Compliance

Ten frameworks, mapped from a single scan

SBCMSP maps every finding to the controls your clients are audited against — continuous coverage, auto-collected evidence and white-label, audit-ready reports.

Get started See how mapping works

SOC 2

21 controls
AICPA Trust Services Criteria

Automate Trust Services Criteria assessments — continuous CC-control monitoring, white-label audit-ready reports and evidence collection …

Explore SOC 2

HIPAA

54 controls
HHS Security Rule

Map the HIPAA Security Rule’s administrative, physical and technical safeguards from a single scan — and prove continuous compliance for …

Explore HIPAA

PCI DSS v4

64 controls
PCI Security Standards Council

Track the PCI DSS v4.0 requirements across your clients’ cardholder-data environment — network security, access control, monitoring and t…

Explore PCI DSS

NIST CSF 2.0

106 controls
NIST Cybersecurity Framework 2.0

Assess your clients against the NIST Cybersecurity Framework 2.0, including the new Govern function — Identify, Protect, Detect, Respond …

Explore NIST CSF

NIST CSF 1.1

108 controls
NIST Cybersecurity Framework 1.1

The 2018 edition — five Functions (Identify, Protect, Detect, Respond, Recover), without Govern. Still named in many contracts; reported alongside 2.0 from the same scan.

Explore NIST CSF

CMMC

110 controls
DoD CMMC 2.0

Track CMMC 2.0 practices (built on NIST SP 800-171) for clients handling CUI — Level 1 and Level 2 readiness, evidenced and reported.

Explore CMMC

ISO 27001

93 controls
ISO/IEC 27001:2022

Assess the 93 Annex A controls across the four 2022 themes — Organizational, People, Physical and Technological — and keep ISMS evidence …

Explore ISO 27001

CIS Controls v8

153 controls
Center for Internet Security

Measure the 18 CIS Controls and 153 safeguards, mapped to Implementation Groups, so clients know exactly which baseline they’ve reached.

Explore CIS v8

FTC Safeguards

9 controls
FTC Safeguards Rule (GLBA)

Track the nine elements of the FTC Safeguards Rule for non-banking financial institutions — including the qualified individual, risk asse…

Explore FTC Safeguards

Cyber Essentials

5 controls
UK NCSC

Check the five technical controls behind UK Cyber Essentials certification: firewalls, secure configuration, access control, malware prot…

Explore Cyber Essentials

Map your clients to 10 frameworks

Run a readiness assessment and see exactly which controls need work.