Subtitle Icon
Framework Mapping

What "mapped to eight frameworks" actually means.

Every SARTUS™ finding is recorded once, in one risk register, against one control taxonomy: NIST SP 800-53 Rev 5, benchmarked to the CIS Benchmarks for Microsoft 365 and Azure. Six technical overlays are applied where the regulatory footprint requires. Four attestation frameworks are crosswalked so an assessor can use the evidence. The register is not a compliance certificate. This page shows the mapping so a CFO, GC, underwriter, or diligence reviewer does not have to take the claim on faith.

Fintech Solution Meta Icon
NIST SP 800-53 Rev 5 Primary
Fintech Solution Meta Icon
CIS Benchmarks · M365 & Azure
Fintech Solution Meta Icon
Six Overlays · Four Attestation Crosswalks
Fintech Hero Icon
1
Register, One Row Per Finding
Fintech Hero Icon
4
Attestation Frameworks Crosswalked
Fintech Hero Icon
8
Baseline and Overlay Frameworks Mapped

As cited in

KrebsOnSecurity · Reuters · ZDNet · CRN · Security Boulevard

One register. Two tiers.

Eight frameworks the register is built on. Four it is crosswalked to.

A control catalog and an attestation are different things. The first tells an engineer what to configure. The second tells a buyer that someone independent checked. SARTUS™ findings carry control IDs from the first tier. They are translated into the language of the second tier so an assessor can use them, and no further.

Tier one: baselines and overlays

Technical control catalogs. Every finding in the register carries an identifier from the two baselines. Overlays are applied where the client’s regulatory footprint requires.

FrameworkVersion mappedRoleWhat it governsWhere the register lands
NIST SP 800-53Rev 5BaselineThe federal control catalog: twenty families, over a thousand controls, adopted voluntarily across regulated mid-marketPrimary taxonomy. Every finding carries a control family and control ID.
CIS BenchmarksM365 Foundations v3.x, Azure Foundations v2.xBaselineConfiguration hardening for Microsoft 365 and Azure, the baseline cyber insurers and PE technical reviewers ask about firstEvery configuration finding carries a Benchmark recommendation number.
NIST SP 800-171Rev 2Overlay110 requirements for protecting Controlled Unclassified Information in nonfederal systems800-53 to 800-171 crosswalk for defense contractors and their acquirers.
CMMC2.0OverlayThe DoD assessment program built on 800-171; Level 2 assessed by a C3PAOPractices in scope flagged. The identity, cloud, and compromise findings that most often stall a Level 2 assessment.
PCI DSS4.0OverlayTwelve requirements on a scoped cardholder data environmentRequirements 7, 8, 10, and 12 where Microsoft 365 or Azure touch the CDE.
CISA SCuBASecure Cloud Business Applications, M365 baselinesOverlayFederal secure-configuration baselines for Entra ID, Exchange, SharePoint, Teams, and DefenderPolicy-level crosswalk by SCuBA baseline ID. The closest thing to a federal answer key for a Microsoft tenant.
MCSBMicrosoft Cloud Security Benchmark v1OverlayMicrosoft’s own control framework for Azure and Microsoft 365Azure findings carry the MCSB control ID, so the register reads against the same taxonomy Defender for Cloud reports in.
NSA hardening guidanceCurrent cybersecurity information sheetsOverlayIdentity, cloud, and network hardening guidance published by the National Security AgencyApplied where a finding matches published guidance, cited by document.

Tier two: attestation and governance crosswalks

Frameworks that produce an opinion, a certificate, or a governance profile rather than a control list. The register translates findings into their language. It does not, and cannot, issue the result.

