Skip to main content
This matrix maps each compliance control to its implementation status in Switchbord. Use this as a starting point for your compliance assessment or vendor questionnaire. Status legend:
  • Implemented — Control is in place and operational
  • 🔄 In Progress — Partially implemented; completion planned
  • 📋 Planned — Tracked in Linear roadmap; not yet implemented

ISO 27001 — Annex A Controls

A.5 — Information Security Policies

A.6 — Organization of Information Security

A.8 — Asset Management

A.9 — Access Control

A.10 — Cryptography

A.12 — Operations Security

A.13 — Communications Security

A.14 — System Acquisition, Development, Maintenance

A.15 — Supplier Relationships

A.16 — Information Security Incident Management

A.17 — Business Continuity

A.18 — Compliance


GDPR — Key Articles


NIS2 — Key Articles


HIPAA — Technical Safeguards (§164.312)


SOC 2 — Trust Service Criteria

CC1 — Control Environment

CC2 — Communication and Information

CC3 — Risk Assessment

CC6 — Logical and Physical Access Controls

CC7 — System Operations

CC8 — Change Management

CC9 — Risk Mitigation


This matrix reflects the current state of Switchbord’s compliance posture. Planned items are actively tracked in Linear. For questions about a specific control or to request evidence artifacts for a vendor assessment, contact the Switchbord security team.