Cloudanix Achieves AWS Security Competency Status for Its CNAPP+ Platform and Just-in-Time Access Engine

Cloudanix – Your Partner in Cloud Security Excellence

Building a Custom Compliance Framework on Top of CIS and NIST: A Practical Guide

  • Abhiram Shindikar Abhiram Shindikar
  • Friday, Sep 18, 2026

Most security teams start their compliance journey by adopting a standard framework — CIS Benchmarks, NIST 800-53, or a similar baseline. That is the right first move. What separates a mature security program from an early one is often what happens next: building a custom internal framework on top of that baseline, one that reflects the company’s own risk priorities, its own control language, and its own ownership model.

This is genuinely harder than adopting CIS or NIST off the shelf, and it is worth doing well. This guide walks through the practical steps: why teams build custom frameworks, how to design one that stays connected to standard baselines, and — critically — how to keep it validated on an ongoing basis instead of letting it decay into a spreadsheet nobody trusts.

Why Build a Custom Framework at All?

CIS and NIST are excellent, well-tested baselines. They are also generic by design — written to apply across a huge range of organizations, industries, and risk profiles. A custom framework built on top solves problems the baseline alone cannot:

  • Business-specific risk categories. Your company may care disproportionately about controls around a specific data type, a specific regulatory obligation, or a specific historical incident that a generic baseline does not weight the same way.
  • Internal control language. Engineers and auditors inside your company may work better with control IDs and descriptions written in your own terminology than with raw CIS recommendation numbers.
  • Ownership mapping. A custom framework can attach an accountable owner to each control — something CIS and NIST, as external standards, have no mechanism to do.
  • Consolidating multiple obligations. If you must satisfy SOC 2, a customer’s security questionnaire, and an internal risk appetite simultaneously, a custom framework can be the single source of truth that maps to all three, rather than tracking three separate lists.

Step 1: Start From the Baseline, Not From Scratch

The most durable custom frameworks are built as a layer on top of CIS and/or NIST, not as an independent invention. Begin by identifying which CIS Benchmark(s) or NIST control families are relevant to your environment (cloud provider-specific CIS Benchmarks are a common starting point for cloud-native companies).

For each area of concern in your business, ask: which existing CIS/NIST control already covers this, even partially? Most of the time, the answer is “several, partially.” Your custom control becomes the aggregation and business-specific refinement of those baseline controls, not a replacement for them.

Step 2: Design Controls With Clear, Testable Intent

A control like “ensure data is protected” is not testable. A good custom control states intent in a way that maps cleanly to something you can check against real infrastructure:

DATA-07: No production data store is reachable from the public internet without a documented, time-limited exception approved by the data owner.

This is specific enough to translate into an actual check (is this RDS instance, S3 bucket, or equivalent publicly reachable?) while still expressing the business intent (production data, public reachability, exception process) that a bare CIS recommendation would not capture on its own.

Give every control:

  • A unique control ID.
  • A clear statement of intent, not just a technical rule.
  • The CIS/NIST control(s) it maps to or extends.
  • An accountable owner.
  • The evidence type that will demonstrate it is satisfied.

Step 3: Map Bidirectionally

Maintain the mapping in both directions: which of your custom controls correspond to which CIS/NIST controls, and which CIS/NIST controls feed into which of your custom controls. This bidirectional map does two things. It lets you answer an auditor’s question in either direction (“show me how you satisfy CIS 2.1.1” or “show me evidence for our internal DATA-07”), and it exposes gaps — a CIS control with no corresponding custom control usually means either it is not relevant to your environment (document why) or your custom framework has a hole.

Step 4: Decide How Exceptions Work Before You Need One

Every real framework has exceptions. A control might be legitimately unmet for a specific resource for a business reason, with sign-off. Decide this in advance:

  • Who can approve an exception (and at what severity/control tier)?
  • What must be documented (reason, expiry date, compensating control if any)?
  • How often are open exceptions reviewed?

Frameworks that do not plan for exceptions tend to have them handled ad hoc, undocumented, and forgotten — which is worse for an audit than having no framework at all, because it creates an inconsistency between the stated policy and observed reality.

Step 5: Choose How You Will Validate It Continuously

This is where most custom frameworks quietly fail. The framework is designed well, documented well, and then validated the way many teams validate compliance generally: once, right before an audit, by manually checking a sample of resources against the control list and writing up a report.

The problem is that “once, manually” cannot keep pace with a live cloud environment. An engineer changes a security group on a Tuesday; your framework’s evidence, generated the previous quarter, does not reflect it. The framework describes an intention. It does not describe the current state.

The alternative is to encode custom controls as checks that run continuously against your actual infrastructure — via a CSPM platform’s custom rule authoring capability (often called Bring Your Own Rules, or BYOR) — so that DATA-07, in the example above, is not a paragraph in a document but an automated check re-evaluated on every relevant change. Standard CIS/NIST controls are typically covered out of the box by a CSPM platform; the custom layer is where BYOR earns its place, letting you express the parts of your framework a standard tool would never know about on its own.

Step 6: Make Evidence a Byproduct, Not a Project

Once controls — standard and custom — are continuously evaluated, evidence generation stops being a pre-audit scramble. The state of every control is always current, and producing an evidence package for an auditor becomes an export rather than a multi-week reconciliation effort. This is the actual payoff of the work in Steps 1–5: the framework you designed carefully finally reflects reality at all times, instead of only on the day someone last checked it by hand.

A Framework Is Only as Good as Its Freshness

The intellectual work of designing a good custom framework — clear controls, sound mapping, a real exception process — is valuable and should not be shortcut. But that work is wasted if the framework’s validation lags weeks or months behind the environment it is supposed to describe. A framework that is accurate once a quarter is, for 89 days out of every 90, a document about the past.

