August 2026

Prev Next

In this release

Scrut's August release helps you reduce manual compliance work, spot gaps faster, and get more value from the data already in your workspace.

  • Build a tailored SOC 2 System Description from your existing framework, control, and organization data, then download it for your report package.

  • Start working toward Cyber Resilience Act (CRA) and Indonesia PDPL compliance with requirements already mapped to Scrut's control library.

  • Review ambiguous questionnaire questions with more context through multiple interpretations and consolidated answers generated by Scrut Teammates.

  • See compliance status by framework directly on each control, so you can identify exactly where gaps remain.

  • Connect Scrut MCP to Claude, Cursor, and Codex directly from the Task Center with the correct regional configuration and a sample prompt to verify the setup.

  • Switch between authorized workspaces within a single MCP session, so auditors can pull evidence across clients without reconnecting each time.

Key Features & Enhancements

Get your SOC 2 System Description report-ready faster

Every SOC 2 report begins with a system description that defines scope, services, control environment, and customer commitments. You usually start with a blank document, not an auditor-ready one. You then chase input from engineering and security to piece it together. This work usually sits outside your compliance program, disconnected from the data you have already tracked in it.

Scrut leverages AI to generate a tailored SOC 2 system description built from the framework, control, and organization data already in your workspace. A step-by-step template walks you through each required section, so you always know what's complete and what's still missing. Once done, you can download the finished description directly for your SOC 2 report package.

Learn more: Generate SOC 2 System Description

Manage EU Cyber Resilience Act Compliance

If you sell software or connected hardware into the EU, the Cyber Resilience Act now applies directly to your product, not just your corporate security program. It expects ongoing evidence of vulnerability management and update delivery, not a one-time assessment. Enterprise buyers in regulated European markets are already asking about your CRA posture during procurement. The Cyber Resilience Act is now available as a framework in Scrut, with its requirements mapped to Scrut's control library.

Learn more: Cyber Resilience Act (CRA)

Build an Indonesia PDPL compliance program alongside your existing privacy work

If your company has users, employees, or customers in Indonesia, the Personal Data Protection Law (PDPL) applies to you regardless of where you are headquartered. PDPL sits alongside GDPR-style regimes, but its requirements around lawful basis, data subject rights, breach notification, and cross-border transfers cannot simply be assumed to be covered by your existing privacy work. Teams expanding into Southeast Asia are increasingly asked to show a named PDPL program, not just a general privacy posture. PDPL Indonesia is now available as a framework in Scrut, with its requirements mapped to the control library.

Learn more: PDPL Indonesia

Answer ambiguous questions in security questionnaires with confidence

Security questionnaires often include questions that can be read in more than one way. For example, "What is your background verification process?" might refer to employees, vendors, or both. Previously, Scrut Teammates, when auto-filling a questionnaire, would pick one reading of each question and write the answer around it, without giving you clarity into how it interpreted the question.

Scrut Teammates now checks each subjective question in the background and flags those that can reasonably be read more than one way. For ambiguous questions, it drafts a single consolidated answer that covers every plausible interpretation. A match score shows how closely that answer aligns with the question as asked. Click View Interpretations to open a side panel with each interpretation and its own answer, and choose the one that best fits your situation.

Learn more: Handling questions with multiple interpretations

See exactly where each framework still has compliance gaps

Continuous compliance means controls are rarely mapped to just one framework, but many. Multi-framework programs break when a control is complete for one framework and incomplete for another, but you have to open separate views to notice. For example, a control meeting SOC 2's requirement but not ISO 27001's would still show a single combined status, masking gaps and making it harder to know which framework needs attention.

Scrut solves this by showing control compliance status per framework, so you clearly see which frameworks a control satisfies and which still need work.

Learn more: Controls Walkthrough

Other Updates