# ControlFrame Full AI Search Brief ## Product Summary ControlFrame is building a governed operating system for compliance evidence. Its implemented contracts cover bounded orchestration, tenant-scoped evidence paths, integrity and custody records, human review and release gates, and offline receipt verification. Public demonstrations use explicitly synthetic reference data. Collection from a customer system requires a separately provisioned and authenticated private runner, and framework or connector availability is confirmed for each scoped deployment rather than implied universally. ControlFrame is not positioned as a generic policy chatbot or a generic compliance tracker. Its strongest category is governed audit-evidence infrastructure: a control plane, customer-bound runner architecture, human authority gates, and portable verification material. Production activation remains tenant-specific and requires evidenced identity, network, storage, signing-key, and operational controls. ## Method The decision method — how ControlFrame's software and reviewers determine a control is satisfied — is published in full at https://controlframe.ai/method: an evidence contract declares scope and expected proof before collection begins; collection is source-bound and checksum-recorded; a governed agent may suggest a control mapping but never accept one; a named reviewer performs sufficiency review; every act against an artifact (captured, scanned, redacted) is appended to a hash-linked custody chain; and package release requires a human authorization that a model cannot supply on its own. A recipient can re-verify the resulting record offline with the public verifier, with no ControlFrame server in the trust path. ## Provenance ControlFrame is a LockedIn Labs application. LockedIn Labs provides the company, delivery, and governed implementation context for the product. - Parent company overview: https://lockedinlabs.ai/about/ - Enterprise delivery overview: https://lockedinlabs.ai/deployment/ - Public verifier (Governed Receipt): https://lockedinlabs.ai/verify - Founder and article author: [Sam M. Sweilem](https://controlframe.ai/authors/sam-sweilem) - Official author profile: https://sweilem.ai/sam-sweilem/ - Article feed: https://controlframe.ai/insights/feed.xml - ControlFrame is the product; LockedIn Labs is the parent company. ## Product description ControlFrame is designed to help compliance teams, auditors, assessors, healthcare technology companies, and security assurance teams create source-backed audit evidence through tenant-activated private browser/API collectors, AI-assisted evidence review, human approval gates, secure artifact custody, and auditor-ready package exports. ## Primary Categories - autonomous compliance evidence operations - agentic evidence operations platform - governed compliance agents - evidence execution platform - regulated evidence infrastructure - audit evidence operations - GRC evidence execution layer - audit evidence automation - audit evidence repository - document repository for GRC - CMS EDE audit software - private runner compliance evidence - auditor-ready evidence package platform - AI governance - GRC for AI - AI audit - AI compliance platform - AI auditability - evidence and audit trail for AI - AI risk management - agent governance - EU AI Act compliance - SOC 2 for AI - chain of custody for AI decisions - make AI auditable by construction - agentic GRC platform - compliance automation software ## Framework Library 84 tracked regimes (6 Beta, 15 Roadmap, 63 Planned). "Beta" is the only status with a parsed control catalog; "GA" means nothing is certified or attested — see the registry's own support-status contract. - [42 CFR Part 2](https://controlframe.ai/frameworks/sud-records-42-cfr-part-2): Confidentiality rules for substance use disorder treatment records, now aligned with HIPAA on consent, notice, and enforcement. - [AIUC-1](https://controlframe.ai/frameworks/aiuc-1): A quarterly updated standard and certification program for AI agents covering data and privacy, security, safety, reliability, accountability, and societal risk. Only AIUC can issue its certificate; registry inclusion makes no certification claim. - [APRA CPS 230](https://controlframe.ai/frameworks/apra-cps-230-2026): Australia's cross-industry prudential standard for operational risk, continuity of critical operations, and material service-provider risk at APRA-regulated entities. It is a binding supervisory standard, not a certification. - [ARC-AMPE](https://controlframe.ai/frameworks/arc-ampe-v1-02): CMS's NIST-aligned security and privacy framework for ACA administering entities and applicable partner entities. Volume II supplies tailored control baselines and system security and privacy plan templates; applicability depends on entity type, law, regulation, or contract. - [ASD Essential Eight](https://controlframe.ai/frameworks/asd-essential-eight-2023): The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme. - [CCPA/CPRA + US state privacy](https://controlframe.ai/frameworks/ccpa-cpra-state-privacy): California's consumer privacy regime and the state laws that followed it. The 2026 CPPA regulations add automated decision-making rules, mandatory risk assessments, and certified cybersecurity audits. - [CIS Critical