records of processing mapped to GDPR.","lgpd",[5147,5150,5152],{"value":5148,"description":5149},"10 legal bases","Lawful-basis determination for every processing activity.",{"value":5046,"description":5151},"Brazil's data protection authority — breach notification workflow built in.",{"value":4727,"description":5153},"LGPD aligns closely with GDPR, so privacy work is reused.","5.frameworks\u002Flgpd","Ic0YUFazdBLe07a6FGsXfN-qbxhAJkU0SmfG7guu0HU",{"id":5157,"title":5158,"advantages":5159,"body":5181,"checklist":5257,"cta":5267,"description":93,"extension":151,"faq":5270,"hero":5284,"lastUpdated":186,"meta":5291,"name":1542,"navigation":188,"path":1541,"resources":5292,"seo":5304,"slug":5307,"stats":5308,"stem":5317,"__hash__":5318},"frameworks\u002F5.frameworks\u002Fnis2.md","Nis2",[5160,5167,5174],{"title":5161,"description":5162,"bullets":5163},"Article 21 measures as controls","The ten baseline risk-management measures implemented and evidenced.",[5164,5165,5166],"Incident handling, BCDR, and crisis management","Supply-chain and third-party security","Cryptography, access control, and MFA",{"title":5168,"description":5169,"bullets":5170},"Incident reporting on the clock","Classify significant incidents and hit every reporting window.",[5171,5172,5173],"24-hour early warning","72-hour incident notification","One-month final report",{"title":5175,"description":5176,"bullets":5177},"Governance and accountability","The management-body oversight and training NIS2 requires.",[5178,5179,5180],"Management-body approval and liability","Security awareness and training","Entity registration with the authority",{"type":29,"value":5182,"toc":5251},[5183,5187,5197,5200,5204,5218,5222,5241,5243],[32,5184,5186],{"id":5185},"what-is-nis2","What is NIS2?",[37,5188,5189,5192,5193,5196],{},[53,5190,5191],{},"NIS2 — Directive (EU) 2022\u002F2555"," — is the European Union's updated cybersecurity directive. It replaces the original 2016 NIS Directive and dramatically expands both the range of organizations in scope and the rigor of what they must do. The transposition deadline for Member States was ",[53,5194,5195],{},"October 17, 2024",", and because national implementation and enforcement have rolled out unevenly, 2026 is a key year as the remaining requirements and supervisory regimes come fully into effect.",[37,5198,5199],{},"Unlike a regulation, a directive is implemented through national law, so the precise rules vary by Member State — but the baseline obligations below are common across the EU.",[32,5201,5203],{"id":5202},"who-is-in-scope","Who is in scope",[37,5205,5206,5207,5210,5211,254,5214,5217],{},"NIS2 applies to medium and large organizations across roughly ",[53,5208,5209],{},"18 sectors",", including energy, transport, banking and financial market infrastructure, health, water, digital infrastructure, ICT service management, public administration, manufacturing, and food. In-scope organizations are classified as ",[53,5212,5213],{},"essential",[53,5215,5216],{},"important"," entities; essential entities face proactive supervision, while important entities are supervised reactively, and the distinction also affects the size of potential fines.",[32,5219,5221],{"id":5220},"core-requirements","Core requirements",[47,5223,5224,5230,5236],{},[50,5225,5226,5229],{},[53,5227,5228],{},"Risk-management measures (Article 21)"," — a baseline set of ten measures including incident handling, business continuity and crisis management, supply-chain security, secure development and vulnerability handling, cryptography, access control, and multi-factor authentication.",[50,5231,5232,5235],{},[53,5233,5234],{},"Incident reporting (Article 23)"," — for a significant incident, a 24-hour early warning, a 72-hour notification, and a one-month final report to the national CSIRT or competent authority.",[50,5237,5238,5240],{},[53,5239,5175],{}," — management bodies must approve and oversee cybersecurity measures and can be held personally liable; staff must receive training, and entities must register with their authority.",[32,5242,244],{"id":243},[37,5244,5245,5246,254,5249,258],{},"episki carries NIS2 obligations as structured records: risk management measures wired to evaluated controls, incident findings with owners and reporting clocks that sync into your engineers' tracker, and supply chain risk run through the TPRM module with review cadences that advance on accepted evidence. Management accountability is backed by approvals that record the approver and the rationale. ",[249,5247,253],{"href":185,"rel":5248},[252],[249,5250,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":5252},[5253,5254,5255,5256],{"id":5185,"depth":94,"text":5186},{"id":5202,"depth":94,"text":5203},{"id":5220,"depth":94,"text":5221},{"id":243,"depth":94,"text":244},{"title":5258,"description":5259,"items":5260},"NIS2 readiness inside episki","What an essential or important entity needs in place.",[5261,5262,5263,5264,5265,5266],"Scope determination (essential vs. important entity)","Article 21 risk-management measures as controls","Incident classification and 24h \u002F 72h \u002F 1-month reporting","Supply-chain and third-party security program","Business continuity, backup, and crisis management","Management-body oversight, training, and registration",{"title":5268,"description":5269},"Build a NIS2 program in episki","Implement the Article 21 measures once and reuse your ISO 27001 evidence to get there faster.",{"title":5271,"items":5272},"NIS2 frequently asked questions",[5273,5276,5279,5282],{"label":5274,"content":5275},"What is the NIS2 Directive?","NIS2 (Directive (EU) 2022\u002F2555) is the EU's updated cybersecurity directive, replacing the original 2016 NIS Directive. It significantly broadens the sectors and entities in scope, raises baseline risk-management requirements, introduces strict incident-reporting timelines, and makes management bodies accountable for cybersecurity. As a directive, it is implemented through each Member State's national law.",{"label":5277,"content":5278},"Who is in scope?","NIS2 covers medium and large organizations across roughly 18 sectors — energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, public administration, space, postal services, manufacturing, food, and more. In-scope organizations are classified as either 'essential' or 'important' entities, which determines the level of supervision and the size of potential fines.",{"label":5280,"content":5281},"What are the reporting deadlines?","For a significant incident, NIS2 requires an early warning within 24 hours, a fuller incident notification within 72 hours, and a final report within one month. episki tracks each window per incident so deadlines are not missed.",{"label":1793,"content":5283},"Penalties are tiered by entity type. Essential entities can face fines up to €10 million or 2% of total worldwide annual turnover, whichever is higher; important entities up to €7 million or 1.4%. Senior management can be held personally accountable for compliance failures.",{"headline":5285,"title":5286,"description":5287,"links":5288},"NIS2, without the guesswork","Comply with the EU NIS2 Directive","The Article 21 risk-management measures as controls, Article 23 incident reporting timers, supply-chain security, and management-body oversight — mapped to ISO 27001 so you don't start from scratch.",[5289,5290],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},{"headline":5293,"title":5294,"description":5295,"items":5296},"NIS2 accelerators","NIS2 readiness accelerators","Translate the Directive into a working program your regulator will recognize.",[5297,5300,5302],{"title":5298,"description":5299},"Scope assessment","Determine whether you are an essential or important entity, and your obligations.",{"title":1607,"description":5301},"Track the early-warning, notification, and final-report windows per incident.",{"title":1414,"description":5303},"Reuse your ISO 27001 Annex A controls to satisfy the Article 21 measures.",{"title":5305,"description":5306},"NIS2 Directive Compliance Software","Meet the EU NIS2 Directive (2022\u002F2555) — risk-management measures, incident reporting timers, supply-chain security, and management accountability, mapped to ISO 27001.","nis2",[5309,5311,5314],{"value":5209,"description":5310},"Essential and important entities across energy, health, digital, finance, and more.",{"value":5312,"description":5313},"24h \u002F 72h","Early-warning and notification timers for significant incidents, tracked to the deadline.",{"value":5315,"description":5316},"ISO 27001 mapped","Article 21 measures cross-walked to ISO 27001 Annex A for evidence reuse.","5.frameworks\u002Fnis2","FR69x59C11xL5kDaYNmNFgagmZlqT9AJBSmAUm-j5Ew",{"id":5320,"title":5321,"advantages":5322,"body":5344,"checklist":5386,"cta":5395,"description":93,"extension":151,"faq":5398,"hero":5412,"lastUpdated":186,"meta":5419,"name":1934,"navigation":188,"path":1933,"resources":5420,"seo":5433,"slug":5436,"stats":5437,"stem":5447,"__hash__":5448},"frameworks\u002F5.frameworks\u002Fnist-800-171.md","Nist 800 171",[5323,5330,5337],{"title":5324,"description":5325,"bullets":5326},"14 control families, pre-mapped","Every 800-171 requirement implemented as a control with mapped evidence and testing.",[5327,5328,5329],"Access Control, Audit, AT, CM, IR, MA, MP, PE, PS, RM, CA, SC, SI","Identification & Authentication, plus all enhancements","Pre-built testing procedures per requirement",{"title":5331,"description":5332,"bullets":5333},"SSP and POA&M","Generate your System Security Plan and Plan of Action & Milestones from live evidence.",[5334,5335,5336],"SSP narrative composed from real controls","POA&M items tracked to closure","Self-assessment scoring per DFARS 252.204-7019\u002F-7020",{"title":5338,"description":5339,"bullets":5340},"Bridge to CMMC Level 2","The same 110 controls map directly to CMMC L2 practices, so your 800-171 work isn't wasted.",[5341,5342,5343],"CMMC Level 2 practice mapping","C3PAO-friendly evidence packaging","Reuse 800-171 evidence in your CMMC assessment",{"type":29,"value":5345,"toc":5381},[5346,5350,5353,5364,5368,5371,5373],[32,5347,5349],{"id":5348},"what-is-nist-800-171","What is NIST 800-171?",[37,5351,5352],{},"NIST Special Publication 800-171 (\"Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations\") is a set of 110 security requirements that organizations must meet when they handle Controlled Unclassified Information on behalf of the US federal government. It is the operative standard underneath DFARS 252.204-7012 (and -7019\u002F-7020\u002F-7021), making it a baseline obligation for nearly every Department of Defense contractor and subcontractor.",[37,5354,5355,5356,5359,5360,5363],{},"The 110 controls are organized into 14 families and are derived from a tailored subset of NIST 800-53 controls. NIST published ",[53,5357,5358],{},"Rev. 3"," in May 2024 — the current revision of the standard itself — but the Department of Defense still requires ",[53,5361,5362],{},"Rev. 2"," (published 2020) for DFARS and CMMC compliance until a future rulemaking adopts Rev. 3. For defense contractors today, Rev. 2 remains the operative baseline.",[32,5365,5367],{"id":5366},"who-needs-800-171","Who needs 800-171",[37,5369,5370],{},"If you're a DoD prime or subcontractor handling Controlled Unclassified Information — or if you expect to be one — 800-171 applies to you. Many primes flow the obligation down to their entire supply chain via contract.",[32,5372,244],{"id":243},[37,5374,5375,5376,254,5379,258],{},"episki maps all 110 requirements to controls evaluated on every sync, derives the CMMC crosswalk through the SCF hub with recorded provenance, and turns a failing check into a POA&M item with an owner and a due date that syncs into Jira, Linear, or GitHub. The CUI boundary is enforceable through scope rules on cloud account, region, resource, and tag. ",[249,5377,253],{"href":185,"rel":5378},[252],[249,5380,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":5382},[5383,5384,5385],{"id":5348,"depth":94,"text":5349},{"id":5366,"depth":94,"text":5367},{"id":243,"depth":94,"text":244},{"title":5387,"description":5388,"items":5389},"NIST 800-171 readiness inside episki","Everything DoD primes look for, ready to deploy.",[5390,5391,5392,5393,5394,5341],"800-171 Rev. 2 control catalog at the requirement level","SSP narrative generated from control evidence","POA&M tracking with milestone management","DFARS self-assessment scoring methodology","Supplier Performance Risk System (SPRS) score export",{"title":5396,"description":5397},"Get a credible 800-171 program standing","Start in episki, score yourself, and bridge to CMMC Level 2 in the same workspace.",{"title":5399,"items":5400},"NIST 800-171 frequently asked questions",[5401,5403,5406,5409],{"label":5349,"content":5402},"NIST Special Publication 800-171 is a set of 110 security requirements protecting Controlled Unclassified Information (CUI) in non-federal information systems and organizations. It's the baseline DoD contractors must meet under DFARS 252.204-7012.",{"label":5404,"content":5405},"What's the relationship between 800-171 and CMMC?","CMMC Level 2 requires implementing the same 110 800-171 controls, plus a formal assessment by a C3PAO. CMMC Level 3 adds additional controls from NIST 800-172. So 800-171 work directly transfers to CMMC.",{"label":5407,"content":5408},"Do we need to be assessed?","For DFARS, primes generally rely on contractor self-assessments scored and posted to SPRS. For CMMC Level 2, a C3PAO assessment is required. Many contractors run a basic self-assessment now and prepare for CMMC formally.",{"label":5410,"content":5411},"What is the SPRS score?","The Supplier Performance Risk System score is a numeric value (from 110 down to -203 depending on non-compliance) that you submit to DoD reflecting your 800-171 self-assessment status. Many primes filter subs based on SPRS score.",{"headline":5413,"title":5414,"description":5415,"links":5416},"800-171 without the SSP-Word-document slog","Protect CUI without the spreadsheet","All 14 control families and 110 security requirements pre-mapped. SSP and POA&M workflows ready out of the box. A lift-and-shift path to CMMC Level 2.",[5417,5418],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},{"headline":5421,"title":5422,"description":5423,"items":5424},"NIST 800-171 accelerators","NIST 800-171 program accelerators","Move from \"we got the letter from our prime\" to a credible SSP fast.",[5425,5428,5430],{"title":5426,"description":5427},"SPRS scoring calculator","Compute your DoD self-assessment score with the official methodology.",{"title":2548,"description":5429},"Compose the SSP narrative from your control implementations.",{"title":5431,"description":5432},"CMMC Level 2 mapping","See exactly which 800-171 controls become which CMMC practices.",{"title":5434,"description":5435},"NIST 800-171 Compliance Software","Protect Controlled Unclassified Information (CUI) as a DoD contractor with the 110 controls of NIST 800-171 — the foundation underneath CMMC Level 2.","nist-800-171",[5438,5441,5444],{"value":5439,"description":5440},"110 controls","The full 800-171 Rev. 2 catalog implemented as living episki controls.",{"value":5442,"description":5443},"14 families","Access Control through System and Information Integrity, all covered.",{"value":5445,"description":5446},"CMMC L2 ready","The 110 controls are the foundation of CMMC Level 2 — same evidence, same workspace.","5.frameworks\u002Fnist-800-171","E6VJGXEFFzLtNGXDtEcovTQ5ZYMV6s5Cm54nwbRz3OY",{"id":5450,"title":5451,"advantages":5452,"body":5473,"checklist":5507,"cta":5516,"description":93,"extension":151,"faq":5519,"hero":5533,"lastUpdated":186,"meta":5540,"name":1875,"navigation":188,"path":1874,"resources":5541,"seo":5555,"slug":5558,"stats":5559,"stem":5568,"__hash__":5569},"frameworks\u002F5.frameworks\u002Fnist-800-53.md","Nist 800 53",[5453,5460,5467],{"title":5454,"description":5455,"bullets":5456},"Pre-mapped Rev. 5 controls","The current 800-53 Rev. 5 catalog implemented as living controls with evidence and testing.",[5457,5458,5459],"All 20 families covered","Control enhancements selectable per system","Tailoring rationale captured in-platform",{"title":5461,"description":5462,"bullets":5463},"Overlays and tailoring","Apply overlays (FedRAMP, DoD, Privacy) and document tailoring decisions in the same surface.",[5464,5465,5466],"FedRAMP Low\u002FModerate\u002FHigh overlays","Privacy and PII overlays","Tailoring decisions logged for assessors",{"title":5468,"description":5469,"bullets":5470},"Crosswalks","Map once, demonstrate many. 800-53 controls reuse for FedRAMP, CMMC, and CSF.",[5471,5341,5472],"NIST CSF subcategory mapping","FedRAMP control mapping built in",{"type":29,"value":5474,"toc":5502},[5475,5479,5482,5485,5489,5492,5494],[32,5476,5478],{"id":5477},"what-is-nist-800-53","What is NIST 800-53?",[37,5480,5481],{},"NIST Special Publication 800-53 (currently at Revision 5) is the National Institute of Standards and Technology's comprehensive catalog of security and privacy controls for US federal information systems. It is the most-cited control catalog in compliance — directly required by FedRAMP, used to derive CMMC and DoD control sets, mapped to the NIST Cybersecurity Framework, and adopted by many state, healthcare, and education organizations.",[37,5483,5484],{},"The current Rev. 5 catalog organizes ~1,000 controls and control enhancements into 20 families covering access control, audit, configuration management, incident response, supply chain, privacy, and many more. Controls are organized into baselines (Low \u002F Moderate \u002F High) reflecting the impact level of the system being protected.",[32,5486,5488],{"id":5487},"who-uses-nist-800-53","Who uses NIST 800-53",[37,5490,5491],{},"Beyond federal agencies and their contractors, 800-53 is widely adopted by organizations that want a comprehensive, well-maintained, regularly-updated control library. It's the substrate underneath FedRAMP, the spine of CMMC's NIST 800-171 control set, and a primary reference for the NIST CSF.",[32,5493,244],{"id":243},[37,5495,5496,5497,254,5500,258],{},"episki carries the 800-53 control families with continuous evaluation and cross-framework reuse: a control satisfied here counts everywhere it is claimed, with crosswalks derived through the SCF hub and recorded provenance. Baselines are scoped through boundaries on cloud account, region, resource, and tag, and each check writes an explicit pass, fail, or inconclusive verdict. ",[249,5498,253],{"href":185,"rel":5499},[252],[249,5501,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":5503},[5504,5505,5506],{"id":5477,"depth":94,"text":5478},{"id":5487,"depth":94,"text":5488},{"id":243,"depth":94,"text":244},{"title":5508,"description":5509,"items":5510},"NIST 800-53 readiness inside episki","What you need preloaded to start a credible 800-53 program.",[5511,5512,5513,5514,5515,2515],"800-53 Rev. 5 control catalog","System categorization (FIPS 199) workflow","Tailoring and overlay decisions captured per system","Control assessment procedures (SP 800-53A) ready to run","POA&M tracking for non-compliant controls",{"title":5517,"description":5518},"Operationalize 800-53 in episki","Start with the right baseline, capture your tailoring, and stay assessment-ready.",{"title":5520,"items":5521},"NIST 800-53 frequently asked questions",[5522,5524,5527,5530],{"label":5478,"content":5523},"NIST Special Publication 800-53 is a catalog of security and privacy controls for US federal information systems, also widely adopted by non-federal organizations and used as the foundation for FedRAMP, DoD authorizations, and many state-level frameworks.",{"label":5525,"content":5526},"What's the difference between 800-53 and NIST CSF?","800-53 is a detailed catalog of specific controls. The NIST Cybersecurity Framework (CSF) is a higher-level framework organized into Identify\u002FProtect\u002FDetect\u002FRespond\u002FRecover\u002FGovern functions. CSF subcategories often reference 800-53 controls for implementation guidance.",{"label":5528,"content":5529},"When did Rev. 5 come into effect?","NIST 800-53 Revision 5 was published in 2020 and replaced Rev. 4. The current version is fully integrated into FedRAMP. Some legacy authorizations may still reference Rev. 4 controls — episki supports both.",{"label":5531,"content":5532},"Do I need 800-53 if I'm not a federal contractor?","Not strictly, but it's a widely respected control catalog. Many private-sector organizations use 800-53 as a comprehensive control library even when not pursuing FedRAMP, because it's better-maintained and more granular than most alternatives.",{"headline":5534,"title":5535,"description":5536,"links":5537},"800-53, lived in, not photocopied","Operationalize NIST 800-53 control baselines","All 20 control families pre-mapped. Tailoring decisions and overlays captured in-platform. Crosswalks to NIST CSF, FedRAMP, and CMMC so you implement once and demonstrate many.",[5538,5539],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},{"headline":5542,"title":5543,"description":5544,"items":5545},"NIST 800-53 accelerators","NIST 800-53 program accelerators","Get a live, defensible 800-53 program — without the binder-cart aesthetic.",[5546,5549,5552],{"title":5547,"description":5548},"System categorization wizard","FIPS 199-style categorization to pick the right baseline.",{"title":5550,"description":5551},"Tailoring rationale capture","Document why a control was tailored in or out — assessors love it.",{"title":5553,"description":5554},"SP 800-53A test procedures","Pre-mapped assessment procedures for each control family.",{"title":5556,"description":5557},"NIST 800-53 Compliance Software","Manage federal control baselines (Low \u002F Moderate \u002F High) with mapped 800-53 control families, overlays, and tailoring records. Crosswalk to NIST CSF, FedRAMP, and CMMC.","nist-800-53",[5560,5563,5565],{"value":5561,"description":5562},"20 families","AC through SR — every NIST 800-53 Rev. 5 control family pre-mapped.",{"value":2562,"description":5564},"Low, Moderate, and High baselines selectable per system.",{"value":5566,"description":5567},"1 control graph","800-53, CSF, FedRAMP, and CMMC mapped to the same underlying controls.","5.frameworks\u002Fnist-800-53","SJa8f2bI2U3dB9myti7igHPOgLP14i6TbLGs0zNDYbc",{"id":5571,"title":5572,"advantages":5573,"body":5593,"checklist":5681,"cta":5691,"description":93,"extension":151,"faq":5694,"hero":5708,"lastUpdated":186,"meta":5715,"name":4984,"navigation":188,"path":5716,"resources":5717,"seo":5731,"slug":5734,"stats":5735,"stem":5745,"__hash__":5746},"frameworks\u002F5.frameworks\u002Fnist-ai-rmf.md","Nist Ai Rmf",[5574,5581,5588],{"title":5575,"description":5576,"bullets":5577},"Govern, Map, Measure, Manage","The four AI RMF functions as a repeatable workflow, not a PDF.",[5578,5579,5580],"Govern — AI policy, roles, and accountability","Map and Measure — context, risks, and metrics","Manage — prioritized treatments and monitoring",{"title":5582,"description":5583,"bullets":5584},"AI and agent registry","Inventory every model, system, and autonomous agent with its risk profile.",[5585,5586,5587],"Use-case and model inventory with owners","Third-party and foundation-model tracking","Generative AI Profile considerations built in",{"title":1647,"description":5589,"bullets":5590},"AI RMF evidence feeds ISO 42001 certification and EU AI Act obligations.",[1650,5591,5592],"Crosswalk to EU AI Act risk tiers","Reuse security evidence from ISO 27001 \u002F SOC 2",{"type":29,"value":5594,"toc":5675},[5595,5599,5609,5616,5620,5623,5648,5652,5665,5667],[32,5596,5598],{"id":5597},"what-is-the-nist-ai-rmf","What is the NIST AI RMF?",[37,5600,367,5601,5604,5605,5608],{},[53,5602,5603],{},"NIST AI Risk Management Framework (AI RMF 1.0)"," — published as ",[53,5606,5607],{},"NIST AI 100-1 in January 2023"," — is voluntary guidance for identifying and managing the risks of artificial intelligence across its lifecycle, from design and development through deployment and decommissioning. It was developed through an open, multi-stakeholder process at the direction of Congress and has quickly become the de facto reference for AI governance in the United States.",[37,5610,5611,5612,5615],{},"Rather than prescribe specific controls, the AI RMF defines a set of ",[53,5613,5614],{},"trustworthy-AI characteristics"," — valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair (with harmful bias managed) — and a flexible process for achieving them.",[32,5617,5619],{"id":5618},"the-four-functions","The four functions",[37,5621,5622],{},"The AI RMF core organizes that process into four functions:",[47,5624,5625,5630,5636,5642],{},[50,5626,5627,5629],{},[53,5628,445],{}," — the foundation. It establishes the organization's AI risk culture, policies, roles, and accountability, including who approves high-risk use cases, how third-party and foundation models are introduced, and how resources are allocated to testing.",[50,5631,5632,5635],{},[53,5633,5634],{},"Map"," — the scoping function. It builds the context for each AI system and identifies the risks that context creates.",[50,5637,5638,5641],{},[53,5639,5640],{},"Measure"," — analyzes, assesses, benchmarks, and monitors AI risks with quantitative and qualitative methods.",[50,5643,5644,5647],{},[53,5645,5646],{},"Manage"," — allocates resources to prioritized risks, applies treatments (mitigate, transfer, avoid, accept), documents residual risk, and handles monitoring, incident response, and recovery.",[32,5649,5651],{"id":5650},"who-uses-the-ai-rmf","Who uses the AI RMF",[37,5653,5654,5655,5657,5658,5660,5661,5664],{},"Any organization that builds, deploys, or procures AI — including generative AI and autonomous agents — uses the AI RMF to put structure around AI risk. It is especially common for US-based companies and federal contractors, and it is the natural companion to the certifiable ",[249,5656,4956],{"href":4957}," AI management system and to ",[249,5659,1803],{"href":1804}," readiness. NIST's companion ",[53,5662,5663],{},"Generative AI Profile (NIST AI 600-1)",", published in July 2024, extends the framework with risks specific to generative models.",[32,5666,244],{"id":243},[37,5668,5669,5670,254,5673,258],{},"episki maps the NIST AI RMF functions to controls in the AI Governance module, with an agent and use-case registry, AI risk treatments tied to evidence, and crosswalks to ISO 42001 and the EU AI Act derived through the SCF hub. Because episki governs its own agents through the same module, the registry reflects the AI actually running in your workspace rather than a separate inventory. ",[249,5671,253],{"href":185,"rel":5672},[252],[249,5674,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":5676},[5677,5678,5679,5680],{"id":5597,"depth":94,"text":5598},{"id":5618,"depth":94,"text":5619},{"id":5650,"depth":94,"text":5651},{"id":243,"depth":94,"text":244},{"title":5682,"description":5683,"items":5684},"NIST AI RMF readiness inside episki","What an AI governance program needs in place.",[5685,5686,5687,5688,5689,5690],"AI system, model, and agent inventory","AI governance policy and accountable roles (Govern)","Context and risk mapping per AI use case (Map)","Risk metrics and evaluation evidence (Measure)","Risk treatments, monitoring, and incident response (Manage)","Crosswalks to ISO 42001 and the EU AI Act",{"title":5692,"description":5693},"Build a trustworthy-AI program in episki","Run the NIST AI RMF once and reuse the work for ISO 42001 and the EU AI Act.",{"title":5695,"items":5696},"NIST AI RMF frequently asked questions",[5697,5699,5702,5705],{"label":5598,"content":5698},"The NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0, published as NIST AI 100-1 in January 2023) is voluntary guidance for managing risks across the AI lifecycle. It is organized around four core functions — Govern, Map, Measure, and Manage — and a set of trustworthy-AI characteristics such as validity, safety, security, accountability, transparency, privacy, and fairness.",{"label":5700,"content":5701},"What are the four functions?","Govern establishes the AI risk culture, policies, and accountability. Map develops the context and identifies risks for each AI use case. Measure analyzes, assesses, and tracks those risks with appropriate metrics. Manage prioritizes and acts on risks — mitigate, transfer, avoid, or accept — and handles monitoring and incident response.",{"label":5703,"content":5704},"Is the AI RMF mandatory?","The AI RMF itself is voluntary, but it has become the de facto US baseline for AI governance and is widely referenced in contracts, procurement, and policy. It also pairs naturally with the certifiable ISO\u002FIEC 42001 standard and helps structure EU AI Act readiness.",{"label":5706,"content":5707},"What is the Generative AI Profile?","NIST published a companion Generative AI Profile (NIST AI 600-1) in July 2024 that identifies risks unique to generative AI and suggested actions across the four functions. episki incorporates these considerations for organizations deploying generative models and agents.",{"headline":5709,"title":5710,"description":5711,"links":5712},"Trustworthy AI, operationalized","Run the NIST AI Risk Management Framework","An AI and agent inventory, risk mapping and measurement, and the Govern-Map-Measure-Manage workflow — pre-mapped to ISO 42001 and the EU AI Act so one AI program serves them all.",[5713,5714],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"\u002Fframeworks\u002Fnist-ai-rmf",{"headline":5718,"title":5719,"description":5720,"items":5721},"NIST AI RMF accelerators","AI risk program accelerators","Stand up trustworthy-AI governance without starting from a blank page.",[5722,5725,5728],{"title":5723,"description":5724},"AI use-case intake","Capture new AI systems and agents with risk tiering at request time.",{"title":5726,"description":5727},"Risk profile builder","Map and measure risks against the trustworthy-AI characteristics.",{"title":5729,"description":5730},"ISO 42001 \u002F EU AI Act crosswalk","See which AI RMF outcomes satisfy which 42001 clauses and AI Act obligations.",{"title":5732,"description":5733},"NIST AI RMF Compliance Software","Operationalize the NIST AI Risk Management Framework (AI RMF 1.0) — Govern, Map, Measure, Manage — with an AI\u002Fagent registry, risk treatments, and crosswalks to ISO 42001 and the EU AI Act.","nist-ai-rmf",[5736,5739,5742],{"value":5737,"description":5738},"4 functions","Govern, Map, Measure, and Manage implemented as a working AI risk workflow.",{"value":5740,"description":5741},"AI inventory","A live registry of AI systems, models, and agents with owners and risk tiers.",{"value":5743,"description":5744},"ISO 42001 mapped","AI RMF outcomes cross-walked to ISO 42001 and the EU AI Act for reuse.","5.frameworks\u002Fnist-ai-rmf","HgAGZr-JS6zQTSUdIv5QEpUtWbiXefuqYILioGhXS-4",{"id":5748,"title":5749,"advantages":5750,"body":5772,"checklist":6312,"cta":6321,"description":93,"extension":151,"faq":6324,"hero":6341,"lastUpdated":186,"meta":6350,"name":465,"navigation":188,"path":464,"resources":6351,"seo":6364,"slug":6367,"stats":6368,"stem":6378,"__hash__":6379},"frameworks\u002F5.frameworks\u002Fnistcsf.md","Nistcsf",[5751,5758,5765],{"title":5752,"description":5753,"bullets":5754},"Tailored CSF roadmap","Start with opinionated baseline controls, then layer your own.",[5755,5756,5757],"Gap analysis highlights missing outcomes","Auto-generated improvement initiatives","Budget impact estimates for