ComplianceDL Winter Release: Evidence Automation and Custom Frameworks
Since launching Continuous Control Monitoring last summer, one request has topped every customer conversation: go further. Automate more of the evidence lifecycle, and let us bring our own requirements — not just the big-name frameworks — into the same system. The Winter Release delivers both, along with upgrades across policies and audit management.
Here’s what’s new.
Evidence Automation 2.0
Evidence collection has been rebuilt end to end.
Scheduled collection from every integration
Evidence tasks can now pull directly from any connected integration on a recurring schedule — access listings from your identity provider, configuration snapshots from your cloud accounts, training completion records from your HR system, ticket samples from your issue tracker. Each artifact lands with a timestamp, source, collection method, and a cryptographic hash, so provenance is never in question.
Evidence reuse across frameworks and audits
Collect once, satisfy everywhere. An access review collected for SOC 2 CC6 now automatically attaches to the corresponding ISO 27001 Annex A controls, HIPAA access management requirements, and PCI DSS account management requirements — anywhere your control mapping says it applies. Customers running multiple frameworks in early access reported cutting evidence effort roughly in half.
Freshness policies and gap alerts
Define how recent each evidence type must be — 90 days for access reviews, 30 days for vulnerability scans, a year for policy acknowledgments. ComplianceDL tracks freshness continuously and alerts owners before evidence expires, so audit prep stops being a race against staleness.
Custom Frameworks
ComplianceDL has always shipped deep support for SOC 2, ISO 27001, HIPAA, GDPR, and PCI DSS. But real programs don’t stop at the standard list: internal security baselines, customer contractual requirements, regional regulations, industry questionnaires.
With Custom Frameworks, you can now:
- Build a framework from scratch with your own domains, requirements, and guidance text
- Import requirements from a structured spreadsheet to get started in minutes
- Map requirements to your existing controls, so current evidence and monitoring coverage apply immediately
- Track readiness with the same dashboards, ownership, and reporting as any built-in framework
One early-access customer, a payments infrastructure team, modeled their largest customer’s 300-item security addendum as a custom framework and discovered 85 percent of it was already satisfied by controls they were monitoring. The remaining gaps became a tracked project instead of an annual scramble.
Also in this release
Policy workflows, upgraded
Policy management gains version comparison, delegated approvals, and campaign-based acknowledgments. Send a policy update to exactly the affected teams, watch acknowledgment rates in real time, and export the completion record as evidence with one click.
Auditor workspaces
Give your audit firm scoped, read-only access to exactly the frameworks, controls, and evidence in the engagement — nothing else. Auditors can leave requests and comments inline, and every action is logged. Early users report meaningfully fewer back-and-forth evidence requests per audit.
Reporting refresh
New executive reports summarize posture by framework, evidence freshness, open risks, and remediation velocity — exportable as board-ready PDFs or scheduled straight to stakeholders’ inboxes.
Availability
- Evidence Automation 2.0 is rolling out to all plans over the next two weeks; scheduled collection and freshness policies are included everywhere, with advanced reuse mapping on Growth and Enterprise.
- Custom Frameworks is available today on Growth and Enterprise plans — Growth includes up to three custom frameworks, Enterprise unlimited.
- Auditor workspaces and the reporting refresh are live now on all plans.
No action is required to upgrade: features appear in your workspace automatically as the rollout reaches your region. Head to /platform for a full tour, or /plans to compare tiers.
This release reflects a simple belief: compliance teams shouldn’t spend their time collecting proof of work that already happened. With evidence that gathers itself and frameworks that flex to your actual obligations, that time goes back where it belongs — improving the program, not documenting it.