FrameworkVersionWho asks for itWhat it certifiesWhat it does not askWhat the register provides
SOC 22017 TSC, 2022 points of focusEnterprise customers, PE diligence, vendor risk teamsControls as designed and tested on sample dates, opined by a CPA firmWhether an attacker was in the tenant between samplesCC6 and CC7 crosswalk. Evidence for the auditor. Not the opinion.
ISO/IEC 270012022International enterprise customersAn Information Security Management System exists and operates, certified by an accredited bodyWhether the environment the ISMS governs is defensibleAnnex A themes 5 and 8 crosswalk. Evidence for the certification audit. Not the certificate.
HIPAA Security Rule45 CFR 164.308 to 164.312Covered entities, business associates, healthcare acquirersAdministrative, physical, and technical safeguards; a documented risk analysisWhether the risk analysis found the breach already underwayTechnical safeguards 164.312(a), (b), (d), (e) crosswalk. The register serves as the technical risk analysis artifact. Administrative and physical safeguards are marked out of scope.
NIST CSF2.0Boards, SEC registrants, PE portfolio reportingSix functions; a profile of intended postureCurrent state, measuredGovern, Identify, Protect, and Detect crosswalk at the category level. A measured current-state profile a board can compare to the target profile.

Crosswalks are conservative. Where a requirement is only partially satisfied by a control the register measures, the crosswalk says partial. Over-mapping is how compliant organizations end up in the Breach Library.

How the register is built

One finding, one row, one control ID.

Recorded once

A finding is written once. The row carries the observed condition, the affected asset or identity, the NIST SP 800-53 control family and control ID, the CIS Benchmark recommendation where applicable, the crosswalk to the other six frameworks, and a severity rating.

Closure status is the column assessors read first

Most third-party assessment findings remain open beyond ninety days without a closure engagement. The register separates closed inside SARTUS™, closed with a documented path and separate quote, and accepted by leadership. That is the difference between a finding and an attestation gap.

Dated and defensible

Every row carries the date it was observed and the date it was closed. A QSA, C3PAO, SOC 2 auditor, or diligence reviewer can trace each control claim to evidence without a follow-up request.

What the register is not

Mapped is not the same as compliant.

  • It is not a certification. No document Cloudskope produces satisfies a PCI Report on Compliance, a C3PAO assessment, a SOC 2 opinion, or an ISO certificate. Those remain the work of independent assessors, and independence rules prevent the assessor from fixing what they find. SARTUS™ is the engagement that fixes it first.
  • It is not continuous monitoring. It is a six-day measurement and a six-day remediation, dated. Organizations that need the state held between assessments pair it with continuous controls monitoring. The register is the baseline that program starts from.
  • It is not a substitute for reading the frameworks. The explainers below are written for the CFO, GC, and board member who has to sign the attestation.

Read the frameworks

Plain-English explainers for the people who sign the attestation.

Questions assessors and buyers ask

Frequently asked questions.

Is the SARTUS™ risk register accepted by auditors?

Assessors accept evidence, not registers. Each row is structured as evidence: control ID, observed state, remediation record, date. QSAs, C3PAOs, and SOC 2 auditors have used Cloudskope registers as the starting point for scoping and evidence requests. The register does not replace their opinion.

Which framework is the primary mapping?

NIST SP 800-53 Rev 5, benchmarked to the CIS Benchmarks for Microsoft 365 and Azure. Six technical overlays (NIST SP 800-171, CMMC, PCI DSS, CISA SCuBA, MCSB, and NSA hardening guidance) are applied where the regulatory footprint requires. SOC 2, ISO 27001, HIPAA, and NIST CSF are crosswalked from 800-53 as attestation and governance frameworks.

Does SARTUS™ cover all of PCI DSS or all of CMMC?

No. SARTUS™ measures the Microsoft 365, Azure, endpoint, and identity surface plus dark web and active-compromise exposure. Where those surfaces are in scope for PCI DSS or CMMC, the register crosswalks the requirements. Physical controls, policy documentation, and out-of-scope systems are not measured.

Can the register serve as the HIPAA Security Rule risk analysis?

For the technical safeguards on the measured surface, yes, and it is dated and signed. Administrative and physical safeguards are documented as out of scope so the gap is visible rather than implied.

How is "eight frameworks mapped" different from "eight frameworks compliant"?

Mapped means each finding is expressed in the language of each framework. Compliant is a determination only an independent assessor can make. Cloudskope does not claim the second.

No risk to start. If we don’t find it, the engagement is free.

Book a Strategy Session

Assessment. Closure. Evidence. In six days.

If your organization has never formally answered where are we exposed, are we already compromised, and who is going to fix it — SARTUS™ answers all three in one engagement, in one week, at one fixed fee.

Limited CapacityOnly 3 SARTUS™ engagements per week

Contact us for current availability