Attestkeep docs

Compliance frameworks

A framework mapping turns what the cluster did into what an auditor asked for. It does not turn either one into a certification.

What an evidence package contains

For a period you choose:

The allows matter as much as the denials. Evidence that only lists blocks can show that something was blocked; it cannot show that a control was operating.

Mapped frameworks

FrameworkWhere it applies
Cyber Resilience Act — Regulation (EU) 2024/2847EU
NIS2 — Directive (EU) 2022/2555EU
DORA — Regulation (EU) 2022/2554EU financial entities
GDPR Article 32EU
NIST SP 800-218 (SSDF)US
NIST SP 800-190US
NIST SP 800-53 Rev. 5US
SOC 2US, widely used elsewhere
ISO/IEC 27001international

Community includes one framework, and it is yours to choose rather than a fixed one. A company doing only ISO 27001 should not be asked to pay for a SOC 2 mapping it will never open.

What this does not claim

A mapping is an argument, not a verdict. It says: this control text asks for evidence of X, and here is what your cluster did about X. Whether your auditor accepts it is between you and your auditor, and no tool can promise otherwise.

Container images are also one slice of any of these frameworks. None of them is satisfied by what happens at admission alone, and a product that implied otherwise would be selling a false finish line.

Where the mappings come from

Each mapping is read from the published text of the framework and cites the clause it maps to, so you can check the reading rather than trust it. Where a clause is genuinely ambiguous about containers, the mapping says so instead of picking the flattering interpretation.