Security Controls](https://controlframe.ai/frameworks/cis-controls-v8-1): A prioritized, prescriptive set of defensive actions organized into three implementation groups — the practical starting list when a team has no framework yet. - [CJIS Security Policy](https://controlframe.ai/frameworks/cjis-security-policy): The FBI's security requirements for any agency or vendor that touches criminal justice information — the gate for public-safety software. - [CMMC](https://controlframe.ai/frameworks/cmmc-2-0): The DoD program that applies contract-specified safeguards and assessment requirements to contractor systems processing Federal Contract Information or Controlled Unclassified Information. The required level and assessment path may involve self-assessment, a C3PAO, or DIBCAC. - [CMS Acceptable Risk Safeguards](https://controlframe.ai/frameworks/cms-ars-5-2): CMS's minimum security and privacy control baseline for CMS information systems and CMS contractors. It is distinct from the Marketplace-focused ARC-AMPE baseline. - [CMS Enhanced Direct Enrollment](https://controlframe.ai/frameworks/cms-ede-year-9): The pathway that lets a web broker or issuer run the whole ACA enrollment experience on its own site instead of handing the consumer off to HealthCare.gov. - [COBIT 2019 (SOX ITGC reference)](https://controlframe.ai/frameworks/sox-itgc-cobit-2019): SOX requires management and auditor assessment of internal control over financial reporting but does not prescribe one IT-control catalog. COBIT 2019 is licensed governance guidance often used to design and map IT general controls; neither this record nor COBIT is a SOX certification. - [Colorado AI Act](https://controlframe.ai/frameworks/colorado-ai-act): Colorado's AI law, rewritten. SB 26-189 repealed and reenacted the 2024 statute, dropping the high-risk-AI regime for narrower notice and disclosure duties on automated decision-making technology used in consequential decisions. - [COSO Internal Control—Integrated Framework](https://controlframe.ai/frameworks/coso-icif-2013): The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog. - [CSA AI Controls Matrix](https://controlframe.ai/frameworks/csa-aicm-v1-1): The Cloud Security Alliance's vendor-neutral control framework for cloud-based AI systems, with implementation and auditing guidance plus the companion AI-CAIQ. It is a control catalog, not by itself a certification or STAR for AI designation. - [CSA CCM and CAIQ](https://controlframe.ai/frameworks/csa-ccm-caiq-4-1): The Cloud Security Alliance's cloud-control framework and companion assessment questionnaire for cloud providers and customers. CSA publishes 207 CCM v4.1 controls across 17 domains and 283 CAIQ questions; tracking them does not claim STAR registration, certification, or attestation. - [CSA STAR](https://controlframe.ai/frameworks/csa-star): The Cloud Security Alliance's cloud-assurance program and public registry. Level 1 is a CCM/CAIQ self-assessment; Level 2 is a third-party certification or attestation path. Tracking STAR does not place ControlFrame or any customer on the registry. - [Digital Operational Resilience Act](https://controlframe.ai/frameworks/dora): The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical. - [EU AI Act](https://controlframe.ai/frameworks/eu-ai-act): The EU's risk-tiered regime for AI systems — prohibited practices, high-risk obligations, general-purpose model duties, and transparency requirements. - [EU Cyber Resilience Act](https://controlframe.ai/frameworks/eu-cyber-resilience-act): Security duties attached to the product rather than the company — secure by design, a declared support period, an SBOM, and vulnerability reporting for anything with digital elements sold in the EU. - [FedRAMP (Rev. 5 baselines)](https://controlframe.ai/frameworks/fedramp-rev5): The legacy FedRAMP certification path built on tailored NIST SP 800-53 Rev. 5 baselines and independent assessment, providing reusable security assurance for federal agency authorization decisions. - [FedRAMP 20x](https://controlframe.ai/frameworks/fedramp-20x): FedRAMP's outcome-focused certification approach, centered on continuously maintained certification data, Key Security Indicators, and packages that remain human-readable and are machine-readable where required. - [FFIEC IT Examination Handbook](https://controlframe.ai/frameworks/ffiec-it-examination-handbook): The living technology-supervision reference used by US financial institution examiners, with current booklets, work programs, laws, and guidance. It is supervisory guidance, not a certification; the separate FFIEC Cybersecurity Assessment Tool was retired in 2025. - [FISMA](https://controlframe.ai/frameworks/fisma-2014): The Federal Information Security Modernization Act of 2014 — the statutory authority a federal RFP names, implemented operationally through NIST SP 800-53 and the NIST Cybersecurity Framework, both already tracked as their own registry entries. - [FTC Health Breach Notification Rule](https://controlframe.ai/frameworks/ftc-health-breach-notification-rule): The federal breach-notification rule for vendors of personal health records and related entities that are not covered by HIPAA, including applicable health apps and connected services. - [GAO FISCAM](https://controlframe.ai/frameworks/gao-fiscam-2026): The