Controls library · 12 frameworks · 14 control domains
Every product we sell is mapped to NIST 800-53, ISO 27001, SOC 2, NIS2, CMMC, and CIS Controls v8. Use this library to justify hardware purchases against your audit requirements or build a compliant stack from scratch.
Supported frameworks
Browse controls by framework, or scroll down to see the full cross-framework mapping.
NIST SP 800-53 Rev 5
Security and privacy controls for federal information systems. Baseline for FedRAMP, DoD, and regulated US industries. The most granular US control catalog.
Federal agencies, defense contractors, FedRAMP ISVs
View 14 controlsNIST Cybersecurity Framework 2.0
Voluntary risk management framework widely adopted by US enterprises. Updated in 2024 to add a Govern function and expand supply chain guidance.
All US organizations, increasingly global
View 14 controlsISO/IEC 27001:2022
International standard for information security management systems. Globally recognized certification. 2022 revision reorganized Annex A controls around four themes.
Global enterprises, EU market, APAC, financial services
View 14 controlsSOC 2 (AICPA Trust Services Criteria)
AICPA audit standard for service organizations. Enterprise buyers increasingly require SOC 2 Type II. Five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, Privacy.
SaaS providers, cloud services, B2B service organizations
View 14 controlsEU NIS2 Directive (2022/2555)
EU mandatory cybersecurity directive for essential and important entities. Effective October 2024. Covers endpoint security, supply chain, incident response, and management accountability.
EU-operating organizations in energy, transport, health, finance, digital infrastructure
View 14 controlsCybersecurity Maturity Model Certification 2.0
DoD certification required for all prime and sub-contractors handling CUI. Level 2 maps to NIST 800-171. Hardware controls are a key differentiator in assessments.
US defense industrial base, DoD prime and sub-contractors
View 14 controlsPCI DSS v4.0.1 (Payment Card Industry Data Security Standard)
Mandatory for any organization that stores, processes, or transmits cardholder data. v4.x is the only active version; the 51 future-dated requirements became mandatory on 31 March 2025. Uniquely, PCI is explicit about phishing-resistant authentication: under Req 8.4.2 a FIDO2 authenticator can stand alone in place of MFA — the only major framework that credits hardware keys this directly.
Merchants, payment processors, service providers, any e-commerce operator
View 11 controlsHIPAA Security Rule (45 CFR Part 164, Subpart C)
Technical, physical, and administrative safeguards for electronic protected health information. Mappings here are to the CURRENT rule in force. The December 2024 NPRM would add an explicit MFA mandate and remove the "addressable" status from encryption — but it is still a proposed rule: OCR received ~5,000 comments, and the federal agenda now shows final action no earlier than July 2027. Nothing on this page treats the proposal as a requirement.
Covered entities, business associates, health-tech vendors
View 13 controlsEU Digital Operational Resilience Act (Regulation (EU) 2022/2554)
Binding EU regulation for financial entities, applicable since 17 January 2025. Article 9 requires strong authentication for remote and privileged access and protection of data at rest, in use, and in transit. Detailed requirements are set by the ICT risk management RTS, Commission Delegated Regulation (EU) 2024/1774.
EU banks, insurers, investment firms, crypto-asset providers, and their ICT suppliers
View 10 controlsASD Essential Eight Maturity Model (November 2023)
The Australian Signals Directorate's prioritized baseline — eight mitigation strategies across four maturity levels. The November 2023 revision bolstered MFA to require PHISHING-RESISTANT MFA, citing FIDO2/WebAuthn by name, and pulled that requirement down to a lower maturity level. Only eight strategies exist, so most hardware domains here are simply outside its scope.
Australian government entities and their suppliers, AU critical infrastructure
View 2 controlsUK NCSC Cyber Essentials — Requirements for IT Infrastructure v3.3 (April 2026)
UK government-backed certification, required for many public-sector contracts. Five technical control themes. v3.3 applies to assessments registered from 26 April 2026 and defines passwordless authentication explicitly around "FIDO2 authenticators… security keys or tokens", with "a physically separate token" listed as an accepted MFA factor.
