Custom upload tests allow you to author your own upload tests in the Secureframe platform. If the existing Secureframe authored tests do not cover your company’s criteria, you can create a new test or set of tests that take uploads as evidence. These can be standalone tests or can be mapped to controls in existing security frameworks activated in your account.
Create a Custom Upload Test
Navigate to the Test Page in your sidebar
Click “+ Add Test” button in the top right portion of the page
Select "Custom Upload test"
Fill out the required fields:
Map Test to existing Control
If applicable, you can also map this new Test to existing Controls.
To map controls, click “Edit Controls”
Select the relevant controls, and add them by clicking the middle arrow.
Add remediation guidance if applicable
Click “Create”
Frequently Asked Questions (FAQ)
Who can use Custom Upload Tests?
Your company must be on our new and improved Test Page. If you have a Test Page icon in your sidebar you will have access to Custom Upload Tests. Please reach out to your Customer Success Manager if you have any questions!
How do I delete a Custom Upload Test?
Disabling a Custom Upload Test will ensure that it does not cause any issues come audit time.
I want to create a task (e.g., run a phishing simulation every 6 months) and then tie it to a specific control. How can I do this?
You can achieve this by creating a Custom Upload Test and optionally mapping it to a control. Once the test is created, you can attach a task with a due date.
Here's how:
Go to the Tests page.
Click Add Test and select Custom Upload Test.
Fill in the test name and description (e.g., “Run a phishing simulation every 6 months”).
On the second page of the flow, you’ll have the option to map the test to any control — this step is optional.
After the test is created, go to the Tasks tab on that test.
Click Add Task and set a reminder or due date
This is a great way to track recurring actions (like security trainings, tabletop exercises, or policy reviews) even if they aren't directly tied to automated evidence collection or pre-mapped controls.
