How many compliance frameworks does the platform actually support?

The Compliance Management Platform™ maintains one control library mapped across 35 frameworks, including ISO 27001, SOC 2, GDPR, HIPAA, DPDP and PCI DSS. Instead of separate spreadsheets per framework, controls are entered once and cross-mapped, so evidence gathered for one framework can also satisfy overlapping requirements in another.

What exactly is a framework crosswalk?

A framework crosswalk maps a single control, such as an access-control policy, to its equivalent requirement across multiple standards like ISO 27001, SOC 2, NIST, HIPAA and GDPR. Instead of proving the same control separately for each audit, you record it once and the platform shows where it also applies elsewhere.

Can one piece of evidence satisfy more than one framework?

Yes. Because controls are shared and cross-mapped automatically, a single piece of evidence, such as a firewall configuration export or an access-control policy, can be linked to its matching control under ISO 27001, SOC 2 or any other framework you have active, rather than being collected and uploaded separately for each.

Does the platform collect audit evidence automatically or manually?

It collects automatically. The platform continuously pulls evidence from systems you already run, such as AWS, GitHub and Google Workspace, along with your operating systems, and matches each item to the right control. Recent examples include a firewall configuration export auto-collected against an ISO 27001 control, cutting manual exports and spreadsheet chasing before an audit.

Where do we track our Statement of Applicability?

The Statement of Applicability sits inside the Risk & Compliance section of the platform alongside the risk register and threat register. Since it draws on the same shared control library used across frameworks, applicability decisions recorded there stay linked to the underlying controls rather than living in a separate offline document.

How does the platform track ISO 27001 controls day to day?

Each ISO 27001 control, for example A.5.1 information security policies or A.8.12 data leakage prevention, is listed with an assigned owner and a live status such as compliant or in review. Evidence tied to that control, like an access-control policy upload, appears alongside it so you can see readiness without pulling a separate report.

Is SOC 2 readiness tracked the same way as ISO 27001?

Yes, SOC 2 controls such as CC6.1 logical access controls sit in the same control library and dashboard as ISO 27001 controls, each with an owner and status. Because controls are cross-mapped, work done to satisfy an overlapping ISO 27001 requirement can also move the matching SOC 2 control forward.

Why does GDPR Article 32 show up as a tracked control?

GDPR Article 32 covers security of processing, and the platform tracks it as an individual control with an assigned owner and a live status, the same way it tracks ISO 27001 or SOC 2 controls. That lets you see whether your processing safeguards are compliant or need action without checking GDPR separately from your other frameworks.

Do we need a separate tool for DPDP Act compliance?

No, DPDP is one of the frameworks already tracked on the compliance dashboard, and the platform supports running a DPDP gap assessment inside the same workspace used for ISO 27001, SOC 2 and other frameworks. Progress on that assessment shows up in the same activity feed as your other compliance work, so a separate tool is not needed.

How is HIPAA access control monitored in the platform?

HIPAA's access control requirement, referenced as section 164.312, is tracked as an individual control with an assigned owner and a current status such as compliant. It sits in the same shared control library as your other frameworks, so evidence supporting HIPAA access control can also be checked against overlapping ISO 27001 or SOC 2 controls.

Is PCI DSS one of the frameworks we can manage?

Yes, PCI DSS appears alongside ISO 27001, SOC 2, GDPR, HIPAA and DPDP in the platform's audit readiness view. It draws on the same shared control library and evidence locker, so evidence already collected for another framework can be checked against overlapping PCI DSS requirements instead of being gathered again.

Why keep the risk register alongside compliance controls?

Keeping the risk register in the same platform as your controls means a risk can be linked to the control it affects and tracked through to mitigation from a single source of truth. Risk assessments, remediation plans and control status stay in one place instead of a risk spreadsheet that has to be reconciled against a separate compliance tracker by hand.

Can we manage vendor and third-party risk here too?

Yes, the platform includes a dedicated third-party section for vendor reviews, alongside the risk and compliance registers. Vendor assessments and remediation plans run through the same workflow structure as internal controls, so third-party risk is visible next to your own control status rather than tracked in a separate tool.

Where do compliance policies and documents live in the system?

Policies live in a dedicated Policy Library under Documents & Records, alongside version-tracked documents such as an access-control policy. The platform also tracks policy acknowledgments, so you can confirm staff have read and accepted a policy rather than assuming it based on the document simply being published.

