Certification support

Compliance-ready delivery evidence for confidential files

Steek does not certify an organization by itself. It helps compliance, security, legal, healthcare, payment, finance, and audit teams produce defensible evidence for the controlled delivery part of ISO 27001, NIST CSF 2.0, NIS2, SOC 2, COBIT, GDPR, HIPAA, PCI DSS, and DORA programs.

Framework coverage

One delivery workflow, many audit questions

The same controlled delivery events can support multiple control families: verified identity, access restriction, protected transfer, revocation, retention, incident review, and supplier communication evidence.

ISO 27001

ISO/IEC 27001:2022 Annex A

Helps support Annex A information transfer, access, cryptography, logging, monitoring, and secure disposal evidence across the 2022 control themes.

NIST CSF 2.0

NIST Cybersecurity Framework 2.0

Maps secure delivery evidence to Govern, Identify, Protect, Detect, Respond, and Recover outcomes in CSF 2.0.

NIS2

NIS2 Directive Article 21

Supports Article 21 cybersecurity risk-management measures for secure communication, access control, cryptography, supply-chain handoffs, and incident handling.

Control mapping

Framework-by-framework support

Each row lists the framework's control or requirement ID and the specific Steek delivery evidence that can help your company satisfy that part of the control.

ISO 27001

ISO/IEC 27001:2022 Annex A

Helps support Annex A information transfer, access, cryptography, logging, monitoring, and secure disposal evidence across the 2022 control themes.

Organizational controls

Policy, asset handling, access governance, supplier delivery, incident readiness, and evidence collection.

Control

A.5.10

Acceptable use of information and associated assets

Restricts sensitive document exchange to a controlled delivery workflow instead of reusable attachments or public file links.

Control

A.5.12

Classification of information

Supports classified confidential handoffs with delivery records that do not expose plaintext content or source document metadata.

Control

A.5.14

Information transfer

Provides encrypted transfer, recipient verification, expiry, revocation, and QR handoff evidence for sensitive exchanges.

Control

A.5.15

Access control

Limits document opens to intended recipients and records access decisions for later review.

Control

A.5.16

Identity management

Ties recipient access to passkey-verified identity rather than possession of a forwarded link.

Control

A.5.24

Information security incident management planning and preparation

Gives teams delivery and access events that can be reviewed during incident triage or customer support investigations.

People controls

Human responsibilities, awareness, confidentiality obligations, and event reporting around sensitive handoffs.

Control

A.6.3

Information security awareness, education and training

Makes the preferred secure delivery behavior concrete for teams replacing email attachments.

Control

A.6.6

Confidentiality or non-disclosure agreements

Supports confidential recipient handoffs with controlled access history when NDAs or confidentiality obligations apply.

Control

A.6.8

Information security event reporting

Records delivery, open, expiry, revocation, and failed access states that can inform security reporting.

Physical controls

Physical access and media handling evidence when documents move through QR or in-person workflows.

Control

A.7.9

Security of assets off-premises

Keeps off-premises recipients in a verified open flow instead of uncontrolled local copies distributed by email.

Control

A.7.10

Storage media

Reduces dependence on removable media by supporting secure QR handoff and encrypted package delivery.

Control

A.7.14

Secure disposal or re-use of equipment

Supports revocation and expiration records when access should stop after a device, room, or process changes hands.

Technological controls

Authentication, protected data handling, cryptography, logging, monitoring, and network delivery controls.

Control

A.8.2

Privileged access rights

Separates routine delivery from administrative actions and preserves evidence of controlled recipient access.

Control

A.8.3

Information access restriction

Restricts document access to authorized recipients and eligible trusted devices.

Control

A.8.5

Secure authentication

Uses passkey recipient verification before sensitive document access continues.

Control

A.8.10

Information deletion

Supports access expiry, revocation, and incomplete upload cleanup evidence where delivery should no longer be available.

Control

A.8.12

Data leakage prevention

Replaces broad attachment distribution with expiring, recipient-bound confidential delivery.

Control

A.8.15

Logging

Creates a reviewable record of share creation, recipient access, open events, revocation, and delivery state changes.

Control

A.8.16

Monitoring activities

Makes recipient delivery and access outcomes visible for compliance and security review.

