Skip to main content
POST
Create a compliance period

Authorizations

Authorization
string
header
required

An sre_ak_* API key holding the api:admin scope (or api:config_read, which every write refuses with read_only_key).

Body

application/json
ends_on
string
required

The last day it covers, as YYYY-MM-DD. It must be after starts_on.

framework
enum<string>
required

One of iso27001_2022, soc2, cis_aws, nist_csf_2.

Available options:
iso27001_2022,
soc2,
cis_aws,
nist_csf_2
name
string
required

What the window is called, unique in this organization and at most 120 characters. The auditor's own name for it reads best (SOC 2 FY26).

starts_on
string
required

The first day the window covers, as YYYY-MM-DD.

Response

Created.