Etch
Framework mapping

Compliance framework mapping index

Seven regulatory frameworks pre mapped to the specific Etch endpoints or product properties that address each named control. Every claim is defensible from public materials as of the statement date. Every response describes what Etch signs on the chain that helps demonstrate the control is met. Etch is an evidence layer and does not enforce controls at runtime.

On formal attestations. A control mapping is a statement of how Etch addresses a named control. A formal third party attestation (for example SOC 2 Type I or Type II) is a separate independent audit. Etch does not hold a formal third party attestation today. Mappings below are the control response layer, not a substitute for a formal attestation report. Enterprise engagements that require a formal SOC 2 attestation can request the current audit posture via security@etch.systems.

SOC 2

AICPA - 22 control mappings
System and Organization Controls 2. Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy. Etch addresses Security and Processing Integrity primarily. Availability, Confidentiality, and Privacy are partially addressed through the signing and audit surface documented below.

ISO 42001

ISO/IEC - 22 control mappings
AI Management System (AIMS) requirements. Etch addresses clauses 7 (Support), 8 (Operation), and 9 (Performance evaluation) through signed governance records, bounded authority receipts, and continuous measurement primitives.

NIST AI RMF

NIST - 23 control mappings
AI Risk Management Framework. Etch addresses Govern, Map, Measure, and Manage functions through chain signed evidence of role assignments, decisions, and measurements over time.

HIPAA

US HHS - 24 control mappings
Health Insurance Portability and Accountability Act. Etch addresses the technical safeguards at 164.312, the administrative safeguards at 164.308, and the record retention posture at 164.316.

EU AI Act

European Union - 23 control mappings
AI Act for high risk AI systems. Etch addresses Article 12 record keeping, Article 14 human oversight, Article 15 accuracy and robustness, and Article 50 transparency obligations.

NERC CIP

NERC - 22 control mappings
Critical Infrastructure Protection standards for Bulk Electric System operators. Etch addresses CIP-007 systems security management and CIP-011 information protection through signed evidence trails and BYOK HSM attestation.

HITRUST

HITRUST - 23 control mappings
Common Security Framework. Etch addresses the audit logging control family, integrity control family, and cryptography control family primarily.