Control

A.8.24

Use of cryptography

Supports cryptography policy evidence with local encryption and versioned protection profiles for document delivery.

NIST CSF 2.0

NIST Cybersecurity Framework 2.0

Maps secure delivery evidence to Govern, Identify, Protect, Detect, Respond, and Recover outcomes in CSF 2.0.

Govern

Cybersecurity risk strategy, policy, oversight, and supplier communication outcomes.

Control

GV.OC-03

Legal, regulatory, and contractual requirements

Gives compliance teams document-delivery evidence they can map to external confidentiality and security obligations.

Control

GV.PO-01

Cybersecurity risk policy

Operationalizes a policy choice that confidential files leave the organization through controlled delivery.

Control

GV.SC-05

Supply chain cybersecurity requirements

Supports supplier and customer agreements that require protected document exchange and auditable handoff records.

Identify

Data inventory, risk assessment, improvement, and supplier-risk context.

Control

ID.AM-07

Data and metadata inventories

Helps identify controlled confidential delivery records without exposing plaintext document contents in the visible handoff.

Control

ID.RA-06

Risk responses

Documents a practical risk response for sensitive external file transfer and recipient uncertainty.

Control

ID.IM-03

Improvements from operational activities

Provides delivery outcomes and access history that can feed process improvement reviews.

Protect

Identity, authentication, access control, and data security safeguards.

Control

PR.AA-03

Users are authenticated

Requires recipient passkey verification before a sensitive document open flow continues.

Control

PR.AA-04

Identity assertions are protected and verified

Binds delivery decisions to verified recipient identity instead of link possession.

Control

PR.AA-05

Access permissions and authorizations

Supports least-privilege document access with intended recipients, expiry, and revocation.

Control

PR.DS-01

Data-at-rest protection

Keeps stored document packages encrypted so the service does not need plaintext files.

Control

PR.DS-02

Data-in-transit protection

Uses controlled encrypted delivery and expiring access paths for confidential transfer.

Detect

Monitoring and analysis of potentially adverse access or delivery events.

Control

DE.CM-03

Personnel activity monitoring

Records sender and recipient delivery actions in a form that is safe to hand to a reviewer.

Control

DE.AE-02

Adverse event analysis

Supports investigation of unexpected opens, failed validation, revocation, and token consumption events.

Respond

Incident triage, analysis, coordination, and evidence preservation.

Control

RS.MA-02

Incident reports are triaged and validated

Provides delivery records that help validate whether a document was opened, expired, or revoked.

Control

RS.AN-06

Investigation records integrity and provenance

Preserves access and delivery event history for incident investigation workflows.

Control

RS.CO-03

Information shared with stakeholders

Enables controlled sharing with designated external recipients while preserving delivery context.

Recover

Recovery communication and restoration evidence after incidents or process disruption.

Control

RC.RP-06

Incident-related documentation is completed

Helps close document-delivery incidents with a clear history of access, revocation, and final state.

Control

RC.CO-03

Recovery activities are communicated

Supports verified resending or renewed access when recovery requires a safe replacement handoff.

NIS2

NIS2 Directive Article 21

Supports Article 21 cybersecurity risk-management measures for secure communication, access control, cryptography, supply-chain handoffs, and incident handling.

Article 21(2) risk-management measures

All-hazards cybersecurity measures that include communication, access, cryptography, suppliers, and incident handling.

Control

Art. 21(2)(a)

Risk analysis and information system security policies

Supports a policy-backed move from attachments to controlled confidential delivery.

Control

Art. 21(2)(b)

Incident handling

Provides access, expiry, revocation, and open records for document-delivery incident review.

Control

Art. 21(2)(d)

Supply chain security

Controls sensitive document exchanges with suppliers, customers, and service partners.

Control

Art. 21(2)(f)

Effectiveness assessment

Gives reviewers evidence that secure delivery controls are used and producing auditable events.

Control

Art. 21(2)(h)

Cryptography and encryption

Supports encryption policy evidence for confidential file delivery without server-side plaintext access.

Control

Art. 21(2)(i)

Access control and asset management

Maps recipient verification, intended-recipient access, and revocation records to access-control procedures.

