# What security and compliance frameworks does Cyber Crucible align to?

**Short answer:** Cyber Crucible maps its controls to the NIST Cybersecurity Framework, relevant NIST SP 800-53 control families, and the CIS Critical Security Controls, and it maps to the SOC 2 Trust-Service Criteria for reviewer convenience. These are **self-assessed alignments**, offered so a reviewer can relate Cyber Crucible's controls to a standard they know — not certifications or third-party audit opinions.

## Alignment, stated honestly

| Framework | Status |
|---|---|
| NIST Cybersecurity Framework (CSF) | Controls self-mapped; not a certification |
| NIST SP 800-53 control families | Aligned where applicable; not an authorization |
| CIS Critical Security Controls | Aligned; not certified |
| SOC 2 Trust-Service Criteria | Mapped for reviewer convenience; no report held |
| Microsoft WHCP (driver) | Held — an independent, external validation |

## Why say it this way

A vendor that lists frameworks it has not been audited against invites the reviewer to distrust every other answer. Cyber Crucible states what is a certification (WHCP) and what is a self-assessed mapping (the rest), so a reviewer can weigh each accordingly.