Help Center / Framework coverage

Framework coverage

Covenant maps the evidence you collect on each vendor to supply-chain control families across five frameworks, so you can show an auditor which third-party controls you have covered.

What counts as evidence

A vendor accumulates "evidence kinds" as you work:

Evidence kindEarned when
assessmentThe vendor's questionnaire has at least one answer.
baaThe BAA status is signed or pending.
scanThe vendor has any findings (from a scan or logged manually).
risk_acceptanceA risk decision has been recorded.

Each framework control declares which evidence kinds satisfy it; a control is "covered" when the vendor has at least one of those kinds.

The frameworks

FrameworkScopeControls
NIST 800-171 / 800-53 SRSupply Chain Risk Management7
CMMC L2 — SR familyDIB suppliers (defense supply chain)3
HIPAA Security Rule — Business Associates§164.308(b) / 3144
SOC 2 (TSC)CC9.2 vendor risk2
ISO/IEC 27001:2022 Annex AA.5.19–A.5.23 supplier relationships5

Per-vendor coverage

On a vendor's detail page, the Framework coverage & evidence card lists each framework with its covered/total controls and a percentage, based on that vendor's evidence kinds.

Portfolio rollup (Coverage tab)

The Coverage tab shows a portfolio-wide rollup: each framework's controls and whether any vendor's evidence covers them, with a tooltip showing via which evidence kind.

The evidence payload

Each vendor can produce a canonical, PHI-safe evidence object: