Compliance

Auditable output for compliance teams.

Every scan produces artifacts you can hand to an auditor. PDF reports with per-finding evidence citations, JSON exports for pipeline ingestion, and per-CVE traceability (matched CPE, fix version, log line that triggered it). No third-party attestation yet — the mapping below documents which existing framework requirements a BootIntel report can support as evidence.

For enterprise procurement questions (SOC 2 status, DPA, subprocessor list, private deployment), see the Trust Center.

Common frameworks we map to

NIST 800-53
Evidence for system integrity, secure configuration, and vulnerability management reporting.
NIST 800-171
Supports program evidence for system integrity and remediation tracking.
ISO 27001
Aligns to asset security, hardening, and secure update processes.
IEC 62443
Supports industrial device security programs and secure development practices.
FDA Premarket
Evidence generation for medical device cybersecurity risk management.
EU CRA / UK PSTI
Baseline security evidence for connected product requirements.

Finding categories

Boot chain integrity
Bootloader version, signature/hash failures, interruptable autoboot windows.
Debug interface exposure
UART consoles bound to physical pins, JTAG/SWD leftover, factory-mode indicators.
Firmware update path security
OTA URLs, unsigned image loads, TFTP/NFS boot exposure, unauthenticated flash paths.
Version-based vulnerability status
Per-component CVE match (bootloader, kernel, userland packages) with fix version.

Need a formal control mapping?

For customers running an active NIST 800-53, ISO 27001, IEC 62443, or FDA Premarket program, BootIntel can provide a tailored control matrix that maps each finding category in your BootIntel report to the specific controls or requirements your program is scored against. Reach out and describe your framework + scope.

[email protected]
Compliance mapping — BootIntel · BootIntel