Control-by-control mappings of SimpliKeys IAM capability across eight frameworks — not a checklist in a PDF, a live mapping you can explore.
SimpliKeys is a single unified platform: the capabilities described below are facets of one system applied to each control, not separate products. It protects every identity with the same vaulting, brokering and session recording, and applies strong authentication from a configurable spectrum of factors that can be targeted per system, chained, and stepped up within a session.
Every rating below holds only to the extent of two things: (1) breadth — the scope of the environment SimpliKeys is protecting; a control is supported only where SimpliKeys sits in the access path, not for systems outside its reach; and (2) depth — how SimpliKeys is configured. The analysis assumes SimpliKeys is deployed and configured as the central authentication manager for the in-scope environment.
Entries describe summarised SimpliKeys capability under common circumstances and when appropriately configured. They do not represent verified or certified behaviour.
Reference version: 2017 TSC (revised points of focus, 2022) · Prepared mid-2026 · Capability mapping, not a compliance attestation
Reference version: ISO/IEC 27001:2022 (incl. Amd 1:2024) · Prepared mid-2026 · Capability mapping, not a compliance attestation
Reference version: NIST CSF 2.0 (Feb 2024) · Prepared mid-2026 · Capability mapping, not a compliance attestation
NIST SP 800-53 Rev 5 (Release 5.2.0) · Prepared mid-2026 · Capability mapping, not a compliance attestation
Reference version: PCI DSS v4.0.1 · Prepared mid-2026 · Capability mapping, not a compliance attestation
Current HIPAA Security Rule (45 CFR Part 164, Subpart C) · Prepared mid-2026 · Capability mapping, not a compliance attestation
Regulation (EU) 2024/1689 · Prepared mid-2026 · Operational capability view, not legal advice or a compliance assertion
CIS Controls v8.1 (June 2024) · Prepared mid-2026 · Capability mapping, not a compliance attestation
Every mapping is a capability view, not a compliance attestation, certification, or legal advice — each page carries its own scope, coverage legend, and customer responsibilities. Confirm against your environment and your auditor, assessor, or counsel before relying on it.
30 minutes against a real environment — we’ll walk your controls line by line.
Book demo