Frameworks
Coverage matrix with honest status labels.
Every row states the split between automated cloud-configuration checks and evidence you must supply, because that distinction is the whole substance. A weaker honest label beats a strong false one.
| Framework | Status | Disclosure |
|---|---|---|
| DPDP Act 2023 + Rules 2025 | Implemented | 29 automated controls + 2 evidence workflows. No backlog. |
| CIS AWS Foundations v3.0.0 | Implemented | 55 automated controls + 7 evidence workflows. No backlog. |
| SOC 2 Type II | Implemented | 9 automated controls + 24 evidence workflows. No backlog. Attestation not claimed — only a licensed CPA firm can issue one. |
| ISO/IEC 27001:2022 | Implemented | 19 automated controls + 73 evidence workflows. 1 control still in backlog. Certification is granted against Clauses 4-10 (the ISMS), not Annex A — certification not claimed. |
| GDPR (EU 2016/679) | Implemented | 9 automated controls + 31 evidence workflows. 1 control still in backlog. There is no GDPR certificate; compliance is a legal determination only a supervisory authority can make. |
| PCI DSS v4.0 | Implemented | 21 automated controls + 23 evidence workflows. 2 controls still in backlog. Not a RoC, AoC or SAQ. Validation is by a QSA against a cardholder data environment you define. |
| HIPAA Security Rule + HITECH | Implemented | 19 automated controls + 27 evidence workflows. No backlog. No certification exists; HHS certifies no one. Data-centre physical security sits with the cloud provider under your BAA, but §164.310 workstation and device controls remain yours to evidence. |
| RBI Cyber Security Framework | Chunked release | 18 automated controls + 5 evidence workflows. 19 controls still in backlog. |
| IRDAI Information & Cyber Security | Implemented | 20 automated controls + 20 evidence workflows. 1 control still in backlog. Gated to ap-south-1 / ap-south-2. |
| SEBI CSCRF 2024 | Implemented | 17 automated controls + 22 evidence workflows. No backlog. Gated to ap-south-1 / ap-south-2. |
| MeitY Cloud Guidelines + MeghRaj | Implemented | 17 automated controls + 18 evidence workflows. No backlog. |
| NIST CSF v1.1 | Chunked release | 22 automated controls + 63 evidence workflows. 23 controls still in backlog. |
| CCPA / CPRA | Chunked release | 23 automated controls + 9 evidence workflows. 8 controls still in backlog. AWS-only; Azure and GCP mapping pending. |
| SWIFT CSCF v2024 | Chunked release | 15 automated controls + 11 evidence workflows. 6 controls still in backlog. AWS-only; Azure and GCP mapping pending. |
| FedRAMP Moderate (Rev 5) | Chunked release | 20 automated controls + 13 evidence workflows. 36 controls still in backlog. Not an authorization package and not a path to ATO. |
| AWS Well-Architected | Implemented | All six pillars, automated checks plus evidence anchors per pillar. |
| OpsVision Cloud Review | Implemented | Internal operational review across security, cost and reliability. Not a compliance certification. |
| Cloud cost governance | Implemented | Operational controls only. Not a compliance certification. |
Need a framework before it is fully automated?
Enterprise customers can request custom framework mapping with explicit manual-evidence labels and no false certification claims.