Skip to main content

Compliance Frameworks

BleedWatch maps your security findings to major compliance frameworks, giving you a real-time compliance score and control-by-control breakdown. Instead of manual audits and spreadsheets, your compliance posture updates automatically as findings are created and resolved.

Supported Frameworks

FrameworkScopeTypical Use Case
GDPREU data protectionOrganizations processing EU personal data
NIS2EU cybersecurity directiveEssential and important entities in the EU
ISO 27001Information security managementOrganizations seeking ISO certification
PCI DSS 4.0Payment card data securityMerchants and payment service providers
SOC 2Service organization controlsSaaS and cloud service providers
DORADigital operational resilienceFinancial entities in the EU
Jurisdiction Recommendations

BleedWatch automatically suggests relevant frameworks based on your organization's jurisdiction. EU-based organizations will see NIS2 and GDPR highlighted as mandatory frameworks.

Compliance Score

Each framework shows an overall compliance score from 0% to 100%, calculated from the status of individual controls:

Control StatusMeaningImpact on Score
PassAll findings for this control are resolved or no findings applyPositive
FailOpen findings exist that violate this controlNegative
Not ObservableBleedWatch doesn't have enough data to assess this controlNeutral (excluded from calculation)

The score formula: Pass / (Pass + Fail) × 100. Controls marked "Not Observable" are excluded — the score reflects only what BleedWatch can verify.

Score Trend

Premium Plan Required

The 90-day compliance score trend chart is available on Premium plans and above.

Track how your compliance posture evolves over time. The trend chart shows daily score snapshots for the past 90 days, helping you:

  • Demonstrate improvement to auditors and leadership
  • Detect regressions when new findings impact compliance
  • Correlate changes with specific remediation efforts

Control Breakdown

Below the score card, a table lists every control in the selected framework:

ColumnDescription
Control IDThe framework's control identifier (e.g., A.8.2 for ISO 27001)
Control NameHuman-readable control description
CategoryControl category or domain
StatusPass / Fail / Not Observable
FindingsNumber of open findings mapped to this control

Control Drilldown

Click any control row to open a detail panel showing:

  1. Control description — Full text of the compliance requirement
  2. Mapped findings — Every BleedWatch finding that affects this control, with severity and status
  3. Remediation guidance — Steps to bring this control into compliance
  4. Evidence — What BleedWatch observed to determine the control status

How Findings Map to Controls

BleedWatch uses a deterministic mapping engine that connects finding types to framework controls:

Finding TypeExample Framework Controls
Exposed secretsISO 27001 A.9.4, PCI DSS 8.3, SOC 2 CC6.1
Vulnerable dependenciesISO 27001 A.12.6, PCI DSS 6.3, NIS2 Art.21(2)(e)
SSL/TLS issuesPCI DSS 4.1, ISO 27001 A.10.1, DORA Art.9
Missing security headersPCI DSS 6.4, SOC 2 CC6.6
Exposed credentials (dark web)GDPR Art.33, NIS2 Art.23, ISO 27001 A.16.1
WAF bypass / Origin exposurePCI DSS 6.6, ISO 27001 A.13.1, NIS2 Art.21(2)(d)

Mappings are updated as BleedWatch adds new finding types.

Using Compliance for Audits

Generating Compliance Evidence

  1. Select the framework your auditor requires
  2. Review each control's status and associated findings
  3. Export the compliance report from Reports → Builder with the "Compliance" section enabled
  4. The report includes: framework name, date, overall score, control-by-control status, and remediation history

Preparing for Certification

For ISO 27001 or SOC 2 certification:

  1. Start with the compliance view to identify all failing controls
  2. Prioritize remediation of failed controls by category
  3. Track score improvement over 90 days (Premium plan)
  4. Generate the compliance report monthly to show auditors your trajectory
  5. Use the control drilldown to document evidence for each requirement

NIS2 Incident Reporting

If you're subject to NIS2, BleedWatch's compliance view helps you meet the 24-hour incident notification requirement by:

  • Mapping critical findings to NIS2 Article 23 (incident reporting)
  • Providing timestamps for when incidents were detected and resolved
  • Generating evidence packs with finding details and remediation steps

Troubleshooting

Score Shows 0%

A zero score means either no findings have been created yet, or all controls are marked "Not Observable." Ensure that:

  1. You have active assets configured
  2. At least one scan cycle has completed
  3. The selected framework matches your organization's activity

Controls Stuck on "Not Observable"

Some controls require specific finding types that BleedWatch may not have detected yet. For example, SSL/TLS controls require a domain scan — if you haven't added domains to your assets, these controls won't be assessable.

Score Dropped Suddenly

A sudden score drop usually means new findings were created that map to previously passing controls. Check Findings for recent critical or high-severity findings, and review the compliance drilldown to see which controls were affected.

  • Attack Surface — Visualize how findings connect across your exposure
  • Reports — Generate compliance evidence packs
  • Alerts — Get notified when compliance score drops below a threshold