leadership",{"title":5759,"description":5760,"bullets":5761},"Continuous monitoring and AI ops","Stream alerts, detections, and incidents into CSF context.",[5762,5763,5764],"Connect SIEM, EDR, and cloud posture tools","AI summarizes incidents for exec updates","Workflows escalate unreviewed alerts",{"title":5766,"description":5767,"bullets":5768},"Board and customer alignment","Share progress externally with confidence.",[5769,5770,5771],"Customizable scorecards for customers or partners","Trend lines show quarter-over-quarter improvements","Trust room access with expiring links",{"type":29,"value":5773,"toc":6289},[5774,5778,5785,5788,5792,5799,5802,5806,5809,5818,5822,5825,5828,5867,5873,5877,5880,5883,5887,5896,5900,5910,5914,5924,5928,5938,5942,5952,5956,5966,5969,5973,5980,6006,6012,6016,6022,6025,6039,6042,6053,6057,6067,6084,6091,6095,6103,6109,6120,6124,6127,6174,6177,6181,6184,6216,6219,6222,6226,6229,6273,6276,6279,6281],[32,5775,5777],{"id":5776},"what-is-nist-csf","What is NIST CSF?",[37,5779,5780,5781,5784],{},"The NIST Cybersecurity Framework (NIST CSF) is a voluntary, outcome-based set of cybersecurity guidelines published by the ",[249,5782,5783],{"href":690},"National Institute of Standards and Technology",". The NIST Cybersecurity Framework gives organizations a shared vocabulary and a prioritized structure for managing cybersecurity risk, measuring program maturity, and communicating security posture to executives, boards, regulators, customers, and insurers.",[37,5786,5787],{},"NIST CSF is not a certification, a control catalog, or a compliance standard. It is a framework — a model that organizes cybersecurity activities into functions, categories, and subcategories so that any organization can describe its current cybersecurity posture, describe its target cybersecurity posture, identify and prioritize opportunities for improvement, assess progress, and communicate cybersecurity risk in a consistent way. Because NIST CSF is technology- and sector-neutral, it has become one of the most widely adopted cybersecurity frameworks in the world, used by Fortune 500 companies, federal contractors, critical infrastructure operators, state and local governments, startups, nonprofits, and multinational enterprises.",[597,5789,5791],{"id":5790},"nist-origin-and-executive-order-13636","NIST origin and Executive Order 13636",[37,5793,5794,5795,5798],{},"The NIST Cybersecurity Framework was created in response to a growing wave of attacks against United States critical infrastructure. In February 2013, President Barack Obama signed ",[53,5796,5797],{},"Executive Order 13636 — Improving Critical Infrastructure Cybersecurity",", which directed NIST to work with industry, academia, and other government agencies to develop a voluntary cybersecurity framework for critical infrastructure operators. The executive order explicitly called for a flexible, repeatable, performance-based, and cost-effective approach that could scale from small municipal utilities to the largest financial institutions.",[37,5800,5801],{},"NIST published version 1.0 of the NIST Cybersecurity Framework in February 2014 after a year of public workshops, industry comment periods, and collaboration with more than three thousand individuals and organizations. The first version of NIST CSF introduced the five core functions — Identify, Protect, Detect, Respond, and Recover — along with the concept of framework profiles and implementation tiers. Even though NIST CSF was designed for critical infrastructure, organizations in every sector quickly adopted it because it filled a gap that prescriptive standards did not: a business-friendly model for talking about cybersecurity risk.",[597,5803,5805],{"id":5804},"the-evolution-of-nist-csf","The evolution of NIST CSF",[37,5807,5808],{},"In April 2018, NIST released NIST CSF version 1.1. This incremental update clarified existing guidance, added a new Supply Chain Risk Management category (ID.SC), improved the self-assessment language, and added authentication and identity proofing subcategories. NIST CSF 1.1 contained 108 subcategories grouped under 23 categories across the five functions, and it remained the dominant version of the NIST Cybersecurity Framework for six years.",[37,5810,5811,5812,5814,5815,5817],{},"In February 2024, NIST published ",[53,5813,441],{}," — the first major revision of the NIST Cybersecurity Framework. NIST CSF 2.0 expanded the scope of the framework beyond critical infrastructure, added a brand-new sixth function called ",[53,5816,445],{},", reorganized several categories, and introduced a richer set of implementation resources including quick-start guides, informative references, and community profiles.",[32,5819,5821],{"id":5820},"nist-csf-20-changes","NIST CSF 2.0 changes",[37,5823,5824],{},"The jump from NIST CSF 1.1 to NIST CSF 2.0 is the most significant update the NIST Cybersecurity Framework has ever received. The changes are not cosmetic — they reshape how organizations are expected to structure and govern their cybersecurity programs.",[37,5826,5827],{},"Highlights of NIST CSF 2.0:",[47,5829,5830,5836,5842,5848,5861],{},[50,5831,5832,5835],{},[53,5833,5834],{},"A sixth function — Govern (GV)"," — elevates cybersecurity governance from a sub-category under Identify to a standalone top-level function covering organizational context, risk management strategy, roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management.",[50,5837,5838,5841],{},[53,5839,5840],{},"Explicit scope expansion"," — NIST CSF 2.0 applies to organizations of any size, sector, or maturity level, not just critical infrastructure. Small-business quick-start guides, community profiles, and sector-specific profiles make the NIST Cybersecurity Framework accessible to organizations that previously found NIST CSF 1.1 too enterprise-centric.",[50,5843,5844,5847],{},[53,5845,5846],{},"Stronger supply chain focus"," — GV.SC expands the NIST CSF treatment of third-party risk, supplier due diligence, and software supply chain security, reflecting the lessons of SolarWinds, Kaseya, Log4j, and MOVEit.",[50,5849,5850,5853,5854,5857,5858,5860],{},[53,5851,5852],{},"Improved implementation guidance"," — NIST CSF 2.0 ships with a companion CSF Reference Tool, searchable informative references mapping NIST CSF subcategories to ",[249,5855,5856],{"href":690},"NIST SP 800-53",", ISO 27001, CIS Controls, ",[249,5859,475],{"href":474},", and more.",[50,5862,5863,5866],{},[53,5864,5865],{},"Refreshed implementation tiers"," — the four-tier maturity model (Partial, Risk-Informed, Repeatable, Adaptive) now explicitly incorporates governance and supply chain considerations.",[37,5868,5869,5870,3322],{},"For a deep dive into every structural and categorical change between NIST CSF 1.1 and NIST CSF 2.0, see our ",[249,5871,5821],{"href":5872},"\u002Fframeworks\u002Fnistcsf\u002Fv2-changes",[32,5874,5876],{"id":5875},"the-six-core-functions-of-nist-csf-20","The six core functions of NIST CSF 2.0",[37,5878,5879],{},"The NIST Cybersecurity Framework organizes cybersecurity activity into a small number of top-level functions. NIST CSF 1.1 defined five functions; NIST CSF 2.0 defines six. Each function represents a category of outcomes that a mature cybersecurity program must deliver, and each function decomposes into categories and subcategories that describe the outcomes in progressively more specific terms.",[37,5881,5882],{},"The six NIST CSF 2.0 functions are:",[597,5884,5886],{"id":5885},"govern-gv","Govern (GV)",[37,5888,367,5889,5891,5892,258],{},[53,5890,445],{}," function — new in NIST CSF 2.0 — establishes, communicates, and monitors the organization's cybersecurity risk management strategy, expectations, and policy. Govern is the leadership and accountability layer of NIST CSF. It sits above the other five functions and informs everything the organization does to identify, protect, detect, respond, and recover. Deep dive: ",[249,5893,5895],{"href":5894},"\u002Fframeworks\u002Fnistcsf\u002Fgovern-function","NIST CSF Govern function",[597,5897,5899],{"id":5898},"identify-id","Identify (ID)",[37,5901,367,5902,5905,5906,258],{},[53,5903,5904],{},"Identify"," function develops an organizational understanding of cybersecurity risk to systems, people, assets, data, and capabilities. Identify is where you inventory what you have, understand the business context in which it operates, and decide what matters most. Without Identify, the rest of the NIST Cybersecurity Framework has nothing to act on. Deep dive: ",[249,5907,5909],{"href":5908},"\u002Fframeworks\u002Fnistcsf\u002Fidentify-function","NIST CSF Identify function",[597,5911,5913],{"id":5912},"protect-pr","Protect (PR)",[37,5915,367,5916,5919,5920,258],{},[53,5917,5918],{},"Protect"," function implements safeguards to ensure delivery of critical services and limit or contain the impact of cybersecurity events. Protect encompasses identity and access management, awareness and training, data security, information protection processes, maintenance, and protective technology. Deep dive: ",[249,5921,5923],{"href":5922},"\u002Fframeworks\u002Fnistcsf\u002Fprotect-function","NIST CSF Protect function",[597,5925,5927],{"id":5926},"detect-de","Detect (DE)",[37,5929,367,5930,5933,5934,258],{},[53,5931,5932],{},"Detect"," function develops and implements appropriate activities to identify the occurrence of a cybersecurity event in a timely manner. Detect covers continuous monitoring, anomaly analysis, and detection processes — the telemetry, alerting, and threat-hunting capabilities that surface attacks as they happen. Deep dive: ",[249,5935,5937],{"href":5936},"\u002Fframeworks\u002Fnistcsf\u002Fdetect-function","NIST CSF Detect function",[597,5939,5941],{"id":5940},"respond-rs","Respond (RS)",[37,5943,367,5944,5947,5948,258],{},[53,5945,5946],{},"Respond"," function contains activities to take action regarding a detected cybersecurity incident. Respond covers incident response planning, communications, analysis, containment, eradication, and lessons-learned improvements. A strong Respond capability is what separates a contained incident from a front-page breach. Deep dive: ",[249,5949,5951],{"href":5950},"\u002Fframeworks\u002Fnistcsf\u002Frespond-function","NIST CSF Respond function",[597,5953,5955],{"id":5954},"recover-rc","Recover (RC)",[37,5957,367,5958,5961,5962,258],{},[53,5959,5960],{},"Recover"," function contains activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity incident. Recover covers recovery planning, improvements, and communications. Recover is how organizations return to normal operations while capturing lessons learned to strengthen the program. Deep dive: ",[249,5963,5965],{"href":5964},"\u002Fframeworks\u002Fnistcsf\u002Frecover-function","NIST CSF Recover function",[37,5967,5968],{},"Together, the six NIST CSF functions describe the complete cybersecurity lifecycle. Mature organizations operate all six functions simultaneously and continuously, not in a linear sequence.",[32,5970,5972],{"id":5971},"nist-csf-implementation-tiers","NIST CSF implementation tiers",[37,5974,5975,5976,5979],{},"NIST CSF uses ",[53,5977,5978],{},"implementation tiers"," to describe the degree to which an organization's cybersecurity risk management practices exhibit the characteristics defined in the NIST Cybersecurity Framework. The four tiers are not a maturity scale in the traditional sense — NIST is careful to say that Tier 4 is not required for every organization. Instead, implementation tiers help organizations choose an appropriate level of rigor given their risk tolerance, mission, regulatory obligations, threat environment, and resources.",[47,5981,5982,5988,5994,6000],{},[50,5983,5984,5987],{},[53,5985,5986],{},"Tier 1 — Partial",": Cybersecurity risk management is ad hoc and reactive. Policies are informal, risk awareness is limited, and supply chain considerations are rarely formalized.",[50,5989,5990,5993],{},[53,5991,5992],{},"Tier 2 — Risk-Informed",": Risk management practices are approved by management but may not be established organization-wide. Cybersecurity activities consider organizational risk objectives.",[50,5995,5996,5999],{},[53,5997,5998],{},"Tier 3 — Repeatable",": Formal policies exist and are applied consistently. The organization has the people, processes, and tooling to operate the NIST Cybersecurity Framework repeatably.",[50,6001,6002,6005],{},[53,6003,6004],{},"Tier 4 — Adaptive",": The organization adapts its cybersecurity practices based on lessons learned, threat intelligence, and changes in the business environment. Cybersecurity risk management is part of the organizational culture.",[37,6007,6008,6009,3322],{},"For a complete walkthrough of each tier, including how to select a target tier and move between tiers, see our ",[249,6010,5972],{"href":6011},"\u002Fframeworks\u002Fnistcsf\u002Fimplementation-tiers",[32,6013,6015],{"id":6014},"nist-csf-framework-profiles","NIST CSF framework profiles",[37,6017,2098,6018,6021],{},[53,6019,6020],{},"framework profile"," is the unique alignment of NIST CSF functions, categories, and subcategories with the organization's business requirements, risk tolerance, and resources. Profiles are the tool that turns the NIST Cybersecurity Framework from a generic model into a specific plan for a specific organization.",[37,6023,6024],{},"NIST CSF supports two kinds of profiles:",[47,6026,6027,6033],{},[50,6028,2098,6029,6032],{},[53,6030,6031],{},"Current Profile"," describes the cybersecurity outcomes the organization is achieving today.",[50,6034,2098,6035,6038],{},[53,6036,6037],{},"Target Profile"," describes the cybersecurity outcomes the organization wants to achieve.",[37,6040,6041],{},"The gap between the Current Profile and the Target Profile becomes a prioritized roadmap: which NIST CSF subcategories need investment, in what order, and at what cost. Community profiles published by NIST (for small business, healthcare, financial services, manufacturing, and others) give organizations a head start by providing pre-built Target Profiles tailored to specific sectors.",[37,6043,6044,6045,6049,6050,258],{},"For a complete framework profiles walkthrough — including how to build your first profile, how to use community profiles, and how to link profiles to your ",[249,6046,6048],{"href":6047},"\u002Fglossary\u002Fcontrol-framework","control framework"," — see ",[249,6051,6015],{"href":6052},"\u002Fframeworks\u002Fnistcsf\u002Fframework-profiles",[32,6054,6056],{"id":6055},"nist-csf-categories-and-subcategories","NIST CSF categories and subcategories",[37,6058,6059,6060,392,6063,6066],{},"Below the function layer, NIST CSF decomposes cybersecurity activity into ",[53,6061,6062],{},"categories",[53,6064,6065],{},"subcategories",". Categories group related outcomes within a function (for example, Asset Management, Access Control, Continuous Monitoring), and subcategories express specific outcome statements that a mature program should achieve.",[47,6068,6069,6079],{},[50,6070,6071,6074,6075,6078],{},[53,6072,6073],{},"NIST CSF 1.1"," defined 23 categories and ",[53,6076,6077],{},"108 subcategories"," across the five original functions.",[50,6080,6081,6083],{},[53,6082,441],{}," reorganized the catalog around six functions. The total number of subcategories in NIST CSF 2.0 was restructured (and slightly reduced after consolidation) to roughly 106, grouped under 22 categories, with Govern contributing six new categories of its own.",[37,6085,6086,6087,6090],{},"Every NIST CSF subcategory is written as an outcome — for example, \"PR.AA-01: Identities and credentials for authorized users, services, and hardware are managed by the organization.\" NIST intentionally avoids prescribing specific technologies, controls, or implementation details. Instead, NIST CSF provides ",[53,6088,6089],{},"informative references"," that map each subcategory to specific controls in NIST SP 800-53, ISO 27001 Annex A, CIS Critical Security Controls, COBIT, and other authoritative sources. This outcome-first design is what makes NIST CSF work across industries, company sizes, and technology stacks.",[32,6092,6094],{"id":6093},"mapping-nist-csf-to-other-frameworks","Mapping NIST CSF to other frameworks",[37,6096,6097,6098,466,6100,6102],{},"One of the most valuable properties of the NIST Cybersecurity Framework is its ability to act as a unifying layer across multiple compliance regimes. Organizations that need to satisfy ",[249,6099,475],{"href":474},[249,6101,470],{"href":469},", HIPAA, PCI DSS, GDPR, FedRAMP, CMMC, and NIST SP 800-171 at the same time can use NIST CSF as the \"Rosetta Stone\" that maps each requirement to a common set of outcomes.",[37,6104,6105,6106,6108],{},"For federal contractors in particular, NIST CSF acts as the governance umbrella above NIST SP 800-171 and ",[249,6107,1048],{"href":698},", both of which are derived from the NIST family of publications. A NIST CSF Target Profile that references NIST SP 800-53 informative references can be reused — with minor adjustments — as an ISO 27001 Statement of Applicability, a SOC 2 Trust Services Criteria mapping, and a HIPAA Security Rule crosswalk.",[37,6110,6111,6112,6114,6115,6119],{},"For a detailed crosswalk between NIST CSF and the major compliance frameworks — including worked examples of how a single NIST CSF subcategory maps to multiple standards — see ",[249,6113,6094],{"href":4307},". If you are actively building that mapping into a live compliance program, our ",[249,6116,6118],{"href":6117},"\u002Fblog\u002Fnist-csf-mapping-compliance","NIST CSF mapping compliance"," guide walks through the operational mechanics.",[32,6121,6123],{"id":6122},"who-uses-nist-csf","Who uses NIST CSF?",[37,6125,6126],{},"The NIST Cybersecurity Framework started as a voluntary framework for United States critical infrastructure. A decade later, NIST CSF is used by:",[47,6128,6129,6135,6144,6150,6156,6162,6168],{},[50,6130,6131,6134],{},[53,6132,6133],{},"Critical infrastructure operators"," — energy, water, transportation, communications, healthcare, and financial services organizations that fall under the 16 critical infrastructure sectors originally targeted by Executive Order 13636.",[50,6136,6137,6140,6141,258],{},[53,6138,6139],{},"Federal agencies and federal contractors"," — Executive Order 13800 required federal agencies to use NIST CSF to manage cybersecurity risk. Agencies and their contractors routinely use NIST CSF alongside ",[249,6142,6143],{"href":698},"NIST SP 800-171 and the CMMC program",[50,6145,6146,6149],{},[53,6147,6148],{},"State, local, tribal, and territorial (SLTT) governments"," — many states have adopted NIST CSF as the baseline cybersecurity model for agencies and municipal systems.",[50,6151,6152,6155],{},[53,6153,6154],{},"Large enterprises"," — Fortune 500 companies use NIST CSF to communicate cybersecurity risk to boards, investors, insurers, and regulators.",[50,6157,6158,6161],{},[53,6159,6160],{},"Small and mid-sized businesses (SMBs)"," — especially after NIST CSF 2.0, which ships with SMB-specific quick-start guides and community profiles.",[50,6163,6164,6167],{},[53,6165,6166],{},"Non-US organizations"," — NIST CSF is widely used outside the United States as a practical cybersecurity model that complements ISO 27001 and other international standards.",[50,6169,6170,6173],{},[53,6171,6172],{},"Insurers and investors"," — cyber insurance carriers and private-equity diligence teams increasingly ask portfolio companies to report maturity against NIST CSF as evidence of disciplined cybersecurity risk management.",[37,6175,6176],{},"The common thread is that NIST CSF works for any organization that needs to manage cybersecurity risk and communicate that risk to non-technical stakeholders. That is essentially every organization.",[32,6178,6180],{"id":6179},"nist-csf-vs-nist-sp-800-53-vs-nist-sp-800-171","NIST CSF vs NIST SP 800-53 vs NIST SP 800-171",[37,6182,6183],{},"NIST publishes dozens of cybersecurity documents, and three of them — NIST CSF, NIST SP 800-53, and NIST SP 800-171 — are often confused. Here is how they differ and how they fit together.",[47,6185,6186,6196,6206],{},[50,6187,6188,6191,6192,6195],{},[53,6189,6190],{},"NIST CSF (Cybersecurity Framework)"," is an ",[53,6193,6194],{},"outcome-based framework",". It defines what cybersecurity outcomes to achieve (the subcategories) but does not tell you exactly how to achieve them. NIST CSF is voluntary, technology-neutral, and applies to any organization.",[50,6197,6198,6201,6202,6205],{},[53,6199,6200],{},"NIST SP 800-53 (Security and Privacy Controls for Information Systems and Organizations)"," is a comprehensive ",[53,6203,6204],{},"control catalog",". SP 800-53 contains more than one thousand security and privacy controls organized into families such as Access Control (AC), Audit and Accountability (AU), and System and Communications Protection (SC). NIST SP 800-53 is mandatory for US federal information systems under FISMA and the Risk Management Framework (RMF).",[50,6207,6208,6211,6212,6215],{},[53,6209,6210],{},"NIST SP 800-171 (Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations)"," is a ",[53,6213,6214],{},"derived subset"," of NIST SP 800-53 focused on protecting Controlled Unclassified Information (CUI) in nonfederal systems. SP 800-171 is mandatory for any organization that handles CUI on behalf of the federal government and forms the basis for CMMC.",[37,6217,6218],{},"The relationship between the three is straightforward: NIST CSF describes the outcomes, NIST SP 800-53 and NIST SP 800-171 describe the controls that deliver those outcomes, and the NIST CSF informative references tell you which 800-53 and 800-171 controls satisfy each NIST CSF subcategory. Organizations use NIST CSF to frame the strategy and use NIST SP 800-53 or NIST SP 800-171 to implement the controls.",[37,6220,6221],{},"Federal contractors that handle CUI will typically use all three: NIST CSF for executive communication and maturity scoring, NIST SP 800-171 as the binding control baseline, and NIST SP 800-53 as the deeper reference catalog.",[32,6223,6225],{"id":6224},"getting-started-with-nist-csf","Getting started with NIST CSF",[37,6227,6228],{},"Implementing the NIST Cybersecurity Framework does not require a multi-year consulting engagement. A typical first NIST CSF implementation follows a repeatable pattern:",[903,6230,6231,6237,6243,6249,6255,6261,6267],{},[50,6232,6233,6236],{},[53,6234,6235],{},"Scope and prioritize"," — decide which parts of the organization are in scope for this iteration of NIST CSF. Startups often scope the entire company. Enterprises may scope a business unit, a product line, or a critical system.",[50,6238,6239,6242],{},[53,6240,6241],{},"Build a Current Profile"," — score the organization's current performance against each NIST CSF subcategory. Be honest. Many organizations discover that half of their NIST CSF subcategories are informal or partially implemented.",[50,6244,6245,6248],{},[53,6246,6247],{},"Build a Target Profile"," — decide what level of NIST CSF maturity the organization needs. Community profiles and sector profiles published by NIST are excellent starting points.",[50,6250,6251,6254],{},[53,6252,6253],{},"Perform a gap analysis"," — the delta between Current and Target is your NIST CSF roadmap. Prioritize by business impact, risk, and cost.",[50,6256,6257,6260],{},[53,6258,6259],{},"Select implementation tiers"," — match each part of the program to an appropriate tier. Not every subcategory needs to be Tier 4.",[50,6262,6263,6266],{},[53,6264,6265],{},"Execute and measure"," — track initiatives, re-score the NIST CSF profile quarterly, and report progress to leadership.",[50,6268,6269,6272],{},[53,6270,6271],{},"Map to other frameworks"," — reuse the NIST CSF profile as the source of truth for SOC 2, ISO 27001, HIPAA, and CMMC evidence.",[37,6274,6275],{},"episki was built for exactly this workflow. episki turns NIST CSF into a live scorecard: you import or build a Current Profile, choose a Target Profile, and episki generates the initiatives, tasks, and evidence collection needed to close the gap — all mapped to your other frameworks automatically. If you are starting from scratch or migrating from NIST CSF 1.1 to NIST CSF 2.0, episki can help you skip the spreadsheet phase entirely.",[37,6277,6278],{},"Ready to operationalize the NIST Cybersecurity Framework? Start a trial, import your controls, and share a NIST CSF scorecard with leadership the same day.",[32,6280,244],{"id":243},[37,6282,6283,6284,254,6287,258],{},"episki maps all six CSF 2.0 functions to controls evaluated continuously across your connected estate, with the Govern function backed by structured ownership, risk treatments, and — for organizations adopting AI — an agent and use-case registry with allowlists and safety floors. Crosswalks to your other frameworks are derived through the SCF hub with a controlled relationship vocabulary and recorded provenance, so CSF work carries into ISO 27001, SOC 2, and PCI DSS rather than being duplicated. ",[249,6285,253],{"href":185,"rel":6286},[252],[249,6288,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":6290},[6291,6295,6296,6304,6305,6306,6307,6308,6309,6310,6311],{"id":5776,"depth":94,"text":5777,"children":6292},[6293,6294],{"id":5790,"depth":995,"text":5791},{"id":5804,"depth":995,"text":5805},{"id":5820,"depth":94,"text":5821},{"id":5875,"depth":94,"text":5876,"children":6297},[6298,6299,6300,6301,6302,6303],{"id":5885,"depth":995,"text":5886},{"id":5898,"depth":995,"text":5899},{"id":5912,"depth":995,"text":5913},{"id":5926,"depth":995,"text":5927},{"id":5940,"depth":995,"text":5941},{"id":5954,"depth":995,"text":5955},{"id":5971,"depth":94,"text":5972},{"id":6014,"depth":94,"text":6015},{"id":6055,"depth":94,"text":6056},{"id":6093,"depth":94,"text":6094},{"id":6122,"depth":94,"text":6123},{"id":6179,"depth":94,"text":6180},{"id":6224,"depth":94,"text":6225},{"id":243,"depth":94,"text":244},{"title":6313,"description":6314,"items":6315},"NIST CSF launch guide","Use episki’s free trial to benchmark, prioritize, and communicate fast.",[6316,6317,6318,6319,6320],"Baseline maturity assessment","Control library mapped to CSF categories","Initiative tracker with due dates and owners","Risk register tied to CSF outcomes","Executive report template",{"title":6322,"description":6323},"See your NIST CSF score in episki","Start the trial, import controls, and share a scorecard the same day.",{"title":6325,"items":6326},"NIST CSF frequently asked questions",[6327,6329,6332,6335,6338],{"label":5777,"content":6328},"The NIST Cybersecurity Framework (CSF) is a voluntary framework published by the National Institute of Standards and Technology that helps organizations manage and reduce cybersecurity risk. It provides a common language for understanding, managing, and expressing cybersecurity risk through five core functions.",{"label":6330,"content":6331},"What is the difference between NIST CSF and ISO 27001?","NIST CSF is a voluntary, outcome-focused maturity framework that helps organizations assess and improve their cybersecurity posture. ISO 27001 is a certifiable standard requiring a formal ISMS. Many organizations use NIST CSF as an internal maturity model alongside ISO 27001 certification for external assurance.",{"label":6333,"content":6334},"Is NIST CSF mandatory?","NIST CSF is voluntary for most private-sector organizations but is mandatory for US federal agencies under Executive Order 13800. Many industries and regulators reference it as a best-practice baseline, and customers increasingly expect suppliers to demonstrate alignment.",{"label":6336,"content":6337},"What are the NIST CSF implementation tiers?","The four tiers describe the maturity of an organization's cybersecurity risk management. Tier 1 (Partial) is ad hoc and reactive. Tier 2 (Risk-Informed) has some risk awareness. Tier 3 (Repeatable) has formal policies. Tier 4 (Adaptive) continuously improves based on lessons learned and threat intelligence.",{"label":6339,"content":6340},"How does NIST CSF relate to other compliance frameworks?","NIST CSF maps to many standards including SOC 2, ISO 27001, HIPAA, and PCI DSS. Organizations use it as a unifying layer to identify control gaps and overlaps across multiple compliance requirements, reducing duplicate work when pursuing multiple frameworks.",{"headline":6342,"title":6343,"description":6344,"links":6345},"Measure security maturity","Operationalize NIST CSF across Identify, Protect, Detect, Respond, and Recover","episki translates CSF categories into action plans with real-time scoring and executive reporting.",[6346,6348],{"label":6347,"icon":182,"to":185},"Start NIST CSF trial",{"label":176,"icon":6349,"color":183,"variant":184,"to":178,"target":179},"i-lucide-presentation",{},{"headline":6352,"title":6352,"description":6353,"items":6354},"NIST CSF toolset","Everything you need to show measurable progress.",[6355,6358,6361],{"title":6356,"description":6357},"Quarterly business review pack","Slides with KPIs, upcoming initiatives, and resource needs.",{"title":6359,"description":6360},"Customer assurance brief","Explains how NIST CSF maps to their requirements.",{"title":6362,"description":6363},"Automation cookbook","Step-by-step instructions for connecting your tooling.",{"title":6365,"description":6366},"NIST CSF Framework Software","Operationalize NIST CSF with live maturity scoring, risk registers, and executive dashboards. Benchmark and improve your cybersecurity posture with episki.","nistcsf",[6369,6372,6375],{"value":6370,"description":6371},"Live maturity score","Automated scoring by category, tier, and business unit.",{"value":6373,"description":6374},"Unified risk register","Link risks to CSF categories with AI-prioritized remediation.",{"value":6376,"description":6377},"Executive-ready","Dashboards turn security work into business milestones.","5.frameworks\u002Fnistcsf","pbH2Ff2CeX0rvq_75SSa3BaLUOU8nYSmM9OwlsF-9Vw",{"id":6381,"title":6382,"advantages":6383,"body":6405,"checklist":6554,"cta":6566,"description":93,"extension":151,"faq":6569,"hero":6586,"lastUpdated":186,"meta":6593,"name":6594,"navigation":188,"path":6595,"resources":6596,"seo":6610,"slug":6613,"stats":6614,"stem":6623,"__hash__":6624},"frameworks\u002F5.frameworks\u002Fnydfs.md","Nydfs",[6384,6391,6398],{"title":6385,"description":6386,"bullets":6387},"Second Amendment, fully covered","Every requirement phased in through November 1, 2025 — implemented as controls, not a checklist.",[6388,6389,6390],"Universal MFA (§500.12) and asset inventory (§500.13)","Expanded governance and senior-governing-body oversight","Class A enhanced requirements scoped when they apply",{"title":6392,"description":6393,"bullets":6394},"CISO program and reporting","The written program, policies, and CISO reporting the regulation requires — kept current automatically.",[6395,6396,6397],"Board\u002Fsenior-governing-body-approved policies","CISO written report to the governing body","Annual risk assessment tied to control treatments",{"title":6399,"description":6400,"bullets":6401},"Reporting and certification","Hit the 72-hour and ransomware-payment notification windows, and build the annual certification from real evidence.",[6402,6403,6404],"72-hour cybersecurity-event notification workflow","Ransomware extortion-payment reporting (24h \u002F 30-day)","§500.17 certification or acknowledgment with remediation plan",{"type":29,"value":6406,"toc":6545},[6407,6411,6418,6428,6430,6437,6444,6448,6459,6491,6493,6496,6500,6515,6519,6535,6537],[32,6408,6410],{"id":6409},"what-is-the-ny-dfs-cybersecurity-regulation","What