Control

Art. 21(2)(j)

Multi-factor or continuous authentication and secure communications

Uses passkey verification and protected delivery paths for high-risk external communication.

SOC 2

SOC 2 Trust Services Criteria

Helps support Security, Availability, Processing Integrity, Confidentiality, and Privacy evidence where confidential delivery is in scope.

Security

Common Criteria for logical access, operations, monitoring, change, and risk mitigation.

Control

CC6.1

Logical access security

Supports logical access evidence with recipient verification, access restriction, and encrypted document packages.

Control

CC6.2

Credentials and registration

Supports verified recipient onboarding through passkey-based identity checks.

Control

CC6.3

Access modification and removal

Provides revocation and expiry records for changing document access after delivery.

Control

CC6.7

Transmission, movement, and removal of information

Replaces uncontrolled attachments with encrypted, recipient-bound delivery and audit history.

Control

CC7.2

Security event monitoring

Records document access and delivery events for compliance and security review.

Control

CC7.3

Security event evaluation

Helps teams evaluate unexpected delivery outcomes such as failed validation, expired access, or revoked links.

Control

CC9.2

Vendor and business partner risk

Supports controlled exchange of confidential documents with customers, suppliers, and partners.

Availability

Committed availability and recovery expectations for the secure delivery workflow.

Control

A1.2

Environmental, software, data, and infrastructure recovery

Supports recovery evidence when a delivery needs to be reissued, revoked, or reopened through a controlled workflow.

Processing Integrity

Complete, valid, accurate, timely, and authorized processing commitments.

Control

PI1.4

Processing corrections

Helps correct mistaken delivery by revoking or expiring access and creating a fresh controlled handoff.

Confidentiality

Protection and disposal of information designated as confidential.

Control

C1.1

Confidential information protection

Protects confidential files with local encryption, intended-recipient access, and delivery audit trails.

Control

C1.2

Confidential information disposal

Supports expiry, revocation, and cleanup evidence for delivery access that should no longer be available.

Privacy

Personal information handling commitments when recipient or sender data is in scope.

Control

P4.1

Privacy use, retention, and disposal

Helps limit delivery metadata and retention to the evidence needed for secure document sharing.

Control

P6.1

Privacy disclosure and notification

Supports controlled disclosure to intended recipients with recipient-scoped access evidence.

COBIT

COBIT 2019

Uses COBIT governance and management objective IDs for risk, security, data, service, and compliance evidence around document delivery.

Governance objectives

Evaluate, Direct and Monitor objectives for governance system, benefits, risk, resources, and stakeholder transparency.

Control

EDM03

Ensured Risk Optimization

Supports governance decisions to reduce external document-delivery risk with verified, revocable access.

Control

EDM05

Ensured Stakeholder Engagement

Provides clear delivery evidence for stakeholders asking how confidential files are protected after sending.

Management objectives

Align, Plan and Organize; Build, Acquire and Implement; Deliver, Service and Support; Monitor, Evaluate and Assess.

Control

APO12

Managed Risk

Documents a repeatable response to the risk of uncontrolled attachments and public links.

Control

APO13

Managed Security

Supports security management with encrypted delivery, recipient verification, and auditable access events.

Control

APO14

Managed Data

Helps keep confidential document delivery aligned with data handling and metadata minimization expectations.

Control

BAI08

Managed Knowledge

Creates reusable evidence and delivery patterns teams can apply across legal, finance, HR, and customer workflows.

Control

DSS05

Managed Security Services

Supports day-to-day protected delivery with authentication, encryption, monitoring, and revocation.

Control

DSS06

Managed Business Process Controls

Adds control points to business document handoffs without forcing recipients through a heavy portal.

Control

MEA03

Managed Compliance With External Requirements

Gives compliance teams control-ID-ready evidence for external audit and customer assurance requests.

GDPR

General Data Protection Regulation

Helps legal and privacy teams evidence controlled disclosure, access limitation, encryption, breach investigation, and accountability for personal-data document handoffs.

Chapter II - Principles

Core processing principles and accountability duties for personal data handled through confidential delivery.

