Skip to content
Tier 2 · Regulatory

Regulatory

Maintain the license to operate

Tier 2 covers conditions that threaten certification, contract, or regulatory standing. The consequence is not a breach but a finding in someone else's report: a qualified SOC 2 opinion, a failed PCI DSS assessment, a GDPR Article 32 exposure. These are deadline-driven rather than threat-driven, and the deadline belongs to the auditor.

The test for this tier

Would a named auditor, regulator, or contractual counterparty record this as a deficiency?

See the full decision procedure
Remediate within
30 days
Escalation
Security manager review at 14 days
Owned by
Compliance, with engineering executing the remediation
Budgeted from
Planned work — scheduled against the audit calendar

Where CVSS fits

Findings in this tier typically score 4.0 – 6.9, or any score where a control is mandated — but the score is an input, never the decision. A CVSS 9.8 with no reachability does not belong in Tier 1, and a CVSS 6.5 in the CISA KEV catalog on an internet-facing host does. How Beacon relates to CVSS, EPSS and KEV.

12 finding classes

Tier 2 findings by domain

Tier sets the deadline; domain sets the owner. Each entry links to its full definition, detection guidance, and remediation steps.

Network

NETWhat can be reached, and from where?

Identity & Access Management

IAMWho can act, and how strongly is that proven?

Data Protection

DATWhat happens to the data if everything else fails?

Processing Protection

PRCIs the compute that runs the business trustworthy and available?