Security Compliance Hub — Knowledge Base
Guides, references, and glossary for every assessment, feature, and compliance framework on the platform.
What is Security Compliance Hub?
Security Compliance Hub (SCH) is a client-side web platform that helps organisations assess their readiness across the major UK and EU cybersecurity compliance frameworks. It runs entirely in the browser — assessments are saved locally and submitted to the platform only when you run a Phronesis AI analysis.
Frameworks covered
30-question cross-framework health check. Best starting point.
NCSC-backed UK certification. 6 controls, 45+ questions.
Critical National Infrastructure. 14 principles, 83 questions.
EU financial sector resilience. 5 pillars, 49 questions.
ISMS certification. 8 clauses, 58 questions.
EU AI Act, ISO 42001, NIST AI RMF. 42 questions.
IASME-aligned maturity scoring across 14 themes. 70 questions.
6 functions incl. GOVERN, indicative Implementation Tier. 70 questions.
18 Controls, 153 Safeguards across 3 Implementation Groups.
EU essential/important entities, Article 21(2). 56 questions.
Five specialist assessments — PE Cyber Due Diligence, SOC Maturity & AI Readiness, CMMC Level 2 Readiness, FedRAMP Rev5 Moderate Readiness, and HIPAA Security Rule Assessment — require access credentials granted via the MSP & vCISO Partner Hub. All five are also shown as Restricted-access cards on the public landing page's "More Frameworks" section.
How results work
Every question maps to a scoring axis. Scores of 70 % or above are considered compliant / in good standing. 40–69 % indicates partial compliance. Below 40 % signals critical gaps requiring priority remediation. These thresholds apply across all frameworks with consistent meaning.
Quick Start
- Visit securitycompliancehub.io and click Sign In. Create an account with email or Google — your 7-day free trial begins automatically.
- From the landing page, click Compliance Readiness (the "START HERE" card). This 30-question assessment maps your current posture across all frameworks and recommends where to focus next.
- Answer each question honestly. Use the Phronesis AI button at any point during an assessment for context-aware guidance on a specific question.
- Click Analyse with Phronesis to generate your full AI report — scores, critical gaps, strengths, and a prioritised roadmap.
- Open My Hub to see all your results in one place, track progress over time, and access the Compliance Passport for a printable summary.
Choosing a Framework
Start with Compliance Readiness if you're unsure — it identifies your priority framework in 10–15 minutes. Otherwise use this guide:
By organisation type
- UK public sector / government supplier / CNI operator → NCSC CAF
- EU bank, insurer, investment firm, or payment institution → DORA (mandatory from January 2025)
- EU essential or important entity in scope of the NIS2 Directive → NIS2 Directive (energy, transport, health, digital infrastructure, and more)
- Any UK or international organisation seeking ISMS certification → ISO 27001
- SME, charity, or supplier wanting a demonstrable UK baseline cert → Cyber Essentials
- Organisation wanting a prioritised, evidence-based technical control baseline → CIS Controls v8 — tiered by Implementation Group (IG1/IG2/IG3) to match your size and risk
- AI developer, deployer, or public-sector AI user → AI Governance
- US-aligned organisation, or any wanting a globally recognised risk-management framework → NIST CSF 2.0 — includes an indicative Implementation Tier
- Want a broad maturity baseline before picking a single certification → Cyber Resilience Maturity Assessment — recommends your next framework based on the strongest readiness signal
- Private equity investor or M&A team assessing a target → PE Due Diligence (contact for access)
- SOC team or MSSP assessing operational maturity → SOC Maturity (contact for access)
- Defense Industrial Base contractor pursuing DoD CMMC Level 2 certification → CMMC Level 2 Readiness (contact for access)
- Cloud Service Provider pursuing a FedRAMP Moderate Authorization to Operate → FedRAMP Rev5 Moderate Readiness (contact for access)
- US covered entity or business associate handling electronic protected health information → HIPAA Security Rule Assessment (contact for access)
Framework relationships
Frameworks are not mutually exclusive. A strong Cyber Essentials result significantly overlaps with the ISO 27001 technical controls (Annex A), which in turn covers much of the DORA ICT risk requirements. Achieving CAF Achieved/Partially Achieved across all principles provides strong evidence for NIS2 Article compliance. The Compliance Readiness Assessment cross-maps all four simultaneously.
Trial & Access
7-day free trial
All new accounts automatically receive a 7-day trial of the Assessment Bundle, giving access to all nine core assessments (Compliance Readiness is always free). Trial restrictions:
- PDF and JSON export are disabled on trial — you can run assessments and view results, but cannot download them.
- Sharing (generating shareable result links) is also disabled on trial.
- Phronesis AI analysis is capped at one run per assessment type during the trial (Phronesis chat and per-question guidance are unlimited).
Subscription options
- Assessment Bundle — Full access to all 9 core assessments (3 Phronesis AI analysis runs per month, shared across all your assessments, raised on request), PDF/JSON export, and sharing. See Pricing.
- CE One-Shot — Single Cyber Essentials analysis with 30-day read-only access. Useful for one-off assessments.
- PE Due Diligence / SOC Maturity / CMMC Level 2 / FedRAMP Moderate / HIPAA Security Rule — Delivered via the MSP & vCISO Partner Hub. Repeatable analysis, metered by a shared monthly allowance (default 3 runs/month, raised on request — same mechanism as the Assessment Bundle). Contact for access and pricing.
