Skip to content

Compliance lead

Stop assembling evidence the week before the audit.

You are assessed against several frameworks that overlap heavily, and you gather the same evidence repeatedly because nothing maps it.

What changes

What your week looks like

Left is the week you have. Right is the same week on the platform. Nothing else on this page matters more than whether the left column is recognisable.

  1. One control is assessed three times for three frameworks.

    NIST CSF 2.0 and CIS Controls v8 run on one assessment engine with one maturity scale, so the lifecycle and the evidence handling are shared.

  2. Evidence collection means chasing colleagues for screenshots.

    Identity, logging and asset-inventory controls answer from your connected cloud and SIEM tools instead of from a person.

  3. The gap register grows faster than it closes because nothing has an owner.

    Every gap carries a priority, an owner, a target date and a client response, worked from one queue across every assessment.

  4. You cannot state today's position without a week of work.

    The score, the function breakdown and the document progress are live, and the export is a button rather than a fortnight.

Access

What you own, and what you can reach.

The platform has three roles, not six. This is the one you would hold, enforced at the route on the client and again on the server rather than hidden in the interface.

Platform role

Analyst

What it opens
Both assessment agents, their controls, the document library, and the gaps and issues queues across every assessment.
What it does not
Organisation settings and user management are Admin. Running an assessment does not need either.

The measure

The numbers you would be judged on.

Published targets and platform behaviour, not projections. Where one of these is a target rather than an achievement, it says so.

  • 106

    CSF controls

    Across six functions, generated with the assessment and its checklist.

  • 153

    CIS safeguards

    Across 18 controls, narrowed by scoping before you score anything.

  • 0 to 3

    Maturity scale

    Which derives the compliant, partial or non-compliant status shown throughout.

  • 4

    Evidence states

    Requested, received, under review, accepted, tracked per document.

Your workspaces

What you would actually open.

You can turn one on and add the others later. A connector configured for one is available to the rest.

Also part of this role

Coming soon

SOC 2 Readiness

Continuous SOC 2 monitoring with automated evidence collection and control mapping.

Coming soon

Third-Party Risk

Vendor risk scoring, questionnaire automation, and continuous supply-chain monitoring.

Questions

The things people ask first.

  • Does running both frameworks mean doing the work twice?

    No. They share the assessment engine, the maturity scale, the lifecycle, the evidence handling and the gaps queue. What differs is the content and the scoping: CSF generates all 106 controls, CIS narrows first through a five-step wizard on implementation group, cloud footprint and service model.

  • How much can be answered without asking anyone?

    The controls that map to telemetry: identity, logging and asset inventory read from connected cloud and SIEM APIs and generate their own findings, such as MFA gaps, stale accounts and certificate expiry. Governance and policy controls still need a person and a document.

  • Will an assessor accept the export?

    It carries the executive summary, the per-function or per-control breakdown, the findings and the remediation roadmap, as DOCX or PDF, with the scoping decisions recorded so a reader can see what was considered out of scope and why. Whether it satisfies your auditor is their call, not ours.

  • Why does a higher implementation group score lower?

    Because IG is cumulative. IG2 contains everything in IG1 and IG3 contains both, so choosing a higher group widens the safeguard set instead of replacing it. The figure is reported against the group you selected rather than as an absolute.