Framework mapping
Compliance framework mapping index
Seven regulatory frameworks pre mapped to the specific Etch endpoints or product properties that address each named control. Every claim is defensible from public materials as of the statement date. Every response describes what Etch signs on the chain that helps demonstrate the control is met. Etch is an evidence layer and does not enforce controls at runtime.
On formal attestations. A control mapping is
a statement of how Etch addresses a named control. A formal
third party attestation (for example SOC 2 Type I or Type II)
is a separate independent audit. Etch does not hold a formal
third party attestation today. Mappings below are the control
response layer, not a substitute for a formal attestation
report. Enterprise engagements that require a formal SOC 2
attestation can request the current audit posture via
security@etch.systems.
SOC 2
AICPA - 22 control mappings
System and Organization Controls 2. Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy. Etch addresses Security and Processing Integrity primarily. Availability, Confidentiality, and Privacy are partially addressed through the signing and audit surface documented below.
ISO 42001
ISO/IEC - 22 control mappings
AI Management System (AIMS) requirements. Etch addresses clauses 7 (Support), 8 (Operation), and 9 (Performance evaluation) through signed governance records, bounded authority receipts, and continuous measurement primitives.
NIST AI RMF
NIST - 23 control mappings
AI Risk Management Framework. Etch addresses Govern, Map, Measure, and Manage functions through chain signed evidence of role assignments, decisions, and measurements over time.
HIPAA
US HHS - 24 control mappings
Health Insurance Portability and Accountability Act. Etch addresses the technical safeguards at 164.312, the administrative safeguards at 164.308, and the record retention posture at 164.316.
EU AI Act
European Union - 23 control mappings
AI Act for high risk AI systems. Etch addresses Article 12 record keeping, Article 14 human oversight, Article 15 accuracy and robustness, and Article 50 transparency obligations.
NERC CIP
NERC - 22 control mappings
Critical Infrastructure Protection standards for Bulk Electric System operators. Etch addresses CIP-007 systems security management and CIP-011 information protection through signed evidence trails and BYOK HSM attestation.
HITRUST
HITRUST - 23 control mappings
Common Security Framework. Etch addresses the audit logging control family, integrity control family, and cryptography control family primarily.