- Demo access — Sales-demo accounts (
demo_accessclaim) get unlimited access to every assessment in the platform including PE Due Diligence, SOC Maturity, CMMC Level 2, FedRAMP Moderate, and HIPAA Security Rule, with no trial restrictions, no export gate, and no monthly analysis limit.
Compliance Readiness Assessment Free
A 30-question cross-framework health check that simultaneously maps your posture against Cyber Essentials, ISO 27001, NCSC CAF, and DORA. Designed as a starting point — takes 10–15 minutes and requires no login for analysis (anonymous session).
Domains covered
Governance & Risk, Identity & Access, Network Security, Endpoint Protection, Data Governance, Incident Response, and Supplier & Third-Party Risk. Each question maps to one or more of the four target frameworks.
Output
Phronesis produces a cross-framework readiness matrix showing which framework you're closest to achieving, a prioritised gap list, and a recommended roadmap sequencing your compliance journey.
Cyber Essentials CE
Aligned to the NCSC Cyber Essentials v3.3 scheme — the UK government-backed baseline certification covering five technical controls plus an optional supply chain module.
The six controls
- Boundary Firewalls & Internet Gateways — Controlling inbound and outbound network traffic.
- Secure Configuration — Removing unnecessary accounts, services, and default credentials.
- Security Update Management — Patching operating systems, firmware, and third-party software within 14 days of critical releases.
- User Access Control — Principle of least privilege, MFA for all internet-facing services and admin accounts.
- Malware Protection — Anti-malware, application allow-listing, or sandboxing.
- Scope — Defining and documenting the in-scope boundary for certification.
Scoping your organisation
When you start a new Cyber Essentials assessment, a short "Scope your organisation" questionnaire appears first. Scope is the first thing a certifying body checks and the most common reason an application is sent back, so it is captured up front rather than buried in the questions. It takes about 90 seconds and runs over three steps:
- Who is being certified — legal entity name, assessment contact, and whether you are scoping the whole organisation or a sub-scope (a division, subsidiary, or single site). If you choose a sub-scope you'll be asked to describe the boundary and how it is separated.
- What is inside the boundary — sites and countries, whether staff work from home on in-scope devices, a device count broken down by type (desktops, laptops, tablets, phones, servers, thin clients, virtual machines), the operating systems and versions in use, and your cloud services grouped by SaaS, PaaS, and IaaS.
- Engagement intent — whether you are working towards Cyber Essentials or Cyber Essentials Plus, an optional target date, and whether third parties have access to in-scope systems.
You can skip it and start answering straight away — an amber bar stays at the top of the assessment with a Complete scope button. However, scope must be completed before an assessment can be finalised, because an unscoped result should never reach your Trust Centre, Audit Pack, or Compliance Passport.
The questionnaire only appears for a genuinely new assessment. Once answered, it will not interrupt a run that is in progress or already analysed. When you finalise a run and later start a fresh one — a re-certification, typically — you'll be asked to confirm scope again, which is exactly when scope changes tend to have crept in.
Once you run an analysis, the declared scope appears as its own Scope Declaration appendix page at the very end of the results report — legal entity, scope type and boundary, locations, remote working, device counts, operating systems, cloud services, and your CE vs CE Plus target. It is deliberately last, not first: a certification body such as IASME reviews the findings, then turns to the appendix to check what every answer actually refers to. It prints on its own page when you export to PDF, and is also included in the Audit Pack download alongside your question-by-question Assessment Record — so an assessor working from the pack gets the same declared boundary as one reading the on-screen report.
Conditional questions
Some questions only appear based on your earlier answers (e.g. if you confirm cloud services are in scope, cloud-specific questions become visible). Answers to hidden questions are automatically cleared to avoid stale scoring.
Supply chain module
The optional supply-chain section is switched on for you based on your scoping answer: if you said third parties or sub-contractors have access to your in-scope systems, it appears automatically. That is only a starting point — the Supply Chain button in the assessment header turns it on or off at any time, and once you have used that button your choice takes precedence. If you have already added vendors, the section is never hidden automatically.
An optional 7th section lets you assess each vendor individually across 8 weighted questions. Vendor risk is scored 0–100 and adjusted by access level (system, network, data, physical, cloud, limited). Vendors scoring below 40 are flagged as high risk.
Cross-framework hints from CAF, ISO 27001, CIS Controls, NIST CSF 2.0, and NIS2
If you've already finalised a CAF, ISO 27001, CIS Controls, NIST CSF 2.0, or NIS2 assessment, related Cyber Essentials questions show a small note underneath them summarising what you answered on the related item there — e.g. "NCSC CAF B4.b — Secure Configuration: 'Is the config hardened?': Achieved." None of these six frameworks share an official control catalog with each other, so this is Security Compliance Hub's own analysis relating similar requirements across frameworks, never an official or certified equivalence — and it is always purely informational. It tells you what you answered elsewhere; it never fills in or suggests a Cyber Essentials answer for you.
NCSC Cyber Assessment Framework CAF
The NCSC CAF is the assurance framework for Operators of Essential Services (OES) and relevant digital service providers under NIS Regulations. The assessment covers all 14 principles across four objectives.
Scoring
Each question uses a four-point scale: Achieved (100), Partially Achieved (50), Not Achieved (0), N/A (excluded from averages). A principle is considered achieved at ≥70 %, partially achieved at 40–69 %, not achieved below 40 %.
Indicators of Good Practice
Every outcome (e.g. A1.a — Board Direction) carries a Show Indicators of Good Practice button. Click it and the official NCSC CAF v4.0 wording for what Achieved, Partially Achieved, and Not Achieved actually look like appears beneath the questions for that outcome — so you can score against NCSC's own criteria without leaving the page or cross-referencing the CAF PDF. A small number of outcomes have no official Partially Achieved wording at all (NCSC treats them as a binary Achieved/Not Achieved judgement); the panel says so rather than showing an empty list. This is a reference only — selecting an indicator doesn't set your score for you, since NCSC's own guidance treats these as points for expert judgement across the whole set, not a checklist to tick.
If you run a Deep Analysis (the more thorough of the two analysis depths, available from the Analyse button) and have left a supporting evidence note against a question, Phronesis also cross-checks your declared score and evidence against the official indicator wording for that outcome and flags it under Indicator Contradictions if they genuinely don't line up — for example, evidence describing password-only access for standard users on an outcome scored Achieved for MFA coverage. It only surfaces genuine, material mismatches, not missing detail. Standard-depth analysis is unaffected — this check only runs on Deep Analysis, and only for outcomes where you left evidence.
Deep Analysis on CAF also produces a CAF Practitioner's Supporting Analysis card: your evidence notes, synthesised into bullet points grouped by principle, giving Phronesis a chance to note roadmap items, budget constraints, or planned work as partial mitigations rather than just reading the raw score.
NIS2 cross-mapping
NIS2 has its own dedicated assessment (see the NIS2 Directive Compliance guide) and the Unified Compliance Dashboard pulls its score directly from a completed run, the same way it does for CAF. Your CAF principle, DORA pillar, and ISO 27001 clause scores still appear alongside each of the 14 NIS2 sections in the dashboard's Cross-Framework Mapping table — useful reference context for where the frameworks relate — but no longer feed the NIS2 score itself.
NHS DSPT mode
If you set your sector to Health & Social Care, an NHS DSPT Mode bar appears. Enabling it adds Objective E — Using & Sharing Information Appropriately: the 8 NHS Information Governance outcomes (privacy & transparency, data subject rights, consent, the national data opt-out, information sharing for direct and secondary care, records management, and clinical coding) that the NHS CAF-aligned Data Security and Protection Toolkit layers on top of the standard 39 CAF outcomes — a full 47-outcome assessment.
Tell the tool your organisation type (NHS Trust, ICB, GP practice, supplier, or other) and it tailors the experience: ICBs don't perform clinical coding, so that question is hidden and scored N/A automatically, and the independent-assessment expectation is set correctly per type (Trusts and ICBs typically require an independent audit before publication; designated suppliers face a mandatory DSPT audit; GP practices and others follow a self-assessment route).
Your results gain a DSPT Readiness card showing your CAF score, your Objective E score, and a combined DSPT readiness percentage with a plain-English status — On track for Standards Met (≥70 %), Approaching Standards (50–69 %), or Not yet meeting Standards (<50 %). Any outcome rated "Not Achieved" is flagged as a DSPT-blocking risk, and a second radar chart maps all eight Objective E outcomes beside your 14 CAF principles. Phronesis analysis, per-question guidance, and the chat panel all become DSPT-aware, referencing NHS outcome codes (E1.a–E4.b), UK GDPR articles, and the Caldicott Principles. DSPT mode is opt-in and doesn't affect standard CAF assessments.
Cross-framework hints from Cyber Essentials, ISO 27001, CIS Controls, NIST CSF 2.0, and NIS2
Once you've finalised a Cyber Essentials, ISO 27001, CIS Controls, NIST CSF 2.0, or NIS2 assessment, related CAF outcomes show a small note underneath the first question in that outcome group summarising what you answered on the related item elsewhere, along with the date it was finalised. As with the equivalent hints on Cyber Essentials, ISO 27001, CIS Controls, NIST CSF 2.0, and NIS2, this is Security Compliance Hub's own judgement about related requirements — not a recognised industry equivalence — and it never suggests an answer for the CAF question itself.
DORA DORA
The Digital Operational Resilience Act (EU 2022/2554) applies to EU-regulated financial entities from January 2025. The assessment maps to Articles 5–45 across five pillars.
The five pillars
- ICT Risk Management (Arts. 5–16) — Governance framework, risk identification, protection, detection, response, recovery.
- ICT Incident Management (Arts. 17–23) — Classification, reporting, post-incident review.
- Digital Operational Resilience Testing (Arts. 24–27) — Including Threat-Led Penetration Testing (TLPT) for significant entities.
- ICT Third-Party Risk (Arts. 28–44) — Provider registers, contractual requirements, concentration risk.
- Information Sharing (Art. 45) — Participation in cyber threat intelligence communities.
Entity type selector
Selecting your entity type (credit institution, investment firm, insurance, payment institution, crypto-asset service provider, CSD, fund manager, or ICT third-party provider) tailors the Phronesis guidance to the applicable regulatory Technical Standards and proportionality provisions.
ISO 27001:2022 ISO
An ISMS assessment aligned to the 2022 revision of ISO/IEC 27001, covering both the mandatory management system clauses (4–10) and the Annex A control catalogue.
Sections
Clause 4 (Context), Clause 5 (Leadership), Clause 6 (Planning), Clause 7 (Support), Clause 8 (Operation), Clause 9 (Performance Evaluation), Clause 10 (Improvement), and Annex A technical controls. The Annex A section maps to the 93 controls reorganised across 4 themes in the 2022 revision (Organisational, People, Physical, Technological).