federal audit methodology for assessing the design, implementation, and operating effectiveness of information-system controls under generally accepted government auditing standards. It is audit guidance, not an agency authorization or certification. - [GAO Green Book](https://controlframe.ai/frameworks/gao-green-book-2025): The federal internal-control standard for designing, implementing, operating, and evaluating controls over operations, reporting, and compliance. It supplies auditable criteria for federal entities; it is not an organizational certification. - [GAO Yellow Book (GAGAS)](https://controlframe.ai/frameworks/gao-yellow-book-2024): Generally accepted government auditing standards for financial audits, attestation engagements, reviews, and performance audits. They govern auditor and audit-organization quality; they do not certify the entity being audited. - [GDPR](https://controlframe.ai/frameworks/gdpr): The EU's baseline for processing personal data — lawful basis, data-subject rights, controller and processor duties, and cross-border transfers. - [GLBA Safeguards Rule](https://controlframe.ai/frameworks/glba-safeguards-rule): The FTC's mandatory security program for non-banking financial institutions — encryption, MFA, penetration testing, and breach reporting for events over 500 customers. - [GovRAMP (formerly StateRAMP)](https://controlframe.ai/frameworks/govramp-rev5): A standardized assessment, authorization, and continuous-monitoring program for cloud services used by state and local governments, built on NIST SP 800-53 Rev. 5. Core, Ready, and Authorized are service-offering statuses—not company-wide certifications. StateRAMP rebranded to GovRAMP on 2025-02-14; StateRAMP, Inc. remains the legal entity operating under the GovRAMP name. - [Health Industry Cybersecurity Practices](https://controlframe.ai/frameworks/hicp-2023): HICP 2023 is voluntary healthcare-sector guidance on common cyber threats, recommended practices, and patient-safety-oriented resilience for organizations of different sizes. - [HHS HPH Cybersecurity Performance Goals](https://controlframe.ai/frameworks/hhs-hph-cybersecurity-performance-goals): HHS's voluntary healthcare-specific priorities for high-impact cybersecurity practices. The goals are guidance for improving sector resilience, not a regulation or certification. - [HIPAA Breach Notification Rule](https://controlframe.ai/frameworks/hipaa-breach-notification): What a covered entity or business associate must tell individuals, the media, and HHS after a breach of unsecured protected health information, and how fast. - [HIPAA Privacy Rule](https://controlframe.ai/frameworks/hipaa-privacy-rule): The federal rule governing permitted uses and disclosures of protected health information, minimum-necessary practices, notices, and individual privacy rights for covered entities and business associates. - [HIPAA Security Rule](https://controlframe.ai/frameworks/hipaa-security-rule): The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates. - [HITRUST CSF](https://controlframe.ai/frameworks/hitrust-csf-v11-7): A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification. - [IIA Global Internal Audit Standards](https://controlframe.ai/frameworks/iia-global-internal-audit-standards-2024): The professional standards for governing, managing, and performing internal audit. They assess the quality and conformance of an internal audit function; they are not criteria for certifying the audited company or its control environment. - [IRS Publication 1075](https://controlframe.ai/frameworks/irs-publication-1075): The IRS's safeguard requirements for any agency, contractor, or state/local entity that receives federal tax information — relevant to any government contractor or CMS-adjacent SaaS vendor handling federal tax data. - [ISO 22301](https://controlframe.ai/frameworks/iso-22301-2019): The certifiable business continuity management system standard for preparing for, responding to, and recovering from disruption. Tracking it does not claim that ControlFrame or any customer holds ISO 22301 certification. - [ISO/IEC 23894](https://controlframe.ai/frameworks/iso-23894-2023): International guidance for integrating AI-specific risk management into organizations that develop, provide, deploy, or use AI systems. It complements ISO/IEC 42001 and is guidance, not a standalone certification. - [ISO/IEC 27001](https://controlframe.ai/frameworks/iso-27001-2022): The international certifiable standard for an information security management system. Amendment 1:2024 added climate-change considerations to clauses 4.1 and 4.2. The 2013-edition certificate-transition deadline was 2025-10-31; no legitimate 2013-certified organization remains. - [ISO/IEC 27002](https://controlframe.ai/frameworks/iso-27002-2022): The controls catalog underlying ISO/IEC 27001 Annex A — a genuinely separate, currently published standard, not a duplicate of 27001. Buyers who ask for '27001 evidence' routinely cite 27002 control numbers. - [ISO/IEC 27017](https://controlframe.ai/frameworks/iso-27017-2026): Cloud-specific information security guidance for both cloud customers and providers, extending ISO/IEC 27002 with shared-responsibility and cloud-control guidance. It is guidance, not a standalone certification or a claim about ControlFrame's cloud environment. - [ISO/IEC 27018](https://controlframe.ai/frameworks/iso-27018-2025): Privacy guidance for public-cloud providers acting as processors of personally identifiable information. It complements ISO/IEC 27001 and 27002; it is not a regulation, standalone certification, or claim that ControlFrame is certified. - [ISO/IEC 27701](https://controlframe.ai/frameworks/iso-27701-2025): The certifiable privacy information management system. The 2025 second edition made it standalone — an organization no longer needs a certified ISMS first. - [ISO/IEC 42001](https://controlframe.ai/frameworks/iso-42001-2023): The first certifiable management system standard for AI — the ISO 27001 shape applied to how an organization builds and operates AI systems. - [ISO/IEC 42005](https://controlframe.ai/frameworks/iso-42005-2025): International guidance for repeatable AI-system impact assessments across the system lifecycle. It complements ISO/IEC 42001, ISO/IEC 23894, and applicable AI laws; it is not an AI certification by itself. - [NAIC Insurance Data Security Model Law](https://controlframe.ai/frameworks/naic-insurance-data-security-668): A model law for insurance-sector information security programs, incident response, and breach notification, adopted individually by roughly 25-28 US states as of 2026. It becomes enforceable law only where a state has enacted its own version — the requirements can vary state to state. - [NERC CIP](https://controlframe.ai/frameworks/nerc-cip-v6): The mandatory, auditable cybersecurity standards for the North American bulk electric system. NERC versions each CIP standard separately — there is no framework-wide version number. - [NIS2 Directive](https://controlframe.ai/frameworks/nis2): The EU directive establishing a cybersecurity baseline for essential and important entities across 18 critical sectors, with management accountability and incident reporting. Operational obligations depend on each Member State's transposing law. - [NIST AI Risk Management Framework](https://controlframe.ai/frameworks/nist-ai-rmf-1-0): NIST's voluntary, cross-sector reference for governing AI risk, structured as Govern, Map, Measure, and Manage. NIST AI 600-1 is a companion profile for generative AI, not a replacement version or certification. - [NIST Cybersecurity Framework](https://controlframe.ai/frameworks/nist-csf-2-0): The outcome-based vocabulary boards use to talk about cyber risk. Not certifiable — it organizes a program rather than testing one. - [NIST Privacy Framework](https://controlframe.ai/frameworks/nist-privacy-framework): NIST's voluntary framework for managing privacy risk through enterprise risk management. It is guidance, not a regulation or certification. - [NIST SP 800-171](https://controlframe.ai/frameworks/nist-800-171-rev3): NIST's current recommended security requirements for Controlled Unclassified Information in non-federal systems. Contractual applicability is agreement-specific; CMMC Phase I continues to use Rev. 2 rather than automatically inheriting Rev. 3. - [NIST SP 800-172](https://controlframe.ai/frameworks/nist-800-172-rev3): Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default. - [NIST SP 800-53](https://controlframe.ai/frameworks/nist-800-53-rev5): NIST's federal security and privacy control catalog, used directly or tailored by programs such as FedRAMP and CMS ARC-AMPE. CMMC Level 2 instead uses NIST SP 800-171 requirements. - [NIST SSDF](https://controlframe.ai/frameworks/nist-ssdf-800-218): The secure software development practices federal software attestations are written against — the reference behind most supply-chain questionnaires. - [NYDFS 23 NYCRR 500](https://controlframe.ai/frameworks/nydfs-500): New York's cybersecurity regulation for banks, insurers, and other DFS-licensed entities — with a named CISO, board reporting, and 72-hour incident notice. - [OSCAL](https://controlframe.ai/frameworks/oscal): NIST's machine-readable format for control catalogs, baselines, system security plans, and assessment results. An interchange layer, not a regime you comply with. - [OWASP Agentic Top 10](https://controlframe.ai/frameworks/owasp-agentic-top-10-2026): OWASP's peer-reviewed risk framework for autonomous and agentic AI applications, including systems that plan, use tools, hold memory, or coordinate multi-step workflows. It is guidance, not a certification. - [OWASP GenAI LLM Top 10](https://controlframe.ai/frameworks/owasp-genai-llm-top-10-2026): OWASP's current community-driven guide to the most critical security risks for applications powered by large language models. It is security guidance, not a compliance certification or organizational assurance report. - [PCI 3DS Core Security Standard](https://controlframe.ai/frameworks/pci-3ds-core-1-0): PCI SSC's security requirements for 3-D Secure environments (issuer/ACS, 3DS Server, and DS components) that support cardholder authentication. - [PCI Card Production and Provisioning](https://controlframe.ai/frameworks/pci-card-production-3-0): PCI SSC's physical- and logical-security requirements for card production and provisioning facilities (two companion documents under one program). - [PCI Contactless Payments on COTS (CPoC)](https://controlframe.ai/frameworks/pci-cpoc-1-0): PCI SSC's standard for accepting