October 1, 2026 · Business Controls · Assessments

Assessments, rebuilt — always know where you stand and what to do next

One framework per assessment, scoped to how your business actually works. Every requirement graded against its own text, with the gaps named. And the whole observation window on one screen, with anything that would become an audit exception called out before fieldwork.

What changed

Assessments is now four views, each answering a single question in the order you’ll ask it. One framework per assessment, every requirement graded against its own text, and the whole observation window on one screen with would-be audit exceptions surfaced before fieldwork.

Scope
One framework per assessment and 250+ to pick from. Your business profile strikes the first pass of what doesn't apply, with a PCI DSS SAQ interview for the frameworks that need one. Every removal records its reason.
Coverage
Every in-scope requirement is a square, pre-graded against its own text with the gaps named. Overlay a second framework to see what your existing evidence already proves before you commit to it.
Continuity
The whole observation window on one screen — automated captures, attestations, drift, and incidents, scoped to the audit you're in. What would become an exception at fieldwork is called out now.
Today
For the days you have twenty minutes: one file to produce, chosen by the gap it closes, with what it needs to contain and how often to repeat it.
Coverage map with every in-scope requirement as a graded squareCoverage map with every in-scope requirement as a graded square
FIG. 1The headline is the verdict: how many requirements are proven, and how many have evidence that would not survive an auditor. Hover any square for the plain-language ask, the grade, and the specific gaps.

Why it matters

A first-time SOC 2 used to open on a wall of requirement rows, every one of them marked critical and most of them overdue the day you switched it on. That was never the job. The job was about 22 files — and knowing which of them would hold up.

A Type II opinion is about whether your controls operated across the period, not whether they existed on the day someone looked. The old assessment surface could tell you what you owed on day one. It couldn’t tell you whether what you had so far would survive the auditor’s testing procedure in month six.

The four-view rebuild answers that. Scope removes what doesn’t apply. Coverage grades the rest and names the gaps. Continuity watches the window. Today picks the next file to produce. The audit should confirm what you already know.

Availability

Shipping today to every platform tier. Existing assessments migrate automatically.

The Standards tab is now Continuity — your open items, findings, and upcoming requirements are all still there, organised by domain and window. Evidence you have already submitted is graded on first load; nothing you have proven is lost. Due dates re-run from your activation and fieldwork dates, so a newly activated framework starts clean rather than opening already-overdue.

Known limitations

Due dates run forward from your activation and fieldwork dates. Historical overdue states don't carry over — a newly activated framework starts with nothing overdue.

Re-grading after an amended file takes about a minute. If a framework corpus updates, snapshot grades don't retroactively re-score; the next cycle picks up the new text.

Framework overlays require the primary assessment's evidence to already be linked. If you're using a framework stub without evidence yet, the overlay will show every requirement as uncovered.