Compliance

CIS, NIST 800-53, PCI DSS 4.0, ISO 27001, GDPR, DORA, FedRAMP, GxP, C5 — evaluated, not surveyed

Nine frameworks, one set of connected accounts. The same evidence collected from Cloud, Identity and SaaS is mapped to each framework's controls, so coverage is a pass/fail state instead of a self-reported answer.

Blog

August 23, 2026 · 11 min read

01

One evidence base, many mappings

Every control evaluated on a connected account is mapped to the frameworks it satisfies. A single misconfigured storage policy can show up as a failed control under more than one framework at once, because it is the same evidence, mapped more than one way — not nine separate collection exercises.

Compliance: framework coverage evaluated from connected accounts, with pass/fail per control.
Compliance: framework coverage evaluated from connected accounts, with pass/fail per control.
02

Coverage by environment

Because the same Cloud, Identity and SaaS environments feed the Security Score, they also feed framework coverage — a reviewer can see PCI DSS 4.0 or ISO 27001 status specifically for the cloud environment, or for identity, or for the SaaS estate.

  • Frameworks evaluated: CIS, NIST 800-53, PCI DSS 4.0, ISO 27001, GDPR, DORA, FedRAMP, GxP, C5
  • Coverage broken down by Cloud, Identity and SaaS
  • No self-attestation step in the evaluation
Compliance — Cloud: framework control state scoped to the cloud environment.
Compliance — Cloud: framework control state scoped to the cloud environment.
03

Identity and SaaS coverage

The same per-framework view is available scoped to identity findings and to the SaaS estate, so a gap in Microsoft 365 configuration or in access hygiene is traceable to the exact framework clause it affects.

Compliance — Identity: framework control state scoped to identity findings.
Compliance — Identity: framework control state scoped to identity findings.
1stone Research

Talk to the team about a third-party program

A working session against your actual third-party portfolio: how workspaces are created, which accounts get connected first, and what the Security Score looks like in week one.

Request a walkthrough