is the NY DFS Cybersecurity Regulation?",[37,6412,6413,6414,6417],{},"The New York State Department of Financial Services (DFS) Cybersecurity Regulation — ",[53,6415,6416],{},"23 NYCRR Part 500"," — sets cybersecurity requirements for financial-services companies that DFS regulates. First effective on March 1, 2017, it was one of the first comprehensive, prescriptive state cybersecurity rules in the United States, and it became a template for later frameworks such as the NAIC Insurance Data Security Model Law.",[37,6419,6420,6421,6424,6425,258],{},"Part 500 is risk-based but specific: it requires a written cybersecurity program and policy, a designated Chief Information Security Officer (CISO), periodic risk assessments, and a defined set of technical and governance controls to protect Nonpublic Information (NPI). It also requires Covered Entities to ",[53,6422,6423],{},"report cybersecurity events to the DFS superintendent within 72 hours"," and to ",[53,6426,6427],{},"certify their compliance annually",[32,6429,1476],{"id":1475},[37,6431,6432,6433,6436],{},"The regulation applies to ",[53,6434,6435],{},"Covered Entities"," — any person or organization operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation, or similar authorization under New York's Banking Law, Insurance Law, or Financial Services Law. That includes NY-licensed banks, insurers, mortgage servicers, and money transmitters. Small entities can qualify for limited exemptions but still must meet a reduced subset of the requirements.",[37,6438,6439,6440,6443],{},"The Second Amendment introduced a ",[53,6441,6442],{},"Class A company"," tier — larger entities (generally at least $20M in NY-sourced gross annual revenue over three fiscal years, and either more than 2,000 employees or more than $1B in gross annual revenue averaged over two years, including affiliates) — which face enhanced obligations including independent audits, endpoint detection and response (EDR), and privileged access management (PAM).",[32,6445,6447],{"id":6446},"the-second-amendment","The Second Amendment",[37,6449,6450,6451,6454,6455,6458],{},"DFS adopted the ",[53,6452,6453],{},"Second Amendment to Part 500 on November 1, 2023",", with requirements phased in through ",[53,6456,6457],{},"November 1, 2025",". As of that final date, the amended regulation is fully in effect. The most significant additions:",[47,6460,6461,6467,6473,6479,6485],{},[50,6462,6463,6466],{},[53,6464,6465],{},"Multi-factor authentication for all access (§500.12)"," — MFA is now required for any individual accessing any information system of a Covered Entity, not just remote or privileged access.",[50,6468,6469,6472],{},[53,6470,6471],{},"Asset inventory (§500.13)"," — written policies and procedures to maintain a complete, accurate, documented inventory of information systems.",[50,6474,6475,6478],{},[53,6476,6477],{},"Stronger governance"," — the CISO must report on the cybersecurity program to the senior governing body, which is expected to exercise meaningful oversight; policies must be approved by the senior governing body or a senior officer.",[50,6480,6481,6484],{},[53,6482,6483],{},"Expanded incident reporting"," — in addition to the 72-hour cybersecurity-event notification, Covered Entities must notify DFS of an extortion (ransomware) payment within 24 hours and provide a written explanation within 30 days.",[50,6486,6487,6490],{},[53,6488,6489],{},"Class A enhanced requirements"," — independent audits, EDR, PAM, and more rigorous, expert-led risk assessments.",[32,6492,5221],{"id":5220},[37,6494,6495],{},"Part 500 covers the controls most security teams already recognize: a written program and policy (§§500.2–500.3), a CISO (§500.4), penetration testing and vulnerability assessments (§500.5), audit trails (§500.6), access privilege management (§500.7), application security (§500.8), risk assessment (§500.9), security personnel and training (§§500.10, 500.14), third-party service provider security policy (§500.11), MFA (§500.12), asset management and data retention (§500.13), monitoring and encryption of NPI (§500.15), an incident response and business continuity plan (§500.16), and notification plus the annual certification (§500.17).",[32,6497,6499],{"id":6498},"the-annual-certification","The annual certification",[37,6501,6502,6503,6506,6507,6510,6511,6514],{},"Each year, a Covered Entity must file a notice to DFS by ",[53,6504,6505],{},"April 15"," covering the prior calendar year — either a ",[53,6508,6509],{},"certification of material compliance"," or a ",[53,6512,6513],{},"written acknowledgment"," that identifies the areas of non-compliance and a remediation plan with timelines. The filing must be signed by the entity's highest-ranking executive and its CISO, and the entity must retain the records and documentation supporting it. A weak or undocumented certification is one of the most common sources of DFS enforcement exposure.",[32,6516,6518],{"id":6517},"how-ny-dfs-maps-to-other-frameworks","How NY DFS maps to other frameworks",[37,6520,6521,6522,6525,6526,6528,6529,6531,6532,6534],{},"Most Part 500 requirements overlap heavily with controls you may already maintain. For US insurers and carriers, the ",[53,6523,6524],{},"NAIC Insurance Data Security Model Law"," is the closest parallel, and the ",[249,6527,470],{"href":469}," Annex A controls, ",[249,6530,475],{"href":474}," Trust Services Criteria, and ",[249,6533,465],{"href":464}," outcomes cover the large majority of Part 500 technical and governance requirements. Mapping NYDFS to a shared control set means a single piece of evidence — an access review, a pen-test report, a risk assessment — can satisfy multiple programs at once.",[32,6536,244],{"id":243},[37,6538,6539,6540,254,6543,258],{},"episki carries 23 NYCRR 500 obligations as structured, evaluated controls: access and MFA posture checked from live identity evidence, encryption and monitoring evaluated per account and region, incident findings with owners and reporting clocks, and third-party service providers tracked with advancing review cadences. Certification inputs accumulate continuously rather than being assembled annually. ",[249,6541,253],{"href":185,"rel":6542},[252],[249,6544,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":6546},[6547,6548,6549,6550,6551,6552,6553],{"id":6409,"depth":94,"text":6410},{"id":1475,"depth":94,"text":1476},{"id":6446,"depth":94,"text":6447},{"id":5220,"depth":94,"text":5221},{"id":6498,"depth":94,"text":6499},{"id":6517,"depth":94,"text":6518},{"id":243,"depth":94,"text":244},{"title":6555,"description":6556,"items":6557},"NY DFS Part 500 readiness inside episki","What a New York-regulated financial institution needs preloaded.",[6558,6559,6560,6561,6562,6563,6564,6565],"Written cybersecurity program and policies (§500.2, §500.3)","CISO designation and annual written report (§500.4)","Risk assessment kept current (§500.9)","Multi-factor authentication across all access (§500.12)","Asset inventory policies and procedures (§500.13)","Incident response and BCDR plans (§500.16)","72-hour cybersecurity-event reporting (§500.17(a))","Annual certification of material compliance (§500.17(b))",{"title":6567,"description":6568},"Build a defensible Part 500 program in episki","Implement 23 NYCRR 500 once, report on time, and reuse the evidence across NAIC, ISO 27001, and SOC 2.",{"title":6570,"items":6571},"NY DFS Part 500 frequently asked questions",[6572,6574,6577,6580,6583],{"label":6410,"content":6573},"23 NYCRR Part 500 is a cybersecurity regulation issued by the New York State Department of Financial Services (DFS). First effective March 1, 2017, it was one of the first comprehensive state cybersecurity rules for financial services and has influenced later standards such as the NAIC Insurance Data Security Model Law. It requires Covered Entities to maintain a risk-based cybersecurity program, designate a CISO, and report cybersecurity events to the DFS.",{"label":6575,"content":6576},"Who is a Covered Entity?","Any individual or organization operating under (or required to operate under) a license, registration, charter, certificate, permit, accreditation, or similar authorization under New York's Banking Law, Insurance Law, or Financial Services Law — for example NY-licensed banks, insurers, mortgage companies, and money transmitters. Limited exemptions exist for very small entities, but even exempt entities must meet a reduced subset of requirements.",{"label":6578,"content":6579},"What changed in the Second Amendment?","The Second Amendment was adopted November 1, 2023 and phased in through November 1, 2025. It added universal multi-factor authentication (§500.12) and documented asset-inventory requirements (§500.13), strengthened governance and senior-governing-body oversight, expanded incident reporting (including ransomware-payment notification), and created a 'Class A company' tier with enhanced requirements. As of November 1, 2025 all phased requirements are in effect.",{"label":6581,"content":6582},"What is a Class A company?","A larger Covered Entity subject to enhanced requirements — generally those with at least $20 million in gross annual revenue from New York operations over the last three fiscal years and either more than 2,000 employees or more than $1 billion in gross annual revenue (averaged over the last two years, including affiliates). Class A companies must perform independent audits, deploy endpoint detection and response and privileged access management, and conduct more rigorous risk assessments.",{"label":6584,"content":6585},"When is the annual certification due?","Covered Entities must file an annual notice to the DFS by April 15 — either a certification of material compliance for the prior calendar year or a written acknowledgment of non-compliance that identifies the gaps and includes a remediation timeline. It must be signed by the highest-ranking executive and the CISO.",{"headline":6587,"title":6588,"description":6589,"links":6590},"NY DFS Part 500, without the binder","Comply with the NY DFS Cybersecurity Regulation","A written cybersecurity program, MFA and asset inventory under the Second Amendment, 72-hour incident reporting, and a defensible annual certification — all driven by live control evidence.",[6591,6592],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"NY DFS Part 500","\u002Fframeworks\u002Fnydfs",{"headline":6597,"title":6598,"description":6599,"items":6600},"NY DFS accelerators","Part 500 program accelerators","Stand up a defensible NYDFS program and reuse the work across your other obligations.",[6601,6604,6607],{"title":6602,"description":6603},"Certification builder","Assemble the §500.17 certification (or acknowledgment of non-compliance with a remediation plan) from live control evidence.",{"title":6605,"description":6606},"Reporting timers","72-hour cybersecurity-event and ransomware-payment notification clocks with owner assignment.",{"title":6608,"description":6609},"NAIC \u002F ISO 27001 crosswalk","Reuse NYDFS evidence against the NAIC Model Law, ISO 27001, and SOC 2.",{"title":6611,"description":6612},"NY DFS 23 NYCRR Part 500 Compliance Software","Meet the New York DFS Cybersecurity Regulation (23 NYCRR Part 500) — CISO program, MFA, asset inventory, 72-hour reporting, and the annual certification — in one workspace.","nydfs",[6615,6618,6620],{"value":6616,"description":6617},"23 NYCRR 500","The full NYDFS Cybersecurity Regulation implemented as living episki controls.",{"value":2856,"description":6619},"Cybersecurity-event reporting to the DFS superintendent tracked with deadline timers.",{"value":6621,"description":6622},"Annual cert","Section 500.17 certification of material compliance, evidenced and ready to sign by April 15.","5.frameworks\u002Fnydfs","1YIJuafIXlQyofuLEWVVYGDP3oNUBOvioyifgBjDt0w",{"id":6626,"title":6627,"advantages":6628,"body":6650,"checklist":7081,"cta":7090,"description":93,"extension":151,"faq":7093,"hero":7111,"lastUpdated":186,"meta":7119,"name":6662,"navigation":188,"path":7120,"resources":7121,"seo":7134,"slug":7137,"stats":7138,"stem":7148,"__hash__":7149},"frameworks\u002F5.frameworks\u002Fpci.md","Pci",[6629,6636,6643],{"title":6630,"description":6631,"bullets":6632},"Cardholder data mapped","Visualize systems, networks, and data flows tied to each DSS requirement.",[6633,6634,6635],"Track segmentation documentation and approvals","Connect SIEM and log tools for retention evidence","Link vulnerability scans and pen tests to controls",{"title":6637,"description":6638,"bullets":6639},"Task orchestration for engineering","Send prioritized remediation tasks to Jira or Linear with context.",[6640,6641,6642],"Auto-created tickets with required evidence","SLA tracking ensures high-risk remediations close on time","Change management logs sync back automatically",{"title":6644,"description":6645,"bullets":6646},"QSA-ready collaboration","Centralize requests, walkthroughs, and findings with secure file sharing.",[6647,6648,6649],"QSA comments resolve next to each control","Expiring links for sensitive diagrams","Exportable ROC narrative drafts",{"type":29,"value":6651,"toc":7067},[6652,6656,6664,6667,6670,6674,6682,6770,6773,6777,6784,6788,6801,6805,6813,6866,6878,6882,6893,6896,6899,6903,6920,6924,6927,6965,6973,6977,6980,6984,6997,7001,7004,7054,7057,7059],[32,6653,6655],{"id":6654},"what-is-pci-dss","What is PCI DSS?",[37,6657,6658,6659,6663],{},"The Payment Card Industry Data Security Standard -- universally known as ",[249,6660,6662],{"href":6661},"\u002Fglossary\u002Fpci-dss","PCI DSS"," -- is the global baseline for protecting payment card data. Any organization that stores, processes, or transmits cardholder data is expected to meet PCI DSS, from a mom-and-pop e-commerce store to a Fortune 500 retailer and every payment processor in between. PCI DSS exists because card data is one of the most monetizable targets on the internet, and a single breach can expose millions of account numbers, trigger steep fines, and end businesses. PCI DSS translates decades of hard-won lessons into a prescriptive framework that security, engineering, and finance teams can operationalize.",[37,6665,6666],{},"PCI DSS is maintained by the Payment Card Industry Security Standards Council (PCI SSC), an independent standards body founded in 2006 by the five major payment brands: Visa, Mastercard, American Express, Discover, and JCB. The PCI SSC writes and publishes the standard, accredits assessors and scanning vendors, and runs supporting programs such as PA-DSS (now replaced by the PCI Secure Software Standard) and P2PE. While the PCI SSC owns the standard itself, it does not enforce PCI DSS. Enforcement is delegated to the card brands, which in turn push obligations down through acquiring banks and payment processors to merchants and service providers. In practice, your acquirer is the entity that tells you which PCI DSS validation path you owe and what happens if you fail it.",[37,6668,6669],{},"PCI DSS emerged from a patchwork of brand-specific programs in the early 2000s, including Visa's Cardholder Information Security Program (CISP) and Mastercard's Site Data Protection (SDP). PCI DSS v1.0 launched in December 2004. PCI DSS v2.0 arrived in 2010, v3.0 in 2013, v3.1 in 2015, v3.2 in 2016, v3.2.1 in 2018, and the long-anticipated PCI DSS v4.0 in March 2022, followed by v4.0.1 clarifications in June 2024 (v4.0 was retired at the end of 2024, leaving v4.0.1 as the only active version). The \"future-dated\" PCI DSS v4.x requirements became mandatory on March 31, 2025. Each revision tightens controls around emerging threats: phishing-resistant authentication, e-commerce script tampering, automated log review, and customized approaches for mature security programs.",[32,6671,6673],{"id":6672},"the-12-pci-dss-requirements","The 12 PCI DSS requirements",[37,6675,6676,6677,6681],{},"PCI DSS organizes technical and operational controls across twelve core requirements grouped into six objectives. The full set of PCI DSS requirements is detailed on the ",[249,6678,6680],{"href":6679},"\u002Fframeworks\u002Fpci\u002Frequirements","PCI DSS requirements page","; at a glance they are:",[903,6683,6684,6694,6700,6716,6722,6728,6734,6740,6746,6752,6758,6764],{},[50,6685,6686,6689,6690,258],{},[53,6687,6688],{},"Install and maintain network security controls"," -- firewalls and equivalent controls around the ",[249,6691,6693],{"href":6692},"\u002Fglossary\u002Fcardholder-data-environment","cardholder data environment",[50,6695,6696,6699],{},[53,6697,6698],{},"Apply secure configurations to all system components"," -- hardening standards, default credential elimination, and secure build baselines.",[50,6701,6702,6705,6706,6710,6711,6715],{},[53,6703,6704],{},"Protect stored account data"," -- encryption, truncation, hashing, or ",[249,6707,6709],{"href":6708},"\u002Fglossary\u002Ftokenization","tokenization"," of the ",[249,6712,6714],{"href":6713},"\u002Fglossary\u002Fpan","PAN"," and prohibition on storing sensitive authentication data.",[50,6717,6718,6721],{},[53,6719,6720],{},"Protect cardholder data with strong cryptography during transmission"," over open, public networks.",[50,6723,6724,6727],{},[53,6725,6726],{},"Protect all systems and networks from malicious software"," -- anti-malware on in-scope systems and defenses against script-based threats.",[50,6729,6730,6733],{},[53,6731,6732],{},"Develop and maintain secure systems and software"," -- secure SDLC, patching, and vulnerability management for in-scope systems.",[50,6735,6736,6739],{},[53,6737,6738],{},"Restrict access to system components and cardholder data by business need to know"," -- least-privilege role design.",[50,6741,6742,6745],{},[53,6743,6744],{},"Identify users and authenticate access to system components"," -- unique IDs, strong authentication, and phishing-resistant MFA.",[50,6747,6748,6751],{},[53,6749,6750],{},"Restrict physical access to cardholder data"," -- physical security for facilities, media, and devices.",[50,6753,6754,6757],{},[53,6755,6756],{},"Log and monitor all access to system components and cardholder data"," -- centralized logging, daily review, and tamper protection.",[50,6759,6760,6763],{},[53,6761,6762],{},"Test security of systems and networks regularly"," -- ASV scans, internal scans, pen tests, and segmentation validation.",[50,6765,6766,6769],{},[53,6767,6768],{},"Support information security with organizational policies and programs"," -- governance, awareness, incident response, and third-party oversight.",[37,6771,6772],{},"Each PCI DSS requirement is broken into numbered sub-requirements with explicit testing procedures that an assessor follows line by line. The \"defined approach\" dictates specific controls; PCI DSS v4.0 also introduces a \"customized approach\" where mature organizations can meet a requirement's objective through alternative controls, documented in a controls matrix and targeted risk analysis.",[32,6774,6776],{"id":6775},"pci-dss-v40-changes","PCI DSS v4.0 changes",[37,6778,6779,6780,258],{},"PCI DSS v4.0 is the largest revision in more than a decade. Its headline shifts include a customized-approach validation path, mandatory multi-factor authentication for all access into the CDE, expanded requirements to detect and respond to e-commerce script tampering, targeted risk analyses replacing prescriptive frequencies, and stronger expectations for continuous security rather than point-in-time compliance. Several of the most material v4.0 controls became mandatory on March 31, 2025 after a two-year grace period. The full changelog, new testing procedures, and a migration checklist are covered in the ",[249,6781,6783],{"href":6782},"\u002Fframeworks\u002Fpci\u002Fv4-changes","PCI DSS v4.0 changes guide",[32,6785,6787],{"id":6786},"merchant-compliance-levels-1-4","Merchant compliance levels 1-4",[37,6789,6790,6791,6795,6796,6800],{},"Every merchant is assigned to one of four PCI DSS compliance levels based on annual card transaction volume across all channels. PCI DSS Level 1 covers merchants processing more than 6 million transactions per year and requires a formal Report on Compliance (ROC) signed by a ",[249,6792,6794],{"href":6793},"\u002Fglossary\u002Fqsa","QSA",". Level 2 covers 1-6 million transactions. Level 3 covers 20,000 to 1 million e-commerce transactions. Level 4 covers everything below those thresholds. Service providers have their own two-level structure. Your acquiring bank can also assign you a higher PCI DSS level at its discretion -- particularly after a breach. The ",[249,6797,6799],{"href":6798},"\u002Fframeworks\u002Fpci\u002Fcompliance-levels","PCI DSS compliance levels page"," breaks down every threshold by card brand and the validation path each level owes.",[32,6802,6804],{"id":6803},"self-assessment-questionnaires-saqs","Self-Assessment Questionnaires (SAQs)",[37,6806,6807,6808,6812],{},"Merchants and service providers that are not required to complete a full PCI DSS Report on Compliance validate using a ",[249,6809,6811],{"href":6810},"\u002Fglossary\u002Fsaq","Self-Assessment Questionnaire",", or SAQ. The PCI SSC publishes nine SAQ types, each tailored to a specific acceptance channel and technology profile:",[47,6814,6815,6821,6827,6833,6839,6845,6851,6857],{},[50,6816,6817,6820],{},[53,6818,6819],{},"SAQ A"," -- card-not-present merchants that fully outsource all cardholder data functions.",[50,6822,6823,6826],{},[53,6824,6825],{},"SAQ A-EP"," -- e-commerce merchants that partially outsource payment processing but host pages that could affect payment page security.",[50,6828,6829,6832],{},[53,6830,6831],{},"SAQ B"," -- merchants using only imprint machines or standalone dial-out terminals.",[50,6834,6835,6838],{},[53,6836,6837],{},"SAQ B-IP"," -- merchants using only standalone IP-connected POI devices.",[50,6840,6841,6844],{},[53,6842,6843],{},"SAQ C-VT"," -- merchants entering transactions into a virtual payment terminal.",[50,6846,6847,6850],{},[53,6848,6849],{},"SAQ C"," -- merchants with payment application systems connected to the internet.",[50,6852,6853,6856],{},[53,6854,6855],{},"SAQ P2PE"," -- merchants using PCI-listed point-to-point encryption solutions.",[50,6858,6859,392,6862,6865],{},[53,6860,6861],{},"SAQ D for Merchants",[53,6863,6864],{},"SAQ D for Service Providers"," -- the catch-all SAQs for entities that store cardholder data or do not qualify for a simpler SAQ.",[37,6867,6868,6869,1123,6873,6877],{},"Eligibility is narrow and precise. Picking the wrong SAQ is one of the most common PCI DSS mistakes -- and one that an acquiring bank or breach investigation can expose instantly. The ",[249,6870,6872],{"href":6871},"\u002Fframeworks\u002Fpci\u002Fself-assessment-questionnaire","SAQ reference",[249,6874,6876],{"href":6875},"\u002Fframeworks\u002Fpci\u002Fsaq-types-explained","SAQ types explained"," page walk through each SAQ's eligibility, question count, and typical pitfalls.",[32,6879,6881],{"id":6880},"cardholder-data-environment-cde-and-scoping","Cardholder data environment (CDE) and scoping",[37,6883,6884,6885,6887,6888,6892],{},"Every PCI DSS program begins with scoping. The ",[249,6886,6693],{"href":6692},", or CDE, is the set of people, processes, and technologies that store, process, or transmit cardholder data or sensitive authentication data, plus any system component that is connected to or could impact the security of those components. Determining what is in ",[249,6889,6891],{"href":6890},"\u002Fglossary\u002Fpci-scope","PCI scope"," is the single highest-leverage activity in a PCI DSS program -- it drives how many controls apply, how much evidence you collect, and how much your QSA engagement costs.",[37,6894,6895],{},"PCI DSS scoping has three categories: CDE systems that directly handle card data; connected-to systems that can route traffic to the CDE, authenticate CDE users, or otherwise interact with CDE components; and security-impacting systems that could affect CDE security even without direct connectivity (think SIEM, patch management, or anti-malware consoles). All three categories are in scope for PCI DSS.",[37,6897,6898],{},"Document your CDE with an annotated network diagram and a data-flow diagram for every payment channel. PCI DSS v4.0 makes these diagrams a requirement, not a nice-to-have, and your assessor will test them during every assessment.",[32,6900,6902],{"id":6901},"scope-reduction-strategies","Scope reduction strategies",[37,6904,6905,6906,6910,6911,6915,6916,6919],{},"Because PCI DSS obligations scale with the CDE, shrinking the CDE is the fastest way to cut PCI DSS cost and risk. Effective ",[249,6907,6909],{"href":6908},"\u002Fframeworks\u002Fpci\u002Fscope-reduction","PCI DSS scope reduction"," typically combines four levers: strong ",[249,6912,6914],{"href":6913},"\u002Fframeworks\u002Fpci\u002Fnetwork-segmentation","network segmentation"," that isolates the CDE onto dedicated VLANs with tightly controlled firewall rules; ",[249,6917,6709],{"href":6918},"\u002Fframeworks\u002Fpci\u002Ftokenization-vs-encryption"," that replaces stored PANs with non-sensitive surrogates; PCI-listed point-to-point encryption (P2PE) that removes in-store networks from PCI scope; and outsourcing card capture to a validated service provider so your systems never touch real card data. Layered correctly, these strategies can reduce a PCI DSS assessment from hundreds of in-scope systems to a handful.",[32,6921,6923],{"id":6922},"key-pci-dss-roles-qsas-asvs-and-isas","Key PCI DSS roles: QSAs, ASVs, and ISAs",[37,6925,6926],{},"Three accredited roles support every PCI DSS program:",[47,6928,6929,6944,6959],{},[50,6930,6931,6938,6939,6943],{},[53,6932,6933,6934,6937],{},"Qualified Security Assessors (",[249,6935,6936],{"href":6793},"QSAs",")"," -- individuals and firms certified by the PCI SSC to perform on-site PCI DSS assessments, produce the ROC, and sign the Attestation of Compliance. Selecting the right QSA shapes your PCI DSS experience for years; the ",[249,6940,6942],{"href":6941},"\u002Fframeworks\u002Fpci\u002Fqsa-selection","QSA selection guide"," covers how to evaluate firms, cost drivers, and red flags.",[50,6945,6946,6953,6954,6958],{},[53,6947,6948,6949,6937],{},"Approved Scanning Vendors (",[249,6950,6952],{"href":6951},"\u002Fglossary\u002Fasv","ASVs"," -- PCI SSC-approved firms that run the quarterly external vulnerability scans required by PCI DSS Requirement 11.3.2. The ",[249,6955,6957],{"href":6956},"\u002Fframeworks\u002Fpci\u002Fasv-program","ASV program guide"," covers vendor selection, scanning cadence, passing thresholds, and remediation workflows.",[50,6960,6961,6964],{},[53,6962,6963],{},"Internal Security Assessors (ISAs)"," -- employees who have completed PCI SSC training and can complete certain internal PCI DSS assessments or support a QSA engagement. ISAs are a cost-effective way to build PCI DSS capability inside large programs.",[37,6966,6967,6968,6972],{},"Penetration testing (Requirement 11.4) sits alongside ASV scanning and is a frequent source of PCI DSS findings. The ",[249,6969,6971],{"href":6970},"\u002Fframeworks\u002Fpci\u002Fpenetration-testing","PCI DSS penetration testing guide"," covers internal vs external scope, segmentation testing, and frequency.",[32,6974,6976],{"id":6975},"penalties-for-non-compliance","Penalties for non-compliance",[37,6978,6979],{},"PCI DSS is not law, but non-compliance carries material financial consequences. Acquirers can levy fines of $5,000 to $100,000 per month for PCI DSS violations, pass fines down to merchants, raise transaction fees, or revoke payment processing privileges outright. After a confirmed breach of card data, a merchant typically faces a forensic PFI investigation, card brand fines, assessments for fraud losses, reissuance costs for compromised cards, and mandatory Level 1 PCI DSS validation going forward. Regulators and state attorneys general may also get involved, and the organization almost always faces litigation. In short, PCI DSS fines are rarely the largest line item -- the true cost of a breach is reputational damage, customer churn, and the fully loaded cost of breach response.",[32,6981,6983],{"id":6982},"pci-dss-vs-other-frameworks","PCI DSS vs other frameworks",[37,6985,6986,6987,6991,6992,6996],{},"PCI DSS is narrower and more prescriptive than most security frameworks. ISO 27001 is a management-system standard focused on the process of running an ISMS; it tells you how to manage risk but does not specify controls the way PCI DSS does. SOC 2 is an attestation framework where you define your own controls against the Trust Services Criteria; PCI DSS prescribes them. HIPAA and HITECH cover protected health information, not cardholder data. NIST CSF and NIST SP 800-53 offer control catalogues and risk management guidance that many organizations map into their PCI DSS program, especially under the v4.0 customized approach. PCI DSS is also one of the few frameworks with ongoing external validation -- ASV scans every quarter, penetration tests at least annually, and a full assessment every year. For businesses in the ",[249,6988,6990],{"href":6989},"\u002Findustry\u002Ffinance","finance industry"," or running ",[249,6993,6995],{"href":6994},"\u002Findustry\u002Fecommerce","e-commerce"," platforms, PCI DSS almost always becomes the binding constraint that the rest of the security program organizes around.",[32,6998,7000],{"id":6999},"getting-pci-compliant","Getting PCI compliant",[37,7002,7003],{},"A typical path to PCI DSS compliance looks like this:",[903,7005,7006,7012,7018,7024,7030,7036,7042,7048],{},[50,7007,7008,7011],{},[53,7009,7010],{},"Define scope"," -- inventory every place card data lives, moves, or could move. Produce annotated network and data-flow diagrams.",[50,7013,7014,7017],{},[53,7015,7016],{},"Reduce scope"," -- apply segmentation, tokenization, P2PE, and outsourcing to shrink the CDE before assessment.",[50,7019,7020,7023],{},[53,7021,7022],{},"Select your validation path"," -- confirm your PCI DSS level with your acquirer and determine whether you owe a ROC or an SAQ.",[50,7025,7026,7029],{},[53,7027,7028],{},"Gap assess"," -- map your current controls to every applicable PCI DSS requirement and prioritize remediation.",[50,7031,7032,7035],{},[53,7033,7034],{},"Remediate and document"," -- close gaps, write the policies and procedures PCI DSS expects, and stand up the logging, monitoring, scanning, and testing programs.",[50,7037,7038,7041],{},[53,7039,7040],{},"Engage your QSA or ASV"," -- commission the ASV scans, book the penetration test, and (for Level 1) schedule your QSA engagement early enough to allow remediation cycles.",[50,7043,7044,7047],{},[53,7045,7046],{},"Validate and attest"," -- produce the ROC or SAQ plus Attestation of Compliance, and submit to your acquirer on the required cadence.",[50,7049,7050,7053],{},[53,7051,7052],{},"Operate continuously"," -- PCI DSS v4.0 expects continuous monitoring, targeted risk analyses, and evidence that controls stay effective between assessments.",[37,7055,7056],{},"episki automates the bulk of the evidence collection, control testing, and QSA collaboration work so your PCI DSS program is audit-ready year-round instead of scrambling at the end of each cycle. If you are starting a new PCI DSS program or rebuilding an existing one, episki can shorten your path from scoping through Report on Compliance.",[32,7058,244],{"id":243},[37,7060,7061,7062,254,7065,258],{},"episki ships full-fidelity PCI DSS ROC and SAQ assessments with an in-app report, summary