Frameworks / Sigstore - Software Artifact Signing and Verification / SIGSTORE-COS-2 Sigstore - Software Artifact Signing and Verification
Sigstore: Cosign Signing and Storage
Sigstore - Software Artifact Signing and Verification SIGSTORE-COS-2: Key-Based Signing Support signing with hardware tokens, KMS systems, or cosign-generated encrypted key pairs
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 78 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection CJIS-8 Media Protection CJIS-9 System and Communications Protection ISO27799-02 ePHI encryption at rest and in transit ISO27799-16 Transmission security and encryption ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit US-ITAR-EAR-DS-01 Technical Data Protection US-ITAR-EAR-DS-02 Cloud and Storage APPI-A34 Request for Correction, Addition or Deletion ASD37-17 TLS encryption between email servers (Limited) BSI-08 Cryptographic protection of data FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 62351-9 Cyber security key management 27400-6.2 Device Identity and Authentication PCI-P2PE-09 Encryption and key management PCI-PIN-09 Encryption and key management PCI-SSF-09 Encryption and key management SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule SOC-CY-C2 Encryption and Data Protection SA-PDPL-13 Encryption of personal data IM8-CLD.2 Cloud Security Controls ISMSP-SYS-02 Encryption Implementation TAIWAN-2 Consent, Notice, Sensitive Data TEXASTDPSA-2 Consumer Rights OB-SEC.2 Transport Layer Security URUGUAY-3 Sensitive Data, Health Data, Children VIRGINIAVCDPA-2 Consumer Rights Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Sigstore: Cosign Signing and Storage Query this from an agent The graph holds this control, the 78 it maps to, and the evidence behind each claim, over MCP and REST.