Assessment library

Know where you actually stand

Each assessment is a curated, self-certified question set drawn from the standard it is named for. You answer, we score it, and you receive a structured report: what is in place, what is missing, and what to do first. Assessments run inside your portal, at no charge, and every run is kept with its date so you can measure the distance you have travelled. These are diagnostics on a single concern, sized to an afternoon. Walking the full control set of a standard, on the way to certifying against it, is what AssessEdge is for.

Cyber Hygiene Baseline
General · 6 domains

The foundations every organisation is expected to have, whatever its size or sector. The right place to start if you are starting.

Based on CIS Controls v8, Implementation Group 1
Available in your portal →
Application Security Posture
AppSec · 6 domains

Whether the software you run, and the way you build it, holds up to the scrutiny a security-conscious customer will apply.

Based on OWASP ASVS and SAMM
Available in your portal →
Product Security (Engineering)
Product Cyber · 6 domains

For teams who ship a product: whether security is engineered into the pipeline or inspected at the end.

Based on NIST Secure Software Development Framework, SP 800-218
Available in your portal →
ISO 27001 Gap (Lite)
Audit and Cert · 6 domains

The distance between where you are and a defensible ISO 27001 certification, expressed as the controls you have yet to put in place.

Based on ISO/IEC 27001:2022 and Annex A
Available in your portal →
PCI DSS Readiness
Audit and Cert · 6 domains

Whether an organisation that touches cardholder data is ready to be asked to prove it.

Based on PCI DSS v4.0
Available in your portal →
Cyber Audit Readiness
Audit and Cert · 6 domains

Not whether your controls work, but whether you could prove they worked, on the day an auditor asks. Most organisations fail here first.

Available in your portal →
Data Protection (PDPL) Lite
Compliance · 6 domains

Your obligations under the UAE personal data law, and which of them you are currently in a position to meet.

Based on UAE PDPL, Federal Decree-Law No. 45 of 2021
Available in your portal →
Cyber as Enabler Maturity
Strategy · 6 domains

Whether security slows the business down or helps it win work. The assessment a board understands without translation.

Available in your portal →
Assessments run at no charge, inside your portal. We set the portal up for you, so there is no sign-up here to complete. Each run is saved with its date under Assessments, and any assessment can be taken again to show what has changed.
What these products establish, and what they do not. These products prepare you for certification and audit. They do not award either. Every figure is derived from what your organisation reports, and is a documented position rather than an independent verification.Read in full

Every SecureEdge Advisory product prepares you for a certification, an audit or an assessment. None of them awards one. A certificate is issued by an accredited certification body, an attestation opinion by an independent auditor, and a regulatory finding by a regulator. We prepare the position and facilitate the process; the affirmation is made by someone else, and we do not blur that line.

Everything a product reports is derived from information supplied by your organisation, or by the person representing it. Ratings, maturity levels, readiness figures, mappings between frameworks and any monetary exposure are calculated from those inputs. Where an input is incomplete, out of date or optimistic, the output carries that forward faithfully. A result is therefore a structured statement of the position you have described, not an independent verification that the position is true.

An assessment is a documented position at a point in time. It is useful precisely because it is explicit about what it rests on, and it should be read that way rather than as a proof. Nothing here is a substitute for an audit, and no output should be presented to a regulator, a customer or a board as one.