AssessmentsNew + improved · included on every plan

Assessments.
Prove your security works, not just that it’s written down.

Every file is graded against the requirement’s own text and sealed the moment you supply it. You see what will have run out by fieldwork day, and when something slips, the fix is on the record next to it. Your auditor sees a program that ran all year, not a folder assembled last week.

The Coverage Map in AssessmentsThe Coverage Map in Assessments
The Coverage Map. Every in-scope requirement is a square, colored by its grade and filled by how much shelf life its evidence has left.
What a percentage hides

Same program, same files. Two very different answers.

A completion percentage counts every requirement with something attached. Assessments reads each file against the requirement’s own text and shows which would hold up, and which will have run out by fieldwork.

A completion percentage

139 of 226 requirements have evidence attached. It doesn’t say whether any of it would pass.

Assessments, same evidence

82 requirements proven, and 40 more where you have evidence that would not survive an auditor.

82
Proven
40
Wouldn’t survive an auditor
17
Awaiting review
87
No evidence yet
ProvenWouldn’t survive an auditorAwaiting reviewNo evidence yet
What changedIf you used Assessments before, here’s the difference.Read the changelog →
BeforeA first-time SOC 2 opened on a wall of requirement rows, every one marked critical.NowThe job is about 22 files, and you know which of them will hold up.
BeforeReady meant ready on the day someone looked.NowA Type II opinion is about whether your controls operated across the period. Continuity shows the whole period.
01 · Scope

Most tools hand you the whole framework. You start with what applies to you.

Based on your business profile, we suggest what doesn’t apply, and say why. Nothing leaves scope until you confirm it.

For frameworks that need it, a short assessor-style interview does the rest. Answer a few questions about how you take card payments and we’ll tell you which SAQ you look like. Disagree, and your reason is recorded for the assessor.

Lock it, and the scope is versioned. Change it later and your auditor sees both versions, with the reason.

The PCI DSS interview recommending SAQ A-EPThe PCI DSS interview recommending SAQ A-EP
A requirement’s grade and its named gapsA requirement’s grade and its named gaps
02 · Prove

A folder of evidence isn’t a pass. Every file is graded against the framework’s own words.

Each piece of evidence is read against what the requirement actually asks: sufficient, partial or insufficient. When it falls short, you get the specific gaps, not a red X.

Fix the file and re-grade it right there. You’ll see which gaps closed. Accept a gap on purpose and your reason goes with it, or send it to a colleague to decide.

That works the same on all 250+ frameworks, not just the popular ones. One file can satisfy requirements in several frameworks, and it’s graded against each of them.

03 · Hold

“Ready today” can lapse by fieldwork. See where you’ll stand on the day it counts.

A quarterly access review is good for a quarter. Every requirement shows how much life its evidence has left, and you can view the map as of your fieldwork date to see what will have run out by then.

If something does lapse, it’s treated as what it is: an incident. Write the root cause and the fix, then sign it with a passkey or an authenticator code, so the signature belongs to a person, not a checkbox. It sits on the timeline next to the lapse. Over a full observation window, Continuity shows the pattern an auditor actually judges: whether you noticed, responded and changed.

Continuity lanes across the observation windowContinuity lanes across the observation window
CC8.1Changes are authorized, tested and approved before release
Your pre-check
Sufficient
Change management procedure v3, sealed Mar 4, graded Sep 16
Your auditor
Effective with exception
Dana Ruiz, Meridian Assurance · Sep 28 · sealed
“24 of 25 sampled changes had approval before deploy. CHG-2304 was approved two hours after release.”
In AuditRespond to the exception on CHG-2304
04 · Hand it over

Your auditor sees when the evidence existed, not just that it exists.

Every file is sealed and timestamped when it’s supplied, and every version is kept. Evidence put together ten days before fieldwork looks exactly like what it is. So does a control that ran all year.

Your auditor joins as a guest and reads your evidence in place, for one framework and one period. They verify it themselves, from a script we ship in the auditor pack, without our help and without our credentials. They can view any requirement as of any date in the window, and draw samples from that fixed view. Every view is logged, and you can revoke access in one click.

Their decisions sit next to your pre-check, never merged into it, and their requests come to you in the Audit tab.

Every day

One next thing. Not a wall of red.

Today picks the single piece of work that matters most: the soonest due, then the one that moves the most requirements. It tells you what the file has to contain. Do it, and the next one appears.

Today: one task, what it must contain, and how many requirements it movesToday: one task, what it must contain, and how many requirements it moves

Every framework, graded.

Scope and grade against any of the 250+ frameworks in the library, on every plan. Evidence you’ve already proven for one carries into the next.

SOC 2ISO 27001PCI DSS v4.0.1HIPAACMMC 2.0FedRAMP ModerateNIST CSF 2.0GDPRISO 42001NIST 800-53 r5CIS Controls v8HITRUST
NIST 800-171ISO 27701CCPA / CPRADORANIS2CSA CCMSOX ITGCNYDFS 500TX-RAMPStateRAMPEU AI ActCyber Essentials
Compared

Where Assessments goes further.

Typical compliance platformsAssessments
Where you standControl status and a completion percentage, as of nowEach requirement graded against its own text, as of today or as of your fieldwork date
When it lapsesA failing test and an alertAn incident with a root cause and fix, signed with a passkey, and its recurrence history across the window
Your auditor seesA point-in-time snapshot of what you chose to shareSealed, timestamped versions, so they can see when each file existed. Their grade sits beside yours.
Frameworks20 to 35+, priced per framework250+, on every plan
Plan
Included on every plan.
In the app
Business Controls → Assessments
To start
Your business profile, and the sources you already use.

Run security. Then prove it.

The Operating Plan is how you run your security program. Assessments is how you show it worked.