Skip to content

Framework coverage

Six frameworks. One control library. Zero duplicated questions.

Most compliance tooling makes you maintain a separate checklist per framework, then asks your engineers the same question three times. CISO Express maps each control once and reuses the evidence everywhere it is accepted.

Coverage

Six frameworks, one control library

Most teams need two or three of these at once. Sentinel maps each piece of evidence to every framework that accepts it, so you never answer the same question twice.

SOC 2 Type II

Readiness on a typical Growth workspace
94%

All five Trust Services Criteria, with the point-in-time controls automated and the 12-month observation window tracked continuously.

  • CC6.1 access controls and CC6.6 MFA evidence pulled from your IdP
  • CC7.2 monitoring and CC7.3 incident follow-ups tracked as issues
  • CC8.1 change management linked to real pull requests
  • Auditor-ready evidence binder export as a signed ZIP

ISO/IEC 27001:2022

Readiness on a typical Growth workspace
87%

The 93 Annex A controls plus clauses 4–10, with a named owner and a maturity rating for every control.

  • Statement of Applicability generated from your control status
  • A.5 organisational and A.8 technological controls mapped 1:1
  • Risk register with treatment plans and review dates
  • Internal audit schedule and management review minutes

NIST CSF 2.0

Readiness on a typical Growth workspace
91%

Govern, Identify, Protect, Detect, Respond and Recover, scored per subcategory with a live maturity level.

  • Per-function maturity scores updated as issues close
  • GV.RM risk appetite statements recorded and versioned
  • Detection and response gaps turned into owned issues
  • Board-level reporting in the language of business risk

GDPR

Readiness on a typical Growth workspace
89%

Records of processing, lawful bases, DSAR runbooks and Article 32 technical measures, kept current as your stack changes.

  • Article 30 records of processing activity auto-populated
  • DSAR and breach notification runbooks with owners and clocks
  • Retention schedules applied to real data stores
  • DPA and international transfer checks per vendor

HIPAA Security Rule

Readiness on a typical Growth workspace
76%

Administrative, physical and technical safeguards with BAA tracking for every vendor that touches ePHI.

  • Required vs. addressable safeguard decision log
  • BAA status tracked per vendor, with expiry reminders
  • ePHI data flow map kept in sync with your architecture
  • Workforce training and sanction policy attestations

PCI DSS 4.0

Readiness on a typical Growth workspace
68%

The 12 requirements and the future-dated 4.0 controls, tracked against your actual cardholder data flows.

  • Cardholder data environment scoping questionnaire
  • Requirement 6 secure development mapped to your repos
  • Requirement 10 logging and monitoring evidence collection
  • SAQ preparation checklist with owner per question

Readiness percentages are illustrative of a Growth workspace in month two. Actual coverage depends on which connectors you authorise and which controls you choose to scope out — Sentinel will tell you what it cannot evidence rather than pretending a control is met.

Mapping

Collect the evidence once, satisfy four frameworks

This is what the control library looks like in practice. One artifact, several clauses, no copy-paste.

Examples of a single evidence artifact satisfying controls in multiple frameworks
Evidence collectedControls it satisfies
MFA enforced on production root accountsSOC 2 CC6.1 · ISO 27001 A.8.5 · NIST CSF PR.AA-03 · PCI DSS 8.4
Quarterly access review completed with approvalsSOC 2 CC6.2 · ISO 27001 A.5.18 · PCI DSS 7.2
Encryption at rest confirmed on customer data storesSOC 2 CC6.7 · ISO 27001 A.8.24 · GDPR Art. 32 · HIPAA §164.312(a)(2)(iv)
Vendor security review with signed DPASOC 2 CC9.2 · ISO 27001 A.5.19–A.5.22 · GDPR Art. 28 · HIPAA BAA
Offboarding checklist completed within 24 hoursSOC 2 CC6.3 · ISO 27001 A.6.5 · NIST CSF PR.AA-05
Backups tested with a restore drillSOC 2 A1.2–A1.3 · ISO 27001 A.8.13 · NIST CSF RC.RP-03 · PCI DSS 12.10.2

How audit preparation works

  1. 1Pick the scope: which frameworks, which entities, which systems are in bounds.
  2. 2Sentinel maps controls to owners and opens the first register — usually 40–70 issues in week one.
  3. 3Systems-provable evidence is collected automatically: MFA state, encryption settings, backup jobs, access lists, change history.
  4. 4Humans are asked only for what only a human can attest to: sign-offs, policy acknowledgements, review approvals.
  5. 5Escalation keeps the clock honest, so nothing sits unassigned for weeks.
  6. 6Before the audit, Sentinel runs a mock evidence request and exports the binder with every artifact mapped to its control.

We do not issue the opinion

A SOC 2 report must be issued by an independent CPA firm, and ISO certification by an accredited body. CISO Express prepares everything they ask for and works with whichever auditor you choose — we never lock you into a partner and never sell you the letter.

Honest coverage reporting

If Sentinel cannot evidence a control with a system of record, it says so instead of marking it green. You get a clear list of what is automated, what needs a human attestation this quarter, and what is out of scope — refreshed continuously.

Scope changes do not break the program

Add a second entity, a new cloud region or a payments flow, and Sentinel re-scores the affected controls and opens the new issues with owners instead of quietly dropping them.

SOC 2 Type II

CC6.1 access controls and CC6.6 MFA evidence pulled from your IdP

ISO/IEC 27001:2022

Statement of Applicability generated from your control status

NIST CSF 2.0

Per-function maturity scores updated as issues close

Put an owner on every issue

Start free, connect Slack or Teams, and Sentinel assigns the first issues before you commit to anything.