Getting Started with Controls
Last updated: March 30, 2026
Overview
Controls are the requirements or safeguards your organization uses to meet compliance and risk objectives. Each control can be validated by linking tests which provide. Controls are either default (provided by Mycroft for specific frameworks) or custom (created by your organization).
Default vs Custom Controls
Default controls are provided by Mycroft for specific frameworks (e.g. SOC 2 Type 2, ISO 27001). They cannot be edited or deleted. You can deactivate them if they do not apply to your organization.
Custom controls are created by your organization. You can edit control details, change frameworks, assign owners, deactivate and delete them.
How Controls Pass
A control is considered passing when it has linked tests that pass. There are three ways to validate a control:
Automated tests — The product runs checks automatically and collects evidence.
Documents — Your organization uploads files, text, or links as evidence.
Policies — The product tracks whether policies have been published.
These three test types are how controls pass. You link one or more of them to a control from the control’s Testing tab.