ProductsAssessEdge

AssessEdge Invited beta Live

The first step on a certification path: rate every control in the standard, track it to a target, and hand a clean position to the evidence work.

SitsUpstream of evidence
ScaleSix level maturity
BasisThe shared control library
OutputMaturity report
What it is

AssessEdge is the first step on a certification path. Pick the standard you intend to certify against, rate every control in it on a six level maturity scale, set a target, and see the whole framework as a position rather than a feeling.

It is organised around the standard, not around a topic. That is the distinction from the assessments in the advisory portal: those take eighteen questions on a single business concern and return a costed position and a ninety day plan. This one walks the entire control set of a framework, and it is where a certification programme starts.

It sits upstream of the evidence work. Assess first, prepare second, certify third. The rating is a self assessment and is presented as one throughout, because a structured statement of position is useful and a self awarded pass is not.

How it works

The same steps for every reader. The last one is what you end up holding.

  1. 1Choose the instrumentThe framework you actually answer to, not a generic questionnaire.
  2. 2Rate each controlMaturity per control, with the guidance inline, so the answer is considered rather than guessed.
  3. 3A domain heatmapWhere you stand by domain, and the overall position behind it.
  4. 4Ranked against a targetThe gap list is ordered by distance from the level you are aiming at.
  5. 5A maturity reportYour position, your gaps, and what closing each one would take.
See it

Screens from the running product, against a demonstration organisation. No customer data appears here.

Overview
AssessEdge overview: two frameworks in progress, SOC 2 at 2.8 out of 5 and ISO 27001 at 2.6, with controls rated and open gaps.
Every framework granted to the organisation, and how far through each one you are.
Assessment · SOC 2
The assessment runner: one control with its requirement text, a nought to five maturity selector, an optional note, and tabs for scenarios, what goes wrong, incidents and how to reach the target.
The library guidance sits under “context to rate honestly”, beside the question.
Maturity assessment report
The maturity report: an overall score of 2.8 out of 5 against a target of 3, five headline figures, a plain-language read, maturity by domain, and prioritised gaps.
The hero deliverable, and what a board actually reads.
Prioritised gaps
Prioritised gaps, each showing the current level, the target level, and the specific actions that close the difference.
Each gap carries the route from where it is to where it needs to be.
Key capabilities
Guidance while you rateEach control carries the library guidance inline, so an assessor is rating against what the control actually requires rather than against a blank cell.
Six level maturityNot implemented through to optimised, plus not applicable, which leaves the denominator alone rather than quietly flattering the score.
Gaps ranked by distance to targetA target level per assessment, and everything below it ordered by how far below. A list of gaps in no order is a list nobody works through.
Comparable over timeRuns are retained, so a later assessment can be set against an earlier one. That comparison is what evidences direction of travel to a board.
What it produces

The artefacts, and who receives each one.

The maturity positionBy domain and overall, comparable run to run so movement is visible rather than claimed.Goes to your executive team
The ranked gap listOrdered by distance from your target level, so the first item is the one worth doing first.Goes to whoever owns remediation
The assessment reportThe instrument, the answers, the date and the position. A documented statement, not a verdict.Goes to your board, and the auditor who asks how you know
Where it sits
SecureEdge GRCeverything, together
The three arms · assess, treat, proveeach one on its own
ControlRegistrythe library they all read
Frameworks it targets
ISO 27001SOC 2UAE PDPLNESANCA ECCNIST 800-53GDPRDubai ISR
Release plan · design → development → live
DesignDevelopmentLive
FeatureMilestoneScope
Per control maturity rating with inline guidancev1.0In MVP v1.0
Domain heatmap and overall positionv1.0In MVP v1.0
Gap list ranked against a target levelv1.0In MVP v1.0
Exportable maturity reportv1.0In MVP v1.0
Run to run comparisonv1.2Planned
Hand off into the evidence workspacev1.3Planned

Milestones are roadmap targets, not shipped dates. Target for MVP v1.0: Live since Aug 2026. The stage above is the honest position today: Live.

What this establishes. These products prepare you for certification and audit. They do not award either. Every figure is derived from what your organisation reports, and is a documented position rather than an independent verification.

Priced per framework, per year

Provisioning is white-glove, never self-serve, and scope follows the due diligence review. If you would rather run it inside your own network, say so and we will talk about that too.

Talk to us