Sigstore - Software Artifact Signing and Verification
Sigstore: Cosign Signing and Storage

Sigstore - Software Artifact Signing and Verification SIGSTORE-COS-2: Key-Based Signing

Support signing with hardware tokens, KMS systems, or cosign-generated encrypted key pairs

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 78 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

ISO 27799:2025 · 2 controls

  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-16 Transmission security and encryption

ISO/IEC 27043:2015 · 2 controls

  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit

ISO/SAE 21434 · 2 controls

  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • US-ITAR-EAR-DS-01 Technical Data Protection
  • US-ITAR-EAR-DS-02 Cloud and Storage

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • ASD37-17 TLS encryption between email servers (Limited)

BSI IT-Grundschutz · 1 control

  • BSI-08 Cryptographic protection of data

Bahrain PDPL · 1 control

  • FFIEC-09 Encryption and key management
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • 62351-9 Cyber security key management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.2 Device Identity and Authentication

NIST SP 800-190 · 1 control

PCI P2PE · 1 control

  • PCI-P2PE-09 Encryption and key management

PCI PIN Security · 1 control

  • PCI-PIN-09 Encryption and key management

PCI SSF · 1 control

  • PCI-SSF-09 Encryption and key management

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • SOC-CY-C2 Encryption and Data Protection

Saudi Arabia PDPL · 1 control

  • SA-PDPL-13 Encryption of personal data
  • IM8-CLD.2 Cloud Security Controls

South Korea ISMS-P · 1 control

  • ISMSP-SYS-02 Encryption Implementation

Taiwan PDPA · 1 control

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TEXASTDPSA-2 Consumer Rights
  • OB-SEC.2 Transport Layer Security

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-2 Consumer Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Sigstore: Cosign Signing and Storage

Query this from an agent

The graph holds this control, the 78 it maps to, and the evidence behind each claim, over MCP and REST.