Cross-framework hints from Cyber Essentials, CAF, CIS Controls, NIST CSF 2.0, and NIS2
If you've already finalised a Cyber Essentials, CAF, CIS Controls, NIST CSF 2.0, or NIS2 assessment, related ISO 27001 controls show a small note underneath them summarising what you answered on the related item elsewhere, with a "Cross-framework references below are Security Compliance Hub's own analysis... not an official or certified equivalence" disclaimer above the first one shown. A control with related items in more than one other framework shows separate notes rather than one combined verdict — nothing here is ever averaged or merged into a suggested ISO answer.
AI Governance AI
An AI governance readiness assessment aligned to the EU AI Act (Regulation 2024/1689), ISO/IEC 42001:2023, and NIST AI RMF across six domains.
Organisation type
A modal on first use asks whether your organisation is an AI Deployer/Consumer, AI Builder/Provider, or Both. Deployer-only organisations see 33 questions — 9 builder-specific questions about training data, model development, and AI security are auto-scored N/A. An inline toggle lets you change this at any time during the assessment.
The six domains
- AI Strategy & Governance
- Risk Management
- Data Governance
- Transparency & Fairness
- AI Security & Robustness
- Lifecycle & Accountability
Cyber Resilience Maturity Assessment CRMA
A broad-based cyber maturity assessment aligned to the IASME Governance maturity model. Designed as a paid alternative to the free Compliance Readiness check — deeper coverage (70 questions across 14 themes), maturity-tier scoring, and an automatic recommendation of which certification framework you are closest to achieving.
Organisation size
A modal on first use asks whether your organisation is micro/small (under 50 staff), medium (50–249), or large/enterprise (250+). Micro/small organisations see 46 questions — 24 enterprise-only questions (board reporting, dedicated SOC, formal pen-testing programmes, etc.) are hidden and auto-scored N/A. An inline toggle lets you change this at any time.
The 14 themes
- Governance
- Risk Management
- Asset Management
- Identity & Access Management
- Data Protection
- Network Security
- Endpoint Security
- Vulnerability Management
- Incident Response
- Business Continuity & Disaster Recovery
- Supply Chain
- Awareness & Training
- Secure Development
- Compliance
Maturity scoring
Each answer scores against the IASME maturity scale: Verified = 100, Partially Verified = 50, Not Verified = 0, N/A = excluded from averages. Theme scores roll up to an overall maturity tier:
- Advanced — 75 % or above
- Established — 50–74 %
- Developing — 25–49 %
- Foundation — under 25 %
Framework readiness derivation
The Phronesis analysis applies a weighted mapping across your theme scores to estimate readiness against five target frameworks: Cyber Essentials, NCSC CAF, DORA, ISO 27001, and AI Governance. The framework with the strongest readiness signal is flagged as Recommended, with a direct link to start that assessment. AI Governance readiness is capped at 65 % because CRMA does not include AI-specific domains.
Output
Results include: an overall maturity tier badge, a 14-axis radar chart with grid rings at 25/50/75/100 % and a dashed red threshold polygon at 50 %, per-theme score bars colour-coded by tier, critical gaps (max 3), warnings (max 3), strengths (max 3), a 90-day roadmap with 4 milestones across 12 weeks, framework readiness cards with progress bars, a Phronesis summary, practitioner analysis notes derived from your evidence, and PDF/JSON/share export.
Supporting evidence
Every question has an optional evidence text field. Evidence text is included in the Phronesis payload and synthesised into a practitionerAnalysis[] section in the JSON response — useful for audit-ready documentation and for justifying maturity scores during certification preparation.
MSP / multi-tenant support
The CRMA can be run on behalf of a client from the MSP / vCISO Portal — assessment state is scoped per client (the localStorage key becomes crma_assessment_v1__msp_<clientId>) and scores are persisted to the MSP client record rather than the operator's personal account.
NIST CSF 2.0 NIST
An assessment against the NIST Cybersecurity Framework 2.0 — the updated US federal baseline for private-sector cybersecurity programme design. Version 2.0 adds a new GOVERN function that covers governance, strategy, risk management, roles, and supply-chain security. Particularly relevant for UK organisations selling into US enterprise or government markets, or seeking to align with internationally recognised security baselines.
Organisation size
A modal on first use asks whether your organisation is micro/small (under 50 staff), medium (50–249), or large/enterprise (250+). Micro/small organisations see 62 questions — 8 enterprise-only questions covering board-level oversight, supply-chain programme management, privileged access, and SOC/monitoring capabilities are hidden and auto-scored N/A. An inline toggle lets you change this at any time.
The six functions
- GOVERN (GV) — Organisational context, risk strategy, roles & responsibilities, policy, oversight, and supply-chain risk (new in v2.0)
- IDENTIFY (ID) — Asset management, risk assessment, and improvement planning
- PROTECT (PR) — Identity & access, awareness & training, data security, platform security, and resilience of the technology infrastructure
- DETECT (DE) — Continuous monitoring and adverse event analysis
- RESPOND (RS) — Incident management, analysis, communications, and mitigation
- RECOVER (RC) — Recovery planning and communications
Scoring
Each answer uses a four-point scale: Achieved = 100, Partially Achieved = 50, Not Achieved = 0, N/A = excluded from averages. Function scores roll up to an overall rating:
- Aligned — 70 % or above
- Partially Aligned — 40–69 %
- Not Aligned — under 40 %
Output
Results include: a 6-axis radar chart (one axis per Function), per-function score bars, critical gaps (up to 5), warnings, strengths, a prioritised next-steps list, and Phronesis AI analysis generating a 90-day action plan and per-gap remediation guidance. JSON export, PDF export, and share link are all available subject to your subscription tier.