matrix, and export — and makes the cardholder data environment an enforceable boundary rather than a diagram. Scope targets carry rules on cloud account, region, resource, and tag, and every record collected from AWS is stamped with the account, region, and provider it came from, so out-of-scope systems cannot contribute evidence to an in-scope control. Controls are evaluated on every sync, failing checks become findings, and a formally accepted condition becomes an exception with an approver and an expiry. ",[249,7063,253],{"href":185,"rel":7064},[252],[249,7066,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":7068},[7069,7070,7071,7072,7073,7074,7075,7076,7077,7078,7079,7080],{"id":6654,"depth":94,"text":6655},{"id":6672,"depth":94,"text":6673},{"id":6775,"depth":94,"text":6776},{"id":6786,"depth":94,"text":6787},{"id":6803,"depth":94,"text":6804},{"id":6880,"depth":94,"text":6881},{"id":6901,"depth":94,"text":6902},{"id":6922,"depth":94,"text":6923},{"id":6975,"depth":94,"text":6976},{"id":6982,"depth":94,"text":6983},{"id":6999,"depth":94,"text":7000},{"id":243,"depth":94,"text":244},{"title":7082,"description":7083,"items":7084},"PCI DSS playbook","Follow structured milestones from scoping through ROC submission.",[7085,7086,7087,7088,7089],"Automated scope confirmation questionnaires","Connector-backed logging and monitoring checks","Quarterly vulnerability and penetration testing tracker","Change-management evidence capture","ROC narrative template and artifact index",{"title":7091,"description":7092},"Keep PCI DSS audit-ready around the clock","Spin up your trial, sync evidence, and invite your QSA in a single day.",{"title":7094,"items":7095},"PCI DSS frequently asked questions",[7096,7099,7102,7105,7108],{"label":7097,"content":7098},"What are the PCI DSS compliance levels?","PCI DSS has four merchant levels based on annual transaction volume. Level 1 (over 6 million transactions) requires a formal Report on Compliance by a QSA. Levels 2-4 may self-assess using the appropriate Self-Assessment Questionnaire (SAQ). Service providers have two levels with different validation requirements.",{"label":7100,"content":7101},"What changed in PCI DSS 4.0?","PCI DSS 4.0 introduced a customized validation approach allowing organizations to meet objectives with alternative controls, expanded multi-factor authentication requirements, strengthened e-commerce and phishing protections, and added emphasis on continuous security rather than point-in-time compliance.",{"label":7103,"content":7104},"Who needs PCI DSS compliance?","Any organization that stores, processes, or transmits cardholder data must comply with PCI DSS. This includes merchants, payment processors, acquirers, issuers, and service providers. The scope is determined by your cardholder data environment (CDE).",{"label":7106,"content":7107},"How often is a PCI DSS assessment required?","PCI DSS assessments are required annually. Level 1 merchants and service providers must complete a formal assessment by a Qualified Security Assessor (QSA). Additionally, quarterly network vulnerability scans by an Approved Scanning Vendor (ASV) are required.",{"label":7109,"content":7110},"What is a cardholder data environment (CDE)?","The CDE includes all people, processes, and technologies that store, process, or transmit cardholder data or sensitive authentication data, plus any systems connected to those components. Accurate CDE scoping is the foundation of an efficient PCI DSS assessment.",{"headline":7112,"title":7113,"description":7114,"links":7115},"PCI controls that stay current","Keep PCI DSS requirements passing even as your CDE evolves","episki maps DSS requirements, automates testing, and keeps QSAs collaborating in one secure workspace.",[7116,7118],{"label":7117,"icon":182,"to":185},"Start PCI trial",{"label":176,"icon":177,"color":183,"variant":184,"to":178,"target":179},{},"\u002Fframeworks\u002Fpci",{"headline":7122,"title":7122,"description":7123,"items":7124},"PCI enablement kit","Give leadership, ops, and QSAs a single source of truth.",[7125,7128,7131],{"title":7126,"description":7127},"CDE architecture report","Share sanitized diagrams and segmentation notes with prospects.",{"title":7129,"description":7130},"Risk and remediation digest","Weekly summary of open items, owners, and due dates.",{"title":7132,"description":7133},"Assessor workspace","Prebuilt template keeps every requirement, artifact, and note aligned.",{"title":7135,"description":7136},"PCI DSS Compliance Tool","Automate PCI DSS evidence collection, manage QSA collaboration, and keep cardholder data controls current. Start your free 14-day trial with episki.","pci",[7139,7142,7145],{"value":7140,"description":7141},"90% automation","Evidence coverage across access, logging, segmentation, and monitoring.",{"value":7143,"description":7144},"QSA portal","Scoped access keeps your assessor in sync without endless spreadsheets.",{"value":7146,"description":7147},"Weekly drift checks","Automated alerts highlight misconfigurations before audits.","5.frameworks\u002Fpci","Mup07EF6TnV6ttfk4AYegXujpDJBZQ-6KdRTXm7xPKQ",{"id":7151,"title":7152,"advantages":7153,"body":7174,"checklist":7258,"cta":7268,"description":93,"extension":151,"faq":7271,"hero":7285,"lastUpdated":186,"meta":7292,"name":7293,"navigation":188,"path":7294,"resources":7295,"seo":7308,"slug":7311,"stats":7312,"stem":7321,"__hash__":7322},"frameworks\u002F5.frameworks\u002Fpipeda.md","Pipeda",[7154,7161,7168],{"title":7155,"description":7156,"bullets":7157},"The 10 fair information principles","PIPEDA's principles, from accountability to consent, as controls.",[7158,7159,7160],"Accountability and identified purposes","Consent, limiting collection, and use","Accuracy, safeguards, and openness",{"title":7162,"description":7163,"bullets":7164},"Rights and breach handling","Access requests and breach reporting handled on time.",[7165,7166,7167],"Individual access and correction requests","Real-risk-of-significant-harm assessment","OPC and individual breach notification",{"title":5007,"description":7169,"bullets":7170},"PIPEDA overlaps heavily with GDPR and CCPA.",[7171,7172,7173],"Crosswalk to GDPR and CCPA","Records of processing reused","Aligns with Quebec Law 25 and provincial PIPA",{"type":29,"value":7175,"toc":7252},[7176,7180,7197,7201,7220,7224,7242,7244],[32,7177,7179],{"id":7178},"what-is-pipeda","What is PIPEDA?",[37,7181,367,7182,5023,7185,7188,7189,7192,7193,7196],{},[53,7183,7184],{},"Personal Information Protection and Electronic Documents Act (PIPEDA)",[53,7186,7187],{},"Canada's federal private-sector privacy law",". It governs how organizations collect, use, and disclose personal information in the course of commercial activity, and it is enforced by the ",[53,7190,7191],{},"Office of the Privacy Commissioner of Canada (OPC)",". At its core are ",[53,7194,7195],{},"10 fair information principles",": accountability; identifying purposes; consent; limiting collection; limiting use, disclosure, and retention; accuracy; safeguards; openness; individual access; and challenging compliance.",[32,7198,7200],{"id":7199},"is-pipeda-changing","Is PIPEDA changing?",[37,7202,7203,7204,7207,7208,7211,7212,7215,7216,7219],{},"There has been a long effort to modernize Canadian privacy law through ",[53,7205,7206],{},"Bill C-27",", which would have replaced PIPEDA's private-sector provisions with the ",[53,7209,7210],{},"Consumer Privacy Protection Act (CPPA)"," and introduced an AI statute (AIDA). That bill ",[53,7213,7214],{},"died on the Order Paper when Parliament was prorogued in January 2025",". As a result, ",[53,7217,7218],{},"PIPEDA remains the law in force in 2026",", and organizations should keep complying with it while watching for future reform.",[32,7221,7223],{"id":7222},"breach-reporting-and-provincial-laws","Breach reporting and provincial laws",[37,7225,7226,7227,7230,7231,7234,7235,1123,7238,7241],{},"Since November 2018, organizations must ",[53,7228,7229],{},"report breaches that pose a real risk of significant harm"," to affected individuals and to the OPC, and keep records of all breaches. Several provinces have their own ",[53,7232,7233],{},"substantially similar"," laws — notably ",[53,7236,7237],{},"Quebec's Law 25",[53,7239,7240],{},"PIPA"," statutes in British Columbia and Alberta — which can apply in place of PIPEDA within those provinces.",[32,7243,244],{"id":243},[37,7245,7246,7247,254,7250,258],{},"episki maps PIPEDA's ten fair information principles to structured records and evaluated controls: consent and purpose documented, safeguards checked continuously from live evidence, and access requests tracked with owners and due dates. Service providers are vendor records with advancing review cadences. ",[249,7248,253],{"href":185,"rel":7249},[252],[249,7251,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":7253},[7254,7255,7256,7257],{"id":7178,"depth":94,"text":7179},{"id":7199,"depth":94,"text":7200},{"id":7222,"depth":94,"text":7223},{"id":243,"depth":94,"text":244},{"title":7259,"description":7260,"items":7261},"PIPEDA readiness inside episki","What an organization handling Canadian personal data needs.",[7262,7263,7264,7265,7266,7267],"Privacy policy and designated accountable individual","Consent and identified-purposes management","Personal information inventory and retention limits","Safeguards proportionate to sensitivity","Access and correction request workflow","Breach assessment and Privacy Commissioner notification",{"title":7269,"description":7270},"Build a PIPEDA program in episki","Implement the fair information principles once and reuse the work for GDPR and CCPA.",{"title":7272,"items":7273},"PIPEDA frequently asked questions",[7274,7276,7279,7282],{"label":7179,"content":7275},"The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada's federal private-sector privacy law. It governs how organizations collect, use, and disclose personal information in the course of commercial activity, and is built on 10 fair information principles, overseen by the Office of the Privacy Commissioner of Canada (OPC).",{"label":7277,"content":7278},"Is PIPEDA being replaced?","Not currently. Bill C-27 — which would have replaced PIPEDA's private-sector provisions with the Consumer Privacy Protection Act (CPPA) and added an AI law (AIDA) — died on the Order Paper when Parliament was prorogued in January 2025. PIPEDA remains the law in force in 2026, and organizations should continue to comply with it.",{"label":7280,"content":7281},"Does PIPEDA require breach reporting?","Yes. Since November 2018, organizations must report breaches that pose a real risk of significant harm to affected individuals and to the Office of the Privacy Commissioner, and keep records of all breaches.",{"label":7283,"content":7284},"How does PIPEDA relate to GDPR and provincial laws?","PIPEDA shares core principles with the GDPR, so much of a GDPR program carries over. Several provinces have their own substantially similar laws — notably Quebec's Law 25 and the PIPA statutes in British Columbia and Alberta — which can apply instead of PIPEDA in those provinces.",{"headline":7286,"title":7287,"description":7288,"links":7289},"Canadian privacy, operationalized","Comply with Canada's PIPEDA","The 10 fair information principles as living controls, consent and access-request workflows, and breach reporting to the Privacy Commissioner — mapped to GDPR and CCPA.",[7290,7291],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"PIPEDA","\u002Fframeworks\u002Fpipeda",{"headline":7296,"title":7296,"description":7297,"items":7298},"PIPEDA accelerators","Stand up Canadian privacy compliance and reuse it elsewhere.",[7299,7302,7305],{"title":7300,"description":7301},"Access-request workflow","Intake and fulfill individual access and correction requests.",{"title":7303,"description":7304},"Breach reporting workflow","Assess real risk of significant harm and notify the OPC.",{"title":7306,"description":7307},"GDPR \u002F CCPA crosswalk","Reuse records of processing and rights workflows across regimes.",{"title":7309,"description":7310},"PIPEDA Compliance Software","Comply with Canada's PIPEDA — the 10 fair information principles, consent, data-subject requests, and breach reporting to the Privacy Commissioner — in one workspace.","pipeda",[7313,7316,7319],{"value":7314,"description":7315},"10 principles","The fair information principles implemented as living controls.",{"value":7317,"description":7318},"Breach reporting","Real-risk-of-significant-harm assessment and OPC notification workflow.",{"value":4727,"description":7320},"Cross-walked to GDPR and CCPA so privacy work is reused.","5.frameworks\u002Fpipeda","tzEGKEqDoqArLvnsDGzYbjqGtZrh5kLWYS2hy25QipE",{"id":7324,"title":7325,"advantages":7326,"body":7346,"checklist":7425,"cta":7435,"description":93,"extension":151,"faq":7438,"hero":7452,"lastUpdated":186,"meta":7459,"name":7460,"navigation":188,"path":7461,"resources":7462,"seo":7473,"slug":7476,"stats":7477,"stem":7486,"__hash__":7487},"frameworks\u002F5.frameworks\u002Fpopia.md","Popia",[7327,7334,7341],{"title":7328,"description":7329,"bullets":7330},"Eight conditions for lawful processing","From accountability to data-subject participation, as controls.",[7331,7332,7333],"Accountability and processing limitation","Purpose specification and further-processing limits","Information quality, openness, and security safeguards",{"title":7335,"description":7336,"bullets":7337},"Roles, rights, and breaches","The information officer, data-subject rights, and breach reporting.",[7338,7339,7340],"Information officer registration and duties","Data-subject access and objection requests","Information Regulator and data-subject breach notice",{"title":5007,"description":7342,"bullets":7343},"POPIA overlaps heavily with GDPR and other privacy laws.",[4612,7344,7345],"Reuse records of processing","Aligns with LGPD, CCPA, and PIPEDA",{"type":29,"value":7347,"toc":7419},[7348,7352,7373,7376,7394,7398,7409,7411],[32,7349,7351],{"id":7350},"what-is-popia","What is POPIA?",[37,7353,367,7354,5023,7357,7360,7361,7364,7365,7368,7369,7372],{},[53,7355,7356],{},"Protection of Personal Information Act (POPIA)",[53,7358,7359],{},"South Africa's data protection law",". It came into ",[53,7362,7363],{},"full force on July 1, 2021"," and is enforced by the ",[53,7366,7367],{},"Information Regulator",". POPIA governs how \"responsible parties\" (the equivalent of controllers) process personal information, and it is built on ",[53,7370,7371],{},"eight conditions for lawful processing",": accountability, processing limitation, purpose specification, further-processing limitation, information quality, openness, security safeguards, and data-subject participation.",[32,7374,7335],{"id":7375},"roles-rights-and-breaches",[37,7377,7378,7379,7382,7383,7386,7387,7389,7390,7393],{},"Organizations must designate and ",[53,7380,7381],{},"register an information officer"," with the Information Regulator, maintain appropriate ",[53,7384,7385],{},"security safeguards",", and honor ",[53,7388,5038],{}," such as access, correction, and objection. Where personal information is accessed or acquired by an unauthorized person, the responsible party must ",[53,7391,7392],{},"notify the Information Regulator and affected data subjects"," as soon as reasonably possible.",[32,7395,7397],{"id":7396},"recent-developments","Recent developments",[37,7399,7400,7401,7404,7405,7408],{},"In ",[53,7402,7403],{},"April 2025",", the Information Regulator published ",[53,7406,7407],{},"amendments to the POPIA Regulations"," that streamlined several processes — including objecting to processing, requesting corrections or deletions, and obtaining consent for direct marketing — strengthening protections for individuals.",[32,7410,244],{"id":243},[37,7412,7413,7414,254,7417,258],{},"episki holds POPIA obligations as structured records — processing activities, lawful bases, data subject requests, and operator agreements — linked to controls that are evaluated continuously. Operators and their subprocessors live on vendor records with review cadences that advance on accepted evidence. ",[249,7415,253],{"href":185,"rel":7416},[252],[249,7418,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":7420},[7421,7422,7423,7424],{"id":7350,"depth":94,"text":7351},{"id":7375,"depth":94,"text":7335},{"id":7396,"depth":94,"text":7397},{"id":243,"depth":94,"text":244},{"title":7426,"description":7427,"items":7428},"POPIA readiness inside episki","What an organization processing South African personal data needs.",[7429,7430,7431,7432,7433,7434],"Information officer registered with the Regulator","Personal information inventory and processing records","Lawful-processing controls across the eight conditions","Security safeguards proportionate to risk","Data-subject request and objection workflow","Breach notification to the Regulator and data subjects",{"title":7436,"description":7437},"Build a POPIA program in episki","Implement the eight conditions once and reuse your GDPR work.",{"title":7439,"items":7440},"POPIA frequently asked questions",[7441,7443,7446,7449],{"label":7351,"content":7442},"The Protection of Personal Information Act (POPIA) is South Africa's data protection law. It came into full force on July 1, 2021 and sets out eight conditions for the lawful processing of personal information, enforced by the Information Regulator. It applies to responsible parties (controllers) that process personal information in South Africa.",{"label":7444,"content":7445},"What are the eight conditions?","POPIA's eight conditions for lawful processing are: accountability; processing limitation; purpose specification; further processing limitation; information quality; openness; security safeguards; and data subject participation. Together they function much like the GDPR's principles and rights.",{"label":7447,"content":7448},"Does POPIA require breach notification?","Yes. Where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorized person, the responsible party must notify the Information Regulator and the affected data subjects as soon as reasonably possible.",{"label":7450,"content":7451},"How does POPIA relate to GDPR?","POPIA closely parallels the GDPR, so much of a GDPR program transfers directly. In April 2025, the Information Regulator published amendments to the POPIA Regulations that streamlined processes such as objecting to processing, requesting corrections or deletions, and consent for direct marketing.",{"headline":7453,"title":7454,"description":7455,"links":7456},"South African privacy, operationalized","Comply with South Africa's POPIA","The eight conditions for lawful processing as living controls, information officer duties, data-subject requests, and Information Regulator breach reporting — mapped to GDPR.",[7457,7458],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"POPIA","\u002Fframeworks\u002Fpopia",{"headline":7463,"title":7463,"description":7464,"items":7465},"POPIA accelerators","Stand up South African privacy compliance and reuse it elsewhere.",[7466,7469,7471],{"title":7467,"description":7468},"Conditions control set","The eight conditions for lawful processing as living controls.",{"title":3039,"description":7470},"Notify the Information Regulator and affected data subjects on time.",{"title":5140,"description":7472},"Reuse your GDPR records and rights workflows for POPIA.",{"title":7474,"description":7475},"POPIA Compliance Software","Comply with South Africa's POPIA — the eight conditions for lawful processing, information officer duties, and Information Regulator breach reporting — in one workspace.","popia",[7478,7481,7484],{"value":7479,"description":7480},"8 conditions","The conditions for lawful processing implemented as living controls.",{"value":7482,"description":7483},"Info Regulator","Breach notification and information-officer registration workflows.",{"value":4727,"description":7485},"POPIA aligns with GDPR, so privacy work is reused.","5.frameworks\u002Fpopia","0_VCD32o9CSiAif_uOHmflYhlgK9qcQfyvdM6lWbUb0",{"id":7489,"title":7490,"advantages":7491,"body":7513,"checklist":7547,"cta":7557,"description":93,"extension":151,"faq":7560,"hero":7574,"lastUpdated":186,"meta":7581,"name":7582,"navigation":188,"path":7583,"resources":7584,"seo":7597,"slug":7600,"stats":7601,"stem":7611,"__hash__":7612},"frameworks\u002F5.frameworks\u002Fsoc1.md","Soc1",[7492,7499,7506],{"title":7493,"description":7494,"bullets":7495},"Control objectives and procedures","A library of common SOC 1 control objectives with mapped control activities and testing procedures.",[7496,7497,7498],"Control objectives library by domain","Testing procedures aligned to SSAE 18","Evidence organized per control activity",{"title":7500,"description":7501,"bullets":7502},"Carve-out and inclusive","Track subservice organizations with the carve-out or inclusive method.",[7503,7504,7505],"Carve-out subservice organization tracking","Inclusive method workflows for tightly coupled subservices","SOC 1 sub-processor risk reviews via TPRM",{"title":7507,"description":7508,"bullets":7509},"Cross-mapped to SOC 2","Many controls do double duty across SOC 1 and SOC 2. Map once, evidence once, report twice.",[7510,7511,7512],"Shared control library between SOC 1 and SOC 2","Single evidence locker","Auditor portal supports both engagement types",{"type":29,"value":7514,"toc":7542},[7515,7519,7522,7525,7529,7532,7534],[32,7516,7518],{"id":7517},"what-is-soc-1","What is SOC 1?",[37,7520,7521],{},"SOC 1 (System and Organization Controls 1) is the AICPA attestation report addressing a service organization's controls that are relevant to its user entities' Internal Control over Financial Reporting (ICFR). It is the modern descendant of SAS 70, now issued under SSAE 18 attestation standards.",[37,7523,7524],{},"SOC 1 reports come in two flavors: Type I (design of controls at a point in time) and Type II (design and operating effectiveness over a period, typically 6-12 months). External auditors of your customers rely on SOC 1 Type II reports when deciding whether to rely on your controls for their customers' financial-statement audits.",[32,7526,7528],{"id":7527},"who-needs-soc-1","Who needs SOC 1",[37,7530,7531],{},"Service organizations whose operations directly affect customers' financial reporting — payroll providers, billing systems, transaction processors, ERP hosting providers, fund administrators, and many SaaS companies serving regulated public-company customers. If your customers' external auditors regularly ask for your SOC 1, you need one.",[32,7533,244],{"id":243},[37,7535,7536,7537,254,7540,258],{},"episki supports SOC 1 alongside SOC 2 and every other framework you run, sharing controls and evidence between them. ITGC controls are evaluated continuously — change management from branch protection and git-only deploy checks, access from live identity evidence — and your service auditor gets scoped guest access per assessment at no extra cost. ",[249,7538,253],{"href":185,"rel":7539},[252],[249,7541,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":7543},[7544,7545,7546],{"id":7517,"depth":94,"text":7518},{"id":7527,"depth":94,"text":7528},{"id":243,"depth":94,"text":244},{"title":7548,"description":7549,"items":7550},"SOC 1 readiness inside episki","From scoping to signed report — what you need preloaded.",[7551,7552,7553,7554,7555,7556],"Control objectives library scoped to your service","Subservice organization treatment (carve-out \u002F inclusive)","Complementary User Entity Controls (CUECs) documented","Type I or Type II report-period decision support","Auditor portal with PBC and walkthrough management","Cross-mapping to SOC 2 for shared scope",{"title":7558,"description":7559},"Issue SOC 1 in episki","Stand up the SOC 1 engagement alongside your SOC 2, sharing evidence and auditor workflows.",{"title":7561,"items":7562},"SOC 1 frequently asked questions",[7563,7565,7568,7571],{"label":7518,"content":7564},"SOC 1 (System and Organization Controls 1) is an AICPA attestation report addressing a service organization's controls relevant to its customers' Internal Control over Financial Reporting (ICFR). It's the modern successor to SAS 70, issued under SSAE 18.",{"label":7566,"content":7567},"SOC 1 vs SOC 2 — when do I need which?","SOC 1 is for services whose operation affects customers' financial reporting (e.g., payroll, billing, transaction processing, ERP hosting). SOC 2 covers controls relevant to security, availability, processing integrity, confidentiality, and privacy. Many SaaS companies issue both.",{"label":7569,"content":7570},"Type I vs Type II?","Type I is a point-in-time report (design of controls only). Type II covers a period (typically 6-12 months) and tests operating effectiveness. Most customers want Type II for financial-reporting reliance.",{"label":7572,"content":7573},"What are CUECs?","Complementary User Entity Controls are controls the user entity (your customer) must implement on their side for the service organization's controls to achieve their objectives. They're a standard part of a SOC 1 report and must be communicated to customers.",{"headline":7575,"title":7576,"description":7577,"links":7578},"SOC 1 without rebuilding SOC 2","Demonstrate effective ICFR for your customers","SOC 1 reports for service providers whose customers depend on you for financial reporting. Pre-mapped to SOC 2 for shared scope, with carve-out and user entity control workflows.",[7579,7580],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"SOC 1 Type I\u002FII","\u002Fframeworks\u002Fsoc1",{"headline":7585,"title":7586,"description":7587,"items":7588},"SOC 1 accelerators","SOC 1 program accelerators","Issue your first SOC 1 without ripping up your SOC 2 program.",[7589,7591,7594],{"title":3739,"description":7590},"Determine relevant control objectives based on your service offering.",{"title":7592,"description":7593},"CUEC catalog","Pre-written Complementary User Entity Controls customizable per customer.",{"title":7595,"description":7596},"SOC 1 ↔ SOC 2 crosswalk","Reuse evidence across both engagements with a clear mapping.",{"title":7598,"description":7599},"SOC 1 Compliance Software","Issue SOC 1 Type I and Type II reports for customers that rely on your service for their financial reporting. Cross-mapped to SOC 2 to reuse evidence.","soc1",[7602,7605,7608],{"value":7603,"description":7604},"Type I + II","Both point-in-time and period-of-time SOC 1 reports supported.",{"value":7606,"description":7607},"SSAE 18","Reports built per the current AICPA SSAE 18 attestation standard.",{"value":7609,"description":7610},"CUEC","Complementary User Entity Control documentation tracked alongside your own controls.","5.frameworks\u002Fsoc1","0n63UCZtITDOmIIxiYRZbNqOk0jqQBx5dKvyjNT5k3E",{"id":7614,"title":7615,"advantages":7616,"body":7638,"checklist":8146,"cta":8155,"description":93,"extension":151,"faq":8158,"hero":8175,"lastUpdated":186,"meta":8183,"name":8184,"navigation":188,"path":474,"resources":8185,"seo":8197,"slug":8200,"stats":8201,"stem":8211,"__hash__":8212},"frameworks\u002F5.frameworks\u002Fsoc2.md","Soc2",[7617,7624,7631],{"title":7618,"description":7619,"bullets":7620},"Mapped once, reused forever","Applies Trust Service Criteria to your existing controls and keeps overlaps synced.",[7621,7622,7623],"Control graph highlights reuse across security, availability, and confidentiality","AI suggests narratives and testing procedures","Version history shows every update for auditors",{"title":7625,"description":7626,"bullets":7627},"Evidence organized by control","Upload and track screenshots, configs, and exports in a structured evidence locker.",[7628,7629,7630],"Organized screenshots, configs, and test exports","Alerting when evidence expires or SLAs slip","Immutable locker with reviewer threads",{"title":7632,"description":7633,"bullets":7634},"Auditor collaboration hub","Invite your auditor with scoped access and keep Q&A right next to each control.",[7635,7636,7637],"Bulk requests & fulfillment tracking","Redacted file sharing with access controls","One-click SOC 2 summaries for customers",{"type":29,"value":7639,"toc":8127},[7640,7644,7647,7654,7662,7668,7672,7675,7681,7687,7702,7706,7711,7715,7718,7722,7730,7734,7737,7741,7749,7753,7760,7764,7767,7770,7787,7795,7799,7806,7848,7851,7855,7858,7861,7899,7907,7911,7914,7972,7975,7979,7982,7989,7996,8003,8014,8022,8026,8034,8066,8069,8073,8076,8079,8116,8118],[32,7641,7643],{"id":7642},"what-is-soc-2","What is SOC 2?",[37,7645,7646],{},"SOC 2 (System and Organization Controls 2) is an auditing standard developed by the American Institute of Certified Public Accountants (AICPA) that evaluates how a service organization manages customer data. A SOC 2 report is the de facto security credential for modern SaaS companies — enterprise buyers request it before signing, procurement teams rely on it during vendor reviews, and auditors consult it when assessing outsourced systems. Unlike a prescriptive standard, SOC 2 is principle-based. It does not tell you which tools to deploy; it tells you which outcomes you must demonstrate and leaves the implementation details to you.",[37,7648,7649,7650,7653],{},"SOC 2 evolved from SAS 70, an older attestation framework used primarily for financial reporting systems. As technology service providers increased their role in handling sensitive data, the AICPA introduced the SOC reporting suite. SOC 1 continued to address controls relevant to financial reporting. SOC 2 and SOC 3 shifted attention to information security, availability, and related commitments. Today, SOC 2 is issued under the AICPA's AT-C 105 and AT-C 205 attestation standards, following the ",[249,7651,7606],{"href":7652},"\u002Fglossary\u002Fssae-18"," framework.",[37,7655,7656,7657,7661],{},"A SOC 2 engagement produces an opinion letter from a licensed CPA firm. That letter is the report buyers ask for. It documents the system under audit, the ",[249,7658,7660],{"href":7659},"\u002Fframeworks\u002Fsoc2\u002Ftrust-services-criteria","Trust Services Criteria"," selected, the controls in place, the testing the auditor performed, and any exceptions noted. A clean SOC 2 opinion signals to the market that a third party examined your controls and found them suitable — or in the case of Type II, found them operating effectively across a defined window.",[37,7663,7664,7665,7667],{},"SOC 2 is built on five ",[53,7666,7660],{},": security, availability, processing integrity, confidentiality, and privacy. Security is mandatory. The other four are optional and chosen based on your service commitments and customer expectations. Most first-time SOC 2 audits cover security alone or security plus one or two additional criteria. Scope expansion happens later, as the program matures.",[32,7669,7671],{"id":7670},"soc-2-type-i-vs-type-ii","SOC 2 Type I vs Type II",[37,7673,7674],{},"Every SOC 2 engagement is either Type I or Type II, and the difference matters.",[37,7676,2098,7677,7680],{},[53,7678,7679],{},"SOC 2 Type I"," report evaluates whether controls are suitably designed and implemented as of a single date. Think of it as a design review. The auditor confirms your policies exist, your technical controls are configured, and your processes are in place. Type I is the fastest path to a SOC 2 report and is useful when a deal is on the line, but it does not prove your controls work day after day.",[37,7682,2098,7683,7686],{},[53,7684,7685],{},"SOC 2 Type II"," report evaluates whether controls operated effectively across an observation period, typically three to twelve months. The auditor samples evidence from throughout the period — access reviews, change approvals, incident tickets, monitoring alerts — to confirm that controls were not just designed but consistently executed. Most enterprise buyers require a Type II, and many will not accept a Type I at all.",[37,7688,7689,7690,7694,7695,392,7699,258],{},"For a full comparison including cost benchmarks, observation period tradeoffs, and decision frameworks, see ",[249,7691,7693],{"href":7692},"\u002Fframeworks\u002Fsoc2\u002Ftype-1-vs-type-2","SOC 2 Type 1 vs Type 2",". Related glossary terms: ",[249,7696,7698],{"href":7697},"\u002Fglossary\u002Fsoc2-type-2","SOC 2 Type 2",[249,7700,7660],{"href":7701},"\u002Fglossary\u002Ftrust-services-criteria",[32,7703,7705],{"id":7704},"the-five-trust-services-criteria","The five Trust Services Criteria",[37,7707,367,7708,7710],{},[249,7709,7660],{"href":7659}," define the principles your controls must satisfy. Each criterion addresses a different aspect of how a service organization protects and manages customer data.",[597,7712,7714],{"id":7713},"security-common-criteria-required","Security (Common Criteria) — required",[37,7716,7717],{},"The security criterion, also called the Common Criteria, is required for every SOC 2 engagement. It evaluates whether the system is protected against unauthorized access — both logical and physical. The Common Criteria are organized into nine categories (CC1 through CC9) that map to the COSO internal control framework and cover governance, communication, risk assessment, monitoring, access control, system operations, change management, and vendor risk. Every SOC 2 report includes testing against these categories.",[597,7719,7721],{"id":7720},"availability","Availability",[37,7723,7724,7725,7729],{},"The availability criterion applies when an organization commits to specific uptime levels or recovery capabilities. It covers environmental protections, capacity planning, disaster recovery, and incident management for availability-impacting events. If your product has published SLAs or customers rely on continuous uptime, include availability. Read the ",[249,7726,7728],{"href":7727},"\u002Fframeworks\u002Fsoc2\u002Favailability-criteria","availability criteria deep dive"," for common controls and implementation patterns.",[597,7731,7733],{"id":7732},"processing-integrity","Processing integrity",[37,7735,7736],{},"Processing integrity focuses on whether the system processes data completely, validly, accurately, timely, and with proper authorization. This criterion is relevant for platforms that perform calculations, process financial transactions, or transform customer data. It is less common in first-time SOC 2 audits but important for fintech, billing platforms, and data pipelines that customers rely on for operational decisions.",[597,7738,7740],{"id":7739},"confidentiality","Confidentiality",[37,7742,7743,7744,7748],{},"The confidentiality criterion addresses information designated as confidential — distinct from personal information. It covers data classification, access restrictions, encryption, and secure disposal of confidential data. If you handle intellectual property, business plans, or other sensitive non-personal information on behalf of clients, include confidentiality. See the ",[249,7745,7747],{"href":7746},"\u002Fframeworks\u002Fsoc2\u002Fconfidentiality-criteria","confidentiality criteria deep dive"," for details.",[597,7750,7752],{"id":7751},"privacy","Privacy",[37,7754,7755,7756,258],{},"The privacy criterion applies to personal information — data that can identify an individual. It evaluates whether your data practices match your stated privacy commitments across notice, choice, collection, use, retention, disclosure, security, and accuracy. Privacy aligns closely with regulations like GDPR and CCPA and is the most demanding criterion in terms of control coverage. For a full walkthrough, see the ",[249,7757,7759],{"href":7758},"\u002Fframeworks\u002Fsoc2\u002Fprivacy-criteria","privacy criteria deep dive",[32,7761,7763],{"id":7762},"who-needs-soc-2-compliance","Who needs SOC 2 compliance?",[37,7765,7766],{},"SOC 2 is not legally mandated, but the market treats it as a cost of doing business. Any SaaS company, cloud service provider, managed service provider, or data processor that handles customer data is a likely SOC 2 candidate. If your customers are businesses and their security teams will scrutinize your controls before signing, SOC 2 is almost certainly on your roadmap.",[37,7768,7769],{},"Companies typically pursue SOC 2 when one or more of the following is true:",[47,7771,7772,7775,7778,7781,7784],{},[50,7773,7774],{},"Enterprise prospects are asking for a report during procurement or vendor reviews.",[50,7776,7777],{},"Sales cycles are slowing because buyers are blocking deals on security questionnaires.",[50,7779,7780],{},"Existing customers are requesting a current SOC 2 report during annual reviews.",[50,7782,7783],{},"Investors or partners are asking about the company's security posture.",[50,7785,7786],{},"The business is entering regulated verticals like financial services, healthcare, or government.",[37,7788,7789,7790,7794],{},"Industries that almost always require SOC 2 from their vendors include financial services, healthcare, legal technology, HR technology, martech that handles PII, and any B2B SaaS selling into enterprise accounts. For SaaS companies specifically, SOC 2 has become table stakes — see ",[249,7791,7793],{"href":7792},"\u002Fblog\u002Fsoc2-for-saas","SOC 2 for SaaS"," for a deeper discussion.",[32,7796,7798],{"id":7797},"the-soc-2-audit-process-overview","The SOC 2 audit process overview",[37,7800,367,7801,7805],{},[249,7802,7804],{"href":7803},"\u002Fframeworks\u002Fsoc2\u002Faudit-process","SOC 2 audit process"," follows a predictable sequence. Understanding each phase prevents surprises and helps you set realistic timelines with your team and auditor.",[903,7807,7808,7824,7830,7836,7842],{},[50,7809,7810,7813,7814,7818,7819,7823],{},[53,7811,7812],{},"Scoping and readiness assessment."," Define what systems and Trust Services Criteria are in scope, then perform a ",[249,7815,7817],{"href":7816},"\u002Fframeworks\u002Fsoc2\u002Freadiness-assessment","readiness assessment"," to compare current controls against ",[249,7820,7822],{"href":7821},"\u002Fframeworks\u002Fsoc2\u002Frequirements","SOC 2 requirements",". The output is a prioritized remediation plan.",[50,7825,7826,7829],{},[53,7827,7828],{},"Remediation."," Close the gaps identified during readiness. Common items include formalizing policies, enabling MFA everywhere, centralizing logging, documenting vendor risk processes, and running tabletop exercises.",[50,7831,7832,7835],{},[53,7833,7834],{},"Auditor selection."," SOC 2 audits must be performed by a CPA firm licensed to issue SOC reports. Request proposals from two to four firms, compare scope and pricing, and check references from similar companies.",[50,7837,7838,7841],{},[53,7839,7840],{},"Audit fieldwork."," For Type I, the auditor validates control design at a point in time. For Type II, the auditor samples evidence from across the observation period and tests operating effectiveness.",[50,7843,7844,7847],{},[53,7845,7846],{},"Report delivery and ongoing operation."," Once the report is issued, plan the next observation period so you maintain continuous coverage with no bridge gaps that buyers might question.",[37,7849,7850],{},"Most organizations complete their first Type I in three to six months and their first Type II in six to eighteen months, depending on starting maturity and observation period length.",[32,7852,7854],{"id":7853},"what-does-soc-2-cost","What does SOC 2 cost?",[37,7856,7857],{},"SOC 2 cost varies widely based on scope, starting maturity, and whether you pursue Type I, Type II, or both. Auditor fees are the largest line item, but they are not the only cost. You should budget for readiness consulting, compliance tooling, internal staff time, remediation work, and penetration testing.",[37,7859,7860],{},"Typical benchmarks for a first-time SOC 2 engagement:",[47,7862,7863,7869,7875,7881,7887,7893],{},[50,7864,7865,7868],{},[53,7866,7867],{},"Type I auditor fees",": $15,000 to $40,000",[50,7870,7871,7874],{},[53,7872,7873],{},"Type II auditor fees",": $25,000 to $80,000",[50,7876,7877,7880],{},[53,7878,7879],{},"Readiness consulting"," (optional): $10,000 to $40,000",[50,7882,7883,7886],{},[53,7884,7885],{},"Compliance platform",": $6,000 to $60,000 annually depending on vendor",[50,7888,7889,7892],{},[53,7890,7891],{},"Penetration testing",": $8,000 to $30,000 per test",[50,7894,7895,7898],{},[53,7896,7897],{},"Internal staff time",": 200 to 600 hours across the first cycle",[37,7900,7901,7902,7906],{},"Total first-year cost for most growth-stage SaaS companies lands between $40,000 and $200,000. See the full ",[249,7903,7905],{"href":7904},"\u002Fframeworks\u002Fsoc2\u002Fcost","SOC 2 cost breakdown"," for detailed ranges and cost-reduction strategies.",[32,7908,7910],{"id":7909},"common-soc-2-challenges","Common SOC 2 challenges",[37,7912,7913],{},"SOC 2 programs rarely fail because the audit is unfair. They fail because organizations underestimate the operational discipline required. The challenges show up in predictable places.",[47,7915,7916,7922,7928,7934,7940,7951,7962],{},[50,7917,7918,7921],{},[53,7919,7920],{},"Scope creep."," Teams add new systems mid-audit or expand Trust Services Criteria without revisiting the control set. Every addition extends timelines and evidence requirements.",[50,7923,7924,7927],{},[53,7925,7926],{},"Evidence gaps."," Screenshots expire. Configurations change. Ownership drifts between quarters. By the time the auditor asks, the evidence trail is broken.",[50,7929,7930,7933],{},[53,7931,7932],{},"Cross-team coordination."," SOC 2 touches engineering, IT, HR, legal, and finance. Without a single source of truth for control status, teams duplicate work or miss handoffs.",[50,7935,7936,7939],{},[53,7937,7938],{},"Policy drift."," Policies written for the audit do not match how the team actually operates. Auditors detect this quickly during interviews and walkthroughs.",[50,7941,7942,7945,7946,7950],{},[53,7943,7944],{},"Vendor oversight."," Third-party vendors handle critical data but are rarely monitored with the same rigor as internal systems. See ",[249,7947,7949],{"href":7948},"\u002Fframeworks\u002Fsoc2\u002Fvendor-management","vendor management"," for how to close this gap.",[50,7952,7953,7956,7957,7961],{},[53,7954,7955],{},"Change management."," Production changes bypass approval workflows, leaving no audit trail. ",[249,7958,7960],{"href":7959},"\u002Fframeworks\u002Fsoc2\u002Fchange-management","Change management"," is a frequent source of Type II exceptions.",[50,7963,7964,7967,7968,258],{},[53,7965,7966],{},"Incident response immaturity."," Teams have an incident response plan but have never tested it. Auditors look for evidence of real incidents handled end to end. See ",[249,7969,7971],{"href":7970},"\u002Fframeworks\u002Fsoc2\u002Fincident-response","incident response",[37,7973,7974],{},"A structured approach — mapping controls, evidence, and owners from day one — removes most of these friction points before they become audit findings.",[32,7976,7978],{"id":7977},"how-soc-2-compares-to-other-frameworks","How SOC 2 compares to other frameworks",[37,7980,7981],{},"SOC 2 is not the only security framework buyers may request. Understanding how SOC 2 relates to other standards helps you plan a cohesive compliance strategy rather than running parallel audits with overlapping work.",[37,7983,7984,7988],{},[53,7985,7986],{},[249,7987,470],{"href":469}," is an international certification focused on information security management systems. Unlike SOC 2, which produces an auditor's opinion letter, ISO 27001 results in a certificate issued by an accredited registrar. ISO 27001 is prescriptive about building an ISMS but the control set in Annex A overlaps heavily with the SOC 2 Common Criteria. Many mature companies pursue both and reuse evidence across them. ISO 27001 tends to be preferred by European and international buyers; SOC 2 is the North American standard.",[37,7990,7991,7995],{},[53,7992,7993],{},[249,7994,3459],{"href":3607}," is a US healthcare law that mandates specific safeguards for protected health information. HIPAA is a regulatory requirement rather than a voluntary attestation — there is no HIPAA certificate, but business associates and covered entities must comply. SOC 2 controls address many HIPAA administrative and technical safeguards, and a SOC 2 Type II report is often used as evidence of HIPAA compliance in vendor due diligence.",[37,7997,7998,8002],{},[53,7999,8000],{},[249,8001,6662],{"href":7120}," is the payment card industry's prescriptive standard for any organization that stores, processes, or transmits cardholder data. Unlike SOC 2, PCI DSS specifies exact controls down to firewall rules and encryption key rotation cadences. SOC 2 and PCI DSS share concepts like encryption, access control, and monitoring, but PCI DSS scope is narrower (cardholder data environment) and the requirements are more specific. Companies that process payments typically need both.",[37,8004,8005,466,8008,8010,8011,8013],{},[53,8006,8007],{},"NIST Cybersecurity Framework",[53,8009,2241],{},", and ",[53,8012,1048],{}," address additional specialized audiences — federal contractors, defense industrial base, and government-adjacent systems. These are out of scope for most commercial SaaS but worth mapping if your buyer base includes public sector.",[37,8015,8016,8017,8021],{},"If you are comparing SOC 2 tooling options, our ",[249,8018,8020],{"href":8019},"\u002Fcompare\u002Fvs\u002Fvanta-vs-drata","Vanta vs Drata comparison"," covers the leading compliance automation platforms.",[32,8023,8025],{"id":8024},"soc-2-readiness-checklist","SOC 2 readiness checklist",[37,8027,8028,8029,8033],{},"A readiness checklist keeps your team focused during the months before the audit begins. The ",[249,8030,8032],{"href":8031},"\u002Fframeworks\u002Fsoc2\u002Fchecklist","full SOC 2 checklist"," covers every category, but at a high level expect to address:",[47,8035,8036,8039,8042,8045,8048,8051,8054,8057,8060,8063],{},[50,8037,8038],{},"Governance and policies (information security policy, acceptable use, code of conduct)",[50,8040,8041],{},"Access control (SSO, MFA, role-based access, quarterly access reviews)",[50,8043,8044],{},"Change management (code review, deployment approvals, production change logs)",[50,8046,8047],{},"Vendor risk management (inventory, assessments, monitoring)",[50,8049,8050],{},"Incident response (documented plan, tested at least annually)",[50,8052,8053],{},"Business continuity and disaster recovery (plan with defined RPO\u002FRTO, tested)",[50,8055,8056],{},"Logging and monitoring (centralized logs, alerting, incident tickets)",[50,8058,8059],{},"Security awareness training (annual minimum, tracked completion)",[50,8061,8062],{},"HR controls (background checks, onboarding, offboarding, confidentiality agreements)",[50,8064,8065],{},"Risk assessment (annual risk review, risk register, treatment plans)",[37,8067,8068],{},"Most companies find that the readiness phase surfaces gaps they did not know existed. That is the point — better to discover them before the auditor arrives.",[32,8070,8072],{"id":8071},"getting-started-with-soc-2","Getting started with SOC 2",[37,8074,8075],{},"The best time to start a SOC 2 program is before the first buyer demands it. The second best time is now.",[37,8077,8078],{},"A reasonable starting sequence:",[903,8080,8081,8087,8093,8098,8104,8110],{},[50,8082,8083,8086],{},[53,8084,8085],{},"Pick your Trust Services Criteria."," Security is required. Add others only if you have customer commitments that map to them.",[50,8088,8089,8092],{},[53,8090,8091],{},"Decide Type I vs Type II."," If you need a report fast for a specific deal, start with Type I. If you have time and buyer pressure is general, skip straight to Type II.",[50,8094,8095,8097],{},[53,8096,2458],{}," Either internally or with a consultant. The goal is a prioritized remediation list, not a polished report.",[50,8099,8100,8103],{},[53,8101,8102],{},"Remediate in priority order."," Address policy gaps, access control weaknesses, and logging first — these are the most common sources of findings.",[50,8105,8106,8109],{},[53,8107,8108],{},"Select an auditor."," Get proposals from two to four CPA firms. Check references from similar companies. Book early — good auditors are scheduled quarters in advance.",[50,8111,8112,8115],{},[53,8113,8114],{},"Operate, collect, and iterate."," Run your controls, collect evidence continuously, and prepare for fieldwork. Do not treat the audit as a one-time event.",[32,8117,244],{"id":243},[37,8119,8120,8121,254,8124,8126],{},"episki maps your controls to the Trust Services Criteria and then evaluates them continuously. Connected systems — AWS across multiple accounts and regions, plus GitHub, Google, Microsoft, Slack, Supabase, Vercel, and Netlify — collect evidence and write an explicit pass, fail, or inconclusive verdict against each criterion, with a failing check raising a finding that syncs bi-directionally into Jira, Linear, or GitHub. Change management evidence comes from branch protection and git-only deploy checks rather than screenshots; availability evidence from point-in-time recovery and deployment protection. Your auditor gets scoped guest access per assessment at no extra cost. ",[249,8122,253],{"href":185,"rel":8123},[252],[249,8125,257],{"href":178}," to see how SOC 2 looks with the scramble removed.",{"title":93,"searchDepth":94,"depth":94,"links":8128},[8129,8130,8131,8138,8139,8140,8141,8142,8143,8144,8145],{"id":7642,"depth":94,"text":7643},{"id":7670,"depth":94,"text":7671},{"id":7704,"depth":94,"text":7705,"children":8132},[8133,8134,8135,8136,8137],{"id":7713,"depth":995,"text":7714},{"id":7720,"depth":995,"text":7721},{"id":7732,"depth":995,"text":7733},{"id":7739,"depth":995,"text":7740},{"id":7751,"depth":995,"text":7752},{"id":7762,"depth":94,"text":7763},{"id":7797,"depth":94,"text":7798},{"id":7853,"depth":94,"text":7854},{"id":7909,"depth":94,"text":7910},{"id":7977,"depth":94,"text":7978},{"id":8024,"depth":94,"text":8025},{"id":8071,"depth":94,"text":8072},{"id":243,"depth":94,"text":244},{"title":8147,"description":8148,"items":8149},"SOC 2 readiness checklist inside episki","Everything is preloaded in your free trial so you can start assigning ownership and collecting proof immediately.",[8150,8151,8152,8153,8154],"Trust Service Criteria library with mapped controls","Policy templates and AI drafting assistant","Evidence library with structured ownership and review cadences","Emulated auditor workspace with sample requests","Customer-facing compliance portal template",{"title":8156,"description":8157},"Launch your SOC 2 workspace today","Import your controls, connect evidence, and invite your auditor in under an hour.",{"title":8159,"items":8160},"SOC 2 frequently asked questions",[8161,8164,8167,8170,8172],{"label":8162,"content":8163},"How long does a SOC 2 audit take?","A SOC 2 Type I audit typically takes 4-8 weeks of preparation plus the audit itself. Type II requires a 3-12 month observation period followed by the assessment. episki's automation can cut preparation time by up to 45 days.",{"label":8165,"content":8166},"What is the difference between SOC 2 Type I and Type II?","SOC 2 Type I evaluates whether controls are suitably designed at a single point in time. Type II tests whether those controls operated effectively over a sustained period, usually 3-12 months. Most enterprise buyers require a Type II report.",{"label":8168,"content":8169},"How much does SOC 2 compliance cost?","Total costs typically range from $20,000 to $100,000+ depending on scope, readiness, and auditor fees. episki covers the platform side at a flat $750\u002Fmonth with no per-seat charges, significantly reducing the software portion of that budget.",{"label":7763,"content":8171},"Any SaaS company, cloud service provider, or data processor handling customer data is a likely candidate. Enterprise buyers in financial services, healthcare, and technology frequently require a current SOC 2 report before signing contracts.",{"label":8173,"content":8174},"What are the SOC 2 Trust Services Criteria?","The five Trust Services Criteria are security (required), availability, processing integrity, confidentiality, and privacy. Security is mandatory for every SOC 2 audit; the other four are optional and selected based on the services you provide.",{"headline":8176,"title":8177,"description":8178,"links":8179},"SOC 2 without the scramble","Ship SOC 2 audits without slowing product velocity","episki maps Trust Service Criteria, automates evidence, and keeps auditors in sync so your team can focus on building.",[8180,8182],{"label":8181,"icon":182,"to":185},"Start SOC 2 trial",{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"SOC 2 Type I\u002FII",{"headline":8186,"title":8186,"description":8187,"items":8188},"SOC 2 acceleration resources","Give execs and customers visibility into progress at every stage.",[8189,8191,8194],{"title":1055,"description":8190},"Summaries translate control work into risk reduction and deals unlocked.",{"title":8192,"description":8193},"Sales enablement kit","SOC 2 FAQ answers and trust collateral ready for GTM teams.",{"title":8195,"description":8196},"Audit retro template","Capture what worked, track remediations, and prep the next period.",{"title":8198,"description":8199},"SOC 2 Compliance Software","Get SOC 2 Type I and Type II audit-ready faster with episki's automated controls, evidence tracking, and auditor collaboration. Start your free 14-day trial.","soc2",[8202,8205,8208],{"value":8203,"description":8204},"45 days faster","Average time saved reaching Type II readiness with episki’s automation.",{"value":8206,"description":8207},"120+ controls","Pre-mapped control narratives with owners, evidence, and review cadences.",{"value":8209,"description":8210},"100% coverage","Auditor portal with control health dashboards and SOC 2 exports.","5.frameworks\u002Fsoc2","UexUtE1HJiFtSL7wv59EdqPVMfsoQCTKsPLQUzdOCwM",{"id":8214,"title":8215,"advantages":8216,"body":8238,"checklist":8305,"cta":8315,"description":93,"extension":151,"faq":8318,"hero":8332,"lastUpdated":186,"meta":8339,"name":8248,"navigation":188,"path":8340,"resources":8341,"seo":8354,"slug":8357,"stats":8358,"stem":8368,"__hash__":8369},"frameworks\u002F5.frameworks\u002Fsoc3.md","Soc3",[8217,8224,8231],{"title":8218,"description":8219,"bullets":8220},"SOC 2's public sibling","SOC 3 reports against the same criteria, in a shareable summary form.",[8221,8222,8223],"Same Trust Services Criteria as SOC 2","Summary report without detailed test results","Freely distributable to anyone",{"title":8225,"description":8226,"bullets":8227},"A marketing-ready artifact","Hand prospects proof of your controls without the NDA dance.",[8228,8229,8230],"Post it publicly on your trust page","Speeds up early sales conversations","Backs up your SOC 2 for buyers who can't see it",{"title":8232,"description":8233,"bullets":8234},"No extra program","SOC 3 reuses your SOC 2 work end to end.",[8235,8236,8237],"Same controls and evidence as SOC 2","Issued by the same CPA firm","Crosswalk to ISO 27001 and CSA STAR",{"type":29,"value":8239,"toc":8299},[8240,8244,8263,8267,8278,8282,8289,8291],[32,8241,8243],{"id":8242},"what-is-soc-3","What is SOC 3?",[37,8245,8246,6211,8249,8252,8253,8255,8256,8258,8259,8262],{},[53,8247,8248],{},"SOC 3",[53,8250,8251],{},"public, general-use report"," based on the AICPA's ",[53,8254,7660],{}," — the same criteria that underpin ",[249,8257,475],{"href":474},". The difference is the audience and the level of detail: a SOC 2 report is restricted and includes the auditor's detailed description of controls and test results, shared with customers under NDA, while a SOC 3 is a ",[53,8260,8261],{},"short, summary-level report you can freely distribute"," — post it on your website, hand it to any prospect, no NDA required.",[32,8264,8266],{"id":8265},"how-it-relates-to-soc-2","How it relates to SOC 2",[37,8268,8269,8270,8273,8274,8277],{},"A SOC 3 is built on the ",[53,8271,8272],{},"same controls, evidence, and audit period"," as a SOC 2 Type 2 and is ",[53,8275,8276],{},"issued by the same CPA firm",". In practice, organizations that already pursue SOC 2 add SOC 3 as a public-facing companion at little additional cost — it is not a separate program.",[32,8279,8281],{"id":8280},"why-publish-one","Why publish one",[37,8283,8284,8285,8288],{},"SOC 3 is a practical trust and marketing asset. It lets you demonstrate that an independent CPA firm examined your controls against the Trust Services Criteria ",[53,8286,8287],{},"without exposing the sensitive detail"," in your SOC 2. That makes it ideal for top-of-funnel sales, public trust pages, and buyers who want assurance early.",[32,8290,244],{"id":243},[37,8292,8293,8294,254,8297,258],{},"A SOC 3 report is the public face of your SOC 2 work, and episki keeps both fed from the same controls and evidence. The Trust module adds a branded trust center where the report sits alongside NDA-gated documents and agent-answered questionnaires, with the portal theme inlined into the first paint so it never flashes episki's colors. ",[249,8295,253],{"href":185,"rel":8296},[252],[249,8298,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":8300},[8301,8302,8303,8304],{"id":8242,"depth":94,"text":8243},{"id":8265,"depth":94,"text":8266},{"id":8280,"depth":94,"text":8281},{"id":243,"depth":94,"text":244},{"title":8306,"description":8307,"items":8308},"SOC 3 readiness inside episki","What you need to add a SOC 3 to your SOC 2.",[8309,8310,8311,8312,8313,8314],"SOC 2 Type 2 program in place","Trust Services Criteria scoped (Security + any others)","Control evidence current and complete","CPA firm engaged for SOC 2 \u002F SOC 3","Public trust-page placement for the report","Crosswalks to ISO 27001 and CSA STAR",{"title":8316,"description":8317},"Add a SOC 3 in episki","Reuse your SOC 2 controls to publish a general-use trust report.",{"title":8319,"items":8320},"SOC 3 frequently asked questions",[8321,8323,8326,8329],{"label":8243,"content":8322},"SOC 3 is a public, general-use report based on the AICPA's Trust Services Criteria — the same criteria used for SOC 2. Unlike a SOC 2 report, which is restricted and detailed, a SOC 3 is a short, summary-level report that can be freely distributed, making it useful as a public trust artifact.",{"label":8324,"content":8325},"How is SOC 3 different from SOC 2?","Both evaluate controls against the Trust Services Criteria, but a SOC 2 report is detailed (including the auditor's tests and results) and shared under NDA with customers and prospects, while a SOC 3 omits those details and is general-use — you can publish it on your website. SOC 3 is typically issued from the same audit as a SOC 2 Type 2.",{"label":8327,"content":8328},"Do I need a separate audit for SOC 3?","Generally no. Most organizations obtain SOC 3 alongside their SOC 2 Type 2 from the same CPA firm, since both rely on the same controls and evidence over the same period.",{"label":8330,"content":8331},"Who should get a SOC 3?","SaaS and service organizations that want a public, shareable proof of their security posture — useful for marketing and for buyers who want assurance before they are far enough along to receive the full SOC 2 under NDA.",{"headline":8333,"title":8334,"description":8335,"links":8336},"A public trust report","Publish a SOC 3 from your SOC 2 program","SOC 3 is the freely distributable, general-use version of SOC 2 — same Trust Services Criteria, summary form. Produce it from the control evidence you already maintain.",[8337,8338],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"\u002Fframeworks\u002Fsoc3",{"headline":8342,"title":8342,"description":8343,"items":8344},"SOC 3 accelerators","Turn your SOC 2 work into a public trust asset.",[8345,8348,8351],{"title":8346,"description":8347},"TSC evidence library","The same control evidence that supports your SOC 2.",{"title":8349,"description":8350},"Trust-page publishing","Place the general-use SOC 3 where prospects can find it.",{"title":8352,"description":8353},"SOC 2 crosswalk","Reuse your SOC 2 program directly for SOC 3.",{"title":8355,"description":8356},"SOC 3 Compliance Software","Produce a public, general-use SOC 3 report from the same Trust Services Criteria as your SOC 2 — a shareable trust artifact generated from live control evidence.","soc3",[8359,8362,8365],{"value":8360,"description":8361},"General use","A public report you can post on your website — no NDA required.",{"value":8363,"description":8364},"Same TSC","Built on the same Trust Services Criteria as SOC 2.",{"value":8366,"description":8367},"One audit","Typically issued alongside a SOC 2 Type 2 by the same CPA firm.","5.frameworks\u002Fsoc3","MujYPLOtIaMYucAVVsyMQTw7-lkEQjOv9NaLNjR3ddc",{"id":8371,"title":8372,"advantages":8373,"body":8400,"checklist":8438,"cta":8448,"description":93,"extension":151,"faq":8451,"hero":8465,"lastUpdated":186,"meta":8472,"name":8473,"navigation":188,"path":8474,"resources":8475,"seo":8489,"slug":8492,"stats":8493,"stem":8503,"__hash__":8504},"frameworks\u002F5.frameworks\u002Fsox.md","Sox",[8374,8386,8393],{"title":8375,"description":8376,"bullets":8377},"ITGC catalog","A library of IT General Controls organized by domain (access, change, operations, program development) and ready to scope per system.",[8378,8380,8382,8384],{"Access controls":8379},"provisioning, periodic review, termination",{"Change management":8381},"SDLC, code review, deployment",{"Computer operations":8383},"backup, scheduling, incident handling",{"Program development":8385},"testing, approval, segregation",{"title":8387,"description":8388,"bullets":8389},"Segregation of duties","SoD matrices tied to your identity provider data so conflicts surface in near-real time.",[8390,8391,8392],"Predefined conflict library","Custom conflict rules per environment","Quarterly review workflow",{"title":8394,"description":8395,"bullets":8396},"External auditor collaboration","Your external auditors get a scoped workspace with the evidence and walkthroughs they need.",[8397,8398,8399],"Walkthrough scheduling","PBC list management","Evidence rooms with watermarking",{"type":29,"value":8401,"toc":8433},[8402,8406,8409,8412,8416,8423,8425],[32,8403,8405],{"id":8404},"what-is-sox","What is SOX?",[37,8407,8408],{},"The Sarbanes-Oxley Act of 2002 — commonly \"SOX\" — is US federal legislation enacted in the wake of the Enron and WorldCom accounting scandals. Among other provisions, it imposes responsibilities on senior management of publicly traded companies for the accuracy of financial reporting and the effectiveness of internal controls over financial reporting (ICFR).",[37,8410,8411],{},"The most operationally significant provisions for IT and security teams are Section 302 (CEO\u002FCFO certifications) and Section 404 (management assessment plus external auditor attestation of ICFR). For most IT organizations, SOX work concentrates in IT General Controls (ITGCs) — access management, change management, computer operations, and program development controls — that support the application controls relied on for financial reporting.",[32,8413,8415],{"id":8414},"who-needs-sox","Who needs SOX",[37,8417,8418,8419,8422],{},"US public companies (and many