What happens when we log a security incident in the platform?

The incident is recorded in the Incidents & Response section, where it sits alongside response playbooks that document the steps your team follows. Because this lives in the same system as your controls and evidence, an incident and any related remediation stay visible next to the framework requirements they affect, rather than in a separate runbook.

What does continuous control monitoring mean in this platform?

Continuous control monitoring, shown as CCM in the Audit & Assurance section, checks controls on an ongoing basis rather than only when an audit is scheduled. Combined with automated evidence collection, this is meant to keep a control's status current between formal audit tests, not just accurate on the day an assessor asks.

How do we run corrective actions after a failed control test?

Failed or weak control tests feed into CAPA, the corrective and preventive action workflow under Audit & Assurance. It sits next to control tests and reviews in the same section, so a control that needs remediation can be tracked from the original test result through to its resolution in one place.

Can business continuity plans be tied to our compliance controls?

Yes, BCP Plans sit in their own Business Continuity section, and supporting evidence such as tabletop exercise minutes can be uploaded and linked back to the relevant controls. In the platform's example activity feed, tabletop minutes are logged as evidence still needing sign-off before they count toward readiness.

Does the platform cover governance for AI systems we use?

Yes, an AI Management section lets you register AI Systems and track governance activity for them alongside your other frameworks. This keeps AI-related risk and control work in the same control library and evidence locker as ISO 27001, SOC 2 or DPDP work, instead of managing it in a separate spreadsheet.

What do assessors actually see when we run an audit?

Assessors are given clean, controlled access to current evidence and an executive readiness report rather than a raw export of every file. Because evidence is already matched to the relevant control, for example a penetration-test report approved for a specific framework, an assessor can review status without you assembling a fresh evidence package.

Does Bitkosh's platform map controls to the NIST framework?

Yes. Compliance Management Platform™ maps common controls across ISO 27001, SOC 2, NIST, HIPAA, GDPR and other leading frameworks through its crosswalk, so a control you already meet under one framework is automatically checked against NIST requirements too, instead of being assessed as a separate, disconnected project.

Can the platform track our company's IT asset inventory?

Yes. Compliance Asset Management includes an Assets Inventory module alongside Endpoint Protection, so hardware and software assets are recorded in the same system as your controls, risks and evidence rather than in a separate spreadsheet that has to be reconciled manually before every audit.

Does endpoint protection status count as compliance evidence?

Endpoint Protection sits inside the platform's Compliance Asset Management section next to the Assets Inventory, so device protection status is recorded alongside the assets it covers. That keeps endpoint security data in the same system as your controls and evidence locker instead of a separate security console you have to check independently.

How do we track employee sign-off on security policies?

Policy acknowledgments are tracked as their own item, separate from the Policy Library where the documents themselves live. This lets you confirm which staff have actually read and accepted a policy version, rather than just knowing the policy exists, which auditors typically ask for as evidence during a review.

Can we get a compliance summary for the board, not just auditors?

Yes. Alongside audit-ready reporting for assessors, the platform has a dedicated Board Report view and executive readiness reports. These are built for leadership to see program status at a glance, separate from the detailed, control-level evidence packages prepared for external auditors and assessors.

Do we still need to write our own incident response playbooks?

The platform gives you a place to build and store them. Response Playbooks sit alongside Incidents under Incidents & Response, so when you log an incident you can attach the relevant playbook and response steps directly to it, rather than keeping the playbook in a separate document outside the system.

What if we haven't connected all our cloud accounts yet?

The dashboard shows integration status openly, for example marking how many of your connected sources, like AWS, GitHub, Google Workspace and your operating systems, are actually linked. An unconnected source simply means evidence from that system won't auto-populate yet; it doesn't block the rest of the platform from working.

Do we get help implementing our framework mappings?

Yes, the platform includes implementation guidance from product engineers as part of getting started. Rather than leaving you to interpret how a framework's controls map onto the shared control library on your own, engineers are involved in setting up those mappings for your specific environment and control ownership.

Can the platform be deployed to fit our own IT setup?

Deployment is designed around your operating model rather than one fixed setup, and access runs on a secure, controlled architecture. That means how controls, evidence and integrations are configured can be adapted to how your organization already runs its systems, instead of forcing everyone into the same rigid structure.

What does 'zero-trust architecture' mean for our compliance data?

