See how XploitScan maps to SOC2, ISO 27001, OWASP Top 10, and CWE controls
SOC 2 (Service Organization Control 2)
A US-based audit framework that evaluates how well a company protects customer data. Created by the AICPA, it covers five trust services categories: security, availability, processing integrity, confidentiality and privacy.
Why it matters: Many B2B customers and enterprise buyers require a SOC 2 report before signing. Mapping findings to the criteria a scanner can evidence gives you a head start on the code-level half of that review — it is not a SOC 2 report and does not make you compliant.
What we map: SOC 2's 2017 Trust Services Criteria define 33 common criteria (CC1.1 through CC9.2). XploitScan maps the ones a code scanner can actually evidence — logical access, system operations and change management. The rest are organizational controls an auditor assesses by interviewing people and reading policies, not by reading source.
9 of 33 common criteria mapped27% of the framework
ISO/IEC 27001
An international standard for information security management. It defines a systematic approach to managing sensitive company and customer information.
Why it matters: Required or preferred by organizations worldwide, especially in Europe and government contracts. ISO 27001 certification demonstrates a mature security program.
What we map: ISO/IEC 27001:2022 Annex A defines 93 controls. XploitScan maps the controls that leave traces in source code, mostly the technological (A.8) ones plus a small number of organizational ones such as A.5.1; the remaining organizational, people and physical controls are outside what any scanner can see.
9 of 93 Annex A controls mapped10% of the framework
NIST SP 800-53 Rev 5
The US federal catalogue of security and privacy controls. It is the reference most other frameworks crosswalk back to, and the basis of FedRAMP.
Why it matters: Government and enterprise buyers ask which 800-53 controls your code bears on. Mapping findings to specific controls gives you a concrete answer for the code-level ones — it is not an assessment, an ATO, or a claim that any control is satisfied.
What we map: NIST SP 800-53 Rev 5 is a catalogue of over a thousand controls and control enhancements across 20 families that an organization tailors to its system — not a checklist to complete. The figure below is how many distinct controls our rules bear on; there is no meaningful percentage to quote against a catalogue nobody implements in full.
46 controls mappedinformational mapping
CIS Critical Security Controls v8.1
A prioritised set of 18 Controls broken into 153 Safeguards, published by the Center for Internet Security and widely used as a practical hardening baseline.
Why it matters: CIS is the framework most often used to answer "what are you actually doing about security?" in plain terms. The application-layer Safeguards are the ones a scanner can evidence; the rest are organizational.
What we map: CIS Controls v8.1 defines 153 Safeguards across 18 Controls. XploitScan maps the application-layer ones that leave traces in source code — most of the rest govern asset inventory, network infrastructure, training and incident response, which no code scanner can see.
26 of 153 safeguards mapped17% of the framework
HIPAA Security Rule (45 CFR Part 164)
The US rule governing how electronic protected health information must be safeguarded. Its technical safeguards at 164.312 are the part that lives in code.
Why it matters: If your product touches health data, a covered entity will ask how you address the technical safeguards before signing a Business Associate Agreement. Mapping findings to those standards is a starting point for that conversation — it is not a HIPAA compliance assessment and does not make you compliant.
What we map: The HIPAA Security Rule's five technical safeguard standards (45 CFR 164.312: access control, audit controls, integrity, person or entity authentication, transmission security) are the part a code scanner can speak to, along with a few administrative specifications such as password management. The physical safeguards at 164.310 are facility controls, and there is no honest denominator that mixes standards with implementation specifications — so this reports what our rules bear on rather than a percentage.
14 safeguards mappedinformational mapping
OWASP Top 10 (2021)
A widely recognized list of the 10 most critical web application security risks, published by the Open Worldwide Application Security Project.
Why it matters: The industry standard for web app security. Addressing OWASP Top 10 risks is the baseline expectation for any web application — auditors and security teams check this first.
What we map: The OWASP Top 10 (2021 edition) is exactly ten categories, and at least one XploitScan rule maps to each of them. That is a mapping, not complete detection of every risk in a category. OWASP has since published a 2025 edition, which this page does not yet map.
10 of 10 categories mapped100% of the framework
CWE (Common Weakness Enumeration)
A community-developed catalog of software and hardware weakness types. Each CWE ID represents a specific type of vulnerability (e.g., CWE-89 is SQL Injection).
Why it matters: CWE IDs are the universal language for describing security weaknesses. They help developers, tools, and security teams communicate precisely about what type of issue was found.
What we map: CWE is a catalog of over 900 weakness types, not a checklist to complete. The figure below is how many distinct CWE IDs our rules map to — there is no meaningful percentage to quote.