SOC 1 Type 1 & Type 2
Identify controls relevant to customers’ financial reporting, document the system, and prepare evidence for an independent CPA examination.
Discuss SOC 1 Type 1 & Type 2 scopeFramework directory
From healthcare assurance and enterprise security to AI governance, explore 61 frameworks and programs. Start with your customer requirements, your data, and the risks you need to manage.
We map shared controls across obligations while keeping each framework’s scope, assessment requirements, and evidence expectations clear.
Discuss your requirementsSecurity programs, assurance reports, and continuity for enterprise buyers.
Identify controls relevant to customers’ financial reporting, document the system, and prepare evidence for an independent CPA examination.
Discuss SOC 1 Type 1 & Type 2 scopeScope the applicable Trust Services Criteria, close readiness gaps, and organize design and operating evidence for a CPA’s SOC 2 examination.
Explore assessment supportPlan general-use assurance reporting on Trust Services Criteria with a CPA, and align the underlying evidence with your broader SOC program.
Discuss SOC 3 scopeBuild an information security management system, assess risk, maintain the Statement of Applicability, and prepare for independent certification audits.
Explore assessment supportClarify cloud provider and customer responsibilities, map cloud security controls, and collect evidence across shared infrastructure and service operations.
Explore assessment supportReview protection of personally identifiable information in public cloud services, including processor responsibilities, customer commitments, and operational safeguards.
Discuss ISO/IEC 27018 scopeCompare current and target cybersecurity profiles across Govern, Identify, Protect, Detect, Respond, and Recover to prioritize a practical improvement roadmap.
Explore assessment supportSelect and tailor security and privacy controls, assign implementation responsibilities, and prepare assessment evidence for the system’s risk context.
Explore assessment supportTrace controlled unclassified information through nonfederal systems, document safeguards, and align assessment preparation with the revision specified by your contract.
Explore assessment supportChoose an appropriate Implementation Group and turn prioritized safeguards into an actionable security backlog with owners and verifiable evidence.
Explore assessment supportMap cloud security practices to the Cloud Controls Matrix, prepare accurate CAIQ responses, and select the STAR assurance pathway your customers require.
Discuss CSA STAR / CAIQ scopeDevelop a business continuity management system using impact analysis, recovery strategies, exercises, and corrective actions to prepare for certification.
Explore assessment supportProtect health information and prepare regulated systems for review.
Evaluate whether the essentials assessment fits customer requirements and your risk profile, then prepare scoped implementation evidence for validation.
Explore assessment supportPrepare for the implemented assessment with defined system boundaries, evidence owners, and remediation of control implementation gaps.
Explore assessment supportPlan a risk-based assessment with the applicable scoping factors, control maturity evidence, and a realistic path from readiness to validation.
Explore assessment supportScope AI security risks, governance responsibilities, and technical safeguards alongside your existing HITRUST program, confirming the applicable assessment requirements.
Discuss HITRUST AI Security Assessment scopeAssess electronic protected health information risks, administrative and technical safeguards, privacy workflows, and business associate responsibilities.
Explore assessment supportReview health data protection and breach-response responsibilities alongside HIPAA, including business associate arrangements and incident escalation procedures.
Discuss HITECH scopeScope regulated electronic records and signatures, review access and audit trails, and organize validation evidence with the applicable predicate rules.
Discuss 21 CFR Part 11 scopeConnect intended use, risk assessment, validation plans, and change controls for computerized systems supporting regulated life-sciences processes.
Discuss GxP / Computer System Validation scopeReview AI-enabled medical software documentation, lifecycle controls, and change-management evidence with regulatory specialists for the intended product pathway.
Discuss FDA AI/ML SaMD Guidance scopeIdentify the relevant healthcare accreditation program and organize policies, operational evidence, and remediation around its published criteria.
Discuss EHNAC scopeMake AI ownership, risk decisions, and lifecycle controls visible.
Establish an AI management system with defined roles, impact assessments, risk treatment, lifecycle controls, and independent certification preparation.
Explore assessment supportIntegrate AI-specific risk identification, analysis, evaluation, and treatment into existing enterprise risk processes and system lifecycle decisions.
Discuss ISO/IEC 23894 scopeApply Govern, Map, Measure, and Manage to your AI use cases, documenting risk ownership, evaluation methods, and monitoring decisions.
Explore assessment supportInventory AI systems, establish provider or deployer roles, and prepare a risk-based obligations and evidence roadmap with legal review.
Explore assessment supportAssess applicability to AI use cases and prepare impact-assessment, notice, oversight, and risk-management workflows against current enacted requirements.
Discuss Colorado AI Act scopeAssess application risks such as prompt injection and unsafe output handling, then connect testing results to practical engineering remediation.
Discuss OWASP Top 10 for LLM Applications scopeConnect data flows, individual rights, and accountable processing.
Map personal data processing, review controller and processor roles, and operationalize records, rights requests, impact assessments, and transfer safeguards.
Explore assessment supportBuild a privacy information management system and prepare the organization’s roles, risk decisions, processing controls, and audit evidence.
Explore assessment supportReview applicability, personal information flows, notices, rights-request processes, and service-provider contracts under California’s privacy framework.
Explore assessment supportBuild a state-by-state applicability matrix and reusable request, notice, consent, and assessment workflows while retaining jurisdiction-specific requirements.
Discuss US State Privacy Laws scopeAssess Canadian and Québec privacy obligations, including accountable processing, consent, impact assessments, breach workflows, and vendor arrangements.
Discuss PIPEDA / Québec Law 25 scopeMap Brazilian personal data processing, identify legal bases and responsibilities, and organize individual-rights, security, and incident-response workflows.
Discuss Brazil LGPD scopePrepare a Digital Personal Data Protection readiness roadmap covering data flows, notices and consent, individual requests, safeguards, and accountable owners.
Explore assessment supportReview UK processing responsibilities, rights handling, impact assessments, and international transfer arrangements alongside your wider privacy program.
Discuss UK GDPR & DPA 2018 scopeAssess eligibility and commitments for the applicable self-certification program, and prepare privacy notices, dispute mechanisms, and ongoing verification processes.
Discuss EU–US Data Privacy Framework scopeReview education records, authorized disclosures, access controls, and institutional or service-provider responsibilities for student information.
Discuss FERPA scopeSupport payment security, financial controls, and operational resilience.
Scope the cardholder data environment, identify the applicable validation approach, and prepare technical, procedural, and recurring security evidence.
Explore assessment supportDocument access, change-management, and IT operations controls that support financial reporting, with evidence aligned to the external auditor’s scope.
Discuss SOX IT General Controls scopeAssess covered financial activities and strengthen the written information security program, risk assessment, service-provider oversight, and response planning.
Discuss GLBA Safeguards Rule scopeReview the covered entity’s cybersecurity program, governance, risk assessment, reporting processes, and evidence against applicable requirements and exemptions.
Discuss NYDFS Part 500 scopeOrganize ICT risk management, resilience testing, incident reporting, and third-party arrangements for financial entities in the regulation’s scope.
Discuss EU DORA scopeThe CAT was retired in August 2025. Map historical assessments to a current cybersecurity approach, such as NIST CSF, and preserve the rationale for transition.
Discuss FFIEC CAT Transition scopeReview the applicable architecture and customer security controls, prepare attestation evidence, and coordinate independent assessment requirements.
Discuss SWIFT Customer Security Programme scopePrepare systems and evidence for government procurement requirements.
Define the cloud service boundary and applicable pathway, assess control and evidence gaps, and plan independent assessment and ongoing monitoring preparation.
Explore assessment supportPrepare cloud security documentation, control evidence, and monitoring processes for the applicable GovRAMP status and public-sector customer requirements.
Explore assessment supportDetermine the Texas cloud-service assessment scope and risk level, organize required security documentation, and plan maintenance of program obligations.
Discuss TX-RAMP scopeScope federal contract information and controlled unclassified information, prepare objective evidence, and align readiness with the contract’s assessment requirements.
Explore assessment supportSupport system categorization, control selection, assessment preparation, and continuous monitoring within the federal agency’s risk-management process.
Discuss FISMA scopeMap criminal justice information flows, personnel and access safeguards, and service-provider responsibilities to the applicable agency requirements.
Discuss CJIS Security Policy scopeIdentify federal tax information handling, assess safeguarding responsibilities, and prepare system, personnel, and operational evidence for agency review.
Discuss IRS Publication 1075 scopeAddress regional and industry assurance requested by your buyers.
Define automotive information-security assessment objectives, scope locations and information handling, and prepare evidence for the selected assessment level.
Discuss TISAX scopePrepare cloud control documentation and operating evidence for a C5 examination, including customer responsibilities and service-specific assurance requirements.
Discuss BSI C5 scopeScope the system and relevant Australian government security controls, prepare an evidence package, and coordinate assessment with an endorsed IRAP assessor.
Discuss IRAP scopeDetermine the applicable system category, map security measures, and prepare governance and operational evidence for the required conformity process.
Discuss Spain ENS scopeReview foundational technical safeguards, define the assessment boundary, and prepare for the appropriate UK certification pathway and verification requirements.
Discuss Cyber Essentials / Plus scopeAssess technology risk governance, system security, resilience, and third-party oversight against applicable Monetary Authority of Singapore expectations.
Discuss Singapore MAS TRM scopeIdentify the applicable Saudi sector and national cybersecurity requirements, map control ownership, and prepare implementation and operating evidence.
Discuss Saudi SAMA CSF / NCA ECC scopeReview applicable UAE information assurance requirements, define the organizational and system scope, and prioritize governance and technical control gaps.
Discuss UAE Information Assurance scopeBuild a service management system with service planning, incident and change processes, performance reviews, and independent certification preparation.
Discuss ISO/IEC 20000-1 scopePrograms include laws, control frameworks, attestations, and certifications. The required pathway depends on your scope and customer obligations. Formal reports, certifications, and authorizations are issued by the relevant independent bodies or authorities.