Industries
Industry-aware programs without starting from a blank framework.
Blaise supports regulated, security-sensitive, and advisory-heavy organizations with vertical framework lenses, evidence workflows, risk programs, vendor oversight, and executive reporting.
Industry-aware
Mapped to your regulators
Frameworks per vertical, out of the box
Healthcare
HIPAA · NIST CSF
Defense / mfg
CMMC · NIST 800-171
Fintech
PCI DSS · FTC Safeguards
Vertical fit
Frameworks, evidence, and risks by industry.
Healthcare
HIPAA · NIST CSF · SOC 2 · State privacy laws
Healthcare organizations and the MSPs serving them need proof for access control, identity hygiene, risk analysis, vendors, incident readiness, policies, and evidence freshness without turning every client into a custom spreadsheet.
Explore HealthcareFinancial Services
GLBA / FTC Safeguards · FFIEC · NYDFS · SOX
Banks, fintechs, RIAs, accounting firms, and financial-adjacent clients need a tight chain from security controls to vendor oversight, audit evidence, risk decisions, and executive sign-off.
Explore Financial ServicesGovernment & Defense
CMMC 2.0 · NIST 800-171 · NIST 800-53 · FedRAMP
Defense contractors, GovCons, and public-sector suppliers need clear control ownership, gap tracking, POA&M discipline, supplier risk visibility, and evidence that survives assessment scrutiny.
Explore Government & DefenseTechnology & SaaS
SOC 2 · ISO 27001 · ISO 27017 · ISO 27018
SaaS and technology companies need to answer customer security reviews, prove control operation, run risk and vendor programs, and keep trust evidence current between audits.
Explore Technology & SaaSManufacturing
CMMC 2.0 · NIST CSF · NIST 800-171 · CIS Controls
Manufacturers need practical security governance across plants, offices, suppliers, and defense-contract obligations, with risk and remediation language executives can fund.
Explore ManufacturingLegal
SOC 2 · GDPR · CCPA / CPRA · State privacy laws
Law firms and legal-service providers need to prove reasonable safeguards, protect sensitive client data, answer client questionnaires, and manage vendors without building a bespoke GRC operation.
Explore LegalOther supported verticals
Built for regulated, security-sensitive buyers.
Healthcare
HIPAA, NIST CSF, cyber insurance
Identity posture, access, policy, risk, incident readiness, vendors, and evidence freshness.
Financial services / fintech
PCI DSS, FTC Safeguards, SOC 2, NIST
Vendor risk, audit evidence, access controls, security posture, and cyber-insurance proof.
Defense and manufacturing
CMMC, NIST 800-171, CIS, NIST CSF
POA&M, asset lifecycle, vulnerabilities, control ownership, supplier risk, and audit packages.
SaaS and technology
SOC 2, ISO 27001, NIST CSF, GDPR
Trust center, customer questionnaires, evidence graph, risk acceptance, and board reporting.
Government and critical infrastructure
NIST CSF, NIS2, CIS, state privacy
Executive posture, incident readiness, external exposure, compliance drift, and vendor oversight.
Retail and ecommerce
PCI DSS, CIS, FTC Safeguards
Payment control evidence, vulnerability exposure, vendor risk, awareness, and incident readiness.
Professional services and legal
SOC 2, ISO 27001, state privacy, cyber insurance
Client trust, policy attestations, data handling, vendor risk, and executive reports.
Education
NIST CSF, CIS, cyber insurance
Identity hygiene, endpoint posture, vendor reviews, policy, awareness, and board-ready security reporting.
Build the stakeholder story before the meeting starts.
See how Blaise turns posture, risk, evidence, vendors, roadmap, and decisions into a board-ready operating rhythm.