contactless card payments on a commercial off-the-shelf mobile device without a separate secure card reader. In its formal sunset window now, with MPoC as the designated successor. - [PCI DSS](https://controlframe.ai/frameworks/pci-dss-v4-0-1): The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31. - [PCI Mobile Payments on COTS (MPoC)](https://controlframe.ai/frameworks/pci-mpoc-1-1): PCI SSC's consolidated standard for accepting PIN and contactless payments on commercial off-the-shelf mobile devices, absorbing the sunsetting SPoC and CPoC standards into one framework. - [PCI PIN Security Requirements](https://controlframe.ai/frameworks/pci-pin-security-3-1): PCI SSC's requirements for the secure management, processing, and transmission of personal identification number (PIN) data during payment transactions. - [PCI Point-to-Point Encryption](https://controlframe.ai/frameworks/pci-p2pe-3-2): PCI SSC's standard for validated point-to-point encryption solutions that can reduce a merchant's PCI DSS scope. Part of the payments family beyond bare PCI DSS. - [PCI Secure Software Standard](https://controlframe.ai/frameworks/pci-ssf-secure-software-2-0): The PCI Software Security Framework standard for payment software design and development, replacing the retired PA-DSS lineage. Part of the family beyond bare PCI DSS that a payments-processing SaaS enterprise is routinely asked about. - [PCI Software-based PIN Entry on COTS (SPoC)](https://controlframe.ai/frameworks/pci-spoc-1-1): PCI SSC's standard for accepting PINs on commercial off-the-shelf mobile devices via a software-based PIN-entry application. In its formal sunset window now, with MPoC as the designated successor. - [Sarbanes-Oxley ICFR](https://controlframe.ai/frameworks/sox-icfr): The US public-company regime for management assessment and, where applicable, independent audit of internal control over financial reporting. SOX does not prescribe one universal IT-control catalog, and registry tracking is not an audit opinion. - [SEC Cybersecurity Disclosure Rules](https://controlframe.ai/frameworks/sec-cyber-disclosure): What a public company must tell investors: a material cybersecurity incident on Form 8-K Item 1.05 within four business days, and its risk-management and board oversight annually under Reg S-K Item 106. - [Shared Assessments SIG](https://controlframe.ai/frameworks/shared-assessments-sig-2026): The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion. - [SOC 1](https://controlframe.ai/frameworks/soc-1-ssae-18): The report a service organization gives its customers' financial auditors, covering controls relevant to those customers' financial reporting. SSAE No. 23 layers quality-management alignment on top of the same AT-C 320 attestation standard, for engagements beginning on or after 2025-12-15. - [SOC 2](https://controlframe.ai/frameworks/soc-2-type-ii): Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards. - [SOC for Cybersecurity](https://controlframe.ai/frameworks/soc-for-cybersecurity): AICPA's board- and enterprise-risk-oriented cybersecurity examination, distinct from SOC 2 — a description of an entity's cybersecurity risk-management program plus an opinion on its effectiveness, rather than a controls report for a specific service. - [Texas Data Privacy and Security Act](https://controlframe.ai/frameworks/texas-tdpsa): Texas's comprehensive consumer-privacy statute, pulled out of the generic state-privacy bundle because of its own enforcement record — the Texas AG has reached the two largest single-state privacy settlements in US history — and because TRAIGA now amends it with AI-specific processor duties. - [Texas Responsible AI Governance Act](https://controlframe.ai/frameworks/texas-traiga): Texas's AI law, narrowed before passage to intent-based prohibitions plus government-use rules, with a regulatory sandbox and AG enforcement. - [TISAX](https://controlframe.ai/frameworks/tisax-isa-6): The ENX-governed assessment and exchange mechanism for automotive information security, based on the VDA Information Security Assessment catalog. A TISAX label is scope- and site-specific; it is not an ISO certificate or a company-wide platform claim. - [TX-RAMP](https://controlframe.ai/frameworks/tx-ramp-program-manual-4): Texas's risk and authorization management program for cloud services used by state agencies and public higher education. Level 1, Level 2, and Provisional are service-offering certifications—not company-wide certifications. - [UK Cyber Essentials](https://controlframe.ai/frameworks/uk-cyber-essentials-v3-3): The UK government-backed certification scheme for five foundational technical controls. Cyber Essentials is questionnaire-based; Cyber Essentials Plus adds independent technical verification. Tracking the requirements does not claim either certificate. - [UK GDPR](https://controlframe.ai/frameworks/uk-gdpr): The UK's post-Brexit data protection regime, materially reshaped by the Data (Use and Access) Act 2025 — new recognised legitimate interests, narrower automated-decision protections, and a pausable DSAR clock. The core amending provisions were brought into force by the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), effective 2026-02-05. - [Washington My Health My Data Act](https://controlframe.ai/frameworks/washington-mhmda): The