Implementation Tier (indicative)
Alongside your percentage score, results show your indicative NIST Implementation Tier — Partial, Risk-Informed, Repeatable, or Adaptive, NIST's own four-stage description of how mature your cybersecurity risk-management process is. Rather than converting your overall score into a Tier, which would misrepresent what a Tier actually measures, it's computed from the specific questions that speak to NIST's three official Tier dimensions: your Integrated Risk Management Program, your Risk Management Process, and your Cybersecurity Supply Chain Risk Management. Your overall Tier reflects your weakest dimension, not an average of the three — a genuinely adaptive supply chain process alongside an ad hoc core risk process wouldn't be a fair "Tier 3" overall. It stays hidden until all three dimensions have at least one answered question, so you'll never see a premature label from a partly-completed assessment. This is Security Compliance Hub's own interpretation of your answers against NIST's framing — not an official NIST determination — and is included in both your JSON export and your PowerPoint report.
Cross-framework hints from Cyber Essentials, CAF, ISO 27001, CIS Controls, and NIS2
If you've already finalised a Cyber Essentials, CAF, ISO 27001, CIS Controls, or NIS2 assessment, related NIST CSF 2.0 Subcategory questions show a small note underneath them summarising what you answered on the related item elsewhere, along with the date it was finalised. As with the equivalent hints on those five frameworks, this is Security Compliance Hub's own judgement about related requirements — not a recognised industry equivalence, and not a transcription of NIST's or CIS's own published informative-reference mappings — and it never suggests an answer for the NIST CSF question itself. A question with related items in more than one other framework shows separate notes rather than one combined verdict.
Suggested answers from a finalised HIPAA assessment
Separately from the cross-framework hints above, if you've finalised a HIPAA Security Rule assessment, related NIST CSF questions show a small note suggesting an answer — this one is grounded in NIST's own official published crosswalk between the HIPAA Security Rule and the Cybersecurity Framework, so unlike the hints above it carries a genuine suggested value you can accept or override. Still never auto-filled. The reverse also holds: a finalised NIST CSF run suggests answers back on the HIPAA assessment.
PE Cyber Due Diligence Restricted
pedd_access custom claim (granted after offline payment via the MSP & vCISO Partner Hub), platform admin, or demo_access for sales-demo accounts.
A cyber risk assessment framework for private equity investors evaluating target companies, aligned to the IASME Governance maturity model. 14 themes, 70 questions, with enterprise-only questions filtered for micro/small targets.
Scoring
IASME tier scoring: Verified = 100, Partially Verified = 50, Not Verified = 0, N/A = excluded. Results include an IASME Tier badge (1–4), a RAG Deal Risk Rating (Red/Amber/Green), a 100-day remediation plan, and an estimated remediation cost band.
Repeatable analysis
Analysis runs are repeatable — re-run the assessment as new information comes to light during due diligence, subject to a shared monthly analysis allowance (the same mechanism used across the platform's other assessments), scoped and agreed with our team as part of your engagement.
SOC Maturity & AI Readiness Restricted
soc_access custom claim (granted after offline payment via the MSP & vCISO Partner Hub), platform admin, or demo_access for sales-demo accounts. Analysis runs are repeatable, subject to a shared monthly allowance — see Pricing.
A SOC capability and AI readiness assessment across 7 domains and 70 questions. Enterprise-only questions are hidden for Small/Mid-size SOC and MSSP configurations.
Domains
- Detection & Response
- Threat Intelligence
- Vulnerability Management
- Identity & Access
- Data Protection
- Incident Management
- AI & Automation Readiness
SOC type
Select Enterprise, Small/Mid-size, or MSSP on the welcome modal. Enterprise-only questions (board reporting, SIEM, SOC-specific tooling, etc.) are hidden for non-enterprise types. The inline toggle lets you switch type at any time — hidden question answers are auto-cleared.
Practitioner evidence
Every question has an optional evidence text field. Evidence text is included in the Phronesis payload and contributes to a practitionerAnalysis[] section in the JSON response — useful for creating audit-ready documentation.
CMMC Level 2 Readiness Restricted
cmmc_fedramp_access custom claim (granted after offline payment via the MSP & vCISO Partner Hub), platform admin, or demo_access for sales-demo accounts. Analysis runs are repeatable — re-run the assessment as many times as you need, subject to a shared monthly allowance (the same mechanism used across the platform's other assessments), scoped and agreed with our team as part of your engagement.
A readiness assessment against all 110 security requirements in NIST SP 800-171 Revision 2, the practice set required for CMMC (Cybersecurity Maturity Model Certification) Level 2 — the tier the US Department of Defense requires for contractors handling Controlled Unclassified Information (CUI). Built for Defense Industrial Base (DIB) organisations preparing for a C3PAO third-party certification assessment, or for a DoD contract eligibility self-assessment.
Requirement families
The 110 practices are organised into the 14 families NIST SP 800-171 defines:
- Access Control (22 practices)
- Awareness and Training (3 practices)
- Audit and Accountability (9 practices)
- Configuration Management (9 practices)
- Identification and Authentication (11 practices)
- Incident Response (3 practices)
- Maintenance (6 practices)
- Media Protection (9 practices)
- Personnel Security (2 practices)
- Physical Protection (6 practices)
- Risk Assessment (3 practices)
- Security Assessment (4 practices)
- System and Communications Protection (16 practices)
- System and Information Integrity (7 practices)
SPRS scoring — not a percentage
Every other assessment on this platform scores as a percentage. CMMC does not: it uses the official DoD Assessment Methodology, the same arithmetic the government itself uses for the Supplier Performance Risk System (SPRS) score a C3PAO or contracting officer will actually check. Scoring starts at 110 points and subtracts 1, 3, or 5 points for every practice that is not fully met, weighted by how much risk that specific gap represents. A perfect score is 110; an assessment with significant gaps can and does go negative.
