Skip to main content

Compliance Framework Support

CaseBender includes native support for major compliance frameworks. Each framework implementation includes control mapping, automated evidence collection, gap analysis, and reporting — built directly into the platform, not bolted on.

Framework Matrix

FrameworkStandardImplementationEvidence CollectionReporting
SOC2 Type IIAICPA TSC 2017Trust Service Criteria mapping, control testing, attestation managementAutomated collectors, 3-year retentionAudit period reports, gap analysis
ISO 27001:2022ISO/IEC 27001:2022Full Annex A controls, Statement of Applicability, risk registerAutomated collectors, evidence reviewInternal audit reports, management review
GDPREU 2016/679Articles 5-88 coverage, DSAR management, consent lifecyclePII registry, processing activity recordsBreach notification, DPIA reports
CMMC Level 2NIST SP 800-171110 practices across 14 domains, SPRS scoringAutomated collectors, POA&M trackingAssessment reports, SPRS score history
FedRAMP ModerateNIST SP 800-53325 controls, continuous monitoring, SSP managementAutomated collectors, ConMon reportsAuthorization packages, SAR reports
HIPAA45 CFR 160-164Security Rule safeguards, breach notification, BAA managementPHI access logging, training recordsDisclosure reports, risk assessments
PCI DSS v4.0PCI SSC12 requirements, 78 sub-requirementsAutomated collectors, control testingAssessment reports, gap analysis
Export ControlEAR / ITARECCN classification, denied party screening, country controlsScreening logs, license trackingTransfer reports, compliance dashboards
EU AI ActEU 2024/1689AI system registration, risk assessment, conformityIncident reports, oversight recordsRisk assessments, transparency reports
Legal HoldFRCP / eDiscoveryLitigation preservation, custodian managementEvidence chain of custodyHold status reports, compliance verification

How Compliance Works in CaseBender

Control Mapping

Each framework’s controls are mapped to CaseBender features and configurations. You can see exactly which platform capabilities satisfy which compliance requirements.

Evidence Collection

Automated collectors gather evidence from the running platform — audit logs, configuration snapshots, access records — without manual effort.

Gap Analysis

Identify which controls are fully implemented, partially implemented, or not yet addressed. Prioritize remediation based on risk.

Audit Management

Track audit periods, schedule evidence collection, manage findings, and generate reports for auditors.

Unified Compliance Dashboard

CaseBender provides a unified view across all enabled compliance frameworks:

Cross-Framework Visibility

  • Compliance Score: Aggregate compliance percentage across all frameworks
  • Control Overlap: Many controls satisfy multiple frameworks simultaneously (e.g., audit logging satisfies SOC2 CC7.2, ISO 27001 A.8.15, CMMC AU.L2-3.3.1, and HIPAA 164.312(b))
  • Gap Prioritization: Gaps are ranked by how many frameworks they affect
  • Deadline Tracking: Upcoming audit deadlines, evidence collection schedules, and remediation due dates
  • Activity Feed: Recent compliance activities across all frameworks

Regulatory Reporting

  • Automated Report Generation: Generate framework-specific reports with collected evidence
  • Scheduled Reports: Configure recurring report generation for continuous compliance
  • Export Formats: PDF, CSV, and structured data exports for auditor consumption
  • Evidence Packages: Bundle evidence artifacts with control mappings for audit submissions

Control Testing

CaseBender includes a unified control testing module that works across all frameworks:

Testing Capabilities

  • Automated Tests: Configurable test procedures that run on schedule
  • Manual Tests: Guided test procedures with evidence capture
  • Cross-Framework Mapping: A single test can satisfy controls across multiple frameworks
  • Test Scheduling: Calendar-based scheduling with reminders and escalation
  • Result Tracking: Pass/fail/partial results with evidence attachment

Testing Workflow

  1. Schedule: Tests are scheduled based on framework requirements (quarterly, annually, etc.)
  2. Execute: Automated tests run automatically; manual tests notify the assigned tester
  3. Evidence: Test results and supporting evidence are captured automatically
  4. Review: Results are reviewed and approved by the compliance team
  5. Report: Test results feed into framework-specific compliance reports

Compliance Training

Track and manage compliance training requirements:
  • Training Programs: Define training requirements per framework and role
  • Assignment Management: Automatically assign training based on user role and team
  • Completion Tracking: Track completion rates, scores, and certification status
  • Compliance Matrix: View training compliance across users, teams, and frameworks
  • Campaign Management: Launch targeted training campaigns for new requirements

Detailed Framework Documentation