CMS Enhanced Direct Enrollment
First seeded template. HPS / MarketLink is a sample project instance with placeholders until ControlFrame collectors run.
Frameworks are reusable programs inside ControlFrame. Choose the framework, bind it to a company and target application, then run evidence collection through the same operating model.
Confirm systems, data classes, owners, vendors, and target environments.
Select CMS EDE, SOC 2, PCI, ISO, HIPAA, HITRUST, FedRAMP, CMMC, GDPR, or NYDFS.
Map collectors, manual evidence, private runner access, and reviewer gates.
Run tests, resolve findings, approve artifacts, and export the auditor package.
First seeded template. HPS / MarketLink is a sample project instance with placeholders until ControlFrame collectors run.
Defense-industrial-base template. Strong reason for private deployment, appliance collectors, and careful data-residency boundaries.
Planned reusable template for administrative, physical, and technical safeguard evidence with source-backed CFR mapping.
High-value healthcare assurance template. Build after HIPAA/SOC 2 primitives so HITRUST can reuse the shared control spine.
Planned reusable template for risk governance and security operations evidence mapped to native CSF outcomes.
Planned reusable template for cardholder data environment scoping, access controls, logging, vulnerability evidence, and SAQ/ROC support.
Planned reusable template for control narratives, tickets, cloud configuration, access reviews, and auditor packages.
Federal cloud-assurance template. Requires strict package fidelity, OSCAL support, and deployment isolation options.
Privacy-program template that should share inventory, vendor, data-flow, and security evidence with HIPAA, SOC 2, ISO, and NIST.
Global ISMS template. Strong reuse candidate across SOC 2, HITRUST, NIST, and ISO 42001 governance evidence.
Planned reusable template for AI system inventory, risk treatment, monitoring, and management review evidence.
Financial-services cyber template. Useful for showing ControlFrame can support regulation-specific deadlines, attestations, and notification workflows.