Three practices work differently from a simple met/not-met:
- Multi-factor authentication (3.5.3) and FIPS-validated cryptography (3.13.11) have a genuine partial-credit state — an incomplete rollout costs fewer points than having nothing in place at all.
- Five practices covering remote access, wireless, and mobile devices (3.1.12, 3.1.13, 3.1.16, 3.1.17, 3.1.18) can be marked N/A at zero cost — but only if your organisation genuinely does not use that technology. Marking N/A when the technology is in use is flagged for review and scored as a full gap.
- A System Security Plan (3.12.4) is not scored at all — it's a prerequisite. Without one, a certification assessment cannot proceed regardless of how high the numeric score is, and the results panel shows a standing warning until it's addressed.
Plans of Action & Milestones (POA&Ms) — a documented plan to close a gap later — are never scored as "met" under this methodology, even though DoD permits their operational use in some circumstances. A practice with an open POA&M is scored exactly as if nothing had been done.
The results panel shows the true SPRS score as the headline number, followed by a section breakdown, a full list of point deductions ranked by size, and any answers flagged for review because they don't fit that practice's legitimate response options.
Plain-English guidance, official wording on demand
Each question shows a short, plain-English explanation of what it's actually asking by default. The original NIST wording — the formal "Determine if..." assessment-objective text C3PAOs work from — hasn't gone anywhere: it's one click away behind a "Show official NIST wording" toggle under each question, and it's still what Phronesis grounds its analysis and per-question guidance in.
Suggested answers from a completed FedRAMP assessment
If you have already finalised a FedRAMP Moderate assessment, CMMC automatically shows the equivalent small suggested-answer note under each shared practice, summarising what you answered on FedRAMP and its date — the reverse direction of the FedRAMP-side feature described below. Same trust model: it's a suggestion only, never fills in the CMMC answer for you, and the note only appears once your FedRAMP run has been finalised (not just analysed). This assessment is fully standalone — you do not need to have completed FedRAMP first.
FedRAMP Rev5 Moderate Readiness Restricted
cmmc_fedramp_access custom claim (granted after offline payment via the MSP & vCISO Partner Hub), platform admin, or demo_access for sales-demo accounts. Analysis runs are repeatable under the same shared monthly allowance used across the platform's other assessments.
A readiness assessment against all 323 security controls in the NIST SP 800-53 Revision 5 Moderate baseline — the control set a cloud service offering must satisfy for a Moderate-impact FedRAMP (Federal Risk and Authorization Management Program) Authorization to Operate (ATO), whether pursued via the Joint Authorization Board (JAB) or an individual federal agency sponsor. Built for Cloud Service Providers (CSPs) preparing for a Third-Party Assessment Organization (3PAO) assessment.
This assessment is fully standalone — you do not need to have completed the CMMC Level 2 assessment first, even though the two share 123 controls in common. If you have already finalised a CMMC run, FedRAMP now shows a suggested-answer note on each shared control — see below.
Control families
The 323 controls are organised into the 18 families NIST SP 800-53 Rev 5 defines for the Moderate baseline:
- Access Control (43 controls)
- Awareness and Training (6 controls)
- Audit and Accountability (16 controls)
- Assessment, Authorization, and Monitoring (14 controls)
- Configuration Management (27 controls)
- Contingency Planning (23 controls)
- Identification and Authentication (27 controls)
- Incident Response (17 controls)
- Maintenance (10 controls)
- Media Protection (7 controls)
- Physical and Environmental Protection (19 controls)
- Planning (7 controls)
- Personnel Security (10 controls)
- Risk Assessment (11 controls)
- System and Services Acquisition (21 controls)
- System and Communications Protection (29 controls)
- System and Information Integrity (24 controls)
- Supply Chain Risk Management (12 controls)
A readiness snapshot, not an authorization
Each control is rated Verified / Partially Verified / Not Verified / Not Applicable, averaged per family into a percentage score. This is deliberately a simple readiness percentage, not the real DoD-style SPRS point-deduction methodology CMMC Level 2 uses above — FedRAMP has no equivalent scoring system of its own. A real FedRAMP assessment is conducted by an accredited 3PAO, documented in a Security Assessment Report, and any unmet control becomes a Plan of Action & Milestones (POA&M) item tracked to closure — a POA&M item is not the same as a met control. After authorization is granted, the system enters Continuous Monitoring (ConMon): ongoing vulnerability scanning, annual reassessment, and significant-change reporting. Nothing in this assessment's result constitutes, contributes to, or accelerates an actual ATO decision.
Plain-English guidance, official wording on demand
Each question shows a short, plain-English explanation of what it's actually asking by default. The original NIST wording — the formal "Determine if..." assessment-objective text a 3PAO assessor works from — hasn't gone anywhere: it's one click away behind a "Show official NIST wording" toggle under each question, and it's still what Phronesis grounds its analysis and per-question guidance in.
Suggested answers from a completed CMMC assessment
If you have already finalised a CMMC Level 2 assessment, FedRAMP automatically shows a small suggested-answer note under each control the two frameworks share (CMMC's SP 800-171 practices map onto SP 800-53 via a published NIST crosswalk), summarising what you answered on CMMC and its date. This is a suggestion only — it never fills in the FedRAMP answer for you, and you should still confirm each control reflects the system actually in scope for FedRAMP (a CMMC assessment scopes your organisation's CUI environment, which may differ from the cloud service offering being assessed for FedRAMP). The note only appears once your CMMC run has been finalised (not just analysed) — an in-progress or analysed-but-unfinalised CMMC run won't be picked up yet.
