Compliance

Four frameworks, one surface, evidence you can hand over unedited.

Audit prep usually means chasing three artifacts and stitching them into a slide. ZelarSOAR rolls CIS, NIST, PCI, and DPDP into a single live view — applied over total, per framework — with signed evidence behind every number.

CIS Controls v8 — Level 1 & 2
Foundational and defence-in-depth endpoint hardening
100 / 102
NIST 800-53 — Moderate baseline
Federal moderate-impact control set
71 / 73
PCI DSS v4.0
Cardholder data environment
38 / 39
DPDP Act 2023
India data protection — 7-year signed evidence retention
24 / 24
ISO 27001 — Annex A
Information security management controls
14 / 16

Figures are the reference values from the Hardening Proof screen. Your rollup reflects your assets, your tenant, and your framework scope.

Why native rollup matters

Evidence at rest is always past tense.

A quarterly attestation proves a control was applied on the day of the audit. It says nothing about the ninety days in between. ZelarSOAR scores continuously, so the framework view is true at the moment you open it — and drift against any control is remediated before it becomes a finding.

Continuous, not quarterly

Posture refreshes every 15 minutes. A control that drifts at 2 a.m. is restored and receipted before the SOC opens.

Signed, not screenshotted

Every export carries the tenant's audit signature and lands in immutable storage. An auditor verifies it without trusting the dashboard.

One surface, not three tools

CIS, NIST, PCI, and DPDP share the same screen and the same evidence chain — no exports to reconcile, no services engagement to stitch them.

Regional obligations

Built for the mandates our buyers actually carry.

BFSI, manufacturing, healthcare, and IT/ITES teams across APAC, MENA, and the Americas map their obligations onto the same rollup. Pre-built packs shorten audit-prep from weeks to hours.

APACDPDP Act 2023, RBI and SEBI cyber directions, and MAS technology risk expectations for financial institutions.
MENASAMA Cyber Security Framework and NCA ECC for Saudi and Gulf compliance-driven enterprises.
USSOC 2, HIPAA, PCI DSS, and NYDFS 500 for mid-market and BFSI buyers.

Framework coverage is configurable per tenant. A framework outside your scope shows as unavailable rather than as a failing score.

Hand your auditor the evidence chain, unedited.

Bring the framework your next audit turns on. We will show the rollup — and the signed receipts behind it — on your assets.