In this release
Scrut's August release helps you reduce manual compliance work, spot gaps faster, and get more value from the data already in your workspace.
Build a tailored SOC 2 System Description from your existing framework, control, and organization data, then download it for your report package.
Start working toward Cyber Resilience Act (CRA) and Indonesia PDPL compliance with requirements already mapped to Scrut's control library.
Review ambiguous questionnaire questions with more context through multiple interpretations and consolidated answers generated by Scrut Teammates.
See compliance status by framework directly on each control, so you can identify exactly where gaps remain.
Connect Scrut MCP to Claude, Cursor, and Codex directly from the Task Center with the correct regional configuration and a sample prompt to verify the setup.
Switch between authorized workspaces within a single MCP session, so auditors can pull evidence across clients without reconnecting each time.
Key Features & Enhancements
Get your SOC 2 System Description report-ready faster
Every SOC 2 report begins with a system description that defines scope, services, control environment, and customer commitments. You usually start with a blank document, not an auditor-ready one. You then chase input from engineering and security to piece it together. This work usually sits outside your compliance program, disconnected from the data you have already tracked in it.
Scrut leverages AI to generate a tailored SOC 2 system description built from the framework, control, and organization data already in your workspace. A step-by-step template walks you through each required section, so you always know what's complete and what's still missing. Once done, you can download the finished description directly for your SOC 2 report package.

Learn more: Generate SOC 2 System Description
Manage EU Cyber Resilience Act Compliance
If you sell software or connected hardware into the EU, the Cyber Resilience Act now applies directly to your product, not just your corporate security program. It expects ongoing evidence of vulnerability management and update delivery, not a one-time assessment. Enterprise buyers in regulated European markets are already asking about your CRA posture during procurement. The Cyber Resilience Act is now available as a framework in Scrut, with its requirements mapped to Scrut's control library.
Learn more: Cyber Resilience Act (CRA)
Build an Indonesia PDPL compliance program alongside your existing privacy work
If your company has users, employees, or customers in Indonesia, the Personal Data Protection Law (PDPL) applies to you regardless of where you are headquartered. PDPL sits alongside GDPR-style regimes, but its requirements around lawful basis, data subject rights, breach notification, and cross-border transfers cannot simply be assumed to be covered by your existing privacy work. Teams expanding into Southeast Asia are increasingly asked to show a named PDPL program, not just a general privacy posture. PDPL Indonesia is now available as a framework in Scrut, with its requirements mapped to the control library.
Learn more: PDPL Indonesia
Answer ambiguous questions in security questionnaires with confidence
Security questionnaires often include questions that can be read in more than one way. For example, "What is your background verification process?" might refer to employees, vendors, or both. Previously, Scrut Teammates, when auto-filling a questionnaire, would pick one reading of each question and write the answer around it, without giving you clarity into how it interpreted the question.
Scrut Teammates now checks each subjective question in the background and flags those that can reasonably be read more than one way. For ambiguous questions, it drafts a single consolidated answer that covers every plausible interpretation. A match score shows how closely that answer aligns with the question as asked. Click View Interpretations to open a side panel with each interpretation and its own answer, and choose the one that best fits your situation.

Learn more: Handling questions with multiple interpretations
See exactly where each framework still has compliance gaps
Continuous compliance means controls are rarely mapped to just one framework, but many. Multi-framework programs break when a control is complete for one framework and incomplete for another, but you have to open separate views to notice. For example, a control meeting SOC 2's requirement but not ISO 27001's would still show a single combined status, masking gaps and making it harder to know which framework needs attention.
Scrut solves this by showing control compliance status per framework, so you clearly see which frameworks a control satisfies and which still need work.

Learn more: Controls Walkthrough
Other Updates
Connect Scrut MCP to Claude, Claude, and Codex without leaving the product. Navigate to the Task Center, select your tool, copy the region-correct config, and verify with a sample prompt.
Auditors can now switch workspaces in an MCP session and pull evidence across every workspace and entity they have access to, instead of reconnecting per client.
Linked automated tests now have a one-click button to generate and attach an export directly to the evidence task, no manual download-and-upload required.
Import vendor questionnaire templates with follow-up questions. Bulk import now supports the same two-level conditional follow-up questions you can build manually.
Mark multiple employees as offboarding completed in one step. Select multiple employees from the list and mark them all as offboarded in a single bulk action. The confirmation dialog flags ineligible employees and any pending offboarding tasks before you proceed.
Release notes are now available in the Scrut Help Center alongside product documentation. Click the megaphone icon in the header in Scrut to see what's new, or browse the complete release note history.