Feature sheet

AssessEdge

The first step on a certification path: rate every control in the standard, track it to a target, and hand a clean position to the evidence work.

DevelopmentAssessmentMVP target Q3 2026
Upstream of evidence
Sits
Six level maturity
Scale
The shared control library
Basis
Maturity report
Output
Walk the simulation →Request access, at launch← Back to the productPrint or save as PDF for a procurement pack.

What it is

AssessEdge is the first step on a certification path. Pick the standard you intend to certify against, rate every control in it on a six level maturity scale, set a target, and see the whole framework as a position rather than a feeling.

It is organised around the standard, not around a topic. That is the distinction from the assessments in the advisory portal: those take eighteen questions on a single business concern and return a costed position and a ninety day plan. This one walks the entire control set of a framework, and it is where a certification programme starts.

It sits upstream of the evidence work. Assess first, prepare second, certify third. The rating is a self assessment and is presented as one throughout, because a structured statement of position is useful and a self awarded pass is not.

Who it is for

Organisations about to commit to a certification

It answers the question that decides scope and budget: how far are we, control by control, from the standard we intend to certify against.

Teams inheriting a compliance programme

A structured position across the whole control set is faster to establish than reading what the last team left behind.

Anyone reporting progress to a board

A maturity position that can be re-run and compared is evidence of direction, which a list of open items is not.

And who it is not for

Capabilities

01
Guidance while you rate

Each control carries the library guidance inline, so an assessor is rating against what the control actually requires rather than against a blank cell.

02
Six level maturity

Not implemented through to optimised, plus not applicable, which leaves the denominator alone rather than quietly flattering the score.

03
Gaps ranked by distance to target

A target level per assessment, and everything below it ordered by how far below. A list of gaps in no order is a list nobody works through.

04
Comparable over time

Runs are retained, so a later assessment can be set against an earlier one. That comparison is what evidences direction of travel to a board.

How it works

  1. 1
    Choose the standard you intend to certify against

    The instrument is the control set of that framework, not a shortened questionnaire about it.

  2. 2
    Rate each control, with the guidance in front of you

    Six levels from not implemented to optimised, plus not applicable. The library guidance sits beside each control so the rating is against what the control requires.

  3. 3
    Set a target level

    Usually defined. Everything below the target becomes a gap, ordered by how far below it sits, which is what turns a rating into a plan.

  4. 4
    Re-run it later and compare

    Runs are retained with their dates. The second run is where the value is, because it shows movement rather than position.

What it does not do

Stated deliberately. A product that only lists what it can do leaves the reader to discover the boundary themselves, usually at the worst moment.

It does not audit you

You rate your own controls. The output is a documented position, useful precisely because it is explicit about resting on your own assessment.

It does not verify what you report

A generous rating produces a generous position. The tool records judgement; it does not test it.

It does not award a maturity certificate

There is no certificate here to display. There is a position you can defend, and a plan you can fund.

It does not replace the diagnostic assessments

Those are concern shaped and return a costed position quickly. This one walks an entire standard.

Frameworks it targets

ISO 27001SOC 2UAE PDPLNESANCA ECCNIST 800-53GDPRDubai ISR

How it fits the family

ControlRegistry

Supplies the controls and the guidance shown while rating.

EvidenceEdge

Downstream. The gaps identified here are where evidence collection starts.

CertEdge

The certification programme begins from the position established here rather than from a blank scope.

Release plan

FeatureMilestoneScope
Per control maturity rating with inline guidancev1.0In MVP v1.0
Domain heatmap and overall positionv1.0In MVP v1.0
Gap list ranked against a target levelv1.0In MVP v1.0
Exportable maturity reportv1.1Planned
Run to run comparisonv1.2Planned
Hand off into the evidence workspacev1.3Planned

Milestones are roadmap targets rather than shipped dates. Target for MVP v1.0: Q3 2026. Provisioning is white-glove, never self-serve.

What these products establish, and what they do not

Every SecureEdge Advisory product prepares you for a certification, an audit or an assessment. None of them awards one. A certificate is issued by an accredited certification body, an attestation opinion by an independent auditor, and a regulatory finding by a regulator. We prepare the position and facilitate the process; the affirmation is made by someone else, and we do not blur that line.

Everything a product reports is derived from information supplied by your organisation, or by the person representing it. Ratings, maturity levels, readiness figures, mappings between frameworks and any monetary exposure are calculated from those inputs. Where an input is incomplete, out of date or optimistic, the output carries that forward faithfully. A result is therefore a structured statement of the position you have described, not an independent verification that the position is true.

An assessment is a documented position at a point in time. It is useful precisely because it is explicit about what it rests on, and it should be read that way rather than as a proof. Nothing here is a substitute for an audit, and no output should be presented to a regulator, a customer or a board as one.

SecureEdge Advisory
AssessEdge

Part of a family of ten products sharing one governed control library. Provisioning is white-glove and scope follows a due diligence review.

secureedgeadvisory.com
cio@secureedgeadvisory.com
Dubai, United Arab Emirates

Before it can be provisioned