CyberSpec

Compliance mappingLIVE

Every open finding mapped to the SOC 2, ISO 27001, and PCI DSS control families it touches — automatically.

Compliance audits ask the same question over and over: which controls does this finding actually touch? CyberSpec answers it automatically by mapping each open finding's underlying weakness class to the control families it affects across SOC 2, ISO 27001, and PCI DSS — so the compliance view stays current with your real security posture instead of a point-in-time spreadsheet someone filled out during the last audit prep cycle.

  • Coverage view across SOC 2, ISO 27001, and PCI DSS control families
  • Driven directly by your current open findings — no separate manual mapping step
  • Free tier: not included. Pro and Enterprise: full coverage view

The mapping is derived, not maintained

The usual approach is a spreadsheet: someone reads each finding, decides which control it affects, and types it into a cell. It is accurate the day it is written and stale the week after. CyberSpec derives the mapping from the weakness class behind each finding, so the coverage view is a live projection of your current open findings. Fix something and the control it was affecting stops being flagged, without anyone updating a row.

What this is not: evidence collection

Control mapping tells you which controls your current exposure touches. It does not collect evidence, run auditor workflows, or capture control attestation sign-off — those are on the roadmap and are deliberately not marketed as shipped. If you need a full audit-management platform today, this is one input to it, not a replacement for it.

Start free scan

Explore the rest of CyberSpec