Compliance
Compliance that unlocks contracts, not just checkboxes
Answer a CAIQ Lite in hours, not weeks. Most teams reach SOC 2 audit-ready in 60 to 90 days. We cover 250+ frameworks out of the box: every major international, federal, state, and local regulatory requirement your enterprise customers might ask about. Satisfy a control once; it counts toward every other framework that shares it. Every certification you earn opens doors your competitors can’t walk through.
A certificate says you passed once. This shows it’s still true.
Everything below serves one loop. It runs the same way for your first framework and your fifteenth.
- 01
Scope it
Size any of 250+ frameworks to the business you actually run.
- 02
Prove it
Every file graded against the real requirement, with gaps named.
- 03
Keep it true
Shelf life, drift and lapses caught as they happen, not at audit time.
- 04
Show it
Your auditor and buyers check the evidence themselves, sealed and verifiable.
01 · Scope it
250+ frameworks, cross-mapped from one corpus
International, federal, state, local, sector-specific, cloud-native. Every framework runs off the same set of 1,468 universal controls, so evidence collected for one inherits to every other framework that shares it. Adding a new framework does not require a roadmap wait.
- SOC 2 Type II
- ISO 27001:2022
- ISO 27017
- ISO 27018
- ISO 27701
- ISO 22301
- ISO 42001
- NIST CSF 2.0
- NIST 800-53 Low
- NIST 800-53 Mod
- NIST 800-53 High
- NIST 800-171
- NIST AI RMF
- PCI DSS v4.0.1
- HIPAA Security
- HITRUST CSF
- CMMC L1
- CMMC L2
- CMMC L3
- FedRAMP Low
- FedRAMP Moderate
- FedRAMP High
- StateRAMP
- CSA CCM
- CSA CAIQ
- CSA STAR
- SOX ITGC
- COBIT 2019
- GDPR
- UK GDPR
- CCPA / CPRA
- VCDPA
- CTDPA
- CDPA
- UCPA
- BIPA
- SHIELD Act
- Alaska PIPA
- PIPEDA
- LGPD
- PDPA (Singapore)
- APPI
- FERPA
- COPPA
- CIPA
- GLBA
- NYDFS 23 NYCRR 500
- MA 201 CMR 17
- DORA
- NIS2
- EU AI Act
- + ~200 more via SCF
Cross-credit
Satisfy a control once. Count it everywhere.
Upload evidence for MFA on Monday. By Tuesday morning every framework that asks about access control (SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF) shows it as satisfied. Every framework, every audit period, without re-collecting the same screenshots. When your auditor opens their view, they see their framework’s own language, not ours.
Under the hood, the platform walks a cross-framework map every time you accept a piece of evidence and writes it against every other framework it applies to. Real records in your assessment, not a UI illusion — if your auditor asks to see the underlying data, we can show it to them.
- Upload once, credit propagates across every framework that shares the control
- See the literal readiness delta per framework before you commit the evidence
- Add a new framework mid-quarter without re-collecting evidence
- Your auditor sees their framework’s native language, not ours
- Built on the Secure Controls Framework (SCF) crosswalk auditors already recognize
Accepting evidence on CC6.1 — Logical Access Controls propagates through the SCF crosswalk to every other active framework that maps to the same universal control.
- SOC 2 Type II43%61%+18%
- ISO 27001:202252%64%+12%
- PCI DSS v4.0.139%44%+5%
- NIST CSF 2.058%65%+7%
- HIPAA Security71%78%+7%
Five frameworks moved on one control. Real records in your assessment, not a UI illusion — if the auditor asks where the credit came from, we show them.
02 · Prove it
Prove your security, not just that it’s written
Pick a framework and answer a few questions about your business. Assessments sizes it to you, then grades every piece of evidence against what the requirement actually asks. You see what’s sufficient, what’s partial, and exactly what’s missing, before your auditor does.
Evidence has a shelf life. A quarterly access review that’s fine today won’t be by fieldwork. You see which requirements will lapse, and when one does, it’s an incident you close with a signed fix your auditor can read.
