SOC 2 (TSC 2017, rev. 2022)
All five Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, Privacy. Mapped to the 2022 points-of-focus revisions.
View SOC 2 deep-diveManual Ends maintains the most complete, freshest-mapped compliance control library on the market — pre-built for SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, NIST CSF 2.0, and the EU AI Act high-risk tier, with cross-framework mappings and a 48-hour regulator-update SLA your auditors can verify.
Fourteen frameworks in production today — including the four most-searched by North American mid-market and enterprise compliance teams, plus the EU AI Act high-risk tier and seven adjacent standards. Click any tile for the control map, evidence workflow, and last regulator sync.
All five Trust Services Criteria — Security, Availability, Processing Integrity, Confidentiality, Privacy. Mapped to the 2022 points-of-focus revisions.
View SOC 2 deep-dive93 Annex A controls reorganized into 4 themes (Organizational, People, Physical, Technological), plus Clauses 4–10.
Administrative, physical, and technical safeguards (§164.308–§164.312), plus the 2024 NPRM amendments and the Privacy Rule.
Articles 5–49 mapped to operational controls, including DPIA workflows, ROPA, and cross-border transfer mechanisms (SCCs, IDTA).
All 12 requirements, including the 64 new v4.0 controls and the future-dated v4.0.1 items. SAQ routing logic built in.
Function → Category → Subcategory hierarchy, including the new Govern function added in CSF 2.0 (Feb 2024).
Articles 6–15 operationalized for high-risk AI systems, including Annex III use cases and the 2024/1689 implementing regulation.
Full 1,000+ control catalog with FedRAMP baseline overlays (Low, Moderate, High) — used for US federal and federal-adjacent workloads.
Privacy information management extension to ISO 27001 — PIMS controls mapped against GDPR, CCPA, and LGPD.
Cybersecurity Maturity Model Certification levels 1–3, mapped to NIST SP 800-171 for CUI handling across the DIB.
California Consumer Privacy Act as amended by the California Privacy Rights Act — including the 2024 ADMT regulations.
Healthcare-focused certification, inheriting from NIST, HIPAA, and ISO. Maturity-level PRISMA-based scoring.
Sarbanes-Oxley IT general controls covering access, change management, and operations across financial-reporting systems.
Upload a custom standard, map it against the existing 2,650-control library, and ship a private tenant in 14 days.
Request a frameworkSOC 2, ISO 27001, HIPAA, and GDPR account for ~84% of every audit Manual Ends has supported in 2024. Here is exactly what each program ships, where teams typically break, and which one-click evidence workflows compress a 77-day audit into 11.
412 controls across Security, Availability, Processing Integrity, Confidentiality, and Privacy. The Type II 96% first-time pass rate holds across 612 audits in 2024 — versus the 38% industry baseline — because every evidence hook is pre-wired before the audit window opens.
93 Annex A controls mapped to the 2022 reorganization (Organizational, People, Physical, Technological), plus Clauses 4–10. The Statement of Applicability is auto-generated from your scoping decisions and risk treatment — no 90-page Word document to maintain.
198 controls covering the Administrative, Physical, and Technical Safeguards (§164.308–§164.312) and the Privacy Rule, with the 2024 Notice of Proposed Rulemaking amendments layered in so you're ready the day the final rule lands.
274 controls mapping Articles 5–49 to operational practice — DPIA workflows for high-risk processing, ROPA auto-built from your system inventory, and Standard Contractual Clauses / IDTA workflows for cross-border data transfers.
Multi-framework programs are where compliance cost spirals. Manual Ends ships a deduplicated control graph so the same evidence satisfies SOC 2 CC6.1, ISO 27001 A.5.15, HIPAA §164.308(a)(1), and PCI DSS 7.1 in a single evidence pull.
Upload a custom framework (regulator-issued, customer-imposed, or internal policy) and our team maps it against the existing 2,650-control library within 14 days — included for every Scale-tier customer.
04 /Talk to a Solutions Architect1,840+ companies have shipped a framework program on Manual Ends. Here is what changed for them, in numbers you can paste straight into your steering-committee deck.
Six questions we hear every week. Answers are factual, sourced from customer data, and explicitly do not constitute legal advice — for legal outcomes, defer to qualified counsel.
The platform's deduplicated control graph maps every evidence source to every framework that accepts it. In a customer benchmark covering 187 multi-framework programs in 2024, the median team replaced ~412 duplicate evidence-collection tasks per quarter with a single pull that satisfied all target frameworks. The $214K/year average reduction in compliance overhead comes mostly from this elimination of duplicate evidence — not from headcount reduction.
Our 48-hour regulator-update SLA is contractual for Scale-tier customers. When a framework is superseded — most recently NIST CSF 1.1 → CSF 2.0 and PCI DSS 3.2.1 → 4.0 — we publish the new control mapping within 48 hours, mark retired controls as deprecated (not deleted), and notify your tenant admin by email. The deprecated controls remain in your historical evidence so prior audit reports remain valid.
Yes. The Custom Framework Module accepts an uploaded control set (CSV, XLSX, or PDF with structured fields), normalizes it to the same canonical control schema, and crosswalks it against the existing 2,650-control library. Standard turnaround is 14 days for Scale-tier customers; Enterprise customers can self-serve via the Framework Studio API. We have onboarded customer-imposed regimes including a defense-sector CMMC Level 3 overlay, a payment-orchestrator PCI P2PE variant, and several large-customer SOC 2 + custom addenda.
The EU AI Act high-risk tier (Articles 6–15 plus Annex III) imposes obligations that don't exist in ISO 27001 or SOC 2 — risk-management system for the AI lifecycle (§9), data-governance for training/validation/test sets (§10), technical documentation and logging (§11, §12), transparency and human oversight (§13, §14), and accuracy/robustness/cybersecurity (§15). Our 156-control mapping treats the Act as a first-class framework and inherits only what is genuinely shared (e.g., access controls) from the existing library. Conformity assessment workflows for Annex III high-risk use cases ship pre-built. We do not provide legal advice on classification; defer to qualified counsel.
A solutions architect will walk through your target frameworks, evidence sources, and audit calendar — 30 minutes, no slide deck.