Frameworks and requirements
The Compliance Program page shows the compliance frameworks enabled for your workspace, the requirements each framework contains, and the controls that satisfy those requirements. Progress for every framework and requirement comes from the status of its controls, so you can see how close you are and which controls still need work.
To open it, click Program in the Compliance section of the sidebar. The Compliance section appears only when your workspace includes Oneleet Compliance, and viewing the page requires a role with access to controls, such as Member or Auditor. The Oneleet team adds and removes frameworks for you; you can’t do it from your workspace.
Frameworks, requirements, and controls
Section titled “Frameworks, requirements, and controls”A framework, such as SOC 2 or ISO 27001, is made up of requirements. Each requirement has a reference id from the framework’s text (for example, “164.312(a)(2)(i)” in HIPAA), a title, and often a longer description.
Controls are the security practices you run. Each requirement is linked to the controls that satisfy it, and a requirement with no linked controls can’t be met. A single control can satisfy requirements in several frameworks at once, so work you do for one framework counts toward every other framework that uses the same control. Shared controls appear in each framework’s totals.
Request a framework
Section titled “Request a framework”On the Frameworks tab, the Available frameworks section lists the frameworks you can request. Each card shows a description, the effort involved when Oneleet has an estimate, and an Estimated readiness percentage. Estimated readiness is the share of the framework’s control types that your workspace already has a passing control for.
To request a framework, click Schedule call on its card, then book a call with your Oneleet contact on the scheduling page that opens in a new tab. If the card shows “Contact us on Slack to get started.” instead of the button, reach out to the Oneleet team on Slack.
If your workspace has no active frameworks yet, you won’t see the Frameworks tab. Contact the Oneleet team to request your first framework.
Once a framework is enabled, your workspace gets:
- Requirements: one for each requirement in the framework.
- Controls: the controls those requirements need. If you already have a control of the same type from another framework, Oneleet reuses it and links it to the new requirements instead of creating a duplicate.
- Monitors and checks: added to the new controls right away, but only for asset types your workspace has. New monitors first run at your workspace’s next hourly run, then every hour after that. A new monitor can start out snoozed if your workspace is in an audit observation period or if the monitor type is brand new.
- Base framework: if the framework builds on another framework, that one is added too, unless it’s already active.
Track framework progress
Section titled “Track framework progress”The Frameworks tab lists each active framework with a Completion percentage: the share of controls linked to that framework that are passing. The same figure appears on the framework tiles on the Overview tab.
A control counts as passing only when all of the following are true:
- Its review has been approved.
- It has at least one check, and every enabled check on it is passing.
- No active evidence request on it is still waiting for Oneleet’s review, whether or not you’ve answered it. Rejected requests and requests scheduled for a future date don’t block.
Controls that aren’t passing show one of these statuses:
- Needs changes: its review was rejected, or one of its checks needs changes and none of them are failing.
- In review: its review is in progress.
- Failing: at least one check is failing.
- Not started: it has no checks, or its checks are still pending and none are passing.
- In progress: it isn’t passing for another reason, such as all checks passing while the review isn’t approved or an evidence request is still open.
A control whose review is rejected or in progress shows Needs changes or In review even if one of its checks is failing.
To find the controls holding a framework back, click the framework’s card to open the Controls tab filtered to that framework. You can also click the controls panel inside the card to open the Control Status menu and jump straight to the controls in one status, such as the failing ones.
The framework filter at the top of the Overview, Controls, and Requirements tabs narrows each tab to the frameworks you pick, and your selection carries across tabs. At least one framework always stays selected.
Work through requirements
Section titled “Work through requirements”The Requirements tab lists every requirement in the selected frameworks, grouped into Unmet and Met. A requirement is met when it has at least one linked control and every one of its controls is passing.
To download the list as a CSV file, click Export. The file includes only the requirements that match your current frameworks, search, and filter.
Click a row to open the requirement’s page, which shows its description and a table of the controls linked to it. From that table, you can:
- See each control’s checks, evidence, and evidence requests. If a control has passing checks but no uploaded evidence, the Evidence column shows a count of passing monitors instead. The count includes passing checks of every type, such as policy checks.
- Assign an owner to a control.
- Select several controls to act on them in bulk.
- Click the framework icons on a control to see the other requirements it satisfies, including those in other frameworks.
To start from a control instead, open its page: the Requirements section lists the requirements it satisfies, grouped by framework. The Controls tab also has a Requirement filter that shows only the controls linked to the requirements you pick.
Share compliance badges
Section titled “Share compliance badges”You can add compliance badges for your frameworks, such as SOC 2 and HIPAA, to your website. Not every framework has a badge yet. One without a badge still appears in the Compliance badges modal, but its badge link won’t load. The Compliance badges button appears at the top of the Program page once at least one framework is active.
-
On the Program page, click Compliance badges.
-
Under Choose theme, pick Light or Dark.
-
Under Badge format, pick SVG link only to copy the image’s URL, or HTML snippet to copy code you can paste into a web page. If your workspace has a published Trust center, the HTML snippet links the badge to it.
-
Click Copy link or Copy code next to the badge you want.
Each badge updates automatically to show its framework’s current compliance status, In progress or Compliant. The Oneleet team sets that status, the framework’s designation where one applies (such as SOC 2 Type 1 or Type 2), and whether the framework appears on your Trust center, so contact them to change any of these.
Limitations
Section titled “Limitations”- Only the Oneleet team can remove a framework. See Removing a framework for what happens to its controls and monitors.
- You can’t mark a requirement as not applicable or a control as out of scope. Every linked control counts toward progress.
- Frameworks with more than one variant, such as two versions of SOC 2, show the same name in your workspace. If you’re unsure which variant you have, ask the Oneleet team.