PCI-DSS, SOC 2, HIPAA, ISO 27001, GDPR — all of them care how you manage keys and certificates. TigerTrust captures the evidence continuously and generates the reports your auditors ask for.
Compliance teams spend weeks chasing spreadsheets, exporting CSVs from three CAs, and negotiating with infra teams for evidence. One missing renewal record and the auditor writes a finding.
Every certificate action — request, approval, issuance, deployment, revocation — recorded with actor, source IP, and cryptographic chain. Nothing can be quietly modified.

Central policy engine enforces algorithm strength, validity limits, name constraints, and approved CA lists. Violations are blocked at request time, not caught at audit time.

Generate a PCI-DSS 4.0 pack, a SOC 2 CC6 evidence bundle, or an ISO 27001 A.8.24 report on demand. Each report is signed, timestamped, and mapped to specific control language.

A dashboard that answers the auditor's question before they ask it: what percent of your inventory meets policy right now, and what needs remediation?

Stop building crosswalks by hand. TigerTrust ships with control mappings for the frameworks that touch cryptographic controls.
From customer audits
Selected cryptographic controls across the five most-common frameworks and the TigerTrust capability that covers each.
| Control | Requirement | TigerTrust Capability |
|---|---|---|
| SOC 2 CC6.1 | Logical access controls restrict access to authorised users, systems, and data. | RBAC on issuers, keys, and templates; SSO/MFA-enforced approval workflows. |
| SOC 2 CC6.6 | Restrict transmission and movement of information to authorised systems. | Enforced mTLS via issuance policy; disallow weak ciphers at the CA layer. |
| SOC 2 CC6.7 | Encrypt data in transit using approved cryptographic methods. | Algorithm allow-lists (RSA-2048+, ECDSA P-256+); TLS 1.2+ certificates only. |
| ISO 27001 A.5.31 | Legal, statutory, regulatory, and contractual requirements are identified and documented. | Region-scoped policy sets; residency-aware issuance; regulator-facing reports. |
| ISO 27001 A.8.24 | Rules for the effective use of cryptography, including key management, are defined and implemented. | HSM-backed key generation, custody, rotation, and revocation with full lineage. |
| PCI-DSS 4.0 Req 4 | Protect cardholder data with strong cryptography during transmission over open networks. | TLS 1.2/1.3 enforced; weak cipher blocklist; discovery of legacy endpoints. |
| PCI-DSS 4.0 Req 6 | Develop and maintain secure systems and software; manage vulnerabilities. | Certificate inventory tied to CVEs (Debian OpenSSL, ROCA, etc.) with auto-rotation. |
| HIPAA §164.312(a)(2)(iv) | Implement a mechanism to encrypt and decrypt electronic protected health information. | PHI-scoped issuance profiles, mandatory HSM key storage, BAA-covered ops. |
| HIPAA §164.312(e)(1) | Implement technical security measures to guard against unauthorised access to ePHI during transmission. | mTLS between clinical systems; automated rotation without transmission gaps. |
| GDPR Article 32 | Implement appropriate technical measures, including encryption of personal data. | Residency-aware CAs, pseudonymisation-ready certificates, DPO evidence packs. |
“PCI, SOC 2, ISO 27001 — three frameworks, three auditors, one evidence pipeline. We stopped screenshotting spreadsheets and started closing findings.”
Ships evidence into the SIEM, GRC, and ticketing tools your compliance team already runs on.
Continuous posture, framework mapping, and evidence packs.
Federated tenants, delegated admin, and global operations.
FedRAMP, FISMA, NIST 800-53, and CMMC 2.0 coverage.
PCI-DSS, PSD2, SOX, and SWIFT CSP framework alignment.