Compliance Management

ComplianceSphere

One Source of Truth for Every Compliance Obligation

Regulations multiply, standards change, and compliance evidence is scattered across dozens of folders. ComplianceSphere unifies regulatory obligations, controls, and evidence in one platform — so your compliance posture is always visible, measurable, and audit-ready.

ComplianceSphere

  • Framework & Regulation Management
  • Statement of Applicability (SoA)
  • Compliance Register & Legal Obligations
  • Controls Library & Cross-Framework Mapping
Compliance Management

2.7×

The cost of non-compliance versus investing in a compliance program

Source: Ponemon Institute, True Cost of Compliance

93

Annex A controls in ISO/IEC 27001:2022 that must be mapped in your SoA

Before counting UU PDP and sector-specific regulations

2%

UU PDP administrative sanctions — up to 2% of annual revenue

On top of far greater reputational risk

Compliance Managed in Spreadsheets Is Always Behind

Most organizations manage compliance reactively: obligations live in spreadsheets, evidence is scattered across email and shared folders, and fulfilment status is only checked when an audit approaches. Gaps surface exactly when it is too late to close them calmly.

When an organization is subject to more than one framework — ISO 27001 for certification, UU PDP as a legal obligation, and industry standards demanded by enterprise customers — the same work is done repeatedly because controls are never mapped across frameworks.

ComplianceSphere turns compliance from a seasonal project into a continuous process: one obligations register, one controls library, one home for evidence — with a score that shows your position at all times.

How ComplianceSphere Works

A simple, structured process your team can run right away.

01

Register Frameworks & Regulations

Select the frameworks that apply to your organization — ISO/IEC 27001, ISO/IEC 27701, ISO 31000, NIST CSF, and UU PDP — and record other legal obligations in the compliance register.

02

Map Controls to Every Framework

Build a central controls library and map one control to multiple frameworks at once, so a single piece of evidence satisfies several requirements without duplicate work.

03

Build the Statement of Applicability

Define which controls apply, justify inclusions and exclusions, and track implementation status — your SoA stays current and ready to hand to auditors.

04

Run Compliance Assessments

Periodically assess how well each obligation is met, attach evidence to every control, and surface the gaps that need follow-up.

05

Monitor Scores & Review Schedules

Compliance score and maturity dashboards show where the organization stands at any moment; the compliance calendar flags reviews and regulatory deadlines before they slip.

Features & Capabilities

Built to meet real operational needs — not just a checklist of features that look good in a brochure.

Framework & Regulation Management

Manage ISO/IEC 27001, ISO/IEC 27701, ISO 31000, NIST CSF, and UU PDP in one place. Add sector regulations or customer contractual requirements as custom frameworks.

Statement of Applicability (SoA)

Build and maintain a living SoA — implementation status, inclusion/exclusion justifications, and evidence links per control. Never rebuild the SoA from scratch each audit cycle.

Compliance Register & Legal Obligations

A central register for every legal, regulatory, and contractual obligation — complete with owners, deadlines, and fulfilment status for each.

Controls Library & Cross-Framework Mapping

One control, many frameworks. Cross-standard mapping eliminates duplicate work — the same evidence automatically counts toward every framework that requires it.

Compliance Score & Maturity Dashboard

Real-time compliance score per framework and program maturity level. Management sees the organization's position without waiting for quarterly reports.

Compliance Calendar & Evidence Traceability

Reminders for periodic reviews, regulatory deadlines, and assessment schedules — plus an evidence trail traceable from obligation to control to document. Every action is captured in the audit log.

Compliance & Supported Standards

ComplianceSphere is designed to help your organization meet the relevant control requirements and information-security standards.

A.5.31

Legal, Statutory, Regulatory and Contractual Requirements

The ComplianceSphere register ensures every legal, regulatory, and contractual requirement is identified, documented, and kept current.

A.5.36

Compliance with Policies, Rules and Standards

Periodic assessments verify compliance with internal policies and standards — with evidence and follow-up status per control.

6.1.3

Statement of Applicability (ISO/IEC 27001)

The SoA is managed as a living document: applicable controls, their justifications, and implementation status — the core evidence every certification auditor requests.

GOVERN

NIST CSF 2.0 — Govern Function

Mapping controls to the NIST CSF 2.0 Govern function helps the organization demonstrate structured security governance to stakeholders.

Service Level Agreement (SLA)

The following SLA applies to all ComplianceSphere Customers and forms part of the jointly signed Service Agreement. All Customers get full access to every platform feature.

Uptime

99.5%

Monthly service availability, excluding scheduled maintenance announced 24 hours in advance

Critical Incident Response

4 business hours

First response time for issues with significant operational impact

Normal Issue Response

1 business day

First response time for general support requests and technical questions

Data Backup

Daily

Automatic daily data backups, retained for a minimum of 30 days

RTO (Recovery Time)

8 hours

Maximum time to restore service after a major incident affecting platform availability

RPO (Recovery Point)

24 hours

The most recent data point guaranteed to be recoverable in a system-failure scenario

Incident Notification

≤ 2 hours

Maximum time to notify Customers once an availability incident is identified

* All SLAs are measured monthly and apply from the subscription activation date.

Who Needs ComplianceSphere?

This platform is designed to address the real pain points of different roles across the organization.

01

Compliance Manager / GRC Lead

Juggles obligations from multiple frameworks in spreadsheets and loses track of evidence every time an auditor asks for documents.

02

CISO / Head of Information Security

Needs one trustworthy number to answer the board's question: how compliant are we today, and where are the biggest gaps?

03

Legal / Corporate Secretary

Must ensure UU PDP and sector regulations are monitored, but has no visibility into the status of technical implementation.

Frequently Asked Questions

Still have questions about ComplianceSphere? Reach out to our team via the contact page or the footer.

How is ComplianceSphere different from RiskSphere?

They complement each other from different angles. RiskSphere starts from risk: identification, assessment, and treatment plans — including a draft SoA from the risk-treatment side (Clause 6.1). ComplianceSphere starts from obligations: the regulatory register, full SoA lifecycle, cross-framework control mapping, and a continuous compliance score. Used together, risk treatments in RiskSphere feed control status in ComplianceSphere.

Which frameworks are supported?

ISO/IEC 27001, ISO/IEC 27701, ISO 31000, NIST CSF, and UU PDP ship as built-in libraries. You can also add custom frameworks — such as OJK/BI sector regulations or security requirements from enterprise customers — and map them to the same controls library.

How does mapping one control to many frameworks work?

Each control in the library can be linked to requirements in several frameworks at once. When you attach evidence and update that control's status, every framework that maps to it updates too — one piece of work satisfies many requirements.

Does ComplianceSphere help with certification audit preparation?

Yes. An always-current SoA, evidence traceable per control, assessment history, and the audit log are exactly the artefacts auditors request. Organizations that maintain continuous compliance in ComplianceSphere cut audit preparation from weeks to days.

How long does ComplianceSphere implementation take?

Typically 2–4 working weeks, covering framework selection, import of existing obligations and controls, and team training. The Cloudsphere team supports the full setup — including migrating your current SoA and compliance register from spreadsheets.

Ready to Try ComplianceSphere?

Schedule a free demo and see firsthand how ComplianceSphere can simplify compliance management in your organization.