- Scope to your business: suggestions from your profile, and nothing leaves scope until you confirm
- Every requirement graded against its own text: sufficient, partial, insufficient, or with a person for review
- Named gaps, each with a fix: amend the file and re-grade in place
- Shelf life on every file, plus a “fieldwork day” view of what will have lapsed
- Continuity: your whole observation window, lane by lane, with incidents and signed fixes
- Today: the one file to produce next, chosen by due date and impact
- Available on every plan, for every framework


03 · Keep it true
Stop chasing people for sign-offs
Compliance work already exists. Today it lives in your inbox, and you’re the one following up. Here, every approval, vendor review and fix goes to the right person with a due date, and follows up on its own if it stalls.
You see only what’s stuck, with the item that unblocks the most frameworks at the top. Approvals come with a recommendation based on how you’ve decided before, and it all syncs with Jira, Linear or Asana, so nobody learns a new tool.
- Each item reaches the right person, with a due date
- Follow-ups and escalation run on their own when something stalls
- The item that unblocks the most frameworks rises to the top
- Approval recommendations based on your past decisions
- Drift alerts when a scanner or red-team finding regresses a control
- Two-way sync with Jira, Linear and Asana, included
- Time-limited exceptions that expire on their own
Readiness reporting
Every gap, before your auditor sees it
Every control carries a live status as evidence and findings land: Compliant, At-Risk or Fail. One open finding on a control shows up as At-Risk, so nothing gets cherry-picked or hidden in a green dashboard. Readiness reports show the gaps that still need remediation, and an executive summary written for a board, not a security team.
- Live control status: Compliant / At-Risk / Fail, updated as evidence lands
- Readiness score for every framework you track
- Executive summary and prioritized-actions list for the next board update
- Live posture score (0–100) built from your key risk indicators
SOC 2 Type II Readiness
Preparedness Report04 · Show it
A trust portal your auditor can check, not just read
Most trust centers show a badge and a document library. Yours lets the person reading it verify the evidence themselves. Invite an auditor, prospect, or partner by magic link. They land in a scoped workspace pinned to one assessment and one observation window, sample against any control at any date, run the chain-integrity verifier from inside the workspace, and prove tamper-evidence themselves.
Every evidence record carries cross-framework reuse badges (“Also satisfies ISO 27001 A.9.1”, “Also satisfies HIPAA §164.312(a)(1)”) surfaced from the SCF crosswalk. The Coverage heatmap plots SCF domains against evidence-strength so the auditor knows where to sample before they start. Invite-scoped instead of public: the exposure is narrower than a static trust page and the auditability is deeper.
- Magic-link invite + TOTP on first login, no account in your tenant
- Coverage heatmap: SCF-domain × evidence-strength
- Live “Chain: verified” badge on every assessment overview
- Cross-framework reuse badges on every evidence record
- Evidence Graph with Auditor + Trace lenses over one sealed graph
- Type I vs Type II observation window on the graph
- Q&A threads scoped to a control or evidence record
Cryptographic audit trail
Evidence anchored to a third-party timestamp, not our word
Your auditor can prove the evidence wasn’t touched between when we collected it and when they reviewed it. They verify it themselves, from a script we ship in the auditor pack, without our help and without our credentials. Every audit-trail entry gets a cryptographic timestamp from a third-party authority (DigiCert, or Sectigo as backup) — the same kind of timestamp banks and courts use to prove documents existed at a point in time.
Same guarantee if you take the archive off-platform: a write-once bucket you control, forgery-resistant, retrievable independent of our database, seven-year retention by default with legal-hold support. The auditor never has to trust us; the third-party timestamp does the trusting for everyone.
