Kyūdō
Compliance Frameworks

Implement once. Satisfy many.

Your organization does not comply with one framework at a time. Neither should your GRC platform. Kyūdō maps controls once across 80+ frameworks simultaneously, using Compliance Graph reasoning, not spreadsheet duplication.

Foundation

Grounded in the Secure Controls Framework

The Secure Controls Framework (SCF) is a comprehensive meta-framework that maps 1,000+ controls across 100+ regulations and standards. Kyūdō uses SCF as its foundation, so you implement once and map to many.

Implement once

Define your controls once using SCF’s unified taxonomy. No duplicate work across frameworks.

Map to many

Automatically map your controls to SOC 2, ISO 27001, CMMC, HIPAA, and other frameworks simultaneously.

Stay current

SCF is continuously updated as regulations evolve. Your mappings stay accurate without manual intervention.

Supported Frameworks

Every framework your organization requires

Whether you're pursuing your first certification or managing multi-framework compliance, Kyūdō has you covered.

Popular

SOC 2

Type I & Type II

SOC 2 is an attestation framework in which an independent auditor reports on your security, availability, processing integrity, confidentiality, and privacy controls. Enterprise customers routinely request it from SaaS and cloud providers.

Kyūdō maps the Trust Services Criteria through the SCF crosswalk and collects supporting evidence continuously from Defender XDR, Sentinel, Purview, Entra ID, and Azure Policy, so the audit window opens with evidence already current.

Trust Service CriteriaSecurity, Availability, Confidentiality, Processing Integrity, Privacy
Common evidenceAccess reviews, change management records, monitoring configuration, incident logs, vendor assessments
Typical Timeline3–6 months (Type I), 6–12 months (Type II)
Best forB2B SaaS, cloud service providers, technology companies

Kyūdō outcomes

  • Automated evidence collection for 80%+ of controls
  • Pre-mapped Microsoft security configurations
  • Auditor-ready evidence packages
Global

ISO 27001

Information Security Management

ISO 27001 is the international standard for information security management systems (ISMS). It is commonly requested in European enterprise procurement and increasingly expected globally.

Kyūdō maps Annex A controls through the SCF crosswalk, so work done for SOC 2 or NIST CSF carries over, and keeps control status and linked evidence current between surveillance audits.

Control domains93 controls across 4 themes (2022 version)
Common evidenceStatement of Applicability, risk assessments, control operation records, internal audit results, management reviews
Typical Timeline6–12 months initial, annual surveillance
Best forGlobal enterprises, European market entry, defense supply chain

Kyūdō outcomes

  • Statement of Applicability (SoA) generation
  • Risk assessment workflows with ISO 27005 alignment
  • Continuous control monitoring
Foundation

NIST CSF v2.0

Cybersecurity Framework

The NIST Cybersecurity Framework is the US government’s voluntary, risk-based cybersecurity framework, now in version 2.0, and a common foundation for many other frameworks.

Kyūdō maps CSF functions to one control set through the SCF crosswalk and keeps the profile current with continuous evidence, so the same controls also serve SOC 2, ISO 27001, and CMMC.

Core FunctionsGovern, Identify, Protect, Detect, Respond, Recover
Common evidenceAsset inventories, detection and response configuration, access control settings, recovery test records
Implementation tiersPartial, Risk-Informed, Repeatable, Adaptive
Best forCritical infrastructure, government contractors, risk-based programs

Kyūdō outcomes

  • Current and target profile generation
  • Gap analysis with prioritized remediation
  • Maturity assessment across functions
Defense

CMMC 2.0

Cybersecurity Maturity Model Certification

CMMC is the US Department of Defense certification program for contractors handling Controlled Unclassified Information (CUI), built on NIST SP 800-171 with third-party assessment requirements. Phase 2 enforcement begins November 10, 2026.

Kyūdō maps CMMC practices through the SCF crosswalk and collects supporting evidence continuously inside your own tenant. Kyūdō prepares readiness; certification is granted by an authorized assessor.

LevelsLevel 1 (Foundational), Level 2 (Advanced), Level 3 (Expert)
Common evidenceSystem Security Plan, POA&M, CUI boundary documentation, access and audit log configuration
Controls17 practices (L1), 110 practices (L2), 110+ (L3)
Best forDoD contractors, defense supply chain, CUI handlers

Kyūdō outcomes

  • NIST 800-171 SSP and POA&M generation
  • CUI boundary documentation
  • Customer-hosted deployment meets Level 2+ requirements
Healthcare

HIPAA

Health Insurance Portability and Accountability Act

HIPAA is the US healthcare privacy and security regulation for covered entities and business associates handling Protected Health Information (PHI).

Kyūdō maps the Security Rule safeguards through the SCF crosswalk and draws continuous evidence from Purview, Entra ID, and Defender signals, so PHI-handling controls carry live proof rather than annual attestations.

