> For the complete documentation index, see [llms.txt](https://docs.sealsecurity.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sealsecurity.io/trust/compliance/frameworks.md).

# Frameworks Seal helps you meet

<figure><img src="/files/tsQqMIQqA6PKAfLRuTAM" alt="Seal helps customers meet FedRAMP, PCI DSS, DORA, and NYDFS requirements"><figcaption><p>Frameworks Seal helps customers meet.</p></figcaption></figure>

Seal's coverage and evidence model map naturally onto several regulatory and industry frameworks. The mapping below is a summary; the specific control mappings for each framework are available from [your Seal account team](/introduction/audience-guides/security-leader.md) on request.

## FedRAMP

The United States federal government's authorization program for cloud services. Seal supports FedRAMP-relevant remediation by:

* Producing sealed iterations of vulnerable packages without forcing version changes that would require re-authorization.
* Publishing per-package attestations that satisfy continuous monitoring evidence requirements.
* Meeting the [72-hour SLA](/trust/compliance/sla.md) on critical- and high-severity vulnerabilities, which aligns with FedRAMP's continuous-monitoring vulnerability response expectations.

## PCI DSS 4.0

PCI DSS 4.0 requires remediation of high-severity vulnerabilities within defined windows. Seal supports PCI compliance by:

* Closing high- and critical-severity vulnerabilities through sealed iterations rather than version changes that may break the cardholder-data environment.
* Producing the per-package evidence (attestations, code diff, signing) auditors need to verify remediation.
* Meeting the [72-hour SLA](/trust/compliance/sla.md), which fits within PCI DSS 4.0's remediation windows for critical-severity findings.

## DORA

The European Union's Digital Operational Resilience Act applies to financial entities. Seal supports DORA compliance by:

* Providing the operational evidence (attestations, audit trails) that DORA's ICT third-party risk management requires.
* Supplying sealed iterations of vulnerable open-source dependencies within timelines compatible with DORA's incident-response expectations.

## NYDFS

The New York Department of Financial Services Cybersecurity Regulation (23 NYCRR Part 500) requires covered entities to maintain a documented vulnerability management program. Seal supports NYDFS compliance by:

* Producing evidence of remediation per vulnerability per package, signed and timestamped.
* Closing critical- and high-severity findings within the [72-hour SLA](/trust/compliance/sla.md).

## How Seal helps in practice

For all of the above, the mechanics on Seal's side are the same: produce sealed iterations, publish the supporting evidence, sign every artifact. What varies is which framework's controls the evidence is being mapped to. The [audit-ready traceability](/trust/compliance/audit-traceability.md) chapter walks through how the artifacts assemble into an audit narrative regardless of which framework you are answering to.

## Related

* [Seal's compliance certifications](/trust/compliance/certifications.md)
* [Audit-ready traceability](/trust/compliance/audit-traceability.md)
