CMAI API Case Studies

MSSP & Consulting

Shifting Compliance Left with IaC Scanning + Mapping

Customer Type: Cloud-Focused MSSP Supporting DevOps Clients

Primary Framework(s): SOC 2 / ISO / PCI / HIPAA

Workflow Type: IaC Scanning → Compliance Enforcement

Read Case Study

Solving the ‘Evidence Bucketing’ Problem

Customer Type: Small Compliance Consultancy Supporting Federal Contractors

Primary Framework(s): CMMC + DFARS + NIST 800-171

Workflow Type: Policies + Evidence → Control Categorization → GRC Import

Read Case Study

Enterprise & Startups

DevSecOps: Pull-Request Compliance Validation

Customer Type: Developer Platform / SDLC Tooling Provider

Primary Framework(s): PCI / NIST / SOC2 + Responsible AI Guidelines

Workflow Type: Code Scan Findings → Control Mapping → PR Gating

Read Case Study

Multi-Cloud Compliance Monitoring + MSP Oversight

Customer Type: Regulated Enterprise with Multiple Operating Entities

Primary Framework(s): HIPAA + Custom Policy-Derived Requirements

Workflow Type: Policies + Findings → Custom Framework → Continuous Monitoring

Read Case Study

SOC 2 Cost Optimization: Mapping-First Approach

Customer Type: Early-Stage Startup Pursuing First SOC2 Report

Primary Framework(s): SOC 2 (plus optional ISO alignment)

Workflow Type: Policies + Findings → Control Coverage → Auditor-Ready Evidence

Read Case Study

OEM in Security Products

Adding Multi-Framework Coverage to an Existing Security Product

Customer Type: Security Tool Vendor / MSP Platform Product Team

Primary Framework(s): NIST → PCI / HIPAA / ISO / SOC2 / CMMC

Workflow Type: Existing Findings → Cross-Framework Mapping → Product Insights

Read Case Study