Compliance
Amnify maps its security checks to industry compliance frameworks, giving you visibility into which requirements you’re meeting and which need attention.Supported frameworks
Amnify supports a comprehensive set of compliance frameworks, varying by cloud provider:| Framework | AWS | Azure | GCP | M365 |
|---|---|---|---|---|
| CIS Benchmarks | Yes | Yes (v2.0–5.0) | Yes | Yes |
| SOC2 | Yes | Yes | Yes | — |
| PCI-DSS | Yes | Yes | Yes | — |
| ISO 27001 | Yes | Yes | — | — |
| HIPAA | Yes | Yes | — | — |
| NIST 800-53 | Yes | Yes | — | — |
| MITRE ATT&CK | Yes | Yes | — | — |
| NIS2 | — | Yes | — | — |
Framework availability depends on your cloud provider and is continuously expanding.
Compliance overview page
The overview page shows all evaluated frameworks at a glance:- Frameworks scanned — Total number of frameworks evaluated
- Total checks — Number of security checks mapped to compliance requirements
- Passing checks — How many are currently passing
- Overall pass rate — Your aggregate compliance rate
Framework detail page
Drill into any framework to see detailed requirement-level status:- Each requirement lists its mapped security checks and their pass/fail status
- Requirements are grouped by section and subsection (e.g., “2.1.1 Ensure Databricks Workspace…”)
- CIS benchmarks show Level 1 vs Level 2 profile distinctions
- Each requirement indicates whether assessment is Automated or Manual
How compliance scoring works
- Each compliance requirement maps to one or more Amnify security checks
- When a scan completes, results are cross-referenced with compliance requirements
- A requirement passes only if all its mapped checks pass
- A single failing check causes the entire requirement to fail
Using compliance data
- Audit preparation — Use the framework detail view to identify gaps before an audit
- Prioritize remediation — Focus on failing requirements for your most critical frameworks
- Track progress — Run regular scans and monitor compliance improvement over time
- Export evidence — Use the PDF export to generate reports for auditors