Skip to main content

Compliance & Maturity

Path: /compliance · Sidebar: Governance → Compliance & Maturity

This module measures your program against industry frameworks and assesses your security maturity, with evidence drawn from your actual scan and finding data.

Framework coverage

Track control coverage against:

  • OWASP Top 10 and OWASP ASVS
  • PCI-DSS v4
  • ISO 27001
  • SOC 2
  • NIST 800-53
  • HIPAA
  • GDPR

For each framework you see which controls are covered, partially covered or gaps, with the evidence (scans, findings, acceptances) backing each.

Maturity assessment

A DSOMM-style maturity view rates your practices across dimensions (e.g. testing depth, coverage, remediation discipline) so you can see where to invest next.

Per-application benchmarking

Compliance and maturity can be viewed per application, so you can hold critical apps to a higher bar and show auditors scope-specific evidence.

Using it

  1. Pick a framework.
  2. Review covered vs. gap controls and drill into the evidence.
  3. Export a compliance report for auditors.
  4. Track maturity over time as the program improves.
Evidence, not checkboxes

Coverage is computed from real assessments and findings - so the compliance view reflects what you actually do, and produces audit-ready evidence rather than self-attested checkboxes.