Compliance lead
Stop assembling evidence the week before the audit.
You are assessed against several frameworks that overlap heavily, and you gather the same evidence repeatedly because nothing maps it.
What changes
What your week looks like
Left is the week you have. Right is the same week on the platform. Nothing else on this page matters more than whether the left column is recognisable.
Today
On CyForte
One control is assessed three times for three frameworks.
NIST CSF 2.0 and CIS Controls v8 run on one assessment engine with one maturity scale, so the lifecycle and the evidence handling are shared.
Evidence collection means chasing colleagues for screenshots.
Identity, logging and asset-inventory controls answer from your connected cloud and SIEM tools instead of from a person.
The gap register grows faster than it closes because nothing has an owner.
Every gap carries a priority, an owner, a target date and a client response, worked from one queue across every assessment.
You cannot state today's position without a week of work.
The score, the function breakdown and the document progress are live, and the export is a button rather than a fortnight.
Access
What you own, and what you can reach.
The platform has three roles, not six. This is the one you would hold, enforced at the route on the client and again on the server rather than hidden in the interface.
Platform role
Analyst
- What it opens
- Both assessment agents, their controls, the document library, and the gaps and issues queues across every assessment.
- What it does not
- Organisation settings and user management are Admin. Running an assessment does not need either.
The measure
The numbers you would be judged on.
Published targets and platform behaviour, not projections. Where one of these is a target rather than an achievement, it says so.
106
CSF controls
Across six functions, generated with the assessment and its checklist.
153
CIS safeguards
Across 18 controls, narrowed by scoping before you score anything.
0 to 3
Maturity scale
Which derives the compliant, partial or non-compliant status shown throughout.
4
Evidence states
Requested, received, under review, accepted, tracked per document.
Your workspaces
What you would actually open.
You can turn one on and add the others later. A connector configured for one is available to the rest.
- Assess and ComplyNIST CSF 2.0 AssessmentScores your maturity across all six CSF 2.0 functions, tracks every gap to an owner, and produces the report your board asked for.
- Assess and ComplyCIS Controls v8 AssessmentAssesses all 153 safeguards against CIS Controls v8, scoped to your implementation group, with the automatable ones checked automatically.
Also part of this role
SOC 2 Readiness
Continuous SOC 2 monitoring with automated evidence collection and control mapping.
Third-Party Risk
Vendor risk scoring, questionnaire automation, and continuous supply-chain monitoring.
Questions
The things people ask first.
Does running both frameworks mean doing the work twice?
No. They share the assessment engine, the maturity scale, the lifecycle, the evidence handling and the gaps queue. What differs is the content and the scoping: CSF generates all 106 controls, CIS narrows first through a five-step wizard on implementation group, cloud footprint and service model.
How much can be answered without asking anyone?
The controls that map to telemetry: identity, logging and asset inventory read from connected cloud and SIEM APIs and generate their own findings, such as MFA gaps, stale accounts and certificate expiry. Governance and policy controls still need a person and a document.
Will an assessor accept the export?
It carries the executive summary, the per-function or per-control breakdown, the findings and the remediation roadmap, as DOCX or PDF, with the scoping decisions recorded so a reader can see what was considered out of scope and why. Whether it satisfies your auditor is their call, not ours.
Why does a higher implementation group score lower?
Because IG is cumulative. IG2 contains everything in IG1 and IG3 contains both, so choosing a higher group widens the safeguard set instead of replacing it. The figure is reported against the group you selected rather than as an absolute.
The rest of the team
You are almost certainly not the only person who has to agree to this.
- CISOPosture, open decisions, and a board-ready report.
- SOC managerQueue depth you can defend, SLA visibility, and handovers that compile themselves.
- SOC analystAlerts that arrive already enriched, grouped, and worth opening.
- IT and infrastructureRemediation that arrives as code, runs in your orchestrator, and can be rolled back.
- MSSP and service providerMulti-tenant isolation, per-client posture, and reporting that scales past headcount.