UK organizations, public-sector suppliers, MOD supply chain
View 4 controlsCIS Critical Security Controls v8
Prioritized set of cybersecurity best practices. Three implementation groups mapped to organization size. Widely used as a practical baseline independent of regulatory requirement.
All organizations, security teams, SMBs
View 14 controlsCross-framework control mapping
One security concern, mapped across every framework we support.
Each row is a security domain our hardware addresses. Columns show the equivalent control ID in each framework. Use this to satisfy multiple audit requirements with a single hardware purchase.
Control domain details
What each domain covers and which products satisfy it.
Phishing-resistant MFA using hardware security keys. Software TOTP and SMS are explicitly excluded from "phishing-resistant" in NIST 800-63B and most modern framework guidance.
Products that satisfy this control:
Hardware-bound key generation and storage. Private keys generated and stored inside a certified secure element (EAL 6+) and are non-exportable by design — for login credentials (Nitrokey) and crypto-asset custody (Ledger) alike.
Products that satisfy this control:
Hardened mobile OS with per-app sensor controls, verified boot, and no background telemetry. Satisfies mobile device management and bring-your-own-device security requirements.
Products that satisfy this control:
Measured boot chain verified on every power-on. Any firmware modification — supply chain implant, evil-maid attack, or malicious update — fails attestation before the OS loads.
Products that satisfy this control:
VM-level compartmentalization means a compromise of one domain (e.g. browser) cannot reach another (e.g. keys, vault). No other consumer laptop provides this by default.
Products that satisfy this control:
Stateful firewall with IPS at the network perimeter. All inbound/outbound traffic inspected with Suricata rule sets. VPN gateway replaces consumer VPN dependency.
Products that satisfy this control:
Hardware-encrypted storage and self-hosted file servers replace cloud storage with hardware you control. Encryption keys never leave your environment.
Products that satisfy this control:
Open-source firmware is publicly auditable and reproducibly built. EU jurisdiction hardware is not subject to US National Security Letters. Directly addresses hardware supply chain risk in CMMC and NIS2.
Products that satisfy this control:
Intel Management Engine disabled at the firmware level across every open-firmware machine we carry (NitroPad, NitroPC, PrivacyGuard, SecurityTitan); SecurityTitan models go further — camera and microphone physically removed, anti-tamper seals verified by Heads + Nitrokey attestation. Least functionality, enforced in hardware.
Products that satisfy this control:
Rated safes and vaults protect physical assets, documents, and hardware backups with UL-certified burglary ratings — from UL 1037 RSC (residential) up to UL 687 TL-15/TL-30 vault-grade for insurance-mandated or enterprise specialty storage (the tier insurers and auditors recognize; see the ratings ladder on /safe). SecurityTitan laptops extend physical protection to devices in transit: glitter-sealed tamper-evident screws with photographic verification make case intrusion detectable.
UL 72 fire-rated safes keep interiors under 350°F through 30-minute to 4-hour furnace exposure — plus explosion and 30-foot drop tests — so original records, storage media, seed-phrase plates, and offline backups survive a facility fire. Distinct from burglary protection: enterprises with records-retention or continuity obligations typically need BOTH ratings on one unit (dual-rated Gardall UL line or TL-rated composite safes — see /safe).
Products that satisfy this control:
Encrypted LoRa mesh radios (Meshtastic / MeshCore / Reticulum) move text and GPS with no cellular, WiFi, internet, or subscription — every node relays for every other, on FCC Part 15 unlicensed 915 MHz spectrum. The out-of-band channel for disaster response, incident communications when primary networks are down or untrusted, remote sites, and executive contingency plans.
Products that satisfy this control:
MIL-STD 188-125 / IEEE 299-tested Faraday shielding (80+ dB) physically severs every radio — cellular/5G, WiFi, Bluetooth, GPS, RFID, NFC — so devices cannot be tracked, remotely wiped, or exfiltrated over RF. Covers executive travel through hostile networks, forensic chain-of-custody transport (a seized phone that must not phone home), and anti-relay protection for keyless-entry fobs.
Products that satisfy this control:
Verified boot ensures the TLS stack is unmodified before communication. VPN gateway encrypts all remote access traffic. Hardware-backed keys prevent interception even if endpoints are observed.
Products that satisfy this control: