AssessmentsNew + improved · included on every plan
Assessments.
Prove your security works, not just that it’s written down.
Every file is graded against the requirement’s own text and sealed the moment you supply it. You see what will have run out by fieldwork day, and when something slips, the fix is on the record next to it. Your auditor sees a program that ran all year, not a folder assembled last week.


Same program, same files. Two very different answers.
A completion percentage counts every requirement with something attached. Assessments reads each file against the requirement’s own text and shows which would hold up, and which will have run out by fieldwork.
139 of 226 requirements have evidence attached. It doesn’t say whether any of it would pass.
82 requirements proven, and 40 more where you have evidence that would not survive an auditor.
- 82
- Proven
- 40
- Wouldn’t survive an auditor
- 17
- Awaiting review
- 87
- No evidence yet
Most tools hand you the whole framework. You start with what applies to you.
Based on your business profile, we suggest what doesn’t apply, and say why. Nothing leaves scope until you confirm it.
For frameworks that need it, a short assessor-style interview does the rest. Answer a few questions about how you take card payments and we’ll tell you which SAQ you look like. Disagree, and your reason is recorded for the assessor.
Lock it, and the scope is versioned. Change it later and your auditor sees both versions, with the reason.




A folder of evidence isn’t a pass. Every file is graded against the framework’s own words.
Each piece of evidence is read against what the requirement actually asks: sufficient, partial or insufficient. When it falls short, you get the specific gaps, not a red X.
Fix the file and re-grade it right there. You’ll see which gaps closed. Accept a gap on purpose and your reason goes with it, or send it to a colleague to decide.
That works the same on all 250+ frameworks, not just the popular ones. One file can satisfy requirements in several frameworks, and it’s graded against each of them.
“Ready today” can lapse by fieldwork. See where you’ll stand on the day it counts.
A quarterly access review is good for a quarter. Every requirement shows how much life its evidence has left, and you can view the map as of your fieldwork date to see what will have run out by then.
If something does lapse, it’s treated as what it is: an incident. Write the root cause and the fix, then sign it with a passkey or an authenticator code, so the signature belongs to a person, not a checkbox. It sits on the timeline next to the lapse. Over a full observation window, Continuity shows the pattern an auditor actually judges: whether you noticed, responded and changed.


Your auditor sees when the evidence existed, not just that it exists.
Every file is sealed and timestamped when it’s supplied, and every version is kept. Evidence put together ten days before fieldwork looks exactly like what it is. So does a control that ran all year.
Your auditor joins as a guest and reads your evidence in place, for one framework and one period. They verify it themselves, from a script we ship in the auditor pack, without our help and without our credentials. They can view any requirement as of any date in the window, and draw samples from that fixed view. Every view is logged, and you can revoke access in one click.
Their decisions sit next to your pre-check, never merged into it, and their requests come to you in the Audit tab.
One next thing. Not a wall of red.
Today picks the single piece of work that matters most: the soonest due, then the one that moves the most requirements. It tells you what the file has to contain. Do it, and the next one appears.


Every framework, graded.
Scope and grade against any of the 250+ frameworks in the library, on every plan. Evidence you’ve already proven for one carries into the next.
Where Assessments goes further.
Run security. Then prove it.
The Operating Plan is how you run your security program. Assessments is how you show it worked.