It means access to controls, evidence and reports inside the platform is verified every time rather than granted by default just because a user is already on the network. Combined with controlled access for assessors, this keeps sensitive compliance data, like uploaded evidence and risk details, restricted to people who need it.

If we add a new framework later, do we redo all our controls?

No. The platform is built around one shared control library that's cross-mapped automatically across frameworks. Adding a new framework mostly means matching it against controls you likely already have in place, rather than rebuilding a separate control set and evidence trail for that framework from scratch.

Does the platform include vulnerability management?

Yes. Vulnerability Mgmt and a Vulnerabilities register sit under Access & Security alongside Access Control, so identified vulnerabilities are tracked in the same workspace as the access and security controls they relate to, instead of living in a separate scanning tool disconnected from the rest of your compliance program.

How is security awareness training for staff tracked?

HR Security Training is tracked as its own item under Audit & Assurance, alongside Audits, CAPA and Control Tests. That keeps training records in the same place as the audit evidence and corrective actions they support, so you can show an assessor that staff training is current without pulling records from HR separately.

Can evidence be pulled automatically from AWS or GitHub?

Yes, the platform connects to systems like AWS, GitHub, Google Workspace and your operating systems, and pulls evidence from them directly, matching it to the relevant controls. A firewall configuration export, for example, can be auto-collected against a control like A.13.1 instead of someone exporting and uploading it by hand.

Does the platform show one overall compliance score?

The dashboard displays a compliance score that reflects the current state of your controls across frameworks, alongside the count of open risks. It's meant as a single, quick indicator of program health for internal teams and leadership, sitting above the framework-level and control-level detail you can still drill into.

Can we see audit readiness broken down by individual framework?

Yes, the dashboard includes an audit readiness view broken out by framework, covering ones like ISO 27001, SOC 2, GDPR, HIPAA, DPDP and PCI DSS. This lets you see which specific framework needs attention rather than only having a single blended score across everything you're tracking.

Is this platform built for large organizations or smaller teams too?

The platform is enterprise ready and built to scale, with expert support available alongside it. The same shared control library and workflows apply whether you're running a small compliance program or a larger one spanning multiple frameworks, so the underlying structure doesn't change as your program grows.

Can we see a live feed of recent compliance activity?

Yes, the dashboard includes a recent activity feed showing actions as they happen, such as a control's evidence being approved, a risk being marked mitigated, or a gap assessment starting. This gives the team visibility into what's moving across the compliance program without having to check each module individually.

Does uploaded evidence count immediately or does it need review?

It depends on the source. Evidence pulled automatically from a connected system, like a firewall config export, is marked auto-collected, while evidence someone uploads, like a policy document, goes into an in-review or needs-sign-off state until it's approved. Only approved evidence is treated as current for a control.

Why does the dashboard show 35 frameworks live when the platform lists 36 plus?

The "frameworks live" figure on the dashboard counts only the frameworks your organization has actually turned on and is actively tracking controls against, while the 36 plus figure describes the full library of frameworks the platform is built to map controls to. An account that hasn't activated every available framework will naturally show a lower live count than the platform's total supported list. Turning on more frameworks raises that number.

What does the open risks number on the compliance dashboard track?

It's a running count of risks in your risk register that are still unresolved, shown next to a percentage change like the minus 4 percent in the example dashboard so you can see whether the backlog is shrinking since the last period. The number updates as risks are logged, escalated or marked mitigated, giving a quick read on risk exposure without opening the full risk register.

Can we book a live demo of the compliance platform before buying?

Yes, the product pages include a request for a private demo and a dedicated booking flow where you pick a time to see the Compliance Management Platform™ in action. It's set up so you can walk through the dashboard, control library, evidence locker and reporting views with Bitkosh before committing, rather than deciding based on the marketing pages alone.

Does every control in the library get assigned to a specific owner?

Yes, each control listed in the platform's control table carries a named owner alongside its framework and current status. Whether it's an ISO 27001 policy control or a SOC 2 access control, an individual is shown as responsible for it rather than leaving it assigned to a team in general, which makes it clear who to follow up with when a control needs attention or updated evidence.

What do control status labels like action needed actually mean?

Each control shown in the platform carries one of a few statuses: Compliant, In review, or Action needed. Compliant means the control is currently satisfied with accepted evidence, In review means evidence has been submitted but not yet confirmed, and Action needed flags a control, such as a data-processing control under GDPR, that still requires work before it can be marked compliant.