Control

Art. 5(1)(f)

Integrity and confidentiality

Supports appropriate security for personal-data documents with encrypted delivery, intended-recipient access, and revocation.

Control

Art. 5(2)

Accountability

Creates delivery records that help controllers demonstrate how sensitive disclosures were controlled.

Chapter IV - Controller and processor

Privacy-by-design, records, security of processing, and breach documentation obligations.

Control

Art. 25

Data protection by design and by default

Makes recipient-bound delivery, expiry, and metadata minimization part of the default document handoff.

Control

Art. 30

Records of processing activities

Provides structured delivery evidence that can support records for controlled external disclosure workflows.

Control

Art. 32(1)(a)

Pseudonymisation and encryption

Supports encryption evidence for personal-data files without requiring server-side plaintext handling.

Control

Art. 32(1)(b)

Confidentiality, integrity, availability and resilience

Adds verified access, encrypted packages, and auditable state changes to confidential document delivery.

Control

Art. 32(1)(d)

Testing and evaluating effectiveness

Gives teams measurable delivery outcomes they can review when assessing secure sharing controls.

Control

Art. 33(5)

Personal data breach documentation

Preserves delivery and access history that can help reconstruct whether a shared document was opened, expired, or revoked.

Control

Art. 34(1)

Communication of a breach to the data subject

Supports controlled follow-up communications to affected recipients when a breach response requires secure document delivery.

HIPAA

HIPAA Security Rule

Helps healthcare teams protect ePHI document delivery with access control, audit controls, integrity checks, person or entity authentication, and transmission security evidence.

Administrative safeguards

Security management, information access, awareness, and incident procedures for ePHI workflows.

Control

45 CFR §164.308(a)(1)(ii)(D)

Information system activity review

Provides access, open, expiry, and revocation records for review of ePHI delivery activity.

Control

45 CFR §164.308(a)(4)(ii)(B)

Access authorization

Supports authorized ePHI handoffs by limiting access to intended verified recipients.

Control

45 CFR §164.308(a)(5)(ii)(C)

Log-in monitoring

Captures failed or unexpected recipient verification outcomes that can inform access monitoring.

Control

45 CFR §164.308(a)(6)(ii)

Response and reporting

Gives incident responders document-delivery evidence when investigating a possible improper disclosure.

Technical safeguards

Access control, audit controls, integrity, authentication, and transmission security for electronic protected health information.

Control

45 CFR §164.312(a)(1)

Access control

Limits ePHI document access to authorized recipients and eligible open flows.

Control

45 CFR §164.312(a)(2)(i)

Unique user identification

Ties sensitive document access to a specific verified recipient rather than a forwarded link.

Control

45 CFR §164.312(a)(2)(iv)

Encryption and decryption

Supports encryption and decryption evidence for ePHI files handled through local protected delivery.

Control

45 CFR §164.312(b)

Audit controls

Records and exposes document-delivery events for authorized compliance and security review.

Control

45 CFR §164.312(c)(1)

Integrity

Supports controlled packages and access history that help detect improper alteration or unauthorized handoff states.

Control

45 CFR §164.312(d)

Person or entity authentication

Requires recipient verification before ePHI document access continues.

Control

45 CFR §164.312(e)(1)

Transmission security

Protects ePHI document transfer through encrypted, recipient-bound delivery rather than open attachments.

Control

45 CFR §164.312(e)(2)(i)

Integrity controls

Helps recipients and senders rely on controlled delivery state and audit events during transmission.

Control

45 CFR §164.312(e)(2)(ii)

Encryption

Supports encryption evidence for transmitted ePHI documents when encryption is appropriate.

Documentation requirements

Documentation retention and availability expectations for Security Rule policies and activity evidence.

Control

45 CFR §164.316(b)(1)

Documentation

Provides exportable delivery evidence that can support documented security procedures.

Control

45 CFR §164.316(b)(2)(i)

Time limit

Supports retention decisions for access evidence while document access itself can expire or be revoked.

PCI DSS

PCI DSS v4.0.1

Helps payment teams replace account-data attachments with controlled, encrypted, auditable delivery when payment documents fall inside PCI DSS scope.

Protect account data

PCI DSS requirements for protecting stored account data and transmissions over open public networks.

