Scrutineer.ai

Scrutineer · By framework

28 CFR Part 202 compliance software, DOJ bulk data rule

28 CFR Part 202, the DOJ bulk data rule run as the Data Security Program, has been fully in force since October 6, 2025. A restricted transaction now requires a written data compliance program, the CISA security requirements, ten years of records and an independent audit every calendar year.

Scrutineer logs each restricted data flow the way the rule asks and maps the CISA requirements to controls you already evidence for SOC 2. Compliance software, not legal advice.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with DOJ bulk data rule compliance

Encryption does not take your data out of scope, and most teams assume it does

The single most common scoping mistake with the bulk data rule is treating encrypted or de-identified data as exempt. It is not. Section 202.206 defines bulk U.S. sensitive personal data as data meeting the thresholds "regardless of whether the data is anonymized, pseudonymized, de-identified, or encrypted." So a vendor in a country of concern that hosts your encrypted health records is still party to a covered data transaction. Encryption matters later, as one of the data-level CISA security requirements that can make a restricted transaction permissible, but it does not shrink the volume count that decides whether you are in scope at all. The thresholds are also cumulative: they aggregate across every covered data transaction with the same foreign person or covered person over the preceding twelve months. A quarterly export of 3,000 patient records to the same offshore support vendor crosses the 10,000 person health data line in the fourth quarter, not the first. Scoping has to be done on a rolling twelve month count per counterparty, which is exactly the kind of number nobody keeps unless a system keeps it for them.

Your SOC 2 program already covers much of the CISA list. The net-new work is the data flow log

The CISA security requirements are drawn from CISA's Cross-Sector Cybersecurity Performance Goals and the NIST Cybersecurity Framework, so a mature SOC 2 or ISO 27001 program already evidences a good share of them: an asset inventory, multi-factor authentication, logging, access control, encryption. Some details are stricter than your current policy may be. Known exploited vulnerabilities on internet-facing systems must be remediated within 45 calendar days, and you need a process to check afterward whether those systems were compromised before the patch. Where MFA is not technically feasible, passwords must be at least 15 characters. What no security framework gives you is the rule's own record: for each restricted transaction, the types and volumes of data involved, the identity and ownership of the parties, the end use, the method of transfer, and the dates it began and ended, all logged in an auditable manner under section 202.1001. That log is where programs are thinnest, and it is what the annual auditor examines first.

The annual audit is a calendar obligation with a named scope, not a SOC 2 you can reuse

Section 202.1002 requires an audit once for each calendar year in which you engage in any restricted transaction, covering the preceding twelve months. The auditor has to be qualified, independent, and cannot be a covered person or a country of concern, which quietly disqualifies an offshore affiliate of your usual firm if it sits in one. The scope is fixed by the rule: your restricted transactions, your data compliance program and how it was implemented, the records section 202.1101 requires, and your implementation of the CISA security requirements. The auditor must deliver a written report within 60 days of finishing. A SOC 2 report will help as supporting evidence for the security half, but it does not examine your restricted transactions or your data flow log, so it cannot stand in for this audit. Plan the evidence for both from one library and the second audit becomes a re-read rather than a new collection.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Logs each restricted transaction with the fields section 202.1001 names: data types and volumes, the identity and ownership of each party, the end use, the transfer method, and the start and end dates
  • Keeps a rolling twelve month count per counterparty against each bulk threshold, so you see a vendor approaching the 10,000 person health or financial data line before it crosses
  • Maps the CISA security requirements for restricted transactions onto the controls you already evidence for SOC 2 and ISO 27001, and shows which ones are net new
  • Records vendor identity and ownership verification for every vendor agreement in scope, including where each vendor stores or accesses covered data
  • Tracks the two written policies the rule requires and the annual officer certification of each, with the certifying person and date on record
  • Holds the evidence the annual independent audit examines, organized by the scope in section 202.1002, and keeps it for the ten year retention period in section 202.1101
  • Puts the March 1 annual report and the 14 day rejected transaction report on a calendar when your facts trigger them, so a deadline does not depend on memory
  • Runs vendor risk on the same library, so a new offshore vendor is caught at intake rather than in the audit
DOJ bulk data rule compliance readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

What your existing program already covers

28 CFR Part 202 obligations against what SOC 2 and ISO 27001 already give you

Most guidance on the bulk data rule is written by law firms and lists the obligations. This table answers the question a security team asks next: which of these do we already evidence, and which are genuinely new work. Each row names the section, what an existing program usually covers, and the gap.