RulesPrivacy Rule, Security Rule, Breach Notification Rule
SafeguardsAdministrative, Physical, Technical
Common evidenceRisk analyses, access control and encryption settings, workforce training records, BAA inventory
Best forHealthcare providers, health tech, business associates

Kyūdō outcomes

  • Security Rule compliance mapping
  • Risk analysis documentation
  • BAA tracking and management
Payments

PCI DSS v4.0

Payment Card Industry Data Security Standard

PCI DSS is the payment card industry's security standard for organizations that store, process, or transmit cardholder data. Version 4.0 introduces customized controls and enhanced authentication requirements.

Kyūdō maps PCI DSS requirements through the SCF crosswalk and keeps scan results, configuration evidence, and compensating control documentation continuously current between validation cycles.

Requirements12 principal requirements, 250+ sub-requirements
Common evidenceNetwork segmentation documentation, quarterly scan results, encryption and key management settings, access logs
ValidationSAQ, ROC, or QSA assessment based on volume
Best forE-commerce, payment processors, financial services

Kyūdō outcomes

  • Cardholder data environment (CDE) scoping
  • Compensating control documentation
  • Quarterly scan and assessment tracking
Privacy

GDPR

General Data Protection Regulation

GDPR is the European Union’s comprehensive data protection regulation. It applies to any organization processing EU resident data, regardless of location.

Kyūdō maps GDPR obligations through the SCF crosswalk and evidences data-handling controls continuously from Purview and Entra ID signals. Because the platform runs inside your own tenant, compliance data itself stays under your residency control.

PrinciplesLawfulness, Purpose limitation, Data minimization, Accuracy, Storage limitation, Security
RightsAccess, Rectification, Erasure, Portability, Objection
Common evidenceRecords of processing activities, data subject request logs, DPAs, transfer impact assessments
Best forAny organization with EU customers or employees

Kyūdō outcomes

  • Records of processing activities (RoPA)
  • Data subject request tracking
  • DPA and transfer impact assessments
AI

NIST AI RMF

AI Risk Management Framework

NIST's voluntary framework for identifying, measuring, and managing risk across the lifecycle of AI systems, organized around four functions: Govern, Map, Measure, Manage.

Kyūdō includes the NIST AI RMF in its 156 unified AI governance controls, so evidence collected once also serves ISO 42001 and the EU AI Act.

Core FunctionsGovern, Map, Measure, Manage
Common evidenceAI system inventory, risk classifications, oversight records, evaluation results
Best forOrganizations formalizing AI risk management on a US framework

Kyūdō outcomes

  • AI systems inventoried as Compliance Graph entities
  • One control set shared with ISO 42001 and the EU AI Act
  • Oversight evidence with hash, lineage, and confidence
AI

ISO 42001

AI Management Systems

The international standard for AI management systems (AIMS): how an organization establishes and maintains governance over the AI it develops or deploys.

Kyūdō maps ISO 42001 into the same 156 AI governance controls as the EU AI Act and NIST AI RMF, and keeps AIMS evidence continuously current inside your tenant. Certification is assessed by an accredited body.

StructureManagement-system clauses plus Annex A AI controls
Common evidenceAIMS documentation, AI impact assessments, human oversight records, supplier AI disclosures
Best forOrganizations seeking certifiable AI governance

Kyūdō outcomes

  • AIMS evidence collected continuously, not assembled per audit
  • Shared control set across all three AI frameworks
  • Vendor AI disclosures tracked in the Compliance Graph
AI

EU AI Act

European Union AI Regulation

The European Union's risk-based regulation of AI systems. Obligations phase in through August 2026, varying by each system's risk classification.

Kyūdō maps EU AI Act obligations into its 156 unified AI governance controls and evidences them continuously, so readiness is a standing posture rather than a deadline project.

Risk classesProhibited, High-risk, Limited-risk, Minimal-risk
Common evidenceAI system inventory with risk classification, technical documentation, human oversight records, monitoring logs
Best forAny organization placing AI systems on the EU market or using them there

Kyūdō outcomes

  • AI systems classified and inventoried in the Compliance Graph
  • Obligations mapped once alongside ISO 42001 and NIST AI RMF
  • Governance evidence with provenance for each system

Additional Frameworks

And many more supported

Kyūdō's SCF foundation enables support for dozens of additional frameworks. Contact us if you don't see your requirements listed.

NIST 800-171 / 800-53
FedRAMP
HITRUST CSF
CIS Controls
StateRAMP
CCPA / CPRA
CSA STAR
ISO 27017 / 27018
Ask About Your Framework
Efficiency

Implement once, satisfy many

Kyūdō's Compliance Graph understands how controls map across frameworks. Implement a control once, and see it automatically satisfy requirements in SOC 2, ISO 27001, and CMMC simultaneously.

100+
Frameworks mapped
1,000+
SCF controls
60%
Typical control overlap

Ready to simplify multi-framework compliance?

See how Kyūdō's unified control framework can accelerate your certification journey.

Frequently Asked

Questions, answered

Looking for more? See all frequently asked questions.