Security / Compliance
Compliance
Track your compliance posture across industry standards and frameworks.
CIS, PCI DSS v4.0.1, and NIST SP 800-53 Rev. 5 can be evaluated through AWS Security Hub once it's connected and synchronized — it is not currently connected to DevControl. NIST coverage reflects AWS Security Hub's own interpretation of the NIST SP 800-53 Rev. 5 guidelines, limited to a DevControl-verified technical subset — not a certification. SOC 2 readiness — technical evidence DevControl observes plus supporting evidence your organization provides, not a full Type II audit or certification — is available separately.
Overall Compliance Score
Loading…
Critical Issues
Loading…
High Risk Issues
Loading…
Frameworks
Active evaluations
Compliance Frameworks
CIS AWS Foundations
Industry-standard security configuration guidelines for AWS infrastructure.
Security Hub-backed
Security Hub is not currently connected to DevControl
SOC 2 Readiness
Technical and customer-provided supporting evidence for SOC 2 criteria — not a certification or Type II audit.
Technical + customer evidence
0 of 6 criteria evaluated
NIST 800-53 Rev. 5
Security and privacy controls framework for federal information systems and organizations — coverage reflects AWS Security Hub’s interpretation of NIST SP 800-53 Rev. 5, limited to a DevControl-verified technical subset.
Security Hub-backed
Security Hub is not currently connected to DevControl
PCI DSS v4.0.1
Payment card industry data security standards for handling cardholder data — Compliance Readiness based on partial AWS/Security Hub evidence, not certification.
Security Hub-backed
Security Hub is not currently connected to DevControl
AWS Security Hub
CIS, PCI DSS v4.0.1 and NIST SP 800-53 Rev. 5 can be evaluated through AWS Security Hub once it is connected and synchronized.
AWS Security Hub continuously evaluates supported security standards and provides findings that can be used to understand your compliance posture.
Active Evaluations
Loading evaluations...
DevControl evaluations use secure, read-only access by default — optional remediation actions require separate, explicit permission and your approval.