
Compliance framing
NIST CSF Evidence Framing
Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.
- Reproduce audit export in trial
- Download trust pack for binders
- Regional hub cross-links
United States NIST Cybersecurity Framework and 800-53 consumer mapping for remote script orchestration.
United States buyers map NIST CSF PR and DE functions to Trustholm audit export, IAM, and signing features-we do not claim FedRAMP or NIST certification.
Framework evidence framing before detailed tables below.

Compliance framing
Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.
This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.
United States buyers evaluating MSP script orchestration often map NIST Cybersecurity Framework (CSF) functions and NIST SP 800-53 control families to SaaS subprocessors. Trustholm is a remote management and script execution platform-not a certified cloud service offering.
We supply consumer-side evidence for identify-protect-detect themes while your organization owns SSP content, continuous monitoring, and third-party risk management outcomes.
PR.AC (Access Control): Portal users authenticate via JWT sessions with tenant binding for authenticated principals. Users and roles UI supports RBAC within tenant scope. MFA flows apply to privileged portal access where configured. SSO integrates via OIDC and SAML-your IdP remains the lifecycle authority for identities.
PR.DS (Data Security): Schema-per-tenant PostgreSQL separation namespaces tenant data. API middleware returns 403 when resolved tenant does not match JWT TenantId for portal users. Agents use tenant code headers and per-agent polling credentials-distinct from human SSO paths.
PR.IP (Information Protection): Signed PowerShell policy executes before run. Script publish and approve events land in the security audit plane with export for assessor windows.
DE.AE (Anomalies and Events): Security audit export provides JSON/CSV with category and datetime filters within documented row caps. HTTP request logs enriched with tenant_id support operational chargeback-they are not a substitute for security audit categories in compliance narratives.
DE.CM (Continuous Monitoring): Super Admin operators observe distributed rate limiting and health signals. Your team owns infrastructure monitoring, vulnerability management, and SIEM forwarding policies. Native Microsoft Sentinel connector remains backlog-do not imply shipped SIEM automation.
Include audit export slices, IAM screenshots, and Shipped/Gap evidence tables in your customer-facing vendor appendix. vCISOs pair our artifacts with pentest results, vulnerability scans, and customer-operated controls. When questionnaire authors ask for FedRAMP or NIST moderate baseline certification, clarify that Trustholm provides technical enabler artifacts-not authorization badges.
Gap honesty: FedRAMP authorization, hash-chain audit immutability, and native SIEM connectors are documented gaps. Your assessor validates control design and operating effectiveness in your environment and system boundary.
Engage security@trustholm.com during trial for control mapping workshops scoped to your deployment. Use this page as evidence framing-not proof of vendor certification.
| Topic | Evidence | Status | Notes |
|---|---|---|---|
| PR.AC identity management | Portal users/roles, JWT sessions, MFA, SSO callbacks | Shipped | - |
| PR.DS data security | Schema-per-tenant PostgreSQL; tenant-bound API access | Shipped | - |
| DE.AE security monitoring | Security audit export JSON/CSV; Event Hub/DCR sink; HTTP logs with tenant enrichment | Shipped | Splunk/Datadog native sink templates remain backlog |
| Vendor NIST 800-53 moderate baseline | Consumer maps controls in SSP; we supply artifact tables | Partial | - |
| FedRAMP authorization | Not claimed | Gap | - |
No. We provide evidence artifacts for customer assessments. FedRAMP authorization is not claimed on marketing pages.
Most directly: Protect (access control, data security) and Detect (audit export, monitoring hooks). Exact mapping depends on your system boundary.
Yes-security audit export supports assessor review. Pair with your log retention and review procedures documented in the SSP.
No. JSON/CSV export ships today; native Sentinel connector is backlog. Forward exports to your SIEM with deployment-specific pipelines.
As vendor evidence in customer vendor appendices-not as product certification. Your customer owns assessment outcomes.
FedRAMP, WORM audit immutability, native SIEM connectors, and customer-operated infrastructure monitoring outside the product.