Independent Audits & Regulatory Mapping
- A SOC 1 Type II examination is performed with an external audit firm; a SOC 2 Type II examination is planned.
- Compliance obligations are mapped across applicable frameworks, including NIST, CMMC, GDPR, and customs/trade requirements.
- A dedicated governance, risk, and compliance (GRC) function owns frameworks, audits, policy management, and customer security questionnaires.
Framework Alignment: NIST CSF GV.OV; SOC 1 Type II; CMMC Level 1; GDPR Art. 30, 24; ISO 27001:2022 A.5.31, A.5.35, A.5.36
- Private