Shared Assessments SIG
The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.
2026 annual release · Shared Assessments
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
Shared Assessments SIG is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Corporate subscription or membership plus the applicable product-integration license is required. SIG questions may not be edited, embedded, or redistributed outside the licensed terms without written permission.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Cybersecurity · Privacy · Data governance · Business resilience · Third-party risk management
- Applies to
- all sectors · financial services · healthcare · technology · US · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-28
03Version ledger
| 2025 annual release | Superseded | date not published |
| 2026 annual release | Current edition · supersedes 2025 annual release | date not published |
06Related frameworks
- HITRUST CSFv11.8.0
Also applies to healthcare · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
- ISO 223012019 (Amd 1:2024)
Also applies to all sectors · The certifiable business continuity management system standard for preparing for, responding to, and recovering from disruption. Tracking it does not claim that ControlFrame or any customer holds ISO 22301 certification.
Also applies to all sectors · NIST's voluntary framework for managing privacy risk through enterprise risk management. It is guidance, not a regulation or certification.
- Digital Operational Resilience ActRegulation (EU) 2022/2554
Also applies to financial services · The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.