foreign private issuers listed on US exchanges) must comply with SOX. Private companies typically start SOX readiness 12-18 months before an IPO. SaaS companies serving public-company customers often issue ",[249,8420,8421],{"href":7583},"SOC 1 Type II"," reports to support their customers' SOX programs.",[32,8424,244],{"id":243},[37,8426,8427,8428,254,8431,258],{},"episki carries SOX ITGC controls with continuous evaluation and an audit trail that records who did what and on whose behalf — including agents, whose writes route through the same path as the UI so they are indistinguishable from hand-made ones in the log. Change management evidence comes from branch protection and deploy checks; access evidence from live identity data. Decisions that carry weight require a recorded approver and rationale. ",[249,8429,253],{"href":185,"rel":8430},[252],[249,8432,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":8434},[8435,8436,8437],{"id":8404,"depth":94,"text":8405},{"id":8414,"depth":94,"text":8415},{"id":243,"depth":94,"text":244},{"title":8439,"description":8440,"items":8441},"SOX readiness inside episki","Built for SOX programs that need to actually run, not just exist.",[8442,8443,8444,8445,8446,8447],"ITGC library scoped to in-scope systems","Segregation-of-duties matrix per system","Management test plan with quarterly cadences","Deficiency tracking with remediation workflows","External auditor portal with PBC management","Walkthrough scheduling and documentation",{"title":8449,"description":8450},"Quiet your SOX quarter","Move ITGC, SoD, and external auditor management into one workspace.",{"title":8452,"items":8453},"SOX frequently asked questions",[8454,8456,8459,8462],{"label":8405,"content":8455},"The Sarbanes-Oxley Act of 2002 is US federal legislation that imposes financial-reporting and internal-control obligations on publicly traded companies. Section 404 requires management to assess and external auditors to attest to the effectiveness of internal controls over financial reporting (ICFR), including IT General Controls (ITGCs).",{"label":8457,"content":8458},"Who needs to comply with SOX?","US public companies (and many foreign private issuers listed on US exchanges) are subject to SOX. Private companies preparing for IPO often start SOX readiness 12-18 months before going public. SOX also flows down to material service providers via SOC 1 reports.",{"label":8460,"content":8461},"What are ITGCs?","IT General Controls are the controls in your IT environment that support the operation of application-level controls relevant to financial reporting. They typically include access provisioning, change management, computer operations, and program development controls.",{"label":8463,"content":8464},"How does SOX differ from SOC 1?","SOX is the regulation; SOC 1 is an attestation report a service provider issues to assure its customers that the provider's controls relevant to the customers' financial reporting are operating effectively. Many SaaS companies issue SOC 1 to support their customers' SOX programs.",{"headline":8466,"title":8467,"description":8468,"links":8469},"SOX, the quiet quarter","Manage SOX ITGC without losing the quarter","ITGC catalog with quarterly test cadences, segregation-of-duties tracking, walkthrough scheduling, and an external-auditor portal — so SOX season stops eating your engineering team.",[8470,8471],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"SOX","\u002Fframeworks\u002Fsox",{"headline":8476,"title":8477,"description":8478,"items":8479},"SOX accelerators","SOX program accelerators","Cut SOX cycle time without compromising audit readiness.",[8480,8483,8486],{"title":8481,"description":8482},"ITGC scoping wizard","Identify in-scope systems based on financial materiality.",{"title":8484,"description":8485},"SoD conflict matrix","Pre-built conflict library, customizable per ERP\u002FHRIS.",{"title":8487,"description":8488},"Deficiency severity calibrator","Calibrate control deficiencies against PCAOB and SAS 145 guidance.",{"title":8490,"description":8491},"SOX (Sarbanes-Oxley) Compliance Software","Manage IT general controls (ITGC) and key reports for Sarbanes-Oxley with structured testing cycles, segregation-of-duties tracking, and external-auditor portals.","sox",[8494,8497,8500],{"value":8495,"description":8496},"ITGC","IT General Controls library covering access, change, operations, and program development.",{"value":8498,"description":8499},"Quarterly","Pre-built test cadences for management-testing cycles and external auditor handoffs.",{"value":8501,"description":8502},"SoD","Segregation-of-duties matrix and conflict detection tied to identity providers.","5.frameworks\u002Fsox","U1l4bNjY8WUK1JevnIoZkRvM9bFDO1QAVQnfEiQeBpM",{"id":8506,"title":8507,"advantages":8508,"body":8528,"checklist":8602,"cta":8612,"description":93,"extension":151,"faq":8615,"hero":8629,"lastUpdated":186,"meta":8636,"name":2257,"navigation":188,"path":2256,"resources":8637,"seo":8649,"slug":8652,"stats":8653,"stem":8662,"__hash__":8663},"frameworks\u002F5.frameworks\u002Fstateramp.md","Stateramp",[8509,8515,8521],{"title":1840,"description":8510,"bullets":8511},"The same NIST 800-53 control work as FedRAMP, scoped to StateRAMP.",[8512,8513,8514],"Low, Moderate, and High baselines","SSP generated from control evidence","POA&M tracked to closure",{"title":1854,"description":8516,"bullets":8517},"The ongoing ConMon deliverables StateRAMP expects.",[8518,8519,8520],"Monthly vulnerability and POA&M reporting","Significant-change workflow","Security Snapshot and progressing status",{"title":8522,"description":8523,"bullets":8524},"FedRAMP reciprocity","Reuse FedRAMP evidence to accelerate StateRAMP, and vice versa.",[8525,8526,8527],"Shared 800-53 control library","3PAO assessment workspace","One program for federal and SLG buyers",{"type":29,"value":8529,"toc":8596},[8530,8534,8550,8554,8573,8576,8586,8588],[32,8531,8533],{"id":8532},"what-is-stateramp","What is StateRAMP?",[37,8535,8536,8538,8539,8542,8543,8545,8546,8549],{},[53,8537,2257],{}," is a nonprofit program that brings a standardized, FedRAMP-style approach to cloud security for ",[53,8540,8541],{},"state and local governments",". Like FedRAMP, it is based on the ",[53,8544,5856],{}," control catalog and uses accredited third-party assessment organizations (3PAOs), and it maintains an ",[53,8547,8548],{},"Authorized Product List (APL)"," of cloud offerings that government agencies can procure with confidence.",[32,8551,8553],{"id":8552},"baselines-and-status","Baselines and status",[37,8555,8556,8557,8560,8561,8564,8565,8568,8569,8572],{},"StateRAMP uses ",[53,8558,8559],{},"Low, Moderate, and High"," impact baselines drawn from NIST 800-53. Providers progress through recognized statuses — from an early-stage ",[53,8562,8563],{},"Security Snapshot"," to ",[53,8566,8567],{},"Ready"," and ultimately ",[53,8570,8571],{},"Authorized"," — reflecting how far an offering has advanced through assessment and continuous monitoring. Authorization requires a government sponsor or review through the StateRAMP PMO.",[32,8574,8522],{"id":8575},"fedramp-reciprocity",[37,8577,8578,8579,8581,8582,8585],{},"Because StateRAMP and ",[249,8580,2241],{"href":2541}," share the same NIST 800-53 foundation, StateRAMP offers ",[53,8583,8584],{},"reciprocity",": a provider's FedRAMP authorization work can be leveraged toward StateRAMP status, and a single 800-53 control program can serve both federal and state\u002Flocal buyers.",[32,8587,244],{"id":243},[37,8589,8590,8591,254,8594,258],{},"episki carries StateRAMP baselines alongside FedRAMP and NIST 800-53, sharing controls and evidence between them rather than duplicating the work. Controls are evaluated continuously, boundaries are enforceable through account, region, resource, and tag rules, and findings carry owners and due dates into Jira, Linear, or GitHub. ",[249,8592,253],{"href":185,"rel":8593},[252],[249,8595,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":8597},[8598,8599,8600,8601],{"id":8532,"depth":94,"text":8533},{"id":8552,"depth":94,"text":8553},{"id":8575,"depth":94,"text":8522},{"id":243,"depth":94,"text":244},{"title":8603,"description":8604,"items":8605},"StateRAMP readiness inside episki","What a cloud provider needs to reach the StateRAMP APL.",[8606,8607,8608,8609,8610,8611],"Impact-level determination (Low \u002F Moderate \u002F High)","NIST 800-53 baseline implemented as controls","System Security Plan from control evidence","3PAO assessment and POA&M tracking","Continuous monitoring cadences and reporting","Government sponsor or StateRAMP PMO path",{"title":8613,"description":8614},"Reach StateRAMP Authorized in episki","Build on your NIST 800-53 and FedRAMP work to serve state and local government.",{"title":8616,"items":8617},"StateRAMP frequently asked questions",[8618,8620,8623,8626],{"label":8533,"content":8619},"StateRAMP is a nonprofit program that standardizes cloud security assessment, authorization, and continuous monitoring for state and local governments — much as FedRAMP does for the federal government. It is based on NIST SP 800-53 and maintains an Authorized Product List of verified cloud offerings.",{"label":8621,"content":8622},"How does StateRAMP relate to FedRAMP?","Both are built on NIST 800-53 baselines and use accredited third-party assessors (3PAOs), and StateRAMP offers reciprocity — providers with FedRAMP authorization can leverage that work toward StateRAMP status. The main difference is the sponsoring government audience.",{"label":8624,"content":8625},"What are the status levels?","StateRAMP recognizes progressing and verified statuses — including a Security Snapshot for early-stage providers, 'Ready,' and 'Authorized' — reflecting how far a cloud offering has advanced through assessment and continuous monitoring.",{"label":8627,"content":8628},"Who needs StateRAMP?","Cloud service providers that sell to state and local government agencies, which increasingly require StateRAMP status (or equivalent) as a procurement condition for handling government data.",{"headline":8630,"title":8631,"description":8632,"links":8633},"StateRAMP, without the binders","Get authorized to serve state and local government","NIST 800-53 baselines for Low, Moderate, and High, a continuous-monitoring program, and FedRAMP reciprocity — managed as living controls for the StateRAMP Authorized Product List.",[8634,8635],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},{"headline":8638,"title":8639,"description":8640,"items":8641},"StateRAMP accelerators","StateRAMP authorization accelerators","Move from intent to the Authorized Product List faster.",[8642,8644,8646],{"title":2548,"description":8643},"Compose the System Security Plan from live control data.",{"title":2554,"description":8645},"Track your monthly continuous-monitoring obligations.",{"title":8647,"description":8648},"FedRAMP crosswalk","Reuse FedRAMP control evidence toward StateRAMP.",{"title":8650,"description":8651},"StateRAMP Compliance Software","Reach StateRAMP Authorized status for state and local government with NIST 800-53 baselines, continuous monitoring, and FedRAMP reciprocity — in one workspace.","stateramp",[8654,8656,8659],{"value":2562,"description":8655},"Low, Moderate, and High impact levels based on NIST 800-53.",{"value":8657,"description":8658},"APL listed","Reach Ready or Authorized status on the StateRAMP Authorized Product List.",{"value":8660,"description":8661},"FedRAMP reuse","Reciprocity lets FedRAMP work carry over to StateRAMP.","5.frameworks\u002Fstateramp","Snx2UFruTJf0EQp6oveRWZgQGVcW1U5IZ80iozdXqcM",{"id":8665,"title":8666,"advantages":8667,"body":8689,"checklist":8760,"cta":8770,"description":93,"extension":151,"faq":8773,"hero":8787,"lastUpdated":186,"meta":8794,"name":8699,"navigation":188,"path":8795,"resources":8796,"seo":8809,"slug":8812,"stats":8813,"stem":8822,"__hash__":8823},"frameworks\u002F5.frameworks\u002Ftisax.md","Tisax",[8668,8675,8682],{"title":8669,"description":8670,"bullets":8671},"VDA ISA as controls","The TISAX questionnaire implemented as a living control library.",[8672,8673,8674],"Information security control catalogue","Prototype protection where in scope","Data protection module aligned to GDPR",{"title":8676,"description":8677,"bullets":8678},"Scoped to the right level","Match the assessment level and labels your OEM or supplier requires.",[8679,8680,8681],"Assessment levels AL1, AL2, and AL3","Information security, prototype, and data protection labels","Maturity-based scoring per control",{"title":8683,"description":8684,"bullets":8685},"Reuse your security program","TISAX overlaps heavily with ISO 27001 controls you may already hold.",[8686,8687,8688],"Crosswalk to ISO 27001 Annex A","Evidence shared with SOC 2 and NIST CSF","One control set, multiple audiences",{"type":29,"value":8690,"toc":8754},[8691,8695,8715,8719,8733,8737,8744,8746],[32,8692,8694],{"id":8693},"what-is-tisax","What is TISAX?",[37,8696,8697,412,8700,8703,8704,8707,8708,8711,8712,258],{},[53,8698,8699],{},"TISAX",[53,8701,8702],{},"Trusted Information Security Assessment Exchange"," — is how the automotive industry assesses and shares information security maturity across its supply chain. It is governed by the ",[53,8705,8706],{},"ENX Association"," and built on the ",[53,8709,8710],{},"VDA ISA"," (Information Security Assessment) catalogue created by the German automotive industry association. Rather than each OEM auditing each supplier, suppliers undergo a single assessment by an accredited audit provider and ",[53,8713,8714],{},"exchange the results with partners on the ENX portal",[32,8716,8718],{"id":8717},"labels-and-assessment-levels","Labels and assessment levels",[37,8720,8721,8722,8725,8726,8729,8730,258],{},"A TISAX assessment is scoped by ",[53,8723,8724],{},"labels"," — information security, prototype protection (for organizations handling pre-series parts and vehicles), and data protection (aligned with GDPR) — and by ",[53,8727,8728],{},"assessment level (AL1, AL2, or AL3)",", which determines how rigorous the audit is. The OEM or customer requesting the assessment specifies the labels and level required. A successful assessment yields labels that are typically ",[53,8731,8732],{},"valid for three years",[32,8734,8736],{"id":8735},"how-tisax-relates-to-iso-27001","How TISAX relates to ISO 27001",[37,8738,8739,8740,8743],{},"The VDA ISA catalogue is closely aligned with ",[53,8741,8742],{},"ISO\u002FIEC 27001",", so an organization with a mature ISMS already meets a large share of TISAX requirements. The main differences are the automotive-specific prototype-protection controls and the maturity-based scoring model.",[32,8745,244],{"id":243},[37,8747,8748,8749,254,8752,258],{},"episki maps the VDA ISA catalogue to controls evaluated continuously, with crosswalks to ISO 27001 derived through the SCF hub so the ISMS work counts for both. Assessment levels are expressed as scope, prototype and data protection requirements carry their own controls, and findings route to owners with due dates. ",[249,8750,253],{"href":185,"rel":8751},[252],[249,8753,257],{"href":178},{"title":93,"searchDepth":94,"depth":94,"links":8755},[8756,8757,8758,8759],{"id":8693,"depth":94,"text":8694},{"id":8717,"depth":94,"text":8718},{"id":8735,"depth":94,"text":8736},{"id":243,"depth":94,"text":244},{"title":8761,"description":8762,"items":8763},"TISAX readiness inside episki","What an automotive supplier needs in place.",[8764,8765,8766,8767,8768,8769],"Scope and assessment-level determination","VDA ISA information-security controls implemented","Prototype protection controls (if in scope)","Data protection module (if in scope)","Maturity-level evidence per control","Audit-provider evidence package and ENX exchange",{"title":8771,"description":8772},"Get TISAX-ready in episki","Implement the VDA ISA catalogue once and reuse your ISO 27001 evidence to get there.",{"title":8774,"items":8775},"TISAX frequently asked questions",[8776,8778,8781,8784],{"label":8694,"content":8777},"TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's mechanism for assessing and sharing information security maturity. It is governed by the ENX Association and based on the VDA ISA (Information Security Assessment) catalogue developed by the German automotive industry. Suppliers are assessed by accredited audit providers and exchange results with partners on the ENX portal.",{"label":8779,"content":8780},"Is TISAX a certification?","Strictly speaking, TISAX produces an assessment result and a label rather than a certificate. A successful assessment yields labels (for information security, prototype protection, and\u002For data protection) that are shared with customers through the ENX portal and are typically valid for three years.",{"label":8782,"content":8783},"What are the assessment levels?","TISAX defines assessment levels AL1, AL2, and AL3 reflecting increasing rigor — from self-assessment-based to in-depth audits with evidence review and on-site or remote validation. The level and labels required are set by the OEM or customer requesting the assessment.",{"label":8785,"content":8786},"How does TISAX relate to ISO 27001?","The VDA ISA catalogue is closely aligned with ISO\u002FIEC 27001, so organizations with an existing ISMS already satisfy much of TISAX. episki maps your ISO 27001 controls to the ISA catalogue so the overlap is reused rather than rebuilt.",{"headline":8788,"title":8789,"description":8790,"links":8791},"TISAX, without the spreadsheet","Prepare for your TISAX assessment","The VDA ISA catalogue implemented as living controls, scoped to the right assessment level and labels, with evidence ready for your audit provider and the ENX portal.",[8792,8793],{"label":181,"icon":182,"to":185},{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"\u002Fframeworks\u002Ftisax",{"headline":8797,"title":8798,"description":8799,"items":8800},"TISAX accelerators","TISAX readiness accelerators","Get assessment-ready and share results with partners faster.",[8801,8804,8807],{"title":8802,"description":8803},"ISA control library","The VDA ISA catalogue as living controls with maturity scoring.",{"title":8805,"description":8806},"Scope and label selector","Pick the assessment level and labels your customer requires.",{"title":1414,"description":8808},"Reuse your ISMS evidence against the ISA catalogue.",{"title":8810,"description":8811},"TISAX Compliance Software","Prepare for a TISAX assessment based on the VDA ISA catalogue — information security, prototype protection, and data protection — with controls and evidence in one workspace.","tisax",[8814,8816,8819],{"value":8710,"description":8815},"The automotive industry's Information Security Assessment catalogue, as controls.",{"value":8817,"description":8818},"AL1 \u002F AL2 \u002F AL3","Scope to the assessment level your customer requires.",{"value":8820,"description":8821},"ENX shared","Results exchanged with partners on the ENX portal, valid for three years.","5.frameworks\u002Ftisax","NVawAz4NY8354z-mkQ-0sfWfO3OZ3Vr1F9eltmCvSYg",[8825,9375],{"id":8826,"title":8827,"body":8828,"description":93,"extension":151,"lastUpdated":186,"meta":9362,"navigation":188,"path":9363,"relatedFrameworks":9364,"relatedTerms":9365,"seo":9369,"slug":9372,"stem":9373,"term":8833,"__hash__":9374},"glossary\u002F8.glossary\u002Faccess-control.md","Access Control",{"type":29,"value":8829,"toc":9348},[8830,8834,8837,8841,8844,8870,8874,8880,8886,8892,8898,8902,8905,8911,8928,8934,8948,8954,8965,8969,8972,9016,9020,9023,9037,9041,9044,9067,9071,9074,9123,9127,9130,9244,9247,9250,9279,9283,9289,9292,9328,9331,9334,9337,9341],[32,8831,8833],{"id":8832},"what-is-access-control","What is Access Control?",[37,8835,8836],{},"Access control is the set of policies, procedures, and technical mechanisms that regulate who can access systems, data, and resources within an organization. It ensures that only authorized individuals can view, modify, or interact with sensitive information and critical systems. Access control is one of the most fundamental and universally required security controls across every major compliance framework.",[597,8838,8840],{"id":8839},"what-are-the-core-principles-of-access-control","What are the core principles of access control?",[37,8842,8843],{},"Access control is built on several foundational principles:",[47,8845,8846,8852,8858,8864],{},[50,8847,8848,8851],{},[53,8849,8850],{},"Least privilege"," — users are granted only the minimum access necessary to perform their job functions",[50,8853,8854,8857],{},[53,8855,8856],{},"Separation of duties"," — critical tasks are divided among multiple individuals to prevent any single person from having unchecked authority",[50,8859,8860,8863],{},[53,8861,8862],{},"Need to know"," — access to information is restricted to those who require it for a specific purpose",[50,8865,8866,8869],{},[53,8867,8868],{},"Default deny"," — access is denied by default unless explicitly granted",[597,8871,8873],{"id":8872},"what-are-the-types-of-access-control","What are the types of access control?",[37,8875,8876,8879],{},[53,8877,8878],{},"Role-Based Access Control (RBAC)"," — access is determined by the user's role within the organization. Roles are defined with specific permissions, and users are assigned to roles. This is the most common model in enterprise environments.",[37,8881,8882,8885],{},[53,8883,8884],{},"Attribute-Based Access Control (ABAC)"," — access decisions are based on attributes of the user, the resource, and the environment (e.g., department, location, time of day, device type).",[37,8887,8888,8891],{},[53,8889,8890],{},"Discretionary Access Control (DAC)"," — resource owners decide who can access their resources. Common in file systems where owners set permissions.",[37,8893,8894,8897],{},[53,8895,8896],{},"Mandatory Access Control (MAC)"," — access is controlled by the system based on security labels and clearance levels. Common in government and military environments.",[597,8899,8901],{"id":8900},"what-are-access-control-components","What are access control components?",[37,8903,8904],{},"A complete access control program addresses:",[37,8906,8907,8910],{},[53,8908,8909],{},"Authentication"," — verifying the identity of users:",[47,8912,8913,8916,8919,8922,8925],{},[50,8914,8915],{},"Passwords and passphrases",[50,8917,8918],{},"Multi-factor authentication (MFA)",[50,8920,8921],{},"Single sign-on (SSO)",[50,8923,8924],{},"Biometric authentication",[50,8926,8927],{},"Certificate-based authentication",[37,8929,8930,8933],{},[53,8931,8932],{},"Authorization"," — determining what authenticated users can do:",[47,8935,8936,8939,8942,8945],{},[50,8937,8938],{},"Permission assignments",[50,8940,8941],{},"Role definitions",[50,8943,8944],{},"Access control lists",[50,8946,8947],{},"Policy enforcement points",[37,8949,8950,8953],{},[53,8951,8952],{},"Access lifecycle management"," — managing access throughout the user lifecycle:",[47,8955,8956,8959,8962],{},[50,8957,8958],{},"Provisioning (granting access when hired or role changes)",[50,8960,8961],{},"Review (periodic access certification)",[50,8963,8964],{},"Deprovisioning (revoking access upon termination or role change)",[597,8966,8968],{"id":8967},"how-do-compliance-frameworks-address-access-control","How do compliance frameworks address access control?",[37,8970,8971],{},"Every major framework requires access control:",[47,8973,8974,8981,8992,9002,9009],{},[50,8975,8976,8980],{},[53,8977,8978],{},[249,8979,475],{"href":474}," — CC6.1 through CC6.8 cover logical and physical access controls",[50,8982,8983,8987,8988,8991],{},[53,8984,8985],{},[249,8986,470],{"href":469}," — ",[249,8989,8990],{"href":4042},"Annex A"," controls A.5.15 through A.5.18 and A.8.2 through A.8.5 address access management",[50,8993,8994,412,8998,9001],{},[53,8995,8996],{},[249,8997,3459],{"href":3607},[249,8999,9000],{"href":3320},"Security Rule"," requires access controls for ePHI (45 CFR 164.312(a))",[50,9003,9004,9008],{},[53,9005,9006],{},[249,9007,6662],{"href":7120}," — Requirements 7 and 8 address access restriction and user identification",[50,9010,9011,9015],{},[53,9012,9013],{},[249,9014,465],{"href":464}," — PR.AC covers identity management, authentication, and access control",[597,9017,9019],{"id":9018},"what-are-access-reviews","What are access reviews?",[37,9021,9022],{},"Regular access reviews (also called access certifications) are a critical control:",[47,9024,9025,9028,9031,9034],{},[50,9026,9027],{},"Review user access rights periodically (quarterly is common for sensitive systems)",[50,9029,9030],{},"Verify that access aligns with current job responsibilities",[50,9032,9033],{},"Identify and remove excessive or unnecessary access",[50,9035,9036],{},"Document review results and remediation actions",[597,9038,9040],{"id":9039},"what-are-common-access-control-weaknesses","What are common access control weaknesses?",[37,9042,9043],{},"Even well-designed access control programs can degrade over time without ongoing attention. Watch for these common issues:",[47,9045,9046,9049,9052,9055,9058,9061,9064],{},[50,9047,9048],{},"Excessive permissions that accumulate over time (privilege creep)",[50,9050,9051],{},"Shared or generic accounts that prevent individual accountability",[50,9053,9054],{},"Delayed deprovisioning when employees leave or change roles",[50,9056,9057],{},"Lack of MFA on critical systems and remote access paths",[50,9059,9060],{},"Inconsistent access review processes with no documented remediation",[50,9062,9063],{},"Service accounts with standing privileged access and no rotation schedule",[50,9065,9066],{},"Lack of visibility into SaaS application access outside the corporate IdP",[597,9068,9070],{"id":9069},"how-do-you-implement-access-control-in-practice","How do you implement access control in practice?",[37,9072,9073],{},"Effective access control programs start with planning and build toward automation. The following steps provide a practical roadmap for organizations at any maturity level:",[903,9075,9076,9082,9088,9094,9100,9106,9117],{},[50,9077,9078,9081],{},[53,9079,9080],{},"Map your environment"," — inventory all systems, applications, and data repositories that require access controls. You cannot protect what you have not identified. Include SaaS applications, cloud infrastructure, on-premises servers, databases, file shares, and third-party integrations.",[50,9083,9084,9087],{},[53,9085,9086],{},"Define roles based on job functions"," — create roles that reflect organizational responsibilities, not individual users. Align roles to the principle of least privilege so each role includes only the permissions required for that function. Review role definitions annually and whenever organizational structure changes.",[50,9089,9090,9093],{},[53,9091,9092],{},"Centralize authentication with SSO"," — implement single sign-on using SAML 2.0 or OpenID Connect (OIDC) to unify identity across cloud and on-premises systems. Centralized authentication reduces password sprawl and gives security teams a single point of enforcement. Ensure all business-critical applications are integrated with your SSO provider before considering the rollout complete.",[50,9095,9096,9099],{},[53,9097,9098],{},"Layer MFA on all critical systems"," — require multi-factor authentication for remote access, privileged accounts, email, cloud consoles, and any system that touches sensitive data. Phishing-resistant methods such as FIDO2 hardware keys are preferred over SMS-based codes. At a minimum, enforce MFA on identity providers, admin consoles, and VPN access.",[50,9101,9102,9105],{},[53,9103,9104],{},"Automate provisioning and deprovisioning"," — connect your HR system to your identity provider (IdP) and use SCIM or directory sync to automate account creation, role assignment, and account removal. When an employee is terminated in the HR system, access should be revoked within minutes, not days. Automation eliminates the human error that leads to orphaned accounts and privilege creep.",[50,9107,9108,9111,9112,9116],{},[53,9109,9110],{},"Build an access request and approval workflow"," — establish a formal process where users request access with documented business justification, managers approve, and the request is logged for audit. This creates an ",[249,9113,9115],{"href":9114},"\u002Fglossary\u002Faudit-trail","audit trail"," that satisfies compliance requirements.",[50,9118,9119,9122],{},[53,9120,9121],{},"Monitor and log access events"," — collect authentication and authorization logs centrally. Monitor for anomalies such as failed login attempts, access from unusual locations, and privilege escalation. Logs are essential for incident response and audit evidence.",[597,9124,9126],{"id":9125},"what-are-the-access-control-requirements","What are the access control requirements?",[37,9128,9129],{},"Different frameworks address the same access control concepts with different control references. The table below maps common requirements to their framework-specific identifiers:",[1947,9131,9132,9149],{},[1950,9133,9134],{},[1953,9135,9136,9139,9141,9143,9145,9147],{},[1956,9137,9138],{},"Requirement",[1956,9140,475],{},[1956,9142,470],{},[1956,9144,3459],{},[1956,9146,6662],{},[1956,9148,465],{},[1969,9150,9151,9171,9190,9210,9227],{},[1953,9152,9153,9156,9159,9162,9165,9168],{},[1974,9154,9155],{},"Unique user IDs",[1974,9157,9158],{},"CC6.1",[1974,9160,9161],{},"A.5.16",[1974,9163,9164],{},"§164.312(a)(2)(i)",[1974,9166,9167],{},"Req 8.2.1",[1974,9169,9170],{},"PR.AC-1",[1953,9172,9173,9176,9178,9181,9184,9187],{},[1974,9174,9175],{},"MFA",[1974,9177,9158],{},[1974,9179,9180],{},"A.8.5",[1974,9182,9183],{},"Addressable",[1974,9185,9186],{},"Req 8.4",[1974,9188,9189],{},"PR.AC-7",[1953,9191,9192,9195,9198,9201,9204,9207],{},[1974,9193,9194],{},"Access reviews",[1974,9196,9197],{},"CC6.2",[1974,9199,9200],{},"A.5.18",[1974,9202,9203],{},"§164.312(a)(1)",[1974,9205,9206],{},"Req 7.2",[1974,9208,9209],{},"PR.AC-4",[1953,9211,9212,9214,9217,9220,9222,9225],{},[1974,9213,8850],{},[1974,9215,9216],{},"CC6.3",[1974,9218,9219],{},"A.5.15",[1974,9221,9203],{},[1974,9223,9224],{},"Req 7.1",[1974,9226,9209],{},[1953,9228,9229,9232,9234,9236,9239,9242],{},[1974,9230,9231],{},"Deprovisioning",[1974,9233,9197],{},[1974,9235,9200],{},[1974,9237,9238],{},"§164.312(a)(2)(ii)",[1974,9240,9241],{},"Req 8.2.6",[1974,9243,9170],{},[37,9245,9246],{},"Organizations subject to multiple frameworks can use this mapping to build a unified access control program that satisfies overlapping requirements without duplicating effort.",[37,9248,9249],{},"A few notes on framework-specific nuances:",[47,9251,9252,9257,9265,9272],{},[50,9253,9254,9256],{},[53,9255,3459],{}," treats MFA as an \"addressable\" implementation specification, meaning covered entities must implement it or document why an equivalent alternative is reasonable. In practice, most organizations implement MFA because the risk of not doing so is difficult to justify.",[50,9258,9259,9264],{},[53,9260,9261,9263],{},[249,9262,6662],{"href":7120}," v4.0"," expanded MFA requirements (Req 8.4) to include all access into the cardholder data environment, not just remote access. Organizations processing card data should verify their MFA coverage meets the updated scope.",[50,9266,9267,9271],{},[53,9268,9269],{},[249,9270,475],{"href":474}," does not prescribe specific technologies but evaluates whether the controls in place are suitably designed and operating effectively. Auditors will look for evidence that access control policies are enforced