Map Security Scans to
6 Compliance Frameworks
ComplianceLayer runs 16 external security modules and automatically maps findings to CMMC, HIPAA, SOC 2, PCI DSS, NIST, and ISO 27001 controls. Get audit-ready evidence without manual spreadsheets.
Choose a Framework
CMMC 2.0 Level 2
Cybersecurity Maturity Model Certification for defense contractors and the DIB supply chain. Maps to NIST SP 800-171 controls.
HIPAA Security Rule
Health Insurance Portability and Accountability Act technical safeguards for protecting electronic protected health information (ePHI).
SOC 2 Type II
Service Organization Control trust service criteria covering security, availability, processing integrity, confidentiality, and privacy.
PCI DSS 4.0
Payment Card Industry Data Security Standard requirements for organizations that store, process, or transmit cardholder data.
NIST CSF / 800-171
National Institute of Standards and Technology Cybersecurity Framework and SP 800-171 controls for protecting CUI.
ISO 27001 Annex A
International standard for information security management systems. Annex A controls cover cryptography, network security, and application security.
From Scan to Compliance Report in Minutes
Submit a domain
Enter any domain and ComplianceLayer runs 16 security modules: SSL/TLS, DNS, email authentication, open ports, security headers, and more.
Automatic mapping
Each finding is mapped to the relevant controls across all 6 frameworks. Pass, fail, and partial statuses are assigned automatically.
Export evidence
Download a PDF report with control-by-control results. Attach it to audit questionnaires, insurance applications, or client deliverables.
One Scan, Multiple Frameworks
Many compliance controls overlap across frameworks. A single ComplianceLayer scan produces evidence that maps to controls in every supported framework simultaneously.
| Security Domain | SOC 2 | PCI DSS | HIPAA | NIST | ISO 27001 |
|---|---|---|---|---|---|
| Encryption & TLS | CC6.7 | 4.1, 4.2.1 | 164.312(e)(1) | PR.DS-2, SC-8 | A.10.1.1 |
| Access Control | CC6.1, CC6.2 | 8.2.1, 8.3.1 | 164.312(a)(1) | PR.AC-5 | A.9.1.2 |
| Network Security | CC6.6 | 1.3.1, 2.2.4 | 164.312(a)(1) | PR.PT-4 | A.13.1.1 |
| Application Security | CC6.8 | 6.5.7, 6.4.3 | 164.312(c)(1) | PR.DS-5 | A.14.2.5 |
| Monitoring | CC7.1, CC7.2 | 11.3.1 | 164.308(a)(1) | DE.CM-8 | A.12.6.1 |
| Email Security | CC6.7 | 4.2.1 | 164.312(e)(1) | PR.DS-2 | A.13.2.3 |
Start scanning your first
domain in 60 seconds.
No credit card. No sales call. No setup. Free tier is permanent.
All scans are passive and external — we never access your servers, install agents, or require credentials. View our security practices, live system status, or browse domain reports.