Scrutineer · By framework
28 CFR Part 202 compliance software, DOJ bulk data rule
28 CFR Part 202, the DOJ bulk data rule run as the Data Security Program, has been fully in force since October 6, 2025. A restricted transaction now requires a written data compliance program, the CISA security requirements, ten years of records and an independent audit every calendar year.
Scrutineer logs each restricted data flow the way the rule asks and maps the CISA requirements to controls you already evidence for SOC 2. Compliance software, not legal advice.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with DOJ bulk data rule compliance
Encryption does not take your data out of scope, and most teams assume it does
The single most common scoping mistake with the bulk data rule is treating encrypted or de-identified data as exempt. It is not. Section 202.206 defines bulk U.S. sensitive personal data as data meeting the thresholds "regardless of whether the data is anonymized, pseudonymized, de-identified, or encrypted." So a vendor in a country of concern that hosts your encrypted health records is still party to a covered data transaction. Encryption matters later, as one of the data-level CISA security requirements that can make a restricted transaction permissible, but it does not shrink the volume count that decides whether you are in scope at all. The thresholds are also cumulative: they aggregate across every covered data transaction with the same foreign person or covered person over the preceding twelve months. A quarterly export of 3,000 patient records to the same offshore support vendor crosses the 10,000 person health data line in the fourth quarter, not the first. Scoping has to be done on a rolling twelve month count per counterparty, which is exactly the kind of number nobody keeps unless a system keeps it for them.
Your SOC 2 program already covers much of the CISA list. The net-new work is the data flow log
The CISA security requirements are drawn from CISA's Cross-Sector Cybersecurity Performance Goals and the NIST Cybersecurity Framework, so a mature SOC 2 or ISO 27001 program already evidences a good share of them: an asset inventory, multi-factor authentication, logging, access control, encryption. Some details are stricter than your current policy may be. Known exploited vulnerabilities on internet-facing systems must be remediated within 45 calendar days, and you need a process to check afterward whether those systems were compromised before the patch. Where MFA is not technically feasible, passwords must be at least 15 characters. What no security framework gives you is the rule's own record: for each restricted transaction, the types and volumes of data involved, the identity and ownership of the parties, the end use, the method of transfer, and the dates it began and ended, all logged in an auditable manner under section 202.1001. That log is where programs are thinnest, and it is what the annual auditor examines first.
The annual audit is a calendar obligation with a named scope, not a SOC 2 you can reuse
Section 202.1002 requires an audit once for each calendar year in which you engage in any restricted transaction, covering the preceding twelve months. The auditor has to be qualified, independent, and cannot be a covered person or a country of concern, which quietly disqualifies an offshore affiliate of your usual firm if it sits in one. The scope is fixed by the rule: your restricted transactions, your data compliance program and how it was implemented, the records section 202.1101 requires, and your implementation of the CISA security requirements. The auditor must deliver a written report within 60 days of finishing. A SOC 2 report will help as supporting evidence for the security half, but it does not examine your restricted transactions or your data flow log, so it cannot stand in for this audit. Plan the evidence for both from one library and the second audit becomes a re-read rather than a new collection.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Logs each restricted transaction with the fields section 202.1001 names: data types and volumes, the identity and ownership of each party, the end use, the transfer method, and the start and end dates
- Keeps a rolling twelve month count per counterparty against each bulk threshold, so you see a vendor approaching the 10,000 person health or financial data line before it crosses
- Maps the CISA security requirements for restricted transactions onto the controls you already evidence for SOC 2 and ISO 27001, and shows which ones are net new
- Records vendor identity and ownership verification for every vendor agreement in scope, including where each vendor stores or accesses covered data
- Tracks the two written policies the rule requires and the annual officer certification of each, with the certifying person and date on record
- Holds the evidence the annual independent audit examines, organized by the scope in section 202.1002, and keeps it for the ten year retention period in section 202.1101
- Puts the March 1 annual report and the 14 day rejected transaction report on a calendar when your facts trigger them, so a deadline does not depend on memory
- Runs vendor risk on the same library, so a new offshore vendor is caught at intake rather than in the audit
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
What your existing program already covers
28 CFR Part 202 obligations against what SOC 2 and ISO 27001 already give you
Most guidance on the bulk data rule is written by law firms and lists the obligations. This table answers the question a security team asks next: which of these do we already evidence, and which are genuinely new work. Each row names the section, what an existing program usually covers, and the gap.
| Obligation | Section | What SOC 2 or ISO 27001 usually already covers | The net-new work | Clock |
|---|---|---|---|---|
| Data compliance program with verified, logged data flows | 202.1001(b)(1) | Asset and data inventories, data classification | A per transaction log of data types, volumes, parties, ownership, end use and transfer method | In place since October 6, 2025 |
| Vendor identity verification | 202.1001(b)(2) | Vendor risk reviews and security questionnaires | Verifying ownership and location of each vendor in a restricted transaction, not just its security posture | At intake and on change |
| Two written policies, each certified annually by an officer | 202.1001(b)(3) and (4) | An information security policy approved by management | A policy describing the data compliance program and one describing how the CISA requirements are implemented, each with a named annual certification | Every year |
| CISA security requirements | 202.248 and 202.401 | MFA, logging, access control, encryption, asset inventory | Known exploited vulnerabilities on internet-facing systems fixed within 45 calendar days with a post-patch compromise check, 15 character passwords where MFA is not feasible, a data risk assessment | Continuous |
| Annual independent audit | 202.1002 | A SOC 2 Type 2 or ISO 27001 surveillance audit on the security controls | An audit of restricted transactions, the program and the records, by an auditor who is not a covered person, reported within 60 days | Every calendar year with a restricted transaction |
| Recordkeeping | 202.1101 | Evidence retained for the audit cycle, often one to three years | Full and accurate records of each transaction available for at least ten years | Ten years per transaction |
| Annual report | 202.1103 | Nothing comparable | A report by March 1 if you run restricted transactions involving cloud computing services and are 25 percent or more owned by a country of concern or covered person | March 1, when triggered |
| Rejected transaction report | 202.1104 | Nothing comparable | A report within 14 days of rejecting an offer to engage in a prohibited data brokerage transaction | 14 days, when triggered |
Good questions
Questions about DOJ bulk data rule compliance
Keep reading
Guides that go deeper on this framework
Best third-party risk management software
Where vendor ownership and location checks live in each platform, and where they do not.
Read the guideBest data privacy management software
The privacy tools that map data flows, and how that map differs from the log this rule wants.
Read the guideFourth-party risk
Your vendor's vendor is where a country of concern usually enters the chain.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification