The provisions this supports, named one by one.
Provision mappings are WestGate Data Science analysis. Churchill supports specific technical provisions; it does not itself confer compliance with any mandate. Every mandate below lists what Churchill does not do for it, at the same weight as what it does.
What an assessor can verify without taking your word for it.
Four properties of the record itself, which is what an assessor tests. These are the properties the Part 500 certification rests on, and they apply to every mandate below.
Every attempt on a protected application is recorded, because nothing reaches the application without passing the gate. There is no sampling rate and no tuning that decides what gets written.
Sequence numbers run continuously per host, so an incomplete record set is provable rather than arguable. That is the difference between evidence you can produce and evidence you have to vouch for.
Your evidence stays in the region agreed at deployment, with no shared global endpoint. Your team reads the logs and replays sessions from your own Churchill dashboard, for the retention period your regime requires.
Each record names the event, the decision, the executable, the process and its parent, the account it ran as, and the time to the nanosecond. An assessor verifies a chain instead of reconstructing a narrative.
Which controls this actually maps to, and which it does not.
Where Churchill technically supports specific provisions within each mandate. It strengthens your evidence for these areas; your program covers the rest.
SWIFT CSP (CSCF v2026)
Attestation window 1 Jul to 31 Dec 2026 · independent assessment requiredCSCF v2026 made Control 2.4 mandatory and brought customer connectors formally into scope. For many institutions that means a set of Linux hosts which sat outside the assessment perimeter last year now sits inside it, assessed against fourteen controls including privileged account control, security updates, system hardening, and logging.
| Provision | How Churchill supports it |
|---|---|
| 1.2 Operating System Privileged Account Control (mandatory) | Control 1.2 governs who is granted administrator-level access to the operating system. It does not govern what that access can reach once granted. Churchill closes that distance. Operations that fall outside the approved application package are denied at the system's core, including operations attempted by an account holding root. The workload keeps running. |
| 6.2 Software Integrity (mandatory) | Software integrity verification is typically a scheduled check, which leaves the interval between checks unverified. Churchill verifies at execution. Any deviation from the approved application package is denied at the point of use rather than reported at the next scan. |
| 6.4 Logging and Monitoring (mandatory) | Logs written in the secure zone are usually modifiable by the same privileged accounts Control 1.2 is intended to constrain, which is why assessors increasingly ask not whether logs exist but whether they can be trusted. Churchill produces a tamper-evident record of every decision, held outside the reach of the host it describes. |
| 2.3 System Hardening (mandatory) | Hardening establishes a configuration. Configurations drift, and drift is rarely visible until an assessment finds it. Churchill denies unauthorized operations against the current state of the host, so the protection does not depend on the configuration having stayed where it was set. |
| 2.2 Security Updates (mandatory) | Churchill does not apply patches. It addresses the exposure that remains between disclosure and remediation, and on the systems that cannot be patched on schedule. For those systems, Churchill provides the documented compensating control that assessors ask for alongside a formal patching exception. |
Control 2.4 back office data flow security itself, 1.1 environment protection, 2.7 vulnerability scanning, 4.1 password policy, 4.2 multi-factor authentication, 5.1 logical access control, and 7.1 incident response planning. Churchill contributes to these controls and produces supporting evidence for them; CSCF controls are assessed against your own environment, and applicability depends on your architecture type.
DORA
Enforcement and proof phase through 2026 · Register of Information due Feb to Apr 2026Around 22,000 EU financial entities, plus non-EU firms serving them: banks, insurers, investment firms, payment institutions. Applies since 17 Jan 2025.
| Provision | How Churchill supports it |
|---|---|
| Maintain critical functions during ICT disruption (Art. 11) | The unapproved change is refused at the kernel and the application keeps running; only code your quorum approved runs. |
| Prevent and detect anomalous activity | The kernel-level gate refuses unauthorized code and surfaces every attempt it contains. |
| Demonstrable, real-time proof of resilience | Tamper-evident recording of contained attacks, held in separate synchronized custody and cryptographically hashed. |
| ICT change management | Change requires at least two approvers from your client-assigned, encrypted quorum; no unilateral change, even with root. |
Incident reporting, the third-party register, the testing program.
PCI DSS 4.0.1
First full assessment cycle in 2026 · no grace periodGlobal: payment processors, card-handling banks, merchants, service providers. Future-dated requirements mandatory since 31 Mar 2025.
| Provision | How Churchill supports it |
|---|---|
| System integrity and tamper detection (Req. 11) | Continuous runtime integrity proves the workload is unmodified; tamper is refused and recorded. |
| Change control and least privilege (Req. 6, 7) | The quorum enforces separation of duties and blocks unilateral change. |
| Audit trails (Req. 10) | Contributes a tamper-evident recording of contained attacks; not the full access-logging Req. 10 also requires. |
Encryption of stored cardholder data (Req. 3), authentication (Req. 8), network controls, full access logging.
NYDFS Part 500
500.17(b) certification due 15 April · signed personally by the CISO and the CEONY-chartered and NY-licensed banks, insurers, and financial services companies. Second Amendment fully in effect since 1 Nov 2025. The certification must rest on data and documentation sufficient to demonstrate material compliance across the whole prior calendar year, not just the filing date, retained five years and producible on request. A gap requires a filed Acknowledgment of Noncompliance naming each provision missed, with no enforcement safe harbor for filing one.
| Provision | How Churchill supports it |
|---|---|
| Audit trail: reconstruct material transactions and security events, retained five years (500.6) | Every attempt, allowed or refused, is hash-chained with host, executable, account, decision, and nanosecond timestamp, held in dual custody so a gap is visible. |
| Application security: applications built and tested with security in mind before deployment (500.8) | Only the version your quorum signed executes. A binary that was not approved is refused at the kernel, so what was tested is what runs. |
| Access privileges: govern and periodically review privileged access (500.7) | No single actor changes the protected system unilaterally, even with root. Approval needs a minimum of two signed receipts from your own pool. |
| Cybersecurity program: detect, respond to, and recover from cybersecurity events (500.2) | Unauthorized execution is refused before it commits and the application keeps running, so there is no recovery step for the attempt that failed. |
| Monitoring: detect unauthorized access and activity (500.14) | Interactive sessions on a protected host are recorded and replayable, live or forensically, with passwords masked before they are written. |
| Records: maintain program records for five years, available to NYDFS on request (500.18) | The evidence chain is the record. Exportable per host, per account, per window, without reconstructing anything. |
| Certification support: data and documentation sufficient to demonstrate material compliance across the period (500.17(b)) | Continuous evidence that the approved state held, rather than a control that was working on the day someone captured a screenshot. |
MFA (500.12), data retention limits (500.13), encryption (500.15), incident response and the 72-hour report (500.16), penetration testing (500.5), third-party oversight (500.11), training (500.14 awareness), risk assessments (500.9). Class A entities also owe independent audits and biannual penetration testing; Churchill supports neither.
HIPAA Security Rule
Integrity safeguards in effect now · proposed update pending final ruleUS healthcare: health plans and payers, clearinghouses, providers, and their business associates (45 CFR 164.312).
| Provision | How Churchill supports it |
|---|---|
| Integrity and availability of ePHI systems (164.312) | Keeps the workload available and proves only authorized code runs. |
| Access and change governance | Your quorum governs every change to the protected system. |
| Audit controls and activity review (164.312(b)) | Tamper-evident recording of contained attacks; aligned with the proposed continuous-validation posture. |
Data-at-rest encryption, authentication, risk-analysis documentation.
Churchill supports specific technical provisions; it does not itself confer compliance with any mandate. Provision mappings are WGDS analysis.
Who can stop a runaway workload in your environment, and prove it?
The AI Kill Switch Act, H.R. 9917, was introduced on 23 July 2026 by Representatives Lieu and Moran and referred to the House Committee on Homeland Security. Its obligations fall on model developers, not on financial institutions. We keep it off the mandate map for that reason: it does not bind you, and pretending otherwise would discount the regimes that do. The question underneath the bill is not legislative. It is architectural, and it is already yours.
A stop that runs below user space, so the workload cannot bypass it. It was in the architecture from the first build, not added for a bill.
Two ways only, and a refused operation is neither of them. Either a sentinel is compromised while the recovery cycle is under repeated attack, or a governed change window closes with the binary still changed, or any one approver vetoes it.
The host stops the protected workload and holds it. That decision is made and carried out on the host, so it holds even if the control plane is unreachable.
Your quorum, after reviewing the evidence. No single administrator can clear a hold, and that is not configurable. Clearing is a review, not a rebuild, and every step lands on the evidence chain.
Legislative status as introduced; the bill had not been enacted at the time of writing. Nothing here claims Churchill satisfies an obligation the act places on model developers.
The mappings above are our analysis, not a determination.
Run them against your own control set, and test the evidence claim on a host you choose before anyone writes it into a program document.