Building the framework and building the mechanism to keep it continuously true are two different projects, and both deserve deliberate attention. Get the design right first. Then make sure something — ideally your CSPM platform, not a person with a spreadsheet — is checking it every day.

People Also Read

What Our Users Are Saying

Customer Reviews

Cloudanix is trusted by security leaders worldwide to deliver proactive, reliable, and cutting-edge cloud security.

One day, I changed the password of a root account, and my CTO called me within less than a minute to confirm if I did so. I was not expecting a reaction this quick. He told me Cloudanix alerted him of this password change and that he wanted to confirm as it was a critical security notification. I couldn't believe it!

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Compliance is one way of staying secure, but what I want is the ability to go deeper and attain 'true security.' Cloudanix provides us the capability to do so.

Vishal Madan
Vishal Madan
Head of Engineering, iMocha

Cloudanix is building for the future of the cloud, which makes the product all the more desirable.

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Cloudanix gave us the visibility we were missing. Being able to move from permanent access to a robust Just-In-Time (JIT) workflow has fundamentally changed our security posture without slowing down our engineering velocity.

Pavan Kumar Lekkala
Pavan Kumar Lekkala
SRE Lead, HugoHub

We are excited to leverage Cloudanix's comprehensive multi-cloud DevSecOps solution to secure our production workloads on AWS. Cloudanix has demonstrated that it can solve many challenges that DevSecOps teams face while continually adding new features such as SOC2 compliance and drift detection.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Managing third-party partner access was once a major concern for our security posture. With Cloudanix JIT Cloud, we've effectively achieved zero third-party risk. We can now grant access confidently, knowing that it is temporary, audited, and automatically revoked, resulting in a 100% reduction in our privileged access exposure.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

The snooze feature and responsible alerts have helped us save time and prioritize what to tackle first.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Implementing Cloudanix JIT internally allowed us to practice what we preach. By eliminating permanent access to our own clouds and databases, we've neutralized the risk of standing privileges, ensuring our own 'keys to the kingdom' are never left exposed.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

The problem with permissions is a lot of times, the gaps are left open due to oversights from inside the organization itself. With Cloudanix's CIEM, we get a complete view of user permissions and access. This enables us to update the permissions, reducing the attack surface.

Nilesh Pethani
Nilesh Pethani
Application Architect, iMocha

In the world of Fintech, trust is our currency. Cloudanix provided the frictionless visibility we needed to secure our EKS workloads across AWS, ensuring we stay audit-ready for SOC2 and GDPR without slowing down our engineering velocity.

Amol Naik
Amol Naik
Head of Security & Infrastructure, HugoHub

Cloudanix delivered value within 5 minutes of onboarding. Continuous monitoring, timely detection, and excellent documentation helped us attain a great cloud security posture.

Divyanshu Shukla
Senior DevSecOps, Meesho

Technology strategies and business strategies are in a state of constant change which includes centralization and decentralization of responsibilities. Regardless of strategic shift, we still have intellectual property to protect. Cloudanix are critical partners for us in our public cloud security posture across our three cloud providers.

Jerry Locke
Jerry Locke
Senior Director Global Solutions Engineering, Eversana

Cloudanix has been amazing. They opened up a common Slack channel with us — and it feels like we are talking to our own team and getting things done with Cloud security. The support team is always available, friendly, helpful, and ready to go out of their way.

Satish Mohan
Satish Mohan
CTO, Airgap Networks

Beyond just access management, Cloudanix CSPM has given us a unified view of our AWS environment. The real-time alerting and anomaly detection allow us to prevent any untoward activity before it happens, which is critical for a marketplace connecting 50+ financial institutions.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

For a Fintech company, data is our most valuable — and most sensitive — asset. Cloudanix DAM hasn't just improved our visibility; it has given us control. The ability to mask data and prevent unauthorized queries in real-time is a game-changer for our compliance and customer trust.

Jiten Gala
Jiten Gala
President Engineering and Product, Kapittx

Our clients, especially in the Middle East financial sector, demand absolute accountability. Cloudanix JIT Cloud has been a competitive differentiator for us, allowing us to provide secure, governed access to customer accounts that meet their strictest audit and compliance requirements.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

Cloudanix is always on my team's lips because of its exceptional support. Be it a small or big query, Cloudanix has gone above and beyond to resolve them. This one's a keeper for us.

Sujit Karpe
Sujit Karpe
CTO, iMocha

For a long-lasting partnership, great support goes a long way. Cloudanix has delivered exceptional support whenever required. Their edge is their team is always ready to go beyond to solve any issues that we have. This speaks volumes about the culture at Cloudanix.

Akash Maheshwari
Akash Maheshwari
Co-founder, MoveInSync

Beyond the technology, Cloudanix feels like an extension of our own team. Their willingness to stand up a dedicated Middle East tenant for us and provide exceptional support at a sensible price makes them a long-term partner for Hugosave.

Surya Tamada
Surya Tamada
CTO, HugoHub

The real-time notifications that Cloudanix provides are a real lifesaver. Their adaptive notifications ensure that my team stays productive and doesn't get interrupted all the time.

Digvijay Singh
Staff Security Engineer, Meesho

The whole point in technological evolution is to help improve the world we live in. We must protect that and to do so requires an effective and efficient security strategy. The Cloudanix team helped make our public cloud security posture management strategy a reality. The symbiotic relationship we have allows for a continuous feedback loop which is how business should operate.

Larry Wheat
Larry Wheat
Staff Solutions Engineer, Eversana

Ready to see your graph?

Connect a cloud account in under 30 minutes. See every finding rooted in identity, asset, and blast radius — with a fix path attached.

Book a Demo