THE COMPLIANCE WIRE
2026 / CYBERNINES ACQUISITION EXPANDS FEDERAL WORK2026 / ISO 42001 ACCREDITATION ADDS AI MANAGEMENT CERTIFICATIONONEAUDIT / ASSESS ONCE, COMPLY TO MANY
COMPANY / SECURITY & COMPLIANCEFIELD NOTES № 01

ControlCase and the art of doing the audit once

Every new security standard can bring another request for the same evidence. ControlCase has built a business around a sensible objection: why collect it twice?

A password policy is a small, dreary document with an unusually busy social life. In ControlCase’s published OneAudit example, evidence about account lockouts, session timeouts and password settings answers questions across six security frameworks. The document has not become more interesting. It has become more useful. That distinction explains much of this company’s appeal.

THE QUICK READ
  • OneAudit maps shared evidence across multiple compliance frameworks.
  • Continuous Compliance checks what changes between assessments.
  • Free GRC software sits alongside paid testing, assessment and managed services.

For a security team, an audit can resemble a dinner party where every guest requests the same story separately. PCI DSS asks about access. ISO 27001 asks about access. Other frameworks arrive with their own vocabulary. Each request has a purpose; the repeated preparation can still consume the people meant to keep the systems safe.

01 / The same question in six costumes

ControlCase’s response is OneAudit, publicly announced in April 2015. Its method combines software, hosted tools and managed services to collect evidence and map controls across standards. A consolidated questionnaire helps organize the work. Dashboards show progress. Automated collection can gather cloud evidence. The appeal is procedural: fewer repeated requests, fewer disconnected schedules, less time spent reconstructing an answer already given.

Consider that password example. ControlCase’s table connects one evidence request to PCI DSS, ISO, SCA, SOC 2, HIPAA and NIST 800-53 requirements. It is a concrete demonstration of overlap, although the published table is illustrative rather than a substitute for checking current requirements. The sensible unit of organization becomes the control and its evidence, with standards mapped onto it.

The slogan is handsome: “Assess once, comply to many.” The qualification matters just as much. Reusable evidence must concern the right systems, period and requirement. Several standards can share a record without becoming interchangeable. OneAudit promises to organize the overlap; an organization still needs to satisfy the differences.

02 / A customer with three sets of demands

Verato provides a useful example. In a 2020 announcement, its information-security and compliance director, Kevin Bellrose, described using ControlCase for PCI DSS, HITRUST and SOC 2. He reported reduced preparation and execution time, costs and duplication. He also singled out a dedicated customer success manager who helped coordinate timelines and resources. The human appointment belongs beside the software feature.

“We use ControlCase One Audit to manage compliance with PCI DSS, HITRUST and SOC 2.”Kevin Bellrose · Verato · 2020

That is the customer problem in miniature: several obligations, one finite team. ControlCase serves merchants, financial institutions, healthcare businesses, cloud providers, outsourcing companies and managed service providers. Its homepage also carries testimonials from Ahold Delhaize and Washington’s transit authority. An overlapping compliance burden travels quite comfortably between a retailer, a technology supplier and a transport system.

03 / The certificate has a quieter sequel

A completed assessment records an environment at a particular time. The environment continues moving. ControlCase’s Continuous Compliance offering addresses missing logs, assets omitted from vulnerability scans, risky firewall rules and overlooked vulnerabilities. These are wonderfully unromantic problems. A server that quietly stops reporting can spoil a very polished dashboard.

The service collects and analyzes information from security systems, provides consolidated reporting and escalation, and offers remediation guidance. Quarterly reviews revisit important compliance questions and scope. Customers can choose packages with or without accompanying cybersecurity services. The working assumption is that evidence and control coverage need maintenance throughout the year.

ControlCase’s published Compliance Hub illustration showing example compliance charts
A dashboard dressed for inspection. ControlCase’s published illustration shows how scattered compliance work can acquire a common view.

Card Data Discovery tackles another awkward detail: sensitive information may be stored where nobody intended it to live. ControlCase’s scanner searches files, databases and email systems for unencrypted card and other sensitive data. A remediation dashboard identifies locations. Finding the data gives the team somewhere specific to begin; removing it or securing its storage remains real work.

04 / Free software, professional obligations

ControlCase advertises Compliance Hub as free GRC software. The wider business sells assessment, certification, testing and ongoing managed services, with engagements scoped through quotes. The entrance may be free; the professional work has a contract. That arrangement suits buyers who need both a place to organize evidence and people capable of evaluating it.

ControlCase occupies territory shared with automation platforms and assessment firms. Drata also collects evidence and maps controls across frameworks. Schellman provides independent assessments across commercial and federal requirements. ControlCase’s particular proposition combines proprietary tools, testing, assessment expertise and managed compliance. Buyers can compare the amount of operational responsibility each arrangement actually covers.

Partners extend that proposition. A ConnectWise Manage integration places Compliance Hub information inside existing company records. The OpenText partner program divides the labor: ControlCase supplies assessment and compliance expertise while MSPs deliver remediation, implementation and ongoing support. Compliance becomes work a provider can offer its customers, with a visible division of responsibilities.

The expertise behind those services comes from hands-on audit, compliance and risk work. ControlCase describes experience across the payment chain, including issuing and acquiring businesses, banks and third-party processors. That breadth helps explain its service mix: a policy review, a vulnerability scan and a certification assessment address different questions. A buyer needs to identify the deliverable before comparing prices, especially when several frameworks and systems share the same engagement.

05 / More frameworks, sharper boundaries

Kishor Vaswani, ControlCase founder and Chief Strategy Officer
Kishor Vaswani, founder and Chief Strategy Officer. The paperwork has multiplied since the company began in 2004.

Founded in 2004, ControlCase was led by Kishor Vaswani until Mike Jenner became CEO in August 2020; Vaswani continued in strategy and on the board. In April 2026, ControlCase acquired CyberNINES, adding federal compliance depth, including CMMC assessment expertise. CyberNINES’ Scott Singer became Federal President. The announcement explicitly preserved separation between consulting and assessment services.

That boundary deserves attention. A convenient combined offering cannot erase impartiality obligations. ControlCase’s published statement bars personnel involved in a client’s management-system consultancy from relevant certification activities within two years after that consultancy ends. Customers buying an integrated program still need to understand which entity and team can perform each role.

In August 2026, ControlCase announced accreditation for ISO/IEC 42001, allowing formal certification assessments for AI management systems. The expanding catalogue suggests why evidence organization matters: new obligations keep arriving. The transferable lesson is modest and useful. Give each evidence item an owner, a date and a defined scope. Map it to applicable requirements. Keep it current. Even a password policy deserves to spend less time making introductions.