Each control carries the library guidance inline, so an assessor is rating against what the control actually requires rather than against a blank cell.
The first step on a certification path: rate every control in the standard, track it to a target, and hand a clean position to the evidence work.
AssessEdge is the first step on a certification path. Pick the standard you intend to certify against, rate every control in it on a six level maturity scale, set a target, and see the whole framework as a position rather than a feeling.
It is organised around the standard, not around a topic. That is the distinction from the assessments in the advisory portal: those take eighteen questions on a single business concern and return a costed position and a ninety day plan. This one walks the entire control set of a framework, and it is where a certification programme starts.
It sits upstream of the evidence work. Assess first, prepare second, certify third. The rating is a self assessment and is presented as one throughout, because a structured statement of position is useful and a self awarded pass is not.
It answers the question that decides scope and budget: how far are we, control by control, from the standard we intend to certify against.
A structured position across the whole control set is faster to establish than reading what the last team left behind.
A maturity position that can be re-run and compared is evidence of direction, which a list of open items is not.
Each control carries the library guidance inline, so an assessor is rating against what the control actually requires rather than against a blank cell.
Not implemented through to optimised, plus not applicable, which leaves the denominator alone rather than quietly flattering the score.
A target level per assessment, and everything below it ordered by how far below. A list of gaps in no order is a list nobody works through.
Runs are retained, so a later assessment can be set against an earlier one. That comparison is what evidences direction of travel to a board.
The instrument is the control set of that framework, not a shortened questionnaire about it.
Six levels from not implemented to optimised, plus not applicable. The library guidance sits beside each control so the rating is against what the control requires.
Usually defined. Everything below the target becomes a gap, ordered by how far below it sits, which is what turns a rating into a plan.
Runs are retained with their dates. The second run is where the value is, because it shows movement rather than position.
Stated deliberately. A product that only lists what it can do leaves the reader to discover the boundary themselves, usually at the worst moment.
You rate your own controls. The output is a documented position, useful precisely because it is explicit about resting on your own assessment.
A generous rating produces a generous position. The tool records judgement; it does not test it.
There is no certificate here to display. There is a position you can defend, and a plan you can fund.
Those are concern shaped and return a costed position quickly. This one walks an entire standard.
Supplies the controls and the guidance shown while rating.
Downstream. The gaps identified here are where evidence collection starts.
The certification programme begins from the position established here rather than from a blank scope.
| Feature | Milestone | Scope |
|---|---|---|
| Per control maturity rating with inline guidance | v1.0 | In MVP v1.0 |
| Domain heatmap and overall position | v1.0 | In MVP v1.0 |
| Gap list ranked against a target level | v1.0 | In MVP v1.0 |
| Exportable maturity report | v1.1 | Planned |
| Run to run comparison | v1.2 | Planned |
| Hand off into the evidence workspace | v1.3 | Planned |
Milestones are roadmap targets rather than shipped dates. Target for MVP v1.0: Q3 2026. Provisioning is white-glove, never self-serve.
Every SecureEdge Advisory product prepares you for a certification, an audit or an assessment. None of them awards one. A certificate is issued by an accredited certification body, an attestation opinion by an independent auditor, and a regulatory finding by a regulator. We prepare the position and facilitate the process; the affirmation is made by someone else, and we do not blur that line.
Everything a product reports is derived from information supplied by your organisation, or by the person representing it. Ratings, maturity levels, readiness figures, mappings between frameworks and any monetary exposure are calculated from those inputs. Where an input is incomplete, out of date or optimistic, the output carries that forward faithfully. A result is therefore a structured statement of the position you have described, not an independent verification that the position is true.
An assessment is a documented position at a point in time. It is useful precisely because it is explicit about what it rests on, and it should be read that way rather than as a proof. Nothing here is a substitute for an audit, and no output should be presented to a regulator, a customer or a board as one.
Part of a family of ten products sharing one governed control library. Provisioning is white-glove and scope follows a due diligence review.