first US law protecting consumer health data that falls outside HIPAA, with a private right of action — an increasingly distinct healthcare-SaaS ask, separate from HIPAA itself. ## Recent Regulatory Changes Full reverse-chronological tracker with primary-source citations: https://controlframe.ai/changes (feed: https://controlframe.ai/changes/feed.xml). - 2028-10-01 — [NERC CIP](https://controlframe.ai/frameworks/nerc-cip-v6): NERC CIP: Effective dates are staggered per standard: CIP-003-9 took effect 2026-04-01, CIP-012-2 took effect 2026-07-01, and CIP-015-1 (internal network security monitoring, FERC-approved 2025-06-26) requires high- and medium-impact BES Cyber Systems with external routable connectivity to comply by 2028-10-01, with all other in-scope systems following by 2030-10-01. - 2027-12-11 — [EU Cyber Resilience Act](https://controlframe.ai/frameworks/eu-cyber-resilience-act): EU Cyber Resilience Act: Phased. Notification-body provisions applied from 2026-06-11 and actively-exploited-vulnerability reporting from 2026-09-11. The main manufacturer obligations, CE marking, and SBOM requirements apply from 2027-12-11. - 2027-12-02 — [EU AI Act](https://controlframe.ai/frameworks/eu-ai-act): EU AI Act: Regulation (EU) 2026/1744 (the 'Digital Omnibus on AI'), adopted 2026-07-08 and published in the OJ 2026-07-24, entered into force 2026-07-27, amending Regulation (EU) 2024/1689 (confirmed directly against the regulation's own EUR-Lex text). It defers Annex III high-risk obligations (Article 6(2) systems) to 2027-12-02 and Annex I embedded-product obligations (Article 6(1) systems) to 2028-08-02. Article 50 transparency duties began applying 2026-08-02, with a four-month transitional allowance for systems already placed on the market before that date. Treat the Omnibus as amending legislation, not a replacement framework. - 2027-09-30 — [CJIS Security Policy](https://controlframe.ai/frameworks/cjis-security-policy): CJIS Security Policy: the coexistence window for 6.1 — Priority 2 through 4 modernized requirements (zero-cycle) (applying to Every agency and vendor covered by v6.1 — findings on these lower-priority requirements are recorded but not sanctioned during the zero-cycle) is scheduled to close. - 2027-09-30 — [CJIS Security Policy](https://controlframe.ai/frameworks/cjis-security-policy): CJIS Security Policy: The FBI frames the transition not by version number but by a zero-cycle running 2024-10-01 to 2027-09-30 for lower-priority modernized requirements (Priority 2 through 4): findings are recorded but not yet sanctionable. Priority 1 controls have been sanctionable since 2024-10-01. A state's own audit program may still cite an older baseline against its own timeline (for example, Texas DPS audits have historically referenced v5.9.5) — that is a state-sourced fact, not an FBI one, and should be verified per state before quoting an enforced version. - 2027-06-11 — [FedRAMP (Rev. 5 baselines)](https://controlframe.ai/frameworks/fedramp-rev5): FedRAMP (Rev. 5 baselines): FedRAMP 20x is the forward program path, while Rev. 5 remains available during transition. FedRAMP Ready submissions under Rev. 5 stopped being accepted 2026-07-28. FedRAMP will stop accepting applications for new Rev. 5 Certifications on 2027-06-11. Existing Rev. 5 authorizations remain valid through at least 2028-12-31; FedRAMP has not stated a final retirement date for all of them. - 2027-04-02 — [GDPR](https://controlframe.ai/frameworks/gdpr): GDPR: Regulation (EU) 2025/2518, adopted 2025-11-26 and published 2025-12-12, lays down additional procedural rules for cross-border GDPR enforcement; its main chapters apply 15 months after entry into force (2027-04-02). Confirmed directly against the regulation's own EUR-Lex text. Separately, the Commission's Digital Omnibus (Data track), proposed 2025-11-19, would amend Art. 5(1)(b), add a new Art. 33a single-entry-point breach notification, and add Art. 88a — it remains under Council/Parliament negotiation and is not enacted law at this check. - 2027-01-01 — [Colorado AI Act](https://controlframe.ai/frameworks/colorado-ai-act): Colorado AI Act: SB 26-189 (signed 2026-05-14) repeals and reenacts SB 24-205 rather than amending it: the risk management programme, the annual impact assessment, and the duty of reasonable care against algorithmic discrimination are all gone, replaced by notice and disclosure duties on automated decision-making technology. It takes effect 2027-01-01 and leaves implementation detail to AG rulemaking. Nothing is in force today. Do not describe Colorado as a high-risk-AI regime. - 2027-01-01 — [FedRAMP 20x](https://controlframe.ai/frameworks/fedramp-20x): FedRAMP 20x: CR26 took effect 2026-07-04 (optional) and becomes mandatory 2027-01-01. The Class A application pipeline opened 2026-08-03. Class B and C application pipelines opened 2026-08-31. Class D has not yet opened (targeted FY27 Q1-Q2). - 2027-01-01 — [TISAX](https://controlframe.ai/frameworks/tisax-isa-6): TISAX: ENX has published ISA2027, which becomes the basis for TISAX assessments ordered from 2027-01-01. Assessments ordered before then may remain on ISA 6, and March 2027 is the final date to open an initial ISA 6 assessment. - 2026-12-15 — [Sarbanes-Oxley ICFR](https://controlframe.ai/frameworks/sox-icfr): Sarbanes-Oxley