Identity · appears in SIG, ISO 27001
Is the domain registration verifiable via WHOIS / RDAP with active status?
Registrar and expiry tell auditors the domain is owned, current, and not about to lapse. An expired or about-to-expire domain fails business-continuity evidence (SOC 2 A1.2).
How to answer this
Whichever verdict your domain earns, this is the wording to put in the response box. Reviewers mark an answer down for vagueness more often than for a "No", so say which state you are in and what evidences it.
- Yes
- WHOIS/RDAP shows the domain is registered and in active status
- Partial
- Registration is verifiable but shows status flags worth review
- No
- The domain registration status could not be verified
Controls this evidences
| Framework | Control | Why it maps |
|---|---|---|
| SOC 2 | CC2.3 | Domain registration data documents ownership and expiry. |
| ISO 27001 | A.5.20 | — |
| NIST 800-53 | PE-2 | — |
Domain Posture is not an audit and does not replace an auditor. See methodology v1 for how each verdict is reached.
When a "Yes" stops being true
Registration entered the expiry window, lapsed, or the registrar/transfer lock was dropped.
That is the whole problem with answering a questionnaire from a screenshot: the answer was true the day you took it. A signed evidence pack is dated, and a schedule re-checks it so you find out before your reviewer does.