Our methodology
for evaluating software

Compliance Labs independently evaluates cybersecurity software across IT, OT and AI regulations and frameworks. Our evaluation process is built on the NIST IR (Internal Report) series, and assessments follow the procedures defined in NIST SP (Special Publication).

25+ years of compliance practice

1000+ software solutions evaluated

Compliance Labs operates on three evaluation levels

Detailed methodology available on request.

1

Compliance Assurance

Compliance Labs reviews proprietary vendor documentation, including SBOM, internal documentation, and audit reports, and maps each software capability to specific regulatory articles and framework controls. It assesses whether controls are suitably designed to address the targeted requirements, following the examine method defined in NIST SP, and independently confirms capabilities and software contribution as examined. Delivered as a CAE report covering control coverage, gap analysis, and configuration dependencies.

3

Evidence Effectiveness

The EEE extends the CAE with direct testing in a controlled environment. Compliance Labs installs, configures, and operates the software to verify that controls function as designed, applying the examine, interview, and test methods defined in NIST SP. Each gap is recorded with expected behavior, observed behavior, and regulatory impact, producing the technical evidence expected by assessors such as QSA, ISO, and DORA. Delivered as an EEE report covering test results per control, a structured evidence pack, and a complete audit trail.

2

Custom Evaluation

It brings the same methodology to software outside the standard market. The examine, interview, and test procedures apply to pre-release versions, internally developed applications, cloud connectors, and proprietary pipelines, with depth adapted to the target environment. For secure development readiness, Compliance Labs reviews the software and its development lifecycle for alignment with NIST SSDF practices and EU Cyber Resilience Act requirements. Delivered as a tailored report covering test results where applicable, gap analysis, the conformity route, and regulatory impact.

OUR EVALUATION PROCESS

From regulatory obligation to software capability

Every Compliance Labs evaluation connects three independently established sources: a regulation’s obligations, the software’s capabilities, established from software documentation and expert input, and a control relationship typology from recognized standards. Building them separately prevents invented links, keeping every relationship documented, traceable, and reproducible.

Step 1

Identify the regulation

The evaluation starts with the regulation or framework the software must address. It determines the scope of every mapping that follows. Nothing is evaluated outside its scope.

Step 2

Map to shared control frameworks

Compliance Labs maps software capabilities to three shared control frameworks: NIST CSF 2.0, or NIST AI RMF for AI systems, NIST SP, and ISO/IEC 27001. These frameworks provide the structured control language that connects software capabilities to regulatory requirements. Because these frameworks are shared across regulations, a single capability assessment carries across every regulation that references them: one evaluation, many regulations.

Step 3

Document the mapping

Each mapping is classified using a control relationship typology drawn from widely recognized standards, so the strength of every link is explicit. Four types are used: Direct, where the capability fulfills the obligation through a mechanism named in the regulation; Contributing, where the capability adds value but the obligation is broader; Supporting, where the capability participates indirectly; and Equivalent, where the capability replaces the obligation's named mechanism. This removes ambiguity from every mapping.

Step 4

Separate delivery from contribution

A cybersecurity software doesn't address regulatory requirements on its own. It delivers technical capabilities that can be verified directly, and it contributes to organizational practices that people operate. Our evaluation measures the two separately, so a compliance officer can see exactly where the software ends and organizational work begins.

Step 5

Write the rationale

Every mapping includes a written rationale explaining why this capability addresses this control, and what the limitations are. The rationale gives auditors, compliance officers, and security architects the context they need to make decisions.

From compliance to threat coverage

Regulatory mapping shows what controls exist. Threat mapping shows what they prevent.

Compliance Labs to MITRE ATT&CK and ATLAS to connect regulatory coverage to real-world attack techniques. You see not only which controls a software addresses, but which adversary techniques its controls are designed to address.

TECHNIQUES
0

Enterprise

TECHNIQUES
0

Mobile

TECHNIQUES
0

ICS

TECHNIQUES
0

AI ATLAS

When Compliance Labs evaluates a software’s access control capabilities for DORA Art. 9, the MITRE mapping shows which credential theft, privilege escalation, and lateral movement techniques those controls would detect or prevent. The compliance map tells you the software addresses the regulation. The threat map tells you what that means against real adversary behavior.

Foundations of every evaluation

The expertise and principles behind every compliance map and report.

Independent evaluations

Every evaluation follows the same methodology regardless of the vendor.

Transparent at every step

Every mapping includes its source, relationship type, and rationale.

Results that hold up over time

25+ years of compliance and cybersecurity experience, structured into a methodology.

Independence and limitations

The three levels of assurance above correspond to Compliance Labs evaluation packages.

A Compliance Labs evaluation is independent of the vendor. Payment covers the depth of examination, not its outcome, and the same method applies at every level. Each evaluation is reviewed by a senior compliance expert before publication. An evaluation measures how a software contributes to regulatory obligations. It does not certify the vendor as compliant, it is not an audit, and it does not constitute legal or compliance advice. Compliance is an organizational outcome, and ultimate responsibility remains with the organization deploying the software.

Contact us today

We are here to help you find the right software solutions to grow your business and achieve your goals.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Vendor
  • Category
  • CL Tier
  • Short description
  • Website
  • What it is
  • Best for
  • Does NOT do
  • CL verdict
  • Regulatory coverage
  • Frameworks tested
  • Capabilities
  • MITRE ATT&CK
  • Strengths
  • Cautions
  • Anti-hype claims
  • Operational metrics
  • Evidence pack
Compare
Compare ×
View comparison Continue browsing software