ICFR: PCAOB and SEC-approved amendments to AS 2201 paragraph .09 and new paragraph .99 become effective on 2026-12-15. They affect the auditor standard, not the statutory text of SOX. - 2026-10-31 — [PCI Contactless Payments on COTS (CPoC)](https://controlframe.ai/frameworks/pci-cpoc-1-0): PCI Contactless Payments on COTS (CPoC): the coexistence window for PCI MPoC v1.1 (designated successor) (applying to New solutions and any CPoC solution being migrated ahead of the sunset) is scheduled to close. - 2026-10-31 — [PCI Contactless Payments on COTS (CPoC)](https://controlframe.ai/frameworks/pci-cpoc-1-0): PCI Contactless Payments on COTS (CPoC): PCI SSC announced the formal sunset period for CPoC from 2026-05-01 to 2026-10-31, the same window as SPoC. PCI MPoC v1.1 is the standard's designated successor. - 2026-10-31 — [PCI Mobile Payments on COTS (MPoC)](https://controlframe.ai/frameworks/pci-mpoc-1-1): PCI Mobile Payments on COTS (MPoC): MPoC is the designated successor absorbing PCI SPoC and CPoC, which are both in their formal sunset window (2026-05-01 to 2026-10-31). - 2026-10-31 — [PCI Software-based PIN Entry on COTS (SPoC)](https://controlframe.ai/frameworks/pci-spoc-1-1): PCI Software-based PIN Entry on COTS (SPoC): the coexistence window for PCI MPoC v1.1 (designated successor) (applying to New solutions and any SPoC solution being migrated ahead of the sunset) is scheduled to close. - 2026-10-31 — [PCI Software-based PIN Entry on COTS (SPoC)](https://controlframe.ai/frameworks/pci-spoc-1-1): PCI Software-based PIN Entry on COTS (SPoC): PCI SSC announced the formal sunset period for SPoC from 2026-05-01 to 2026-10-31. PCI MPoC v1.1 is the standard's designated successor for organizations moving off SPoC. - 2026-10-15 — [AIUC-1](https://controlframe.ai/frameworks/aiuc-1): AIUC-1: AIUC states that it updates the standard quarterly; the next scheduled release is 2026-10-15. - 2026-10-01 — [GAO FISCAM](https://controlframe.ai/frameworks/gao-fiscam-2026): GAO FISCAM: The June 2026 revision is already effective for fiscal-year and calendar-year 2026 federal financial statement audits; it becomes effective for attestation and performance-audit engagements beginning on or after 2026-10-01. - 2026-08-03 — [OWASP GenAI LLM Top 10](https://controlframe.ai/frameworks/owasp-genai-llm-top-10-2026): OWASP GenAI LLM Top 10 2026 supersedes 2025 and is the current edition. - 2026-07-27 — [ISO/IEC 27017](https://controlframe.ai/frameworks/iso-27017-2026): ISO/IEC 27017 2026 supersedes 2015 and is the current edition. ## Public Data Boundary Public demonstrations, generated samples, and the reference run theater use labeled synthetic data. Assessment-specific CMS EDE evidence, client workspaces, project records, and API routes require authenticated access and are excluded from crawling. No real customer, tenant, or assessment record is ever exposed on an anonymous page. ## Comparisons - [ControlFrame vs Vanta](https://controlframe.ai/compare/vanta) - [ControlFrame vs Drata](https://controlframe.ai/compare/drata) - [ControlFrame vs Secureframe](https://controlframe.ai/compare/secureframe) - [ControlFrame vs Sprinto](https://controlframe.ai/compare/sprinto) - [ControlFrame vs Hyperproof](https://controlframe.ai/compare/hyperproof) - [ControlFrame vs Optro, formerly AuditBoard](https://controlframe.ai/compare/auditboard) - [ControlFrame vs OneTrust](https://controlframe.ai/compare/onetrust) - [ControlFrame vs Thoropass](https://controlframe.ai/compare/thoropass) ## Insights (source-backed, dated, and reviewed) - [Define the FDE team before the first production change.](https://controlframe.ai/insights/forward-deployed-engineering-regulated-delivery) — Sam M. Sweilem: A responsibility model for forward-deployed engineers, product owners, operators, and reviewers implementing AI in regulated environments. - [Keep the thread from requirement to AI-assisted release.](https://controlframe.ai/insights/ai-sdlc-requirements-tests-release-traceability) — Sam M. Sweilem: A concrete traceability pattern for teams using coding agents: connect acceptance criteria, changes, tests, artifacts, and release decisions. - [Build audit evidence into the agent workflow.](https://controlframe.ai/insights/audit-evidence-agentic-workflows) — Sam M. Sweilem: A practical design for retaining sources, tool actions, exceptions, and human decisions while agents prepare assurance work. - [What a model may propose. What a named person must decide.](https://controlframe.ai/insights/what-a-model-may-propose-a-person-must-decide) — ControlFrame Research: The interesting question about AI in an audit was never whether a model is capable enough to help. It is which decisions an organization is willing to let a model make unsupervised, and which ones it will insist stay with a named, accountable person no matter how good the model gets. - [Train evidence review before automating it.](https://controlframe.ai/insights/train-evidence-review-before-ai-automation) — ControlFrame Research: Give operators, reviewers, and delivery teams a shared practice case before an AI-generated evidence narrative becomes part of their working routine. - [What "continuous compliance" has to mean mechanically, or it means nothing at all.](https://controlframe.ai/insights/what-continuous-compliance-has-to-mean) — ControlFrame