Obligation Section What SOC 2 or ISO 27001 usually already covers The net-new work Clock
Data compliance program with verified, logged data flows 202.1001(b)(1) Asset and data inventories, data classification A per transaction log of data types, volumes, parties, ownership, end use and transfer method In place since October 6, 2025
Vendor identity verification 202.1001(b)(2) Vendor risk reviews and security questionnaires Verifying ownership and location of each vendor in a restricted transaction, not just its security posture At intake and on change
Two written policies, each certified annually by an officer 202.1001(b)(3) and (4) An information security policy approved by management A policy describing the data compliance program and one describing how the CISA requirements are implemented, each with a named annual certification Every year
CISA security requirements 202.248 and 202.401 MFA, logging, access control, encryption, asset inventory Known exploited vulnerabilities on internet-facing systems fixed within 45 calendar days with a post-patch compromise check, 15 character passwords where MFA is not feasible, a data risk assessment Continuous
Annual independent audit 202.1002 A SOC 2 Type 2 or ISO 27001 surveillance audit on the security controls An audit of restricted transactions, the program and the records, by an auditor who is not a covered person, reported within 60 days Every calendar year with a restricted transaction
Recordkeeping 202.1101 Evidence retained for the audit cycle, often one to three years Full and accurate records of each transaction available for at least ten years Ten years per transaction
Annual report 202.1103 Nothing comparable A report by March 1 if you run restricted transactions involving cloud computing services and are 25 percent or more owned by a country of concern or covered person March 1, when triggered
Rejected transaction report 202.1104 Nothing comparable A report within 14 days of rejecting an offer to engage in a prohibited data brokerage transaction 14 days, when triggered

Good questions

Questions about DOJ bulk data rule compliance

The DOJ bulk data rule is 28 CFR Part 202, the regulation implementing Executive Order 14117 that the Justice Department runs as its Data Security Program. It prohibits or restricts transactions that could give six countries of concern, or persons tied to them, access to bulk U.S. sensitive personal data or government-related data. It took effect April 8, 2025.
It applies to U.S. persons, including companies organized in the United States and their foreign branches, that engage in covered data transactions involving bulk U.S. sensitive personal data or government-related data with a country of concern or a covered person. In practice that reaches data brokers, and any company with offshore vendors, employees or investors connected to those countries.
Measured over the preceding 12 months: more than 100 U.S. persons for human genomic data, more than 1,000 for other human omic data and biometric identifiers, more than 1,000 U.S. devices for precise geolocation data, more than 10,000 U.S. persons for personal health or personal financial data, and more than 100,000 for covered personal identifiers. Government-related data has no threshold.
Section 202.601 names six: China, including Hong Kong and Macau, Cuba, Iran, North Korea, Russia and Venezuela. Covered persons also include entities owned 50 percent or more by those countries or by their persons, entities organized or headquartered there, certain employees and contractors, individuals primarily resident there, and anyone the Attorney General designates.
No. The rule counts data toward the bulk thresholds regardless of whether it is anonymized, pseudonymized, de-identified or encrypted. Encryption is one of the CISA data-level requirements that can make a restricted transaction permissible, but it does not reduce the volume count that decides whether the transaction is covered in the first place.
Under section 202.1001 it needs risk-based procedures to verify and log each restricted data flow, including data types and volumes, party identity and ownership, end use and transfer method; risk-based vendor identity verification; and two written policies, one on the program and one on the CISA security requirements, each certified annually by a responsible officer.
The auditor must be qualified to attest to your compliance, independent, and not a covered person or a country of concern. The audit happens once for each calendar year you engage in a restricted transaction, covers the preceding 12 months, and the written report is due to you within 60 days of the audit finishing.
Violations are enforced under IEEPA. The rule states a civil maximum of the greater of 368,136 dollars or twice the value of the transaction, subject to inflation adjustment. Willful violations are criminal, with fines up to 1,000,000 dollars and, for individuals, up to 20 years in prison. False statements are separately punishable.
No. Scrutineer records the result of your screening, the ownership and location evidence behind it, and when it was done, so the audit trail exists. Run the list check itself with your sanctions screening process or counsel. Scrutineer is readiness software, not a legal determination and not the independent auditor the rule requires.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification