Compliance

A scan result becomes audit evidence — not just a CSV.

Most SMBs have a vulnerability-scanning obligation but no security team. Perimeter maps every finding to the exact control it satisfies, with a timestamp, so your auditor gets evidence instead of a raw export.

The mandates driving this

PCI DSS 4.0

Req. 11.3 mandates internal and external vulnerability scans. Perimeter does both and tags findings 11.3.1 / 11.3.2.

HIPAA 2026

The 2026 Security Rule makes 6-month vuln scans + annual pen test required, no longer addressable. Provable scan recency.

CMMC L2 / 800-171

RA.L2-3.11.2 / 3.11.3 (scan + remediate). Open critical/KEV findings feed Bastion's POA&M with due dates.

Control-mapping at a glance

Finding typeNIST CSF 2.0SOC 2PCI 4.0ISO 27001CMMC L2
Vulnerability identifiedID.RA-01CC7.111.3.1/.2A.8.8RA.L2-3.11.2
Patchable / KEVID.RA-06CC7.16.3.3A.8.8RA.L2-3.11.3
TLS / crypto exposurePR.DS-02CC6.74.2.1A.8.24SC.L2-3.13.8
Exposed service / secretPR.AA-05CC6.12.2.6A.8.9CM.L2-3.4.6
Attack-surface driftID.AM-01CC7.211.3.2A.5.7CA.L2-3.12.3

Mappings are the product-local denormalization of the shared evidence graph; the authoritative cross-product contract is the Keystone canonical evidence object + evidence refs.

Collect once, satisfy many

Because Perimeter publishes to the DosanjhLabs shared evidence graph, one scan result satisfies the matching control in Sightline (across 22+ frameworks), Bastion (800-171 SSP/POA&M) and Ward (HIPAA) simultaneously — no re-entry. No standalone scanner can do this, because none is a suite.