HIPAA Security Rule Assessment Restricted
hipaa_access custom claim (granted after offline payment via the MSP & vCISO Partner Hub), platform admin, or demo_access for sales-demo accounts. Unlike CMMC and FedRAMP, HIPAA has its own dedicated claim, not a shared one. Analysis runs are repeatable, subject to the shared monthly allowance used across the platform's other assessments.
A readiness assessment against the HIPAA Security Rule (45 CFR Part 160 and Part 164 Subpart C) — the Administrative, Physical, and Technical Safeguards that US covered entities and business associates must implement to protect electronic protected health information (ePHI). Built for organisations preparing for their own required Security Risk Analysis, an OCR audit, or a business associate due-diligence review. Scope is deliberately the Security Rule only — the HIPAA Privacy Rule and Breach Notification Rule are not covered.
Required vs. Addressable — not a simple met/not-met
HIPAA's own regulation splits every implementation specification into two kinds, and this assessment scores them differently:
- Required specifications must be implemented as stated — there is no alternative pathway. These questions offer three answers: Met, Not Met, Not Applicable.
- Addressable specifications are not optional, but they're not rigid either: the organisation must assess whether the specification is reasonable and appropriate for its own environment, and either implement it or implement an equivalent alternative measure that achieves the same protective intent. Doing so satisfies the standard — it is not a lesser or partial compliance state. These questions offer a fourth option, "Addressed via alternative measure," scored identically to a full "Met."
Phronesis is told which kind each question is, so it never suggests declining an Addressable specification without a documented risk-based rationale, and never treats a Required specification as if it had an alternative pathway it doesn't.
What's covered
47 questions across three sections, mirroring the Security Rule's own structure: Administrative Safeguards (§164.308 — 28 questions, covering security management, workforce security, information access management, security awareness and training, contingency planning, and business associate agreements) — this section also folds in the related Organizational Requirements (§164.314) and Policies, Procedures & Documentation requirements (§164.316); Physical Safeguards (§164.310 — 10 questions, covering facility access controls, workstation use and security, and device and media controls); and Technical Safeguards (§164.312 — 9 questions, covering access control, audit controls, integrity, person or entity authentication, and transmission security).
Full platform integration
Same treatment as every other paid assessment: Evidence Vault (attach supporting files to any question), Audit Pack export, Remediation Tracker, PDF/JSON/PowerPoint export, shareable read-only links, sector benchmarking, Ask Phronesis chat, and MSP Portal support for practitioners managing multiple client organisations.
Cross-references your NIST CSF 2.0 answers
If you have already finalised a NIST CSF 2.0 assessment, HIPAA automatically shows a small suggested-answer note under each question the two frameworks share (grounded in NIST's own official published crosswalk between the HIPAA Security Rule and the Cybersecurity Framework), summarising what you answered on NIST CSF and its date — and the same happens in reverse on the NIST CSF assessment once a HIPAA run is finalised. This is a suggestion only — it never fills in the answer for you. The note only appears once the source run has been finalised (not just analysed); an in-progress or analysed-but-unfinalised run won't be picked up yet.
A readiness self-assessment, not a compliance determination
Nothing in this assessment's result constitutes a HIPAA compliance determination, a certification, or a substitute for the organisation's own legally-required Security Risk Analysis (45 CFR 164.308(a)(1)(ii)(A)). It's a structured way to prepare for one, track gaps, and generate an evidence-backed record.
CIS Controls v8 CIS
A readiness assessment against all 18 Controls and 153 Safeguards of the CIS Critical Security Controls v8 — one of the most widely adopted, prioritised sets of best practices for defending against the most common cyber attacks. Included in the standard Assessment Bundle subscription and the 7-day free trial, alongside Cyber Essentials, CAF, DORA, ISO 27001, AI Governance, and CRMA — no separate purchase or access request needed.
Choose your Implementation Group
Before you start, you'll be asked which Implementation Group (IG) best matches your organisation's size and risk profile. This is CIS's own scoping mechanism, not a maturity ladder — a smaller organisation genuinely complete at IG1 is not "behind" a larger one assessed at IG3:
- IG1 — 56 Safeguards covering essential cyber hygiene. Recommended as a baseline for every organisation, regardless of size or resourcing.
- IG2 — 130 Safeguards, cumulative (IG1 plus 74 more). For organisations with greater IT complexity, multiple departments, and some exposure to targeted attacks.
- IG3 — all 153 Safeguards. For organisations facing sophisticated adversaries, where the impact of a successful attack is high.
Only the Safeguards in your chosen tier are shown — completing every Safeguard in your tier counts as a 100% complete assessment, not a partial one. You can change your Implementation Group at any time from an inline toggle above the questions, and switching tiers never loses answers you've already given to Safeguards that remain visible.
Controls covered
The 18 Controls span asset and software inventory, data protection, secure configuration, account and access management, vulnerability management, audit logging, malware defence, data recovery, network infrastructure and monitoring, security awareness training, service provider management, application software security, incident response, and penetration testing.
Full platform integration
Same treatment as every other Assessment Bundle framework: Evidence Vault (attach supporting files to any Safeguard), Audit Pack export, Remediation Tracker, PDF/JSON/PowerPoint export, shareable read-only links, sector benchmarking, Ask Phronesis chat, and MSP Portal support for practitioners managing multiple client organisations.
