Compliance & Maturity
Path: /compliance · Sidebar: Governance → Compliance & Maturity
This module measures your program against industry frameworks and assesses your security maturity, with evidence drawn from your actual scan and finding data.
Framework coverage
Track control coverage against:
- OWASP Top 10 and OWASP ASVS
- PCI-DSS v4
- ISO 27001
- SOC 2
- NIST 800-53
- HIPAA
- GDPR
For each framework you see which controls are covered, partially covered or gaps, with the evidence (scans, findings, acceptances) backing each.
Maturity assessment
A DSOMM-style maturity view rates your practices across dimensions (e.g. testing depth, coverage, remediation discipline) so you can see where to invest next.
Per-application benchmarking
Compliance and maturity can be viewed per application, so you can hold critical apps to a higher bar and show auditors scope-specific evidence.
Using it
- Pick a framework.
- Review covered vs. gap controls and drill into the evidence.
- Export a compliance report for auditors.
- Track maturity over time as the program improves.
Coverage is computed from real assessments and findings - so the compliance view reflects what you actually do, and produces audit-ready evidence rather than self-attested checkboxes.