Skip to main content
Framework library
Framework module · shared-assessments-sig-2026

Shared Assessments SIG

The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.

2026 annual release · Shared Assessments

Standing today
Directory entry

00Answer

from the registry record
What is Shared Assessments SIG?
The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.
Who does Shared Assessments SIG apply to?
Shared Assessments SIG applies to all sectors, financial services, healthcare, technology, US, global, per Shared Assessments.
What is the current version of Shared Assessments SIG?
The current edition is 2026 annual release, issued by Shared Assessments. Source: https://sharedassessments.org/sig/.
What does an assessment under Shared Assessments SIG require?
No control catalog has been ingested for Shared Assessments SIG yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

Shared Assessments SIG is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Corporate subscription or membership plus the applicable product-integration license is required. SIG questions may not be edited, embedded, or redistributed outside the licensed terms without written permission.

02Registry record

checked 2026-08-28
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Cybersecurity · Privacy · Data governance · Business resilience · Third-party risk management
Applies to
all sectors · financial services · healthcare · technology · US · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-28

03Version ledger

2 editions
2025 annual releaseSupersededdate not published
2026 annual releaseCurrent edition · supersedes 2025 annual releasedate not published

06Related frameworks

scored from registry facts
  1. Also applies to healthcare · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

  2. ISO 223012019 (Amd 1:2024)

    Also applies to all sectors · The certifiable business continuity management system standard for preparing for, responding to, and recovering from disruption. Tracking it does not claim that ControlFrame or any customer holds ISO 22301 certification.

  3. Also applies to all sectors · NIST's voluntary framework for managing privacy risk through enterprise risk management. It is guidance, not a regulation or certification.

  4. Digital Operational Resilience ActRegulation (EU) 2022/2554

    Also applies to financial services · The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.

Shared Assessments SIG | ControlFrame