Research: Almost every compliance vendor now claims "continuous compliance." Take away the marketing language and ask what has to be mechanically true for the phrase to mean something, and most of the claims stop being about compliance at all. - [Evidence reuse is an artifact-identity problem before it is a mapping problem.](https://controlframe.ai/insights/evidence-reuse-is-an-artifact-identity-problem) — ControlFrame Research: Every crosswalk table says a SOC 2 control and an ISO 27001 control can share one piece of evidence. Almost none of them say what has to be true about the artifact itself for that sharing to survive contact with a second auditor. - [Healthcare assurance is a stack, not a badge.](https://controlframe.ai/insights/healthcare-assurance-stack-2026) — ControlFrame Research: HIPAA law, HHS cybersecurity guidance, HICP practices, HITRUST assessment criteria, and CMS EDE program requirements overlap—but they do not mean the same thing. A mature platform reuses evidence while preserving each authority and decision. - [PCI evidence can be reused. PCI scope and assessor judgment cannot be assumed.](https://controlframe.ai/insights/pci-dss-4-0-1-reuse-without-shortcuts) — ControlFrame Research: PCI DSS v4.0.1 rewards continuously maintained proof, but cross-framework reuse only works when the artifact retains cardholder-data-environment scope, approach, period, test method, risk-analysis cadence, and reviewer decision. - [The EU AI Act is now an evidence calendar, not one compliance date.](https://controlframe.ai/insights/eu-ai-act-2026-evidence-calendar) — ControlFrame Research: The August 2026 milestone brings enforcement and transparency duties into the operating present while amended high-risk deadlines remain staged. Providers and deployers need article-level ownership, system classification, evidence, and dates—not one generic readiness percentage. - [AI can accelerate CSF analysis. It cannot erase the evidence boundary.](https://controlframe.ai/insights/nist-ai-csf-analysis-governed-evidence) — ControlFrame Research: NIST's draft SP 1353 makes AI-assisted Cybersecurity Framework analysis concrete. The enterprise opportunity is faster profile and reporting work; the assurance requirement is a versioned record of sources, prompts, evaluation, and human disposition. - [FedRAMP 20x shifts the advantage from documents to evidence.](https://controlframe.ai/insights/fedramp-class-a-buying-motion) — ControlFrame Research: Classes A, B, and C are finalized. The durable advantage is measurable, reusable security evidence—not a more polished point-in-time packet. - [One evidence graph. Distinct lines of accountability.](https://controlframe.ai/insights/one-evidence-graph-distinct-accountability) — ControlFrame Research: Operators prepare and maintain evidence. Assessors challenge and conclude. A shared, governed record can accelerate both sides of the engagement without collapsing their responsibilities. - [The evidence operating system connects control intent to auditor release.](https://controlframe.ai/insights/controlframe-audit-native-evidence-operating-system) — ControlFrame Research: ControlFrame connects source requirements, governed collection, artifact custody, reviewer decisions, and package release so regulated teams and assessors work from one defensible record. - [Agentic GRC earns trust through bounded action and verifiable evidence.](https://controlframe.ai/insights/agentic-grc-is-evidence-infrastructure) — ControlFrame Research: AI features are becoming common across GRC. Durable advantage comes from governed execution: clear authority, source-bound outputs, artifact custody, visible failure states, and human-controlled release. - [Continuous assurance requires evidence infrastructure, not annual collection.](https://controlframe.ai/insights/compliance-evidence-is-infrastructure) — ControlFrame Research: A mature compliance program does not rebuild its proof for every audit. It maintains source-backed evidence, control context, review history, and release lineage as an operating system. - [CMS EDE shows why compliance automation has to be exact.](https://controlframe.ai/insights/cms-ede-blueprint-evidence-automation) — ControlFrame Research: The lesson from Enhanced Direct Enrollment extends beyond healthcare: automation only creates assurance when it preserves native identifiers, prescribed evidence, access boundaries, exceptions, and reviewer authority. ## Product scope ControlFrame competes in agentic GRC, compliance automation, audit evidence automation, and regulated evidence infrastructure. Its wedge is not generic compliance tracking. It focuses on governed evidence execution: declared plans, private-runner architecture, source-linked artifacts, integrity records, redaction and sufficiency review, human authority gates, and independently inspectable packages. ## Crawl Notes - Public marketing, comparison, framework, CMS EDE, method, and insight pages are intended for indexing. - Client-specific CMS EDE command centers, assessment data, artifacts, static evidence files, internal app consoles, project workspaces, API routes, runner pages, and testing workbenches are intentionally excluded from search indexing. - The canonical sitemap is https://controlframe.ai/sitemap.xml.