SOC 2, ISO 27001 and PCI DSS — mapped automatically to what you actually find
CyberSpec keeps your control coverage view tied to your real, current findings — not a manual spreadsheet that goes stale the week after audit prep.
SOC 2
Trust Services Criteria coverage — CyberSpec maps open findings to the control families they touch (e.g. CC6.1 Logical Access) automatically, so your evidence stays current with your actual security posture, not a point-in-time snapshot.
ISO 27001
Annex A control mapping driven by the same underlying finding data — no separate manual tracking spreadsheet to keep in sync with what your scans actually find.
PCI DSS
Requirement-level coverage for the technical controls PCI DSS cares about most — network segmentation, vulnerability management, and access control findings surface directly against the relevant requirement.
Mapping, not evidence collection
Be clear on what this replaces. CyberSpec answers “which controls does our current exposure touch?” — continuously, from live scan data. It does not collect evidence artefacts, run auditor workflows, or capture control attestation sign-off. Those are on the roadmap and are not being marketed as shipped.
If you already run a compliance platform, this is a feed into it: the technical-control half of the picture, kept current between audits instead of reconstructed during them. If you don't, it is the half most teams fake with a spreadsheet, which is the half auditors probe hardest.
Which plan includes it
Compliance mapping is a Pro and Enterprise feature — the Free plan covers one asset with on-demand scanning and the findings table, without the coverage view. Pro is $20/month for up to 20 assets; Enterprise is priced per organisation and adds uncapped assets and SSO/SAML. Full pricing and billing FAQ.
Auditors also ask how the vendor secures its own accounts. That answer is here — mandatory TOTP MFA on every account and every sign-in method, backup codes, and per-device session control.