Cross-framework hints from Cyber Essentials, CAF, ISO 27001, NIST CSF 2.0, and NIS2
If you've already finalised a Cyber Essentials, CAF, ISO 27001, NIST CSF 2.0, or NIS2 assessment, related CIS Safeguards show a small note underneath them summarising what you answered on the related item elsewhere, along with the date it was finalised. As with the equivalent hints on those other frameworks, this is Security Compliance Hub's own judgement about related requirements — not a recognised industry equivalence — and it never suggests an answer for the CIS question itself. A Safeguard with related items in more than one other framework shows separate notes rather than one combined verdict.
NIS2 Directive NIS2
A readiness assessment against the EU NIS2 Directive (2022/2555) — the risk-management measures, incident reporting obligations, governance accountability, and registration requirements it places on operators of essential and important services across the EU. Included in the standard Assessment Bundle subscription and the 7-day free trial, alongside Cyber Essentials, CAF, DORA, ISO 27001, AI Governance, CRMA, and CIS Controls — no separate purchase or access request needed.
A readiness indicator, not a legal determination
Before you start, you're asked which sector best describes your organisation and roughly how large it is. This is purely informational — nothing about your answers here hides, skips, or auto-completes any question, unlike CIS's Implementation Group picker or CRMA/PE Due Diligence/SOC Maturity's organisation-size filters. Whether NIS2 actually applies to your organisation, and whether you're classed as an "Essential" or "Important" entity, depends on facts (headcount, turnover, sector, and how your national government has transposed the Directive) this platform cannot verify — the results page and the Phronesis AI narrative both frame this as a readiness indicator only, never a legal determination of NIS2 applicability or compliance.
What's covered
56 questions across 14 themes, built around the Directive's own structure: Governance (Article 20 management-body accountability and training) and Risk Analysis & Security Policies lead the assessment; Incident Handling covers your internal detection, triage, and response capability, while a separate Reporting Obligations section walks through the Article 23 notification timeline itself — the 24-hour early warning, the 72-hour follow-up notification, on-demand status updates, and the 1-month final report, plus customer notification and voluntary reporting of sub-threshold incidents. The remaining themes cover Business Continuity & Crisis Management, Supply Chain Security, Secure Acquisition & Development, Vulnerability Management, Cryptography, HR Security & Training, Access Control, Asset Management, MFA & Secured Communications, and Registration & Regulatory Engagement (Article 27).
Full platform integration
Same treatment as every other Assessment Bundle framework: Evidence Vault (attach supporting files to any question), Audit Pack export, Remediation Tracker, PDF/JSON/PowerPoint export, shareable read-only links, sector benchmarking, Ask Phronesis chat, and MSP Portal support for practitioners managing multiple client organisations.
Cross-framework hints reaching Cyber Essentials, CAF, ISO 27001, CIS Controls, and NIST CSF 2.0
Once you've finalised a NIS2 assessment, related questions on any of the other five frameworks show a small note summarising what you answered here, along with the date it was finalised — the reverse direction works too, so a finalised CE/CAF/ISO/CIS/NIST CSF run shows hints on your NIS2 questions. As with every other cross-framework hint in the product, this is Security Compliance Hub's own judgement about related requirements — never a recognised industry equivalence, and never a suggested answer for the target question.
My Hub
The central hub for your compliance posture. Sign in and navigate to My Hub to see all completed assessments, in-progress drafts, peer benchmarks, and your Compliance Passport.
Framework coverage radar
A 6-axis SVG radar showing your latest scores across all frameworks you have access to. Hidden when fewer than 3 frameworks are visible or none are completed. Axes are coloured per framework; a dashed red outline marks the 70 % compliance threshold.
Peer benchmark ribbon
Compares your scores against anonymised sector peers. Set your industry sector in the Dashboard Settings panel to unlock benchmarking. Chips are colour-coded: Top quartile (teal), Above median (green), 25–50th percentile (amber), Below 25th (red). Benchmarks build as more organisations in your sector contribute data (minimum 10 organisations per segment).
Compliance Passport
A printable one-page compliance summary. Click the Compliance Passport button in the Framework Coverage section. The passport includes your organisation name, sector, issue date, a framework scores table with RAG ratings and sector positions, and a plain-English summary. Print or Save as PDF from your browser.
Completed assessments & the full record
Each finalised assessment shows as a card with its score, RAG rating, and top critical issues. Click View completed assessment → to open the read-only results page. If that run has a retained answer record (any assessment finalised since this feature shipped — see Audit Pack), the page also shows an Assessment Record panel: every question, grouped by section, with your actual answer, any evidence note, and any attached files — so you can check exactly what was answered behind a section score, not just the score itself. Older runs, or ones whose 3-year record has since expired, show the page exactly as before with a short note in place of the panel. An analysed run that hasn't been finalised yet shows a plain "View Results →" link instead — finalise it first (the amber banner's Finalise button) to unlock the full record.
Remediation summary
Shows per-framework completion progress for your Phronesis-generated action items. Links to the relevant assessment to continue working through items. When all items across all frameworks are complete, a green completion panel replaces the chips.
Security Tool Integrations
The Security Tool Integrations section on My Hub (and on each client detail view in the MSP Portal) shows connected security tools whose live data surfaces as hints inside assessment questions. Currently available: Microsoft Entra ID (MFA coverage, Conditional Access, device compliance, Secure Score), Okta Identity Engine (MFA enrolment + policy, password policy, group membership, lifecycle), CrowdStrike Falcon (sensor coverage, prevention policies, Spotlