A framework shell is a free compliance framework structure that can be uploaded into Vanta as a Custom Framework. It provides a structured starting point derived from the authoritative source documents published by the relevant standards body or regulator. Each shell contains a controls CSV and a framework CSV, which together define the control IDs, requirement descriptions, and framework structure a customer needs to begin their compliance program.
The shell itself contains no customer data and no pre-mapped evidence. It is a blank starting point, not a completed assessment.
Important: to use a framework shell, customers must have purchased the Custom Frameworks feature in their Vanta plan. Without this, the shell cannot be uploaded or used.
A shell gives customers a head start in building a custom framework inside Vanta. Rather than constructing the control structure from scratch, a customer receives an expert-reviewed starting point based on the original standard.
The shell is useful both before and during a Vanta engagement: before onboarding, it helps customers understand what a framework actually requires and scope their compliance program; during onboarding, it provides the structure into which customers can map their own evidence, policies, and tests.
Framework shells are deliberately scoped. They do not include:
- Policy templates or document placeholders (customers must create or adapt these themselves, or work with a Vanta partner)
- Pre-mapped Vanta tests or automated evidence (no new automation rules come with a shell)
- Interpretation or guidance from Vanta on how to implement specific controls
- Official compliance guidance or any guarantee of compliance with the relevant standard
- Ongoing maintenance (shells are not official Vanta products and will not be automatically updated if the underlying standard changes)
Customers who are on a Growth plan or above can use Vanta AI to help map controls to existing documents and tests after the shell has been imported. They can also reuse automated tests from their existing integrations. However, a shell itself ships with none of this pre-configured.
These shells are intended for Vanta customers who have purchased the Custom Frameworks feature and are working toward certification or attestation under a framework that Vanta does not yet support out of the box. They are particularly useful for:
- Organisations that are new to a framework and want a structured breakdown of what is required
- Teams preparing for an audit who need a starting point for control ownership and evidence tracking
- Vanta implementation partners helping customers scope and build their compliance programs
Each shell lives in its own folder and contains two CSV files and a README. Customers import the shell themselves, which keeps the framework fully under their ownership and control once it is live in their Vanta environment.
The import process is two steps, completed inside the Vanta UI:
Step 1: Import the controls
Navigate to Controls in Vanta, select Import Controls, upload the controls CSV, and confirm the import.
Step 2: Import the framework
Navigate to Frameworks in Vanta, select Import Framework, upload the framework CSV, and confirm. Allow a few minutes for the framework structure to appear correctly.
Detailed guidance and a video walkthrough are available in the Vanta Help Centre under Custom Controls and Creating Custom Frameworks.
After the import, customers should:
- Create or map any policies and documents required by the framework
- Map controls to existing Vanta tests where applicable (Growth plan and above can use Vanta AI to assist with this)
- Work with a Vanta partner if they need help interpreting requirements or building accurate control mappings
Vanta recommends working with a certified partner for frameworks that involve complex regulatory interpretation. Your CSM can suggest a suitable partner.
Shells are organised by framework, with one folder per framework. Each folder contains a README and the CSV files needed to import that shell into Vanta.
These shells are not official Vanta products. Vanta does not guarantee their completeness, accuracy, or ongoing maintenance in line with future regulatory revisions. Customers are responsible for reviewing and updating the framework as needed.
Vanta is not a law firm. Nothing in a framework shell constitutes legal, privacy, security, compliance, or business advice. Customers should consult a licensed attorney or qualified professional when determining their obligations under any regulation or standard.
If you have questions about a specific framework, need help finding a Vanta partner, or are unsure whether a shell is the right approach for your situation, contact your Vanta Customer Success Manager or reach out via the Vanta Help Centre.