Control

Req. 3.5.1

PAN is rendered unreadable wherever it is stored

Supports encrypted package evidence for payment documents while the organization remains responsible for PCI scope and PAN handling.

Control

Req. 4.2.1

Strong cryptography during transmission

Replaces payment-document attachments with protected, recipient-bound transfer and expiring access paths.

Implement strong access control measures

Business-need access, user identification, authentication, and multi-factor access requirements.

Control

Req. 7.2.1

Access model defined and documented

Supports a documented pattern where only intended recipients can open payment-related documents.

Control

Req. 8.2.1

Unique ID before access

Binds access evidence to a verified recipient instead of shared mailbox or forwarded-link possession.

Control

Req. 8.3.1

User access protected by authentication factors

Uses passkey recipient verification before sensitive payment document access continues.

Control

Req. 8.4.2

Multi-factor authentication for access into the CDE

Can support phishing-resistant recipient verification where the delivery workflow is treated as in scope by the assessor.

Regularly monitor and test networks

Audit logging, audit log contents, and review evidence for cardholder-data workflows.

Control

Req. 10.2.1

Audit logs enabled and active

Records share creation, recipient access, failed opens, expiry, and revocation events for payment-document delivery.

Control

Req. 10.3.1

Audit log entries include user identification

Provides recipient and sender context for authorized delivery-event review.

Control

Req. 10.4.1

Audit logs are reviewed

Gives compliance teams delivery events they can include in routine payment-data access review.

Maintain an information security policy

Scope, acceptable use, incident response, and service-provider evidence expectations.

Control

Req. 12.5.2

PCI DSS scope documented and confirmed

Helps document whether payment-document delivery is inside or outside the assessed cardholder data environment.

Control

Req. 12.10.1

Incident response plan

Provides delivery evidence that can help investigate suspected payment-data disclosure incidents.

Control

Req. 12.10.7

Incident response procedures are reviewed and updated

Supports post-incident review with concrete access, expiry, and revocation outcomes.

DORA

Digital Operational Resilience Act

Supports EU financial entities with evidence for ICT risk management, protection, detection, incident handling, and third-party document exchange under Regulation (EU) 2022/2554.

Chapter II - ICT risk management

Risk-management framework, protection, prevention, detection, response, recovery, learning, and communication requirements.

Control

Art. 6

ICT risk management framework

Supports a controlled delivery control within the ICT risk framework for confidential external documents.

Control

Art. 8

Identification

Helps identify sensitive delivery workflows and the records needed to govern them.

Control

Art. 9

Protection and prevention

Adds encryption, recipient verification, expiry, and revocation to prevent uncontrolled disclosure.

Control

Art. 10

Detection

Makes unexpected access, failed verification, and unusual delivery states visible for review.

Control

Art. 11

Response and recovery

Supports revoking, expiring, or reissuing secure delivery after a document-sharing incident.

Control

Art. 12

Backup policies and restoration

Supports controlled replacement handoffs when business recovery requires a document to be resent.

Control

Art. 13

Learning and evolving

Provides delivery outcomes that can feed lessons learned and control-improvement reviews.

Control

Art. 14

Communication

Supports secure communications with customers, counterparties, and regulators when confidential files must be exchanged.

Chapter III - ICT-related incident management

Incident classification, reporting, and notification evidence for ICT-related incidents.

Control

Art. 17

ICT-related incident management process

Provides access and delivery-event evidence for classifying document-sharing incidents.

Control

Art. 18

Classification of ICT-related incidents

Helps determine whether a failed, revoked, or unexpected document access event affects confidentiality.

Control

Art. 19

Reporting of major ICT-related incidents

Preserves delivery history that can support incident reports when a document-sharing event is reportable.

Chapter V - ICT third-party risk

General principles for ICT third-party risk where confidential documents move between regulated entities and providers.

Control

Art. 28

General principles

Supports controlled, auditable exchange with third parties without publishing private implementation or infrastructure details.

Audit-ready handoff

Replace attachment risk with delivery evidence

Use Steek when a sensitive document leaves your organization and the business still needs proof of identity, access control, expiry, revocation, and delivery history.

See why Steek