What do the different evidence locker status tags mean?

Evidence in the locker carries its own status separate from control status. In review means it has been submitted but not yet checked, Approved means it has been accepted as valid support for a control, Auto-collected means the system pulled it in directly from a connected system such as a firewall configuration, and Needs sign-off means a person still has to formally approve it, as with a business continuity exercise report, before it counts as complete.

Why does the compliance score show a plus or minus percentage next to it?

That percentage shows how the overall score has moved since the last period, for example a plus 3 percent gain shown in the dashboard, so you can tell at a glance whether your program is improving or slipping rather than only seeing where it stands today. It's a trend indicator sitting alongside the current score, not a separate score of its own.

Which frameworks appear on the readiness-by-framework chart in the dashboard?

In the platform's dashboard example, the readiness-by-framework chart lists ISO 27001, SOC 2, GDPR, HIPAA, DPDP and PCI DSS together, each with its own readiness view rather than one blended figure. That lets you see at a glance which specific framework is lagging, such as one flagged for action needed, instead of only knowing your overall compliance score.

What does SOC 2 control CC6.1 cover in the platform?

CC6.1 is the SOC 2 control for logical access controls, and in the platform's control table it appears with its own owner and status, shown as Compliant in the example dashboard. It sits in the same control table as ISO 27001 and HIPAA controls, so you can see a specific SOC 2 requirement tracked individually rather than treating SOC 2 as one broad checkbox.

Who gets credited when evidence is uploaded to the locker?

Each entry in the evidence locker records who submitted it and when, for example a policy document shown as uploaded by a named team member a set number of minutes ago, or a report credited to an external auditor an hour ago. That means you can trace any piece of evidence back to its source and timing, not just see that it exists.

How are risk remediation plans different from CAPA corrective actions?

A risk remediation plan is a corrective step tied to a specific risk sitting in your risk register, tracked as part of the platform's risk and vendor workflows. CAPA, by contrast, is created specifically after a control test fails, documenting the action needed to bring that control back into compliance. Both close a gap, but one starts from a risk assessment and the other from a failed control test.

Does each risk get its own tracking ID number?

Yes, risks in the register are given their own reference ID, such as RSK-114 shown in the platform's recent activity feed. That lets you follow one specific risk from when it's first logged through to when it's marked mitigated, rather than tracking risks only by description, which matters once your register has more than a handful of open items.

What is a gap assessment and when does the platform start one?

A gap assessment is a review the platform logs as its own activity, for example a DPDP gap assessment shown starting in the recent activity feed. It compares your current controls against a framework's requirements so you can see where you fall short before that framework is marked ready. It's tracked as a distinct event, separate from routine evidence approvals or risk updates.

How do we know which version of a policy document is current?

Uploaded documents carry a version number, for example an access-control policy shown as v3.2 in the evidence locker. That lets you tell which revision was reviewed and approved and flags when a newer version needs to replace an older one, rather than leaving version control to file names or email threads outside the platform.

What does 24/7 readiness visibility mean if nobody checks the dashboard overnight?

It means the data behind the dashboard, evidence and control status, is kept current continuously as it's pulled in from connected systems, rather than only refreshing on a schedule before an audit. You don't need to be watching for that to happen; whenever you do log in, the readiness view reflects the current state instead of a stale snapshot from your last manual check.

Is it worth switching off our compliance spreadsheets once we're on this platform?

The platform is built specifically to replace that kind of tracking: evidence is pulled continuously from the systems you already run and matched to the right controls automatically, so you're not doing manual exports or chasing spreadsheets together before an audit. Continuous monitoring and reusable control mappings are meant to give your team and leadership one program to look at instead of scattered files.

What does ISO 27001 control A.5.1 cover in the platform's control library?

A.5.1 covers information security policies, and in the platform's control table it appears with its own owner and status, shown as Compliant in the example dashboard. It sits alongside other ISO 27001 controls, such as A.8.12 for data leakage prevention, each individually owned and tracked so ISO 27001 is broken into specific requirements rather than treated as a single checkbox.

Is this platform meant only for security teams or broader compliance too?

