Custom frameworks

Turn any set of security requirements into a custom framework you can test.

Customer addenda, internal security standards, and industry rules rarely match a certification exactly. A dedicated SecureSlate compliance lead turns those requirements into controls, maps them to the SOC 2, ISO 27001, or other controls you already run, and builds only what is missing, while our compliance automation platform tests them alongside every other framework. One fixed price covers the work.

Example addendum32 requirements

Example addendum: 32 requirements, 4 Governance, 6 Access control, 5 Data protection, 4 Vulnerability management, 4 Incident response, 3 Business continuity, 3 Subprocessors, 3 Assurance. 12 highlighted: Covered by your SOC 2 or ISO 27001 controls.

Covered by your SOC 2 or ISO 27001 controlsMapped with your compliance lead
Built from
Contracts, internal standards, and industry rules
Structure
Requirements, controls, tests, and evidence
Reuses
Controls from every framework you already run
The standard

A custom framework turns requirements no standard covers into controls you can test.

Enterprise contracts, internal security standards, industry codes of practice, and regional rules often come with requirements no certification maps exactly. A custom framework gives them the same structure as SOC 2 or ISO 27001: requirements, owners, controls, tests, and evidence.

Your requirements, structured

Each requirement becomes a control with an owner, a description, and the frameworks it maps to. Controls can be imported in bulk from a spreadsheet or added one at a time, and custom items sit in the same Controls table as every standard framework.

Reuse before you rebuild

Most customer and internal requirements overlap with controls you already run for SOC 2, ISO 27001, or HIPAA. Mapping them to those controls means one test and one piece of evidence can count toward several frameworks at once.

Evidence anyone can follow

Custom tests hold the evidence for anything an integration cannot check, with notes for auditors, and custom policies create their own tests automatically, so ownership and review dates are tracked.
How it works

We turn your requirements into a custom framework, then keep it tested like every other.

Four stages from the scoping call to a framework you can report on, with a named compliance lead accountable at every one.

Collect the requirements

We gather the contract clauses, security addenda, questionnaires, and internal standards you need to meet, and agree which ones belong in the framework and how they should be grouped.

Map to what you already run

Your compliance lead matches each requirement to existing controls from your SOC 2, ISO 27001, or other programs, and marks the requirements that need something new.

Build the missing controls and tests

New controls, custom tests, and policies are added for the gaps, with owners assigned and evidence connected through integrations or uploads.

Monitor and report

Controls are tested continuously alongside your other frameworks, so you can show a customer or auditor where each requirement stands at any time, and update the framework when a contract renews.
What is included

Everything a custom framework needs to hold up in a customer review.

Custom framework software and the expert who builds it arrive together under one fixed price, so bespoke requirements do not end up in a spreadsheet nobody maintains.

A dedicated compliance lead

One experienced practitioner turns contract language and internal standards into clear controls, maps them to your existing programs, and answers customer follow-up questions, so your team reviews instead of translating clauses.

Controls imported or added by hand

Bring requirements in from a spreadsheet or add them one at a time, each with an owner, a description, and the frameworks it maps to, marked as custom in your Controls table.

Custom tests and evidence

Evidence for requirements no integration can check, uploaded to custom tests with notes for auditors and linked to every control it supports.

Your own policies

Internal policies added to the Policy Library with an owner, mapped frameworks, and a next review date, each with a test created automatically so review and approval are tracked.

Evidence from the stack you already run

Controls shared with SOC 2, ISO 27001, or any framework you run are tested continuously through integrations, so custom requirements get the same automation.

Faster customer security reviews

Answer security questionnaires from the controls and evidence behind your custom framework, instead of starting from a blank spreadsheet each time a customer asks.
Reuse from SOC 2 and ISO 27001

In this example, 12 of 32 custom framework requirements map to controls you already run.

The addendum above is typical of what enterprise customers send. If you hold SOC 2 or ISO 27001, these requirements map straight to controls you already test, and your compliance lead builds only the rest.
GV2, GV3, GV4 map to SOC 2 CC2.2 and CC5.3, ISO 27001 5.1 and 6.3

Policies and training

Your information security policy, its annual review, and awareness training records already exist for your audit, so these requirements need a mapping, not new work.
AC2, AC3, AC4, AC6 map to SOC 2 CC6.1 to CC6.3, ISO 27001 5.16, 5.18, and 8.5

Access control

Multi-factor authentication, unique accounts, quarterly access reviews, and leaver removal are tested continuously for SOC 2 and ISO 27001 already.
DP1, DP2 map to SOC 2 CC6.1 and CC6.7, ISO 27001 8.24

Encryption

Encryption in transit and at rest is already checked against your cloud configuration, so the same evidence answers the customer's clause.
IR1 map to SOC 2 CC7.4, ISO 27001 5.24

Incident response plan

The incident response plan your auditor reviews covers the customer's requirement too. Notification times and customer reports are the parts that stay custom.
BC1 map to SOC 2 A1.2, ISO 27001 8.13

Backups

Backup configuration and restore tests are already evidenced where availability is in your SOC 2 scope or backup is in your ISO 27001 controls.
SP2 map to SOC 2 CC9.2, ISO 27001 5.19 to 5.22

Vendor security reviews

Vendors that handle customer data already go through your third-party risk process, so the addendum's review requirement maps straight to it.
Beyond Custom Frameworks

A custom framework that works alongside the standards you already run.

Custom frameworks share controls with every framework on the platform, so the same evidence can serve a customer addendum and a certification audit.

SOC 2

The most common foundation. Access, change, vendor, and incident controls from your SOC 2 program cover much of a typical customer addendum.

ISO 27001

Annex A controls map to most contractual security clauses, and the ISMS gives custom requirements an owner, a review cycle, and internal audit.

HIPAA

Healthcare customers add terms that go beyond HIPAA's minimum. A custom framework tracks those terms next to your HIPAA safeguards.

NIST CSF

Internal security standards often borrow the CSF's structure. Track them as a custom framework and keep your CSF alignment visible.

ISO 42001

Customer AI addenda ask about model use, training data, and human oversight. ISO 42001 controls answer much of it, and the rest can stay custom.

DORA

Financial customers send DORA contract terms. Track them as a custom framework on top of the ICT risk controls you already run.
Related guides

Where custom framework requirements usually come from

Three places most custom frameworks start: programs that span several standards, customer security questionnaires, and vendor contracts.

Multi-framework
Best multi-framework compliance platforms in 2026, and how they share controls
Questionnaires
Answer customer security questionnaires from the controls you already run
Contracts
Build a third-party vendor management policy that holds up in contracts
Resources

Read up before your scoping call.

Practical guides and tools for building a program that spans standard and custom requirements.

FAQs

What teams ask before building a custom framework.

Find out what your custom framework will take

Bring the contract, addendum, or internal standard you need to meet. You will leave the call with a mapping to your existing controls, a gap summary, and a fixed price, whether or not you work with us.

Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?