consistently.",[50,9273,9274,9278],{},[53,9275,9276],{},[249,9277,465],{"href":464}," provides a flexible, risk-based approach. The PR.AC subcategory identifiers map to more detailed controls in NIST SP 800-53, which organizations can reference for implementation guidance.",[597,9280,9282],{"id":9281},"how-does-zero-trust-relate-to-access-control","How does zero trust relate to access control?",[37,9284,9285,9286,258],{},"Traditional access control models assume that users inside the network perimeter can be trusted. Zero trust architecture rejects that assumption entirely: ",[53,9287,9288],{},"never trust, always verify",[37,9290,9291],{},"In a zero trust model, every access request is authenticated, authorized, and encrypted regardless of where it originates. Key principles include:",[47,9293,9294,9300,9306,9316,9322],{},[50,9295,9296,9299],{},[53,9297,9298],{},"Continuous verification"," — access decisions are re-evaluated throughout a session, not just at login. Changes in user behavior, location, or risk score can trigger step-up authentication or session termination.",[50,9301,9302,9305],{},[53,9303,9304],{},"Micro-segmentation"," — network resources are divided into small, isolated zones so that compromising one segment does not grant lateral access to others.",[50,9307,9308,9311,9312,9315],{},[53,9309,9310],{},"Device posture checks"," — the security state of the connecting device (patch level, endpoint protection status, disk ",[249,9313,2951],{"href":9314},"\u002Fglossary\u002Fencryption",") is evaluated before access is granted.",[50,9317,9318,9321],{},[53,9319,9320],{},"Identity-centric perimeter"," — the network perimeter is replaced by identity as the primary security boundary. Every user, device, and workload must prove its identity before accessing any resource.",[50,9323,9324,9327],{},[53,9325,9326],{},"Least privilege enforcement at the session level"," — access grants are scoped to the specific resource and action needed, and they expire when the session ends or conditions change.",[37,9329,9330],{},"NIST SP 800-207 defines the zero trust architecture and provides guidance on implementation. Many compliance frameworks are increasingly aligning their access control requirements with zero trust principles, making it a forward-looking strategy for organizations building or modernizing their access control programs.",[37,9332,9333],{},"Zero trust is not a single product but an architectural approach that spans identity, network, endpoints, and data.",[37,9335,9336],{},"Adopting zero trust does not require replacing your existing access control infrastructure overnight. Most organizations begin by enforcing MFA universally, segmenting their most sensitive assets, and adding device posture checks to their conditional access policies. Over time, these incremental improvements compound into a mature zero trust posture.",[597,9338,9340],{"id":9339},"how-does-episki-help-with-access-control","How does episki help with access control?",[37,9342,9343,9344,258],{},"episki evaluates access rather than inventorying it. Identity evidence from Google, Microsoft, and AWS IAM across multiple accounts is collected and then checked, writing pass, fail, or inconclusive against the control — and a check that finds over-broad access raises a finding naming the specific principals. An unreadable or empty response returns inconclusive rather than passing, so an access control is never attested by a collection that failed. Learn more on our ",[249,9345,9347],{"href":9346},"\u002Fframeworks","compliance platform",{"title":93,"searchDepth":94,"depth":94,"links":9349},[9350],{"id":8832,"depth":94,"text":8833,"children":9351},[9352,9353,9354,9355,9356,9357,9358,9359,9360,9361],{"id":8839,"depth":995,"text":8840},{"id":8872,"depth":995,"text":8873},{"id":8900,"depth":995,"text":8901},{"id":8967,"depth":995,"text":8968},{"id":9018,"depth":995,"text":9019},{"id":9039,"depth":995,"text":9040},{"id":9069,"depth":995,"text":9070},{"id":9125,"depth":995,"text":9126},{"id":9281,"depth":995,"text":9282},{"id":9339,"depth":995,"text":9340},{},"\u002Fglossary\u002Faccess-control",[1066,8200,4416,3624,7137,6367],[9366,9367,2951,9368],"minimum-necessary-rule","audit-trail","user-entity-controls",{"title":9370,"description":9371},"Access Control in Compliance: RBAC, MFA & Least Privilege","Access control restricts system and data access to authorized users. Learn RBAC, MFA, least privilege, and requirements across SOC 2, ISO 27001, HIPAA, and PCI DSS.","access-control","8.glossary\u002Faccess-control","9s8m0GbTkTfzK-1ANXSdpQhsVk3cqHqMcU4xDE8iDn0",{"id":9376,"title":8990,"body":9377,"description":93,"extension":151,"lastUpdated":186,"meta":9516,"navigation":188,"path":4042,"relatedFrameworks":9517,"relatedTerms":9518,"seo":9523,"slug":9526,"stem":9527,"term":9382,"__hash__":9528},"glossary\u002F8.glossary\u002Fannex-a.md",{"type":29,"value":9378,"toc":9506},[9379,9383,9393,9397,9400,9426,9430,9433,9450,9453,9457,9460,9464,9467,9481,9484,9488,9497,9501],[32,9380,9382],{"id":9381},"what-is-iso-27001-annex-a","What is ISO 27001 Annex A?",[37,9384,9385,9386,9388,9389,9392],{},"ISO 27001 Annex A is the normative annex to the ",[249,9387,470],{"href":469}," standard that provides a reference list of information security controls. Organizations use Annex A as a checklist to ensure their ",[249,9390,9391],{"href":4134},"Information Security Management System (ISMS)"," addresses a comprehensive range of security topics. As of the 2022 revision, Annex A contains 93 controls organized into four themes.",[597,9394,9396],{"id":9395},"what-are-the-four-themes","What are the four themes?",[37,9398,9399],{},"The 2022 revision reorganized controls from the previous 14 categories into four themes:",[47,9401,9402,9408,9414,9420],{},[50,9403,9404,9407],{},[53,9405,9406],{},"Organizational controls (37 controls)"," — policies, roles and responsibilities, threat intelligence, information security in project management, supplier relationships, and more",[50,9409,9410,9413],{},[53,9411,9412],{},"People controls (8 controls)"," — screening, terms and conditions of employment, security awareness training, disciplinary processes, and responsibilities after termination",[50,9415,9416,9419],{},[53,9417,9418],{},"Physical controls (14 controls)"," — physical security perimeters, entry controls, securing offices and facilities, equipment protection, and clear desk policies",[50,9421,9422,9425],{},[53,9423,9424],{},"Technological controls (34 controls)"," — user endpoint devices, privileged access management, access restrictions, secure authentication, malware protection, logging, encryption, and secure development",[597,9427,9429],{"id":9428},"how-does-annex-a-fit-into-iso-27001","How does Annex A fit into ISO 27001?",[37,9431,9432],{},"Annex A is not a standalone list of mandatory controls. Instead, it works in conjunction with the risk assessment process defined in clauses 6 and 8 of ISO 27001:",[903,9434,9435,9438,9441,9444,9447],{},[50,9436,9437],{},"The organization performs a risk assessment to identify information security risks",[50,9439,9440],{},"The organization determines how to treat each risk (mitigate, accept, transfer, or avoid)",[50,9442,9443],{},"For risks being mitigated, the organization selects appropriate controls",[50,9445,9446],{},"The organization compares selected controls against Annex A to ensure nothing has been overlooked",[50,9448,9449],{},"The results are documented in the Statement of Applicability",[37,9451,9452],{},"This approach ensures that control selection is risk-driven rather than checkbox-driven. An organization may determine that certain Annex A controls are not applicable based on their specific risk profile, and this is acceptable as long as the justification is documented.",[597,9454,9456],{"id":9455},"how-does-annex-a-relate-to-iso-27002","How does Annex A relate to ISO 27002?",[37,9458,9459],{},"ISO 27002 provides detailed implementation guidance for each Annex A control. While Annex A lists the controls with brief descriptions, ISO 27002 explains the purpose, guidance, and other information for each control. Think of Annex A as the \"what\" and ISO 27002 as the \"how.\"",[597,9461,9463],{"id":9462},"what-changed-in-the-2022-revision-of-annex-a","What changed in the 2022 revision of Annex A?",[37,9465,9466],{},"The 2022 update introduced several changes from the 2013 version:",[47,9468,9469,9472,9475,9478],{},[50,9470,9471],{},"Controls were consolidated from 114 to 93",[50,9473,9474],{},"The 14 categories were replaced with 4 themes",[50,9476,9477],{},"11 new controls were added, including threat intelligence, information security for cloud services, ICT readiness for business continuity, and data masking",[50,9479,9480],{},"Each control now includes attributes (control type, cybersecurity concept, operational capability, and security domain) to aid in filtering and mapping",[37,9482,9483],{},"Organizations certified under the 2013 version had a transition period to update their ISMS to align with the 2022 revision.",[597,9485,9487],{"id":9486},"what-is-the-statement-of-applicability","What is the Statement of Applicability?",[37,9489,367,9490,9492,9493,9496],{},[249,9491,4059],{"href":4075}," is the document where an organization records which Annex A controls are applicable, which are not, and the justification for each decision. The SoA is a mandatory document for ",[249,9494,9495],{"href":4008},"ISO 27001 certification"," and is a key artifact reviewed during certification audits.",[597,9498,9500],{"id":9499},"how-does-episki-help-with-annex-a","How does episki help with Annex A?",[37,9502,9503,9504,258],{},"episki maps Annex A to controls evaluated on every sync across your connected estate, with evidence reused by every other framework that claims the same control. A check whose evidence comes back empty or unreadable returns inconclusive and attests nothing, so an Annex A control is never marked satisfied by a collection that silently failed. Learn more about the ",[249,9505,4036],{"href":4053},{"title":93,"searchDepth":94,"depth":94,"links":9507},[9508],{"id":9381,"depth":94,"text":9382,"children":9509},[9510,9511,9512,9513,9514,9515],{"id":9395,"depth":995,"text":9396},{"id":9428,"depth":995,"text":9429},{"id":9455,"depth":995,"text":9456},{"id":9462,"depth":995,"text":9463},{"id":9486,"depth":995,"text":9487},{"id":9499,"depth":995,"text":9500},{},[4416],[4416,9519,9520,9521,9522],"statement-of-applicability","iso-27002","control-objectives","isms",{"title":9524,"description":9525},"ISO 27001 Annex A: All 93 Controls Explained (2022)","ISO 27001 Annex A lists 93 security controls in 4 themes. Learn each control category, how they map to your Statement of Applicability, and implementation tips.","annex-a","8.glossary\u002Fannex-a","ninWoLuGbIvkJx3djy7wTT090WPcFjANjfzM_i_lOn4",[],null,{"id":9532,"title":9533,"body":9534,"comparison":9723,"competitorA":9626,"competitorB":9638,"cta":9771,"description":93,"extension":151,"faq":9774,"hero":9792,"lastUpdated":186,"meta":9800,"navigation":188,"path":9801,"seo":9802,"slug":9805,"slugA":9806,"slugB":9807,"stem":9808,"verdict":9809,"__hash__":9813},"compareVs\u002F7.compare\u002Fvs\u002Fdrata-vs-secureframe.md","Drata Vs Secureframe",{"type":29,"value":9535,"toc":9713},[9536,9540,9543,9547,9550,9556,9559,9563,9566,9569,9572,9576,9579,9582,9586,9589,9660,9663,9666,9670,9673,9676,9680,9683,9686,9689],[32,9537,9539],{"id":9538},"drata-vs-secureframe-the-closest-comparison-in-compliance","Drata vs Secureframe: the closest comparison in compliance",[37,9541,9542],{},"If Vanta is the 800-pound gorilla, Drata and Secureframe are the two challengers most often compared against each other. They target similar buyers, cover similar frameworks, and offer similar automation. The differences are real but subtle — and they matter most in how your team experiences the platform day to day.",[597,9544,9546],{"id":9545},"feature-parity-with-different-emphasis","Feature parity with different emphasis",[37,9548,9549],{},"On paper, Drata and Secureframe look nearly identical. Both automate evidence collection, monitor your compliance posture continuously, support 15+ frameworks, and provide auditor-facing portals. The overlap is so significant that choosing between them often comes down to three factors: onboarding style, dashboard experience, and pricing.",[37,9551,9552,9555],{},[53,9553,9554],{},"Onboarding style"," is the clearest differentiator. Drata leans toward self-serve. The platform guides you through integration setup, control mapping, and evidence configuration with in-app workflows. For teams with compliance experience, this speed is an advantage — you can be operational in 1–2 weeks without waiting for a human to walk you through every step.",[37,9557,9558],{},"Secureframe takes the opposite approach. Every customer gets access to dedicated compliance managers who help interpret requirements, map controls to your environment, and prepare for audit. This white-glove model adds a week or two to implementation but dramatically reduces the learning curve for first-time audit teams.",[597,9560,9562],{"id":9561},"the-dashboard-question","The dashboard question",[37,9564,9565],{},"Drata's compliance dashboard is one of its signature features. The real-time posture view shows passing and failing controls across every framework, with compliance percentages and trend data. For compliance leads who report to a CISO or board, this visual layer simplifies status updates and makes it easy to demonstrate progress.",[37,9567,9568],{},"Secureframe also provides dashboards, but they feel more functional than visual. The platform surfaces actionable items — controls that need attention, evidence that's expiring, gaps to remediate — in a task-oriented format. It's effective, but it doesn't deliver the same at-a-glance executive view that Drata provides.",[37,9570,9571],{},"For teams that need board-ready compliance reporting, Drata has the edge. For teams that care more about daily workflow and task management, Secureframe's approach may feel more productive.",[597,9573,9575],{"id":9574},"integration-depth","Integration depth",[37,9577,9578],{},"Secureframe holds a slight advantage in integration count, with 150+ connections compared to Drata's 100+. The extra integrations primarily cover developer tools, identity providers, and security platforms. For teams running complex stacks with multiple CI\u002FCD pipelines, vulnerability scanners, and endpoint management tools, Secureframe's broader integration library means less manual evidence collection.",[37,9580,9581],{},"Drata's integrations, while fewer in number, tend to offer deeper configuration options for the platforms they do support. If your stack is standard — AWS or GCP, Okta or Google Workspace, GitHub, and a common HR tool — both platforms will serve you equally well.",[597,9583,9585],{"id":9584},"pricing-opacity","Pricing opacity",[37,9587,9588],{},"Neither Drata nor Secureframe publishes pricing. Both require a sales conversation to get a quote, and both scale based on team size, framework count, and contract terms. Here's how the major platforms compare on 2026 pricing, based on market data:",[1947,9590,9591,9606],{},[1950,9592,9593],{},[1953,9594,9595,9598,9601,9603],{},[1956,9596,9597],{},"Platform",[1956,9599,9600],{},"Typical entry price (2026)",[1956,9602,109],{},[1956,9604,9605],{},"Published?",[1969,9607,9608,9622,9634,9646],{},[1953,9609,9610,9613,9616,9619],{},[1974,9611,9612],{},"Vanta",[1974,9614,9615],{},"~$11,000–$15,000\u002Fyr",[1974,9617,9618],{},"Per-seat + framework, custom quote",[1974,9620,9621],{},"No",[1953,9623,9624,9627,9630,9632],{},[1974,9625,9626],{},"Drata",[1974,9628,9629],{},"~$10,000–$15,000\u002Fyr",[1974,9631,9618],{},[1974,9633,9621],{},[1953,9635,9636,9639,9642,9644],{},[1974,9637,9638],{},"Secureframe",[1974,9640,9641],{},"~$8,000–$12,000\u002Fyr",[1974,9643,9618],{},[1974,9645,9621],{},[1953,9647,9648,9651,9654,9657],{},[1974,9649,9650],{},"episki",[1974,9652,9653],{},"$750\u002Fmo ($7,500\u002Fyr)",[1974,9655,9656],{},"Flat platform + modules, unlimited seats",[1974,9658,9659],{},"Yes",[37,9661,9662],{},"At scale, Vanta, Drata, and Secureframe all reach $30,000–$50,000\u002Fyr for larger organizations. Secureframe usually starts slightly cheaper than Drata at the entry tier, but because both scale on seats and frameworks, the gap narrows quickly as your team grows.",[37,9664,9665],{},"This pricing opacity creates a frustrating buying experience. You can't model costs internally before engaging sales. You can't easily compare options. And renewal conversations often involve price increases that are hard to predict at the time of initial purchase.",[597,9667,9669],{"id":9668},"where-both-platforms-struggle","Where both platforms struggle",[37,9671,9672],{},"The irony of comparing Drata and Secureframe is that their most significant limitations are shared. Both use pricing models that punish team growth. Both rely on templated control libraries that resist customization. Both treat policy documentation as a secondary concern — something generated through forms rather than crafted through a proper writing experience.",[37,9674,9675],{},"And both lock you into their workflow assumptions. If your compliance program doesn't map cleanly to their templates — if you run hybrid frameworks, need custom controls, or want to structure programs differently than the default — you'll spend time working around the platform instead of working within it.",[597,9677,9679],{"id":9678},"the-case-for-a-different-approach","The case for a different approach",[37,9681,9682],{},"When two products are this similar, the deciding factor often isn't which one is better — it's whether either one is the right category of tool for your needs. If you want maximum automation and are comfortable with enterprise pricing, Drata and Secureframe both deliver.",[37,9684,9685],{},"But if you want GRC that runs itself, episki offers something neither Drata nor Secureframe provides. Where legacy GRC automates evidence, episki automates the program: agents draft policies, answer security questionnaires, map controls, manage vendors, and keep evidence evergreen — while your team approves the work that matters. The AI authors deterministic recipes that then run without AI in the loop, so output is reproducible and auditor-acceptable. A dedicated AI Governance module (agent and use-case registry, ISO 42001, NIST AI RMF, EU AI Act) covers the governance work neither competitor was built for.",[37,9687,9688],{},"It comes with flat pricing at $750\u002Fmo plus optional modules, unlimited seats, and a Notion-like editor for the documentation your team owns. No per-seat scaling. No opaque quotes. No templated policies that read like every other company's — just a program that runs itself, at a price that doesn't make your CFO wince.",[37,9690,9691,9694,9695,392,9699,9703,9704,9708,9709,9712],{},[53,9692,9693],{},"Related reading:"," dig deeper into each platform's competitors in our ",[249,9696,9698],{"href":9697},"\u002Fblog\u002Fdrata-alternatives","Drata alternatives",[249,9700,9702],{"href":9701},"\u002Fblog\u002Fsecureframe-alternatives","Secureframe alternatives"," guides, see where both rank in the ",[249,9705,9707],{"href":9706},"\u002Fblog\u002Fbest-grc-tools-2026","best GRC tools of 2026",", or compare ",[249,9710,9711],{"href":8019},"Vanta vs Drata"," if Vanta is also on your shortlist.",{"title":93,"searchDepth":94,"depth":94,"links":9714},[9715],{"id":9538,"depth":94,"text":9539,"children":9716},[9717,9718,9719,9720,9721,9722],{"id":9545,"depth":995,"text":9546},{"id":9561,"depth":995,"text":9562},{"id":9574,"depth":995,"text":9575},{"id":9584,"depth":995,"text":9585},{"id":9668,"depth":995,"text":9669},{"id":9678,"depth":995,"text":9679},[9724,9728,9732,9737,9742,9746,9751,9756,9761,9766],{"feature":109,"competitorA":9725,"competitorB":9726,"episki":9727},"Custom pricing, typically starting around $10,000–$15,000\u002Fyr","Custom pricing, typically starting around $8,000–$12,000\u002Fyr","Flat $750\u002Fmo ($7,500\u002Fyr) platform + optional modules; unlimited users, frameworks, and vendors",{"feature":9729,"competitorA":9730,"competitorB":9730,"episki":9731},"Framework coverage","SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and 15+ frameworks","34+ pre-built frameworks (SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, CMMC, FedRAMP, ISO 42001) plus custom",{"feature":9733,"competitorA":9734,"competitorB":9735,"episki":9736},"Automation depth","Automated evidence collection with real-time compliance dashboards","Automated monitoring with continuous evidence collection and alerts","Autonomous GRC — agents draft, answer, and map across the program; humans approve",{"feature":9738,"competitorA":9739,"competitorB":9740,"episki":9741},"Integration count","100+ integrations covering major cloud and SaaS platforms","150+ integrations covering cloud, identity, HR, and developer tools","AWS (multi-account and Organizations), GitHub, Google, Microsoft, Slack, Teams, Jira, Linear, Supabase, Vercel, Netlify — each writing evaluated control coverage",{"feature":9743,"competitorA":9744,"competitorB":9744,"episki":9745},"Control verdicts","Continuous monitoring with pass\u002Ffail tests on a posture dashboard","Every check writes pass, fail, or inconclusive against the control and raises a finding when it fails — empty or unreadable evidence attests nothing, and an approved exception that expires can satisfy a check for named records",{"feature":9747,"competitorA":9748,"competitorB":9749,"episki":9750},"Auditor collaboration","Auditor-facing portal with read-only access and evidence downloads","Auditor-ready evidence rooms with structured access controls","Built-in auditor portal with scoped access and Q&A threads",{"feature":9752,"competitorA":9753,"competitorB":9754,"episki":9755},"AI features","AI-assisted control mapping and compliance recommendations","AI-driven compliance recommendations and automated risk scoring","Agents draft policies, answer questionnaires, map controls, and recommend tasks — AI authors deterministic recipes auditors can accept",{"feature":9757,"competitorA":9758,"competitorB":9759,"episki":9760},"Implementation time","1–3 weeks with self-serve setup and optional guided onboarding","2–3 weeks with guided onboarding and compliance expertise","Same-day setup with self-serve onboarding and optional demo",{"feature":9762,"competitorA":9763,"competitorB":9764,"episki":9765},"Support model","In-app chat, email support, and dedicated CSM for larger accounts","Dedicated compliance managers, email, and in-app support","Self-serve by design, in-app chat, plus vetted Operator Partners (vCISO\u002FvGRC) for advisory",{"feature":9767,"competitorA":9768,"competitorB":9769,"episki":9770},"Free trial","Demo-based sales process, limited free trial availability","Demo-based sales process, no public free trial","14-day free trial with full access, no credit card required",{"title":9772,"description":9773},"Skip the comparison. Try episki free.","14-day trial with full access. No credit card required.",{"title":9775,"items":9776},"Drata vs Secureframe pricing FAQ (2026)",[9777,9780,9783,9786,9789],{"label":9778,"content":9779},"How much does Drata cost in 2026?","Drata does not publish pricing. Based on 2026 market data, plans typically start around $10,000–$15,000\u002Fyr and scale with team size and framework count, reaching $30,000–$50,000\u002Fyr for larger organizations. You need a sales conversation to get a firm quote.",{"label":9781,"content":9782},"How much does Secureframe cost in 2026?","Secureframe also keeps pricing private. In 2026 it typically starts slightly lower than Drata, around $8,000–$12,000\u002Fyr, and scales with seats and frameworks. Expect $30,000–$50,000\u002Fyr at enterprise scale.",{"label":9784,"content":9785},"How do Vanta, Drata, and Secureframe pricing compare in 2026?","All three use custom, per-seat-plus-framework pricing and none publish rates. Rough 2026 entry points: Vanta ~$11,000–$15,000\u002Fyr, Drata ~$10,000–$15,000\u002Fyr, Secureframe ~$8,000–$12,000\u002Fyr. The common thread is that costs rise as your team grows. episki is the outlier at a flat $750\u002Fmo ($7,500\u002Fyr) for the platform plus optional modules, with unlimited seats and published pricing.",{"label":9787,"content":9788},"Which is cheaper, Drata or Secureframe?","At the entry tier, Secureframe is usually slightly cheaper than Drata. But both scale on seats and frameworks, so the gap narrows or reverses depending on your team size and contract. Neither is predictable without a quote — which is why some teams choose a flat-priced platform instead.",{"label":9790,"content":9791},"Do Drata or Secureframe offer a free trial?","Neither offers a true public free trial — both run a demo-led sales process. If you want to evaluate hands-on before committing, episki offers a 14-day free trial with full access and no credit card.",{"headline":9793,"title":9794,"description":9795,"links":9796},"Drata vs Secureframe","Similar features, different approaches to compliance automation","Compare Drata and Secureframe across pricing, onboarding, and compliance workflows. Two closely matched platforms with subtle but important differences for your team.",[9797,9798],{"label":176,"icon":177,"to":178,"target":179},{"label":9799,"icon":182,"color":183,"variant":184,"to":185},"Try episki free",{},"\u002Fcompare\u002Fvs\u002Fdrata-vs-secureframe",{"title":9803,"description":9804},"Drata vs Secureframe (2026): Pricing, Features & Honest Comparison","Drata vs Secureframe compared on pricing, onboarding, framework coverage, and compliance automation. See which platform fits your team — or if neither does.","drata-vs-secureframe","drata","secureframe","7.compare\u002Fvs\u002Fdrata-vs-secureframe",{"chooseA":9810,"chooseB":9811,"chooseEpiski":9812},"Choose Drata if you value self-serve speed and visual compliance dashboards. Drata gets you operational faster and provides the clearest real-time view of your compliance posture — ideal for teams with in-house compliance knowledge.","Choose Secureframe if you want more hands-on guidance from dedicated compliance managers. Secureframe's human-led onboarding is better for teams running their first audit without experienced GRC staff.","Choose episki if you want GRC that runs itself — agents draft policies, answer questionnaires, and keep evidence evergreen while your team approves the work that matters. You get transparent flat pricing ($750\u002Fmo plus optional modules, unlimited seats) and a dedicated AI Governance module.","ZFhZug7YeFTwHWW7ofP4DEaTqpwuaS47YBVKAJnxU-U",{"id":9815,"title":9626,"advantages":9816,"body":9835,"comparison":9898,"competitor":9626,"cta":9938,"description":93,"extension":151,"faq":9941,"hero":9959,"lastUpdated":186,"meta":9965,"navigation":188,"path":4332,"seo":9966,"slug":9806,"stem":9969,"__hash__":9970},"compare\u002F7.compare\u002Fdrata.md",[9817,9823,9830],{"title":9818,"description":9819,"bullets":9820},"Automate the program, not just the monitoring","Drata is excellent at monitoring controls and showing you a dashboard. episki goes further — agents draft the policies, narratives, and questionnaire answers behind those controls, and a human approves. The work advances between audits, not just the status indicators.",[9821,20,9822],"Agents draft policies, narratives, and questionnaire answers from your evidence","Continuous controls and evergreen evidence linked to programs, tasks, and risks",{"title":9824,"description":9825,"bullets":9826},"One flat platform price, expand by module","episki charges a flat $750\u002Fmo for the Compliance Platform with unlimited frameworks, users, and vendors. Add Risk, TPRM, Trust, or AI Governance only when you need them — no tier upgrade for adding your second or third framework.",[9827,9828,9829],"Adding a framework never triggers a higher pricing tier","Unlimited users and vendors; only AI tokens are metered","Annual prepay gives two months free; Operator Partner discounts for vCISO and MSP firms",{"title":22,"description":9831,"bullets":9832},"Most platforms tell you evidence was collected. episki tells you what it proved. Every check evaluates its own evidence and writes pass, fail, or inconclusive — and the ways a check can quietly pass without proving anything are closed by design.",[25,9833,9834],"A failing check raises a finding with the offending records attached, not a dashboard tile","An approved exception can satisfy a check for named records — but it needs an approver and it expires, so an accepted risk is never a permanent carve-out",{"type":29,"value":9836,"toc":9893},[9837,9841,9844,9854,9874,9876,9883,9886,9890],[32,9838,9840],{"id":9839},"why-teams-evaluate-drata-alternatives","Why teams evaluate Drata alternatives",[37,9842,9843],{},"Drata built a polished, real-time compliance dashboard on top of automated evidence collection. For teams that want continuous monitoring with a clean visual posture view, it works well — and its integration coverage across cloud and SaaS platforms is broad.",[37,9845,9846,9847,9850,9851,404],{},"Teams look for alternatives when they want the program to ",[377,9848,9849],{},"run",", not just be ",[377,9852,9853],{},"watched",[47,9855,9856,9862,9868],{},[50,9857,9858,9861],{},[53,9859,9860],{},"Work that runs itself"," — a dashboard tells you a control is failing; episki's agents draft the policy, narrative, or remediation task to fix it, and a human approves.",[50,9863,9864,9867],{},[53,9865,9866],{},"Simpler, flat pricing"," — Drata's tiering by framework count and company size makes budgeting unpredictable. episki is a flat platform price with unlimited frameworks and users.",[50,9869,9870,9873],{},[53,9871,9872],{},"Built-in AI governance"," — episki ships a dedicated AI Governance module and maps ISO 42001, NIST AI RMF, and the EU AI Act out of the box.",[32,9875,72],{"id":71},[37,9877,9878,9879,9882],{},"Legacy GRC automates evidence and renders it on a dashboard. episki automates the program. Agents draft policies, answer questionnaires, map controls across frameworks, and recommend tasks — and the AI authors ",[377,9880,9881],{},"deterministic recipes"," that then run without AI in the loop, so the output is reproducible and defensible in front of an auditor. A human always approves the work that matters.",[37,9884,9885],{},"Everything is connected underneath: programs, assessments, controls, tasks, risks, and evidence link together, and a fast, keyboard-first editor makes the daily work of writing and reviewing feel like a modern tool.",[32,9887,9889],{"id":9888},"when-drata-might-still-be-the-better-fit","When Drata might still be the better fit",[37,9891,9892],{},"Drata is a strong choice for teams that prioritize a clean, real-time monitoring dashboard with broad automated evidence collection, operating primarily in a well-defined framework like SOC 2 or ISO 27001. If continuous visual posture monitoring is your single most important requirement, Drata's dashboard is mature and compelling.",{"title":93,"searchDepth":94,"depth":94,"links":9894},[9895,9896,9897],{"id":9839,"depth":94,"text":9840},{"id":71,"depth":94,"text":72},{"id":9888,"depth":94,"text":9889},[9899,9900,9903,9905,9908,9910,9914,9916,9919,9923,9927,9931,9934],{"feature":101,"episki":102,"competitor":9734},{"feature":109,"episki":9901,"competitor":9902},"Platform $750\u002Fmo (or $7,500\u002Fyr) + optional modules; unlimited users, frameworks, and vendors. Only AI tokens are metered, and every model call is attributed to a surface and an