It's built broader than just a security team tool. Alongside access control and vulnerability management, it covers HR security training, business continuity plans, vendor and third-party risk, and AI systems governance, all inside the same workspace. That spread means compliance, risk and operational teams can work from the same control library and evidence locker rather than security owning it alone.

Can an external auditor add evidence directly into our evidence locker?

Yes, the example evidence locker shows an entry contributed by an external auditor, a penetration-test report marked Approved, sitting alongside items uploaded by internal team members. That means audit-related evidence can come from outside parties as well as your own staff, tracked in the same locker with the same status and timestamp fields as everything else.

What counts as an evidence source besides AWS and GitHub?

The platform also lists Google Workspace and your operating systems as connected evidence sources, not just cloud platform APIs like AWS and GitHub. That means evidence can come from the servers and machines you run directly, in addition to cloud accounts, feeding into the same control library rather than requiring a separate process for infrastructure-level evidence.

Is data leakage prevention tracked as its own ISO 27001 control?

Yes. Data leakage prevention is tracked as control A.8.12 under ISO 27001, sitting in the same control table as A.5.1 and other information security controls. It carries a status such as compliant or in review and an assigned owner, and because the platform uses a shared control library, A.8.12 can also be cross-mapped into any other framework that shares the same underlying requirement.

Can a firewall configuration export count as automated evidence?

Yes. The evidence locker shows a firewall configuration export pulled in and mapped directly to ISO 27001 control A.13.1, tagged auto-collected instead of manually uploaded. It works the same way as evidence pulled from AWS, GitHub, Google Workspace and connected operating systems: the platform ingests the file and links it straight to the relevant control without anyone attaching it by hand.

Does marking a risk as mitigated update the dashboard automatically?

Yes. The change shows up in the platform's recent activity feed with a timestamp, so anyone checking the dashboard can see that a specific risk moved to mitigated without opening the risk register itself. Since the dashboard's open risks figure also changes over time, resolving risks this way is what moves that count down rather than someone updating a separate spreadsheet.

How do we know if evidence in the locker is outdated?

Every entry in the evidence locker carries a relative timestamp, such as minutes, hours or days since it was uploaded or auto-collected, shown next to its review status. This lets a compliance team see at a glance whether the evidence behind a control is current or getting stale, instead of only knowing whether it has been approved.

Are Reports and the Board Report two different things?

Yes. Reports and Board Report are listed as separate items under ISMS Metrics in the platform's navigation. Board Report is the executive-facing summary built for leadership, while Reports sits alongside it as a separate section in the same metrics group, giving compliance teams reporting output beyond just the board-level view.

Is there a general access control module separate from framework rules?

Yes. Access & Security includes a general Access Control item in the navigation, in addition to framework-specific requirements such as HIPAA's access control clause and SOC 2's logical access controls. This means the same underlying access policies can be managed once while still mapping into whichever framework actually requires them.

Who can see our compliance data once it's inside the platform?

Not everyone with a login sees everything by default. Secure architecture and controlled access is listed as one of the platform's core design principles, separate from its zero-trust label, meaning evidence, controls and risk data are restricted rather than open across the whole organization by default.

Does CCM Review happen separately from continuous monitoring itself?

Yes. CCM Review appears as its own item under Audit & Assurance, alongside Audits, CAPA and Control Tests, distinct from continuous control monitoring, which checks controls automatically in the background. Keeping review as a separate step means monitoring output has a dedicated place to be looked at within the same workspace, rather than being treated as finished the moment it's generated.

Do we run risk assessments here or just log risks?

Yes. Risk and vendor workflows in the platform include running assessments, not only recording risks once they've already happened. Assessments sit in the same workflow as remediation plans and third-party reviews, so a risk can be evaluated, tracked through mitigation and reviewed again for vendors from one place instead of switching between separate tools.

Is vendor and risk data kept apart from our compliance controls?

No. Risk registers, assessments, remediation plans and third-party vendor reviews are operated from the same single source of truth as compliance controls, rather than in a separate system. That means updates in one area, such as a remediation plan, stay connected to the same records used for framework compliance tracking, instead of living in a standalone spreadsheet.

Can the same employee own controls in two different frameworks?

Yes. Control ownership in the platform is assigned at the control level, not the framework level, so one owner can appear against a control in ISO 27001 and a separate control in HIPAA or SOC 2 at the same time. Each control still carries its own independent status, so one owner holding compliant controls across frameworks doesn't merge or simplify the underlying tracking.