Use the approved 4.1.0 installer for your edition and confirm the version shown in the installed application. Published package availability is shown in Downloads & beta access.
IT Audit Factory — Framework Workflows
Framework Workflows provides editable, exportable governance response workflows that change with the active framework/program. The same underlying workflow engine is used across editions, while persistence and isolation follow each edition's architecture.
How to use
- Select the client/organization and active certification program where applicable.
- Open Framework Workflows.
- Review the framework-native stages and default guidance.
- Assign owners, contacts, status, priority/severity and stage notes.
- Record timeline/actions, evidence references and closure/lessons learned.
- Save, then export a DOCX when an auditor/client deliverable is needed.
Framework behavior
| Framework | Workflow |
|---|---|
| CMMC Level 2 | Simple 3.6.1 incident handling: preparation, detection, analysis, containment, recovery and user response. |
| ISO/IEC 27001 | Information-security event/incident assessment, response, recovery, learning and evidence preservation. |
| ISO 9001 | Nonconformity, correction/control, cause evaluation, corrective action, effectiveness review and closure. |
| SOC 2 | Security incident detection, evaluation, containment, communication, remediation, recovery and evidence. |
| Other supported packs | Framework-native issue/incident/service/privacy/continuity/AI workflow when applicable. |
CMMC 3.6.1 escalation defaults
| Severity | Initial escalation | If not acknowledged |
|---|---|---|
| SEV-1 Critical | Immediately | 5 minutes |
| SEV-2 High | Immediately | 15 minutes |
| SEV-3 Medium | Within 30 minutes | 30 minutes |
| SEV-4 Low | Within 4 business hours | 4 business hours |
Escalation order: User/Reporter → Service Desk/Incident Intake → Security/IT Lead → Incident Commander → IT/Infrastructure + affected System/Application Owner → Executive/Business Leadership → Legal/Privacy/Compliance → authorized external parties when required. If the primary contact does not acknowledge, contact the backup and advance to the next escalation level.
Isolation
MSP and Enterprise workflows are owned by the active client and certification program. Cross-client view, write, link, export and copy are prohibited. Switching clients must load a separate workflow. Free Edition is single-organization and stores separate local workflow state by framework.