For Procurement & Security Reviewers
Compliance and attestations
What Symbiosis supports today, what is on the roadmap, and how to request the documents your review requires. Everything here is maintained by Symbiosis Advisory LLC.
Framework coverage matrix
Live Live nowBeta BetaRoadmap Roadmap
| Framework | Version | Controls loaded | Crosswalk | Evidence templates | Reports | Status |
|---|---|---|---|---|---|---|
| NIST 800-53 | Rev 5 + enhancements | 997 | Deep | Yes | SSP, SAR, POA&M, Executive | Live |
| CMMC | Level 2 (v2.0) | 110 | Deep | Yes | SSP, POA&M, Gap Report, C3PAO ZIP | Live |
| FedRAMP | Rev 5 Moderate / High baselines | Baseline overlays | Deep | Yes | SSP, POA&M, Executive | Live |
| ISO/IEC 27001 | 2022 | 93 | Deep | Yes | SoA, Executive | Live |
| SOC 2 | TSC 2017 (rev 2022) | Criteria mapped | Standard | Yes | Readiness, Executive | Live |
| HIPAA | Security & Privacy Rules | 45 CFR §164 | Standard | Yes | Readiness, Executive | Live |
| HITRUST CSF | v11.x | Core mapping | Standard | Partial | Readiness, Executive | Live |
| PCI DSS | 4.0.1 | Requirements 1-12 | Standard | Yes | Readiness, Executive | Live |
| GDPR | EU 2016/679 | Articles mapped | Standard | Yes | DPIA, Executive | Live |
| NIST CSF | 2.0 | Functions & categories | Deep | Yes | Readiness, Executive | Live |
| COBIT | 2019 | Objectives mapped | Light | Partial | Maturity | Live |
| COSO ERM | 2017 | Principles mapped | Light | Partial | Maturity | Live |
| FAIR | Quantitative Risk | Model included | Light | Partial | Quantitative risk register | Live |
| EU AI Act | 2024/1689 | High-risk obligations | Standard | Yes | Conformity, Executive | Live |
| NIST AI RMF | 1.0 | Govern / Map / Measure / Manage | Standard | Yes | Readiness, Executive | Live |
| ISO/IEC 42001 | 2023 | AIMS controls | Standard | Yes | Readiness, Executive | Live |
| StateRAMP | Moderate | Overlay in progress | Planned | Planned | SSP overlay | Beta |
| IRS Pub 1075 | 2021 | Overlay in progress | Planned | Planned | SSP overlay | Beta |
| CJIS Security Policy | 5.9.x | Planned | Planned | Planned | Planned | Roadmap |
| TX-RAMP | Levels 1-2 | Planned | Planned | Planned | Planned | Roadmap |
| DORA (EU) | 2022/2554 | 5 pillars scaffolded, detailed controls coming soon | Planned | Planned | Planned | Beta |
| NIS2 (EU) | 2022/2555 | 10 measure areas scaffolded, detailed controls coming soon | Planned | Planned | Planned | Beta |
| Zero Trust Maturity | NIST SP 800-207 with CISA ZTMM 2.0 | 5 pillars and 3 cross-cutting capabilities, 4 stages each | Standard | Yes | Maturity profile, Gap analysis | Live |
Scope and platform capabilities
Organization isolationLive
Per-org RLS, per-org storage buckets, per-org keys.
Multi-organization portfoliosLive
Advisory plan for consultants managing multiple clients.
SSO (SAML)Beta
Google and email today. SAML SSO for Advisory.
SCIM user provisioningRoadmap
Manual invites today; SCIM planned.
Continuous evidence collectionBeta
Weekly system scans; broader connector library planned.
Audit trail exportLive
Evidence integrity manifest and CSV audit logs.
Data residency: USLive
Default region.
Data residency: EURoadmap
Planned for Q3.
Request an attestation package
Tell us what your procurement or security review needs. We'll reply within 2 business days with the requested artifacts and an NDA if applicable.