Skip to content
Kanonik
Menu
Help
Browse Help
On this page

Framework licences

Why a copyrighted framework needs your licence on record, how to record it in Settings, and what adding a framework costs.

Some frameworks are public text, such as NIST CSF 2.0, GDPR and HIPAA. Others are copyrighted standards, such as ISO/IEC 27001:2022 and the AICPA's SOC 2 criteria. Kanonik never ships the copyrighted text of a standard, only its structure and short paraphrases. For a copyrighted standard you work from your own licensed copy, and you record that you hold one. Your auditor sees that record in the export.

Where to do it

Choose Settings in the left-hand menu, then Frameworks. Only a Tenant Admin can record a licence. Manage frameworks on the Where you stand screen opens the same page.

Your frameworks at the top lists each framework with its state. NIST CSF 2.0 is marked Included and needs no licence. Other frameworks show Active once they are in your workspace, or Available on request until then.

Recording a licence

Under Record an attestation:

  1. Framework. Choose the framework you hold a licence for.
  2. Proof-of-purchase reference. Your order, engagement or licence number, for example an ISO or BSI order number, or an AICPA engagement number. It is required for a copyrighted standard. It is stored encrypted in the licence list, and a readable copy is kept with the attestation in your workspace's history, which your admins and approvers can read.
  3. Who holds the licence. You, or your audit firm. For SOC 2 the AICPA licence usually sits with your audit firm. For a copyrighted standard, Default records you as the holder, so choose your audit firm if the licence is theirs.
  4. Optional, under Advanced: a fingerprint (SHA-256) of the licensed text you hold, so your auditor can match it with their copy. The text itself is never sent or stored.

Choose Record attestation.

Adding a framework

NIST CSF 2.0 is included on every plan. The Answer plan includes NIST CSF 2.0 only: recording a licence there cannot add another framework, and certification frameworks come with Assure. On plans that support more frameworks, adding one is a one-time charge. When recording a licence also activates a framework, the page asks you to confirm the charge first: Confirm and activate goes ahead, Cancel backs out. The charge is added to your next invoice.

When it is done, the page confirms that the framework is cleared for the auditor export, and added to your workspace if it was not there already.

Deciding whether a framework applies

Recording a licence and deciding whether a framework applies to you are separate. To record whether a framework applies and why, ask your AI: it records the decision and you approve it. That step has no licence, activation or charge.

More help

Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email [email protected] and a person who works on the product answers.