Your controls, with a scoped lens per framework.
Certification prep as a workspace, one control set satisfies many frameworks.
CertEdge turns certification prep into a single tabbed workspace: work your controls once, mark applicability per framework through a Statement of Applicability, and let cross-framework credit carry the rest. The audit happens in the portal.
Built so a team preps SOC 2, ISO 27001 and regional certifications from one control ground.
This section is being written for CertEdge. It names who the product suits and, more usefully, who it does not. We would rather leave it blank than fill it with something generic.
Your controls, with a scoped lens per framework.
Mark what applies per framework; readiness counts applicable controls only.
Pull baseline credit into each framework.
An external auditor works in-portal, sealed and crypto-verifiable.
| Feature | Milestone | Scope |
|---|---|---|
| Tabbed controls workspace | v1.0 | In MVP v1.0 |
| SoA grid per framework | v1.0 | In MVP v1.0 |
| Framework-aware control detail | v1.1 | Planned |
| Audit Portal (external auditor) | v1.1 | Planned |
| Recertification tab | v1.2 | Planned |
Milestones are roadmap targets rather than shipped dates. Target for MVP v1.0: Q4 2026. Provisioning is white-glove, never self-serve.
Every SecureEdge Advisory product prepares you for a certification, an audit or an assessment. None of them awards one. A certificate is issued by an accredited certification body, an attestation opinion by an independent auditor, and a regulatory finding by a regulator. We prepare the position and facilitate the process; the affirmation is made by someone else, and we do not blur that line.
Everything a product reports is derived from information supplied by your organisation, or by the person representing it. Ratings, maturity levels, readiness figures, mappings between frameworks and any monetary exposure are calculated from those inputs. Where an input is incomplete, out of date or optimistic, the output carries that forward faithfully. A result is therefore a structured statement of the position you have described, not an independent verification that the position is true.
An assessment is a documented position at a point in time. It is useful precisely because it is explicit about what it rests on, and it should be read that way rather than as a proof. Nothing here is a substitute for an audit, and no output should be presented to a regulator, a customer or a board as one.
Part of a family of ten products sharing one governed control library. Provisioning is white-glove and scope follows a due diligence review.