- Auditor verifies tamper-evidence without our help or credentials
- Bundled
verify.shscript in every auditor pack — runs offline - Third-party cryptographic timestamps (RFC 3161, DigiCert / Sectigo)
- 110+ event types tracked across the audit trail
- Off-platform write-once archive, 7-year retention default, legal-hold ready
- Entries verified
- 12,847
- Sequence range
- 8,001 – 20,847
- Observation window
- 90 days
- Last verified
- 34s ago
SHA-256 hash chain, per-entry linking, Merkle checkpoints anchored via RFC 3161 TSA (DigiCert primary, Sectigo fallback). Trust root is the TSA’s public certificate; verification does not require our credentials.
COMMON QUESTIONS
Compliance & questionnaire questions
What is CAIQ Lite?
CAIQ Lite (Consensus Assessments Initiative Questionnaire, Lite version) is a shortened enterprise vendor questionnaire from the Cloud Security Alliance. Roughly 70 questions mapped to the CSA Cloud Controls Matrix, used by enterprise buyers to assess SaaS vendors before signing. It is a shorter, standardized alternative to the full CAIQ.
How does vCISO Lite help answer CAIQ Lite?
vCISO Lite pre-populates CAIQ Lite responses from evidence you already collected for your other framework work (SOC 2, ISO 27001, HIPAA). Answer each underlying control once and it flows through every questionnaire that asks about it. A two-week questionnaire cycle typically compresses to a few hours of review-and-approve.
What frameworks does the compliance platform cover?
250+ frameworks from a single corpus: SOC 2, ISO 27001 (and the 27000-family), HIPAA, PCI DSS v4.0.1, NIST CSF 2.0, NIST 800-53 (Low/Moderate/High/Privacy), NIST 800-171, CMMC L1/L2/L3, FedRAMP (Low/Moderate/High), CSA CCM, GDPR/UK GDPR, FERPA, COPPA, CIPA, NYDFS 23 NYCRR 500, DORA, NIS2, EU AI Act, US state privacy laws, and the rest of the Secure Controls Framework universe. Evidence collected for one framework counts toward every other framework that shares the same universal control.
How long does SOC 2 readiness take with vCISO Lite?
Most startups reach audit-ready in 60 to 90 days from kickoff, assuming reasonable existing security controls. The bulk of manual evidence-collection work (the part that turns a compliance program into a full-time job) is automated. What's left is the strategic work: policy decisions, control design, and stakeholder alignment.
How is evidence graded?
Every piece of evidence is checked against the plain-language ask of each requirement it answers, and graded sufficient, partial or insufficient, with the specific gaps named. Grading is a pre-check, not an audit opinion. Your auditor makes the call. You can amend the file and re-grade, accept it with a written reason, or send it to a person for review. Every grade records which model produced it.
What's the difference between SOC 2 Type I and Type II?
Type I is a point-in-time assessment: do the controls exist today? Type II is a period-of-time assessment: did they operate effectively over three to twelve months? Enterprise buyers typically accept a first-year Type I and expect Type II thereafter. vCISO Lite tracks control operation continuously so you have Type II evidence on-hand, not scrambling to reconstruct. Assessments' Continuity view shows the whole observation window, with any lapses and their signed fixes, so you see what your auditor will see.
How does vCISO Lite prevent evidence tampering?
Every audit-trail event gets a cryptographic timestamp from a third-party authority (DigiCert, or Sectigo as backup) — the same kind of timestamp banks and courts use to prove documents existed at a specific point in time. Your auditor verifies tamper-evidence against the third party directly, using a verify.sh script we ship in the auditor pack. They run it offline, without our credentials, and confirm that nothing changed between when we collected the evidence and when they reviewed it. The underlying mechanics are standard: SHA-256 hash chain per entry, Merkle checkpoints, RFC 3161 timestamps.
What if we already have a partial SOC 2 setup?
The gap analysis identifies what's in place, what's partial, and what's missing across every framework you care about. Bring your existing evidence (spreadsheets, policies, third-party pentests, whatever you've collected) and the platform maps it to the controls it satisfies, then shows exactly what remaining work stands between you and audit-ready.
Ready to unlock your next enterprise deal?
See your compliance gaps in minutes. Audit-ready in weeks.