CMS Enhanced Direct Enrollment
First seeded template. HPS / MarketLink is a sample project instance with placeholders until ControlFrame collectors run.
Frameworks are reusable programs inside ControlFrame. Choose the framework, bind it to a company and target application, then run evidence collection through the same operating model.
Confirm systems, data classes, owners, vendors, and target environments.
Select CMS EDE, SOC 2, PCI, ISO, HIPAA, HITRUST, NIST, FedRAMP, CMMC, CIS, CSA CCM, GLBA, GDPR, or NYDFS.
Map collectors, manual evidence, private runner access, and reviewer gates.
Run tests, resolve findings, approve artifacts, and export the auditor package.
First seeded template. HPS / MarketLink is a sample project instance with placeholders until ControlFrame collectors run.
Practical security baseline template that gives teams a fast control spine before or alongside formal audits.
Defense-industrial-base template. Strong reason for private deployment, appliance collectors, and careful data-residency boundaries.
Planned reusable template for administrative, physical, and technical safeguard evidence with source-backed CFR mapping.
High-value healthcare assurance template. Build after HIPAA/SOC 2 primitives so HITRUST can reuse the shared control spine.
Broad federal-control template that underpins FedRAMP, CMS security packages, and many enterprise control crosswalks.
Planned reusable template for risk governance and security operations evidence mapped to native CSF outcomes.
Planned reusable template for cardholder data environment scoping, access controls, logging, vulnerability evidence, and SAQ/ROC support.
Planned reusable template for control narratives, tickets, cloud configuration, access reviews, and auditor packages.
Cloud assurance template for mapping shared-responsibility controls across SaaS, cloud, and private deployment boundaries.
AI regulatory template that pairs with ISO 42001 for governance, model inventory, and lifecycle control evidence.
Federal cloud-assurance template. Requires strict package fidelity, OSCAL support, and deployment isolation options.
Privacy-program template that should share inventory, vendor, data-flow, and security evidence with HIPAA, SOC 2, ISO, and NIST.
Financial-services privacy/security template for customer-information safeguards and executive governance evidence.
Global ISMS template. Strong reuse candidate across SOC 2, HITRUST, NIST, and ISO 42001 governance evidence.
Planned reusable template for AI system inventory, risk treatment, monitoring, and management review evidence.
Financial-services cyber template. Useful for showing ControlFrame can support regulation-specific deadlines, attestations, and notification workflows.