operation so you can see what consumed them","Tiered pricing based on framework count and company size",{"feature":133,"episki":9755,"competitor":9904},"AI-assisted control mapping and recommendations",{"feature":129,"episki":9906,"competitor":9907},"Continuous controls that produce a verdict — every check evaluates the evidence it collected and writes pass, fail, or inconclusive against the control, and a failing check raises a finding. Empty or undecodable evidence returns inconclusive and attests nothing","Automated evidence collection with 100+ integrations",{"feature":125,"episki":126,"competitor":9909},"Built-in risk management with scoring and treatment plans",{"feature":9911,"episki":9912,"competitor":9913},"AI governance","AI Governance module — agent and use-case registry with allowlists and safety floors, AI risk treatments wired to controls and evidence, and ISO 42001, NIST AI RMF, and the EU AI Act mapped. episki governs its own agents through the same module","ISO 42001 support, and AI Agent Governance in limited availability as of August 2026",{"feature":9729,"episki":9915,"competitor":9730},"34+ pre-built frameworks (SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, CMMC, FedRAMP, ISO 42001) plus custom — all unlimited",{"feature":137,"episki":9917,"competitor":9918},"AWS (multi-account, multi-region, and Organizations), GitHub, Google, Microsoft, Slack, Teams, Jira, Linear, Supabase, Vercel, and Netlify — each writing evaluated control coverage, not just collected files","100+ integrations across major cloud and SaaS platforms",{"feature":9920,"episki":9921,"competitor":9922},"Exception handling","An approved exception can satisfy a specific check for named records — it requires a recorded approver and justification, and it expires, so the control returns to failing on its own when the acceptance lapses","Findings can be accepted or excluded; the acceptance is not itself an expiring, approver-bound object tied to the check",{"feature":9924,"episki":9925,"competitor":9926},"Scope & boundaries","Programs report against individual boundaries, with scope rules on cloud account, region, resource, and tag — so a PCI CDE or a single business unit is a real boundary, not a saved filter","Framework-level scoping, with boundaries usually separated into their own workspace",{"feature":9928,"episki":9929,"competitor":9930},"Remediation workflow","Bi-directional Jira, Linear, and GitHub sync — remediation lives in the tracker your engineers already use, and status flows back without anyone copying it","Ticketing integrations that push tasks outward",{"feature":145,"episki":9932,"competitor":9933},"REST API, a published entity-ontology catalog with a drift checksum, and a hosted MCP server (OAuth 2.1 + PKCE, 20 tools) whose writes route through the same API as the UI — an agent's write is indistinguishable from a hand-made one in the audit log","REST API, webhooks, and an MCP server in beta",{"feature":9935,"episki":9936,"competitor":9937},"Editor experience","Notion-like, keyboard-first editor for policies, narratives, and responses","Structured forms and workflow-based interface",{"title":9939,"description":9940},"See Autonomous GRC for yourself","Start a free trial with the platform and any modules enabled. Import your controls and watch an agent get to work.",{"title":9942,"items":9943},"episki vs Drata — frequently asked questions",[9944,9947,9950,9953,9956],{"label":9945,"content":9946},"Is episki a good alternative to Drata?","Yes — especially for teams that want the program to run itself rather than just be monitored. episki's agents draft policies, answer questionnaires, map controls, and recommend tasks, with humans approving. It links programs, assessments, controls, tasks, risks, and evidence into one connected graph and adds a dedicated AI Governance module.",{"label":9948,"content":9949},"How does episki's pricing compare to Drata's?","episki uses one flat platform price — $750\u002Fmo (or $7,500\u002Fyr) — that includes unlimited frameworks, users, and vendors, plus optional modules you add only when you need them. Drata uses tiered pricing based on framework count and company size, which can make budgeting unpredictable as you add frameworks or grow.",{"label":9951,"content":9952},"Does episki do continuous monitoring like Drata?","episki runs continuous controls with evergreen evidence and ties them to programs, tasks, and risks. Where it differs is what happens next — instead of only surfacing a gap on a dashboard, agents draft the remediation, the policy, or the narrative to close it, and a human approves. Drata's real-time monitoring dashboard is mature and a genuine strength if a visual posture view is your primary need.",{"label":9954,"content":9955},"Does episki support the same frameworks as Drata?","episki ships 34+ pre-built frameworks (SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, CMMC, FedRAMP, ISO 42001, EU AI Act, and more) plus custom frameworks, all unlimited and with cross-framework control reuse. Adding a framework never triggers a higher pricing tier.",{"label":9957,"content":9958},"When is Drata the better choice?","Drata is a strong fit if a clean, real-time monitoring dashboard with broad automated evidence collection is your top priority and you operate primarily in a well-defined framework like SOC 2 or ISO 27001. Its visual posture view and integration coverage are mature.",{"headline":4333,"title":9960,"description":9961,"links":9962},"Autonomous GRC vs a continuous-monitoring dashboard","Drata monitors controls and renders a clean dashboard. episki automates the program itself — agents draft policies, answer security questionnaires, manage vendors, and keep your audit evergreen, with humans approving the work that matters.",[9963,9964],{"label":176,"icon":177,"to":178,"target":179},{"label":181,"icon":182,"color":183,"variant":184,"to":185},{},{"title":9967,"description":9968},"episki vs Drata (2026): Autonomous GRC vs Continuous Monitoring","Compare episki and Drata. episki is the Autonomous GRC platform — agents draft policies, answer questionnaires, and run the program — with transparent pricing.","7.compare\u002Fdrata","lFmdq86x2gQZuIQ-mLfbi-37GdVdgL17sKBQvgvxWSY",{"id":9972,"title":9973,"api":9530,"authors":9974,"body":9980,"category":10436,"date":10437,"description":10438,"extension":151,"faq":9530,"features":9530,"fixes":9530,"highlight":9530,"image":10439,"improvements":9530,"meta":10441,"navigation":188,"path":10442,"seo":10443,"stem":10444,"__hash__":10445},"posts\u002F3.blog\u002Fpci-faq-1331-saq-scope.md","PCI FAQ #1331: SAQ Eligibility Criteria Can No Longer Set Your ROC Scope",[9975],{"name":9976,"to":9977,"avatar":9978},"Justin Leapline","https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fjustinleapline\u002F",{"src":9979},"\u002Fimages\u002Fjustinleapline.png",{"type":29,"value":9981,"toc":10424},[9982,9985,9993,9999,10005,10008,10013,10016,10020,10023,10037,10047,10050,10057,10070,10074,10077,10087,10090,10093,10096,10100,10103,10106,10109,10112,10119,10129,10133,10136,10149,10156,10159,10163,10166,10173,10179,10182,10185,10189,10192,10195,10215,10218,10228,10231,10234,10238,10241,10246,10264,10269,10299,10304,10312,10316,10323,10330,10343,10347,10394,10397,10400],[37,9983,9984],{},"The PCI Security Standards Council just made scoping worse.",[37,9986,9987,9992],{},[249,9988,9991],{"href":9989,"rel":9990},"https:\u002F\u002Fwww.pcisecuritystandards.org\u002Ffaqs\u002F1331\u002F",[252],"FAQ #1331"," was updated this month. If you're not familiar with it, it's the one that let a QSA performing a merchant Report on Compliance reference the control set from the SAQs when the merchant met the eligibility criteria. So if a channel was just an iframe to a compliant payment processor, it was clear which controls should be tested. That clarity is what's gone.",[37,9994,9995,9996,9998],{},"The question the FAQ answers is one that every ",[249,9997,6794],{"href":6793}," and every Level 1 merchant assessment team has relied on for years:",[10000,10001,10002],"blockquote",{},[37,10003,10004],{},"Can SAQ eligibility criteria be used as a guide for determining applicability of PCI DSS requirements for merchant assessments documented in a Report on Compliance?",[37,10006,10007],{},"The updated answer:",[10000,10009,10010],{},[37,10011,10012],{},"Self-Assessment Questionnaires are compliance tools designed for merchants under specific conditions and use cases. They should not serve as a \"guide\" for determining PCI DSS requirement applicability unless the merchant's compliance-accepting entity (such as payment brands or acquirers) explicitly reviews and agrees to this approach.",[37,10014,10015],{},"Scope is now a negotiation. And it creates two problems the Council hasn't addressed.",[32,10017,10019],{"id":10018},"what-actually-changed-and-what-didnt","🎯 What Actually Changed (and What Didn't)",[37,10021,10022],{},"Let's be precise, because this update is getting summarized badly.",[37,10024,10025,10028,10029,10032,10033,10036],{},[53,10026,10027],{},"What didn't change:"," whether you file an ",[249,10030,10031],{"href":6810},"SAQ"," or a Report on Compliance was never your call. That's always been determined by your acquirer or payment brand based on transaction volume and ",[249,10034,10035],{"href":6798},"merchant level",". Nobody lost that freedom, because nobody had it.",[37,10038,10039,10042,10043,10046],{},[53,10040,10041],{},"What changed:"," using SAQ eligibility criteria as a scoping reference ",[377,10044,10045],{},"inside"," a ROC. This is how a lot of e-commerce merchants with a redirect or a hosted iframe ended up with a ROC that, functionally, looked like SAQ A. The SAQ told you which requirements were \"in play.\" The ROC followed along. The assessor documented the rest as Not Applicable and everyone moved on.",[37,10048,10049],{},"That door is now closed unless the compliance-accepting entity has explicitly reviewed, discussed, and agreed to the approach.",[37,10051,10052,10053,10056],{},"Worth being honest about what that practice was actually delivering: ",[53,10054,10055],{},"consistency",". Two assessors looking at the same iframe-to-a-compliant-processor channel would land in roughly the same place, because they were both reasoning from the same published control set. That's the thing being removed. Not a loophole — a shared reference point.",[37,10058,10059,10060,10065,10066,10069],{},"The Council also points to ",[249,10061,10064],{"href":10062,"rel":10063},"https:\u002F\u002Fwww.pcisecuritystandards.org\u002Ffaqs\u002F1473\u002F",[252],"FAQ #1473",", which is the more consequential half of the story. Read them together and the division of labor is unambiguous: compliance-accepting entities determine validation and reporting methods and ",[377,10067,10068],{},"may direct which specific requirements are included",". Assessors are responsible for validating that scope and applicability are accurately defined — and must confirm through testing that a requirement genuinely doesn't apply before marking it Not Applicable.",[32,10071,10073],{"id":10072},"️-the-not-tested-trap-nobody-is-talking-about","⚠️ The \"Not Tested\" Trap Nobody Is Talking About",[37,10075,10076],{},"Here's the part that will bite programs in the next assessment cycle.",[37,10078,10079,10080,10083,10084,258],{},"Under FAQ #1473, if a compliance-accepting entity directs that requirements be excluded from the assessment, the assessor does ",[53,10081,10082],{},"not"," mark them Not Applicable. They mark them ",[53,10085,10086],{},"Not Tested",[37,10088,10089],{},"Those are not the same thing on an Attestation of Compliance. Not Applicable means the assessor tested and confirmed the requirement legitimately doesn't apply to this environment. Not Tested means nobody looked. An Attestation of Compliance carrying Not Tested entries is a materially weaker document — and one that a customer's third-party risk team, a downstream service provider, or a future acquirer will read very differently.",[37,10091,10092],{},"So the \"win\" of getting your acquirer to agree to a narrowed scope may hand you an AOC with visible holes in it. Meanwhile, \"SAQ A doesn't include Requirement 6\" is not evidence that Requirement 6 is inapplicable. It's evidence that a different document, built for a different validation path, didn't ask. Your assessor still owes a testing rationale.",[37,10094,10095],{},"That distinction is the whole ballgame, and almost nobody has priced it into their program yet.",[32,10097,10099],{"id":10098},"problem-one-why-is-a-control-set-acceptable-for-one-merchant-and-not-another","🤔 Problem One: Why Is a Control Set Acceptable for One Merchant and Not Another?",[37,10101,10102],{},"Take two e-commerce merchants. Same redirect to a third-party payment page. Same architecture. Same cardholder data footprint, which is to say essentially none. One does 500 transactions a year and files SAQ A. The other does 8 million and gets a ROC.",[37,10104,10105],{},"SAQ A does not ask the small merchant to demonstrate a secure development lifecycle. Its entire Requirement 6 coverage in v4.0 was three items — 6.3.1, 6.3.3, and 6.4.3 — and 6.4.3 was pulled out in the January 2025 revision. Nothing from 6.2 (secure software development, secure coding training, code review). Nothing from 6.5 (change management). Twenty-odd questions in total, against a standard that runs to hundreds of requirements. The Council has effectively said: for this payment channel, those controls don't move the needle on cardholder data risk.",[37,10107,10108],{},"So is development in scope for the big one?",[37,10110,10111],{},"Not according to the model. Maybe according to the acquirer. Definitely according to whoever is feeling cautious that quarter.",[37,10113,10114,10115,10118],{},"Either the SAQ A control set is a ",[53,10116,10117],{},"risk-based statement about what matters for that payment channel"," — in which case a Level 1 merchant with the identical channel should be able to reason from it — or it isn't, and we are quietly telling small merchants that a thinner control set is good enough for them because nobody is watching.",[37,10120,10121,10122,10125,10126,258],{},"It can't be both. Volume should drive ",[53,10123,10124],{},"validation rigor",": who assesses, how much evidence, how deeply it's tested. It shouldn't silently redefine which controls are ",[377,10127,10128],{},"relevant to the same risk",[597,10130,10132],{"id":10131},"the-council-already-made-eligibility-criteria-do-control-work","The Council Already Made Eligibility Criteria Do Control Work",[37,10134,10135],{},"If you think that's an unfair reading, look at what happened to SAQ A in January 2025.",[37,10137,10138,10139,10144,10145,10148],{},"The Council ",[249,10140,10143],{"href":10141,"rel":10142},"https:\u002F\u002Fblog.pcisecuritystandards.org\u002Fimportant-updates-announced-for-merchants-validating-to-self-assessment-questionnaire-a",[252],"removed Requirements 6.4.3, 11.6.1, and 12.3.1 from SAQ A"," — the payment page script management, tamper detection, and supporting targeted risk analysis items — and replaced them with an ",[53,10146,10147],{},"eligibility criterion",": the merchant confirms their site is not susceptible to attacks from scripts that could affect their e-commerce systems.",[37,10150,10151,10152,10155],{},"Read that again. Three PCI DSS requirements were converted into a self-attested eligibility condition. The eligibility criteria are not a neutral gate that sits outside the control set; in SAQ A they ",[377,10153,10154],{},"are"," part of how the Council decided script risk gets addressed for that channel.",[37,10157,10158],{},"Which makes FAQ #1331's position awkward. Eligibility criteria are apparently substantive enough to stand in for three requirements when a small merchant self-assesses, but not substantive enough to inform an applicability discussion when a QSA assesses the same architecture at scale.",[32,10160,10162],{"id":10161},"problem-two-why-is-this-the-acquirers-call-at-all","🏦 Problem Two: Why Is This the Acquirer's Call at All?",[37,10164,10165],{},"If the merchant meets the eligibility criteria, the criteria are the criteria. They were published by the Council, not invented by the assessor.",[37,10167,10168,10169,10172],{},"Requiring acquirer sign-off doesn't add technical rigor. Most acquirers are not staffed to make architecture-level scoping determinations — their PCI function is a portfolio compliance-tracking operation, not a payments security engineering group. The ones that ",[377,10170,10171],{},"can"," engage at that level will take months to do it. What you get back is a signature, not an answer.",[37,10174,10175,10176],{},"For the veteran QSAs reading this: how many times have we been on that call and heard, ",[53,10177,10178],{},"\"What does your QSA think?\"",[37,10180,10181],{},"That's the part the FAQ doesn't reckon with. Acquirers routinely defer to the assessor on-site, because the assessor is the one who has seen the network diagrams, walked the data flows, and knows the specific conditions in the environment. The acquirer hasn't. Naming them the deciding party in an FAQ does not give them that knowledge, and it does not change the dynamic on the call. The question comes right back to the QSA — except now with a formal expectation attached to it.",[37,10183,10184],{},"There's also a structural asymmetry. The acquirer bears the fine risk, so their rational move on any ambiguous scoping question is to say \"assess everything\" or to say nothing at all. Neither response is a risk determination. One is a cost transfer to the merchant; the other is silence that the merchant has to interpret.",[32,10186,10188],{"id":10187},"where-this-actually-lands-division","🧩 Where This Actually Lands: Division",[37,10190,10191],{},"Push a decision to a party that can't or won't make it, and the decision doesn't disappear. It gets made anyway, less visibly, by whoever is holding the pen.",[37,10193,10194],{},"Here's how this plays out. A QSA will do one of three things:",[903,10196,10197,10203,10209],{},[50,10198,10199,10202],{},[53,10200,10201],{},"Agree with the merchant and scope to the SAQ control set."," Defensible if the acquirer signs off. A problem if the merchant never got that in writing.",[50,10204,10205,10208],{},[53,10206,10207],{},"Disagree and push essentially the full ROC where applicable."," The defensible-by-default posture. Expensive, slow, and it generates evidence for controls with no bearing on the merchant's actual card data risk.",[50,10210,10211,10214],{},[53,10212,10213],{},"Pick and choose a smattering of controls they think apply."," No consistent rationale, no published reference point. I've seen all three of these implemented by QSAs firsthand — and the third was already happening before this update. The FAQ change doesn't fix it. It removes the one shared reference the other two were anchored to.",[37,10216,10217],{},"And now the merchant has to go to their processor to clear scope if they want to use the controls in an already defined and approved SAQ. So they're left with two real options: chase an approval from an acquirer who may never respond, or accept whatever scope their QSA decided on.",[37,10219,10220,10221,10224,10225,258],{},"Most will take option two. Which means the decision didn't move ",[53,10222,10223],{},"up"," a level. It moved ",[53,10226,10227],{},"out of sight",[37,10229,10230],{},"So we end up with division. Some Level 1 merchants will test every applicable control in the ROC. Some will get approval and test the SAQ-scoped set. Some will get whatever their QSA decided was applicable that week. Two merchants with identical architecture, materially different assessments — depending on which QSA they hired and how engaged their acquirer happens to be.",[37,10232,10233],{},"That's worse for comparability, worse for merchants trying to budget, and — the part that should bother the Council most — worse for actual security, because effort gets allocated by liability anxiety instead of by risk.",[32,10235,10237],{"id":10236},"what-to-do-about-it-this-quarter","✅ What to Do About It This Quarter",[37,10239,10240],{},"Setting aside whether the policy is right, it's the policy. Here's the practical response.",[37,10242,10243],{},[53,10244,10245],{},"If you have a ROC in flight that leaned on SAQ criteria to narrow requirements:",[47,10247,10248,10251,10258],{},[50,10249,10250],{},"Raise it with your acquirer now, not at report writing. Scoping questions that arrive alongside a draft ROC get answered with \"assess everything.\"",[50,10252,10253,10254,10257],{},"Ask specifically whether they will agree to the approach ",[53,10255,10256],{},"in writing",", and whether excluded requirements will be documented as Not Applicable (with assessor testing) or Not Tested (at their direction). Make sure you understand which AOC you're going to end up holding.",[50,10259,10260,10261,10263],{},"If they won't engage, get their non-response documented and make a deliberate, defensible applicability decision with your assessor — with a written rationale tied to your actual ",[249,10262,6693],{"href":6692},", not to an SAQ table of contents.",[37,10265,10266],{},[53,10267,10268],{},"If you're scoping next year's assessment:",[47,10270,10271,10282,10285,10288],{},[50,10272,10273,10274,10277,10278,10281],{},"Build your applicability position from first principles. Data flows, system component inventory, ",[249,10275,10276],{"href":6913},"segmentation"," boundaries, and a documented rationale per requirement. That work survives any FAQ revision. See our guide to ",[249,10279,10280],{"href":6908},"PCI scope reduction"," for how to shrink the environment rather than argue about it.",[50,10283,10284],{},"Open the acquirer conversation early in the cycle, not 60 days out. Budget real calendar time for it.",[50,10286,10287],{},"Assume your applicability rationale will be re-litigated by the next QSA you hire. Write it so it holds up without you in the room.",[50,10289,10290,10291,10294,10295,10298],{},"Genuinely reduce scope where you can. ",[249,10292,10293],{"href":6708},"Tokenization"," and hosted payment fields don't just narrow requirements — they narrow the ",[377,10296,10297],{},"argument",", which is now the expensive part.",[37,10300,10301],{},[53,10302,10303],{},"If you're a QSA:",[47,10305,10306,10309],{},[50,10307,10308],{},"Stop treating \"the merchant qualifies for SAQ A\" as a scoping input. It's an interesting data point about architecture, not a determination.",[50,10310,10311],{},"Get the compliance-accepting entity's position in the ROC, in writing, including silence. Document what you asked and when.",[32,10313,10315],{"id":10314},"️-how-episki-helps","🛠️ How episki Helps",[37,10317,10318,10319,10322],{},"The uncomfortable truth of this update is that ",[53,10320,10321],{},"your applicability rationale is now a first-class deliverable",", not an implicit byproduct of picking the right questionnaire. It has to be written down, defended per requirement, and durable across assessor changes.",[37,10324,10325,10329],{},[249,10326,9650],{"href":10327,"rel":10328},"https:\u002F\u002Fapp.episki.com",[252]," is built for that: requirement-level applicability status with a documented rationale and full audit trail, evidence linked to the specific requirement it supports, and a shared workspace where your assessor and your team see the same scoping decisions instead of reconstructing them from email. When a control is scoped out, the reason is recorded next to it — so next year's assessor reads your reasoning rather than inventing their own.",[37,10331,10332,10333,10336,10337,392,10340,258],{},"Explore the ",[249,10334,10335],{"href":7120},"PCI DSS framework on episki"," to see how requirements, applicability, and evidence connect, or read our breakdown of ",[249,10338,10339],{"href":6875},"SAQ types",[249,10341,10342],{"href":6782},"what changed in v4",[32,10344,10346],{"id":10345},"key-takeaways","📝 Key Takeaways",[47,10348,10349,10355,10364,10370,10376,10382,10388],{},[50,10350,10351,10354],{},[53,10352,10353],{},"FAQ #1331 (updated August 2026)"," closes the practice of using SAQ eligibility criteria to determine requirement applicability in a ROC without explicit acquirer or payment brand agreement.",[50,10356,10357,10360,10361,10363],{},[53,10358,10359],{},"Read it with FAQ #1473."," Requirements excluded at the compliance-accepting entity's direction are marked ",[53,10362,10086],{},", not Not Applicable — a visibly weaker AOC.",[50,10365,10366,10369],{},[53,10367,10368],{},"The inconsistency is real."," The same architecture gets a thinner control set at 500 transactions than at 8 million. Volume should drive validation rigor, not which risks are considered relevant.",[50,10371,10372,10375],{},[53,10373,10374],{},"Eligibility criteria already do control work."," SAQ A's January 2025 revision replaced 6.4.3, 11.6.1, and 12.3.1 with a self-attested eligibility criterion.",[50,10377,10378,10381],{},[53,10379,10380],{},"Acquirer sign-off adds a signature, not a determination."," Most aren't staffed for architecture-level scoping, their incentive is to say \"everything\" or nothing, and on the call they'll ask what your QSA thinks.",[50,10383,10384,10387],{},[53,10385,10386],{},"Practice will divide."," Some Level 1 merchants will test everything, some will get approval and test the SAQ-scoped set, some will get whatever their QSA decided that week.",[50,10389,10390,10393],{},[53,10391,10392],{},"Do the work anyway."," A first-principles, documented applicability rationale is the only artifact that holds up regardless of how the Council words this next.",[10395,10396],"hr",{},[37,10398,10399],{},"Curious on thoughts from my QSA peeps and the broader community. Am I right that this is going in the wrong direction, or am I missing something?",[37,10401,10402,10405,10406,10410,10411,10410,10415,10410,10419],{},[53,10403,10404],{},"Sources:"," ",[249,10407,10409],{"href":9989,"rel":10408},[252],"PCI SSC FAQ #1331"," · ",[249,10412,10414],{"href":10062,"rel":10413},[252],"PCI SSC FAQ #1473",[249,10416,10418],{"href":10141,"rel":10417},[252],"Important Updates Announced for Merchants Validating to SAQ A",[249,10420,10423],{"href":10421,"rel":10422},"https:\u002F\u002Fblog.pcisecuritystandards.org\u002Ffaq-clarifies-new-saq-a-eligibility-criteria-for-e-commerce-merchants",[252],"FAQ Clarifies New SAQ A Eligibility Criteria for E-Commerce Merchants",{"title":93,"searchDepth":94,"depth":94,"links":10425},[10426,10427,10428,10431,10432,10433,10434,10435],{"id":10018,"depth":94,"text":10019},{"id":10072,"depth":94,"text":10073},{"id":10098,"depth":94,"text":10099,"children":10429},[10430],{"id":10131,"depth":995,"text":10132},{"id":10161,"depth":94,"text":10162},{"id":10187,"depth":94,"text":10188},{"id":10236,"depth":94,"text":10237},{"id":10314,"depth":94,"text":10315},{"id":10345,"depth":94,"text":10346},"news","2026-08-05","The PCI Council updated FAQ #1331 in August 2026. You can no longer use SAQ eligibility criteria to determine which PCI DSS requirements apply in a Report on Compliance without acquirer agreement. Here's what breaks.",{"src":10440},"\u002Fimages\u002Fblog\u002Fpci-faq-1331-saq-scope.webp",{},"\u002Fblog\u002Fpci-faq-1331-saq-scope",{"title":9973,"description":10438},"3.blog\u002Fpci-faq-1331-saq-scope","Qy7jrphPcuHhcgiLvIRaUbg56-o84BEX8DnxNfgVnYs",{"id":10447,"title":10448,"advantages":10449,"body":10471,"checklist":10478,"cta":10487,"description":10475,"extension":151,"faq":9530,"hero":10490,"lastUpdated":186,"meta":10498,"name":10499,"navigation":188,"path":3526,"resources":10500,"seo":10513,"slug":10516,"stats":10517,"stem":10525,"__hash__":10526},"industries\u002F6.industry\u002F1.healthcare.md","Healthcare",[10450,10457,10464],{"title":10451,"description":10452,"bullets":10453},"PHI-aware control mapping","Map administrative, technical, and physical safeguards to your stack without rebuilding every audit.",[10454,10455,10456],"Track EHR, identity, and cloud evidence with structured ownership","Track segmentation, backups, and log retention against HIPAA safeguards","Map once for HIPAA and reuse for HITRUST or regional requirements",{"title":10458,"description":10459,"bullets":10460},"Clinician-friendly workflows","Keep nurses, clinicians, and ops aligned without burying them in tickets.",[10461,10462,10463],"Role-aware tasks routed to the right owner with due dates","Playbooks show “what good looks like” for PHI handling","Attestations and approvals captured inline for auditors",{"title":10465,"description":10466,"bullets":10467},"Auditor and partner collaboration","Give regulators, payers, and partners scoped access instead of email threads.",[10468,10469,10470],"Auditor portal with threaded Q&A per safeguard","Secure uploads with expirations and access controls","Exports for SOC 2, PCI, or privacy questionnaires",{"type":29,"value":10472,"toc":10476},[10473],[37,10474,10475],{},"Healthcare buyers move fast when they trust your safeguards. episki keeps PHI protections documented, monitored, and shareable without slowing product or patient care.",{"title":93,"searchDepth":94,"depth":94,"links":10477},[],{"title":10479,"description":10480,"items":10481},"Healthtech compliance checklist","Use this inside your trial to assign owners, attach evidence, and track renewals.",[10482,10483,10484,10485,10486],"HIPAA safeguard library mapped to your systems","BAA tracker with renewal reminders and risk scoring","Incident response runbooks with timelines and owners","Access, logging, and backup verification tasks","Third-party risk reviews tied to PHI data flows",{"title":10488,"description":10489},"Launch a healthtech-ready workspace","Connect your stack, invite stakeholders, and show PHI protections the same day.",{"headline":10491,"title":10492,"description":10493,"links":10494},"HIPAA-grade governance without slowing clinicians","Keep PHI protections provable across cloud apps, clinics, and vendors","episki maps safeguards, automates evidence, and gives auditors scoped access so healthtech teams can keep shipping.",[10495,10497],{"label":10496,"icon":182,"to":185},"Start healthtech trial",{"label":176,"icon":300,"color":183,"variant":184,"to":178,"target":179},{},"healthcare and healthtech",{"headline":10501,"title":10501,"description":10502,"items":10503},"Healthcare enablement kit","Keep leadership, clinicians, and auditors aligned on the same story.",[10504,10507,10510],{"title":10505,"description":10506},"PHI data flow deck","Share sanitized diagrams plus segmentation notes for customers and partners.",{"title":10508,"description":10509},"Board + payer brief","Summarize control health, incidents, and remediation in plain language.",{"title":10511,"description":10512},"Auditor-ready workspace","Prebuilt template for requests, evidence, and walkthrough scheduling.",{"title":10514,"description":10515},"Healthcare Compliance Software","HIPAA-ready GRC for healthtech teams. Map safeguards, track PHI evidence, and collaborate with auditors in one secure workspace. Start your free trial.","healthcare",[10518,10520,10522],{"value":3627,"description":10519},"Move from baseline controls to monitored safeguards in under a month.",{"value":3630,"description":10521},"Role-based portals keep BAAs, policies, and diagrams organized and protected.",{"value":10523,"description":10524},"Continuous watch","Drift detection across access, logging, vendors, and incidents.","6.industry\u002F1.healthcare","u08a7hidKILzMlQgEwXI8WBgv7i08HXpMKdsEpMA3Tw",1788228934539]