Get audit-ready
Walk into the audit with the evidence already collected.
Audit readiness assembled in the two weeks before an audit is a project. Assembled continuously, it's just a state you're in.
The situation
What this usually looks like
If more than two of these are true, the work below is the work you are already doing by hand.
The assessment lives in a spreadsheet that one person understands.
The programme's memory is one laptop.
Evidence is gathered by asking people for screenshots.
Collection cost scales with the control count, every single time.
The same control is assessed separately for three different frameworks.
Three answers to one question, and they drift apart.
Nobody can answer where you stand today without a week of work.
Your position is a project rather than a state.
The mechanism
See, decide, act, and then wait.
Four movements, in order. The fourth is the one that matters: nothing destructive happens without a person releasing it.
- 1
See
Scope first, then collect
A NIST CSF 2.0 assessment generates all 106 controls across the six functions with its document checklist. CIS Controls v8 narrows first, through a five-step wizard on Implementation Group, cloud footprint and service model, so you score the safeguards that apply, not all eighteen controls at once.
- 106 CSF controls
- 18 CIS controls
- IG1 / IG2 / IG3
- Document requests
- 2
Decide
Scored control by control
Maturity from 0 to 3 derives the compliance status: Optimized and Managed pass, Repeatable is partial, Ad Hoc fails, and Not Assessed says so instead of defaulting to something. Identity, logging and asset-inventory controls offer a one-click scan that answers from connected cloud and SIEM APIs instead of from a questionnaire.
- Maturity 0 to 3
- Manual / Hybrid / Automated
AWS CloudTrail
Azure Monitor
- 3
Act
Gaps that carry an owner
Every non-compliant or partially compliant control surfaces on Gaps and Findings and can be promoted to a tracked issue with a priority from Critical to Low, an owner, a target date, a recommendation and a client response. A separate queue works them across every assessment at once.
- Priority
- Owner
- Target date
- Cross-assessment queue
- 4
Gate
The evidence pack is a by-product
Documents move Requested, Received, Under Review, then Accepted, with files attached per control. The assessment exports as DOCX or PDF with the scoping decisions recorded, so a reader can see which safeguards were considered out of scope and why.
- Requested to Accepted
- DOCX and PDF
- Scoping recorded
The mechanism
See, decide, act, and then wait.
See
Scope first, then collect
A NIST CSF 2.0 assessment generates all 106 controls across the six functions with its document checklist. CIS Controls v8 narrows first, through a five-step wizard on Implementation Group, cloud footprint and service model, so you score the safeguards that apply, not all eighteen controls at once.
Decide
Scored control by control
Maturity from 0 to 3 derives the compliance status: Optimized and Managed pass, Repeatable is partial, Ad Hoc fails, and Not Assessed says so instead of defaulting to something. Identity, logging and asset-inventory controls offer a one-click scan that answers from connected cloud and SIEM APIs instead of from a questionnaire.
Act
Gaps that carry an owner
Every non-compliant or partially compliant control surfaces on Gaps and Findings and can be promoted to a tracked issue with a priority from Critical to Low, an owner, a target date, a recommendation and a client response. A separate queue works them across every assessment at once.
Gate
The evidence pack is a by-product
Documents move Requested, Received, Under Review, then Accepted, with files attached per control. The assessment exports as DOCX or PDF with the scoping decisions recorded, so a reader can see which safeguards were considered out of scope and why.
Four shapes in, one shape out. Normalised before anyone opens it.
The gate
How a control gets answered
Three methods, and the assessment records which one answered every control, so a score can be traced back to how it was reached rather than taken on trust.
Runs on its own
Automated
Answered from a connected tool. Identity, logging and asset inventory read from cloud and SIEM APIs and generate their own findings: MFA gaps, stale accounts, certificate expiry, segregation-of-duties violations.
The ruleRecorded on the control as Automated.
Waits for a person
Hybrid
A scan supplies part of the answer and an assessor supplies the rest, with evidence attached to the control.
The ruleRecorded as Hybrid, so the split is visible.
Logged only
Manual
Assessed by a person against evidence, which is what a governance or policy control actually needs.
The ruleUp to ten files of 10 MB each, per control.
Assessments move Draft, Scoping, Evidence Collection, Assessor Review, Client Review, Completed, and optionally Archived. The status is changed from the assessment header, not inferred from progress.
Who does the work
2 agents, each owning its part.
You can turn one on and add the others later. A connector configured for one is available to the rest.
Assess and Comply
NIST CSF 2.0 Assessment
Scores your maturity across all six CSF 2.0 functions, tracks every gap to an owner, and produces the report your board asked for.
Assess and Comply
CIS Controls v8 Assessment
Assesses all 153 safeguards against CIS Controls v8, scoped to your implementation group, with the automatable ones checked automatically.
Also named in this outcome
SOC 2 Readiness
Continuous SOC 2 monitoring with automated evidence collection and control mapping.
Third-Party Risk
Vendor risk scoring, questionnaire automation, and continuous supply-chain monitoring.
Questions
The things people ask first.
Does this make us compliant?
No, and nothing that scores a control can. It measures maturity against the framework's own controls, tracks the gaps with owners and dates, and produces the evidence pack an assessor asks for. The judgement stays with your auditor.
NIST CSF or CIS: which one?
They answer different questions. CSF is descriptive and asks how mature your governance is across six functions. CIS is prescriptive and asks whether a specific safeguard is in place. They share the same assessment engine, lifecycle, evidence handling and gaps queue, so running both isn't two projects.
Why does a higher Implementation Group score lower?
Because IG is cumulative. IG2 contains everything in IG1 and IG3 contains both, so choosing a higher group widens the safeguard set instead of replacing it. The score is reported against the group you selected, not as an absolute figure.
How much can be answered without asking anyone?
The controls that map to telemetry: identity, logging and asset inventory read from connected cloud and SIEM APIs and generate their own findings. Governance and policy controls still need a person and a document, and the assessment records which method was used for each.
What is in an evidence pack?
The executive summary, the per-function or per-control breakdown, the findings, and a remediation roadmap, exported as DOCX or PDF with the scoping decisions included. Evidence files attach per control.
The other outcomes
- Cut alert volumeClassify, group, and close the noise.
- Contain email compromiseScope and remove a malicious message on approval.
- Stop account takeoverCatch takeover signals, then contain the account.
- Govern AI usageDiscover AI tools, inspect what leaves, enforce policy.
- Clear the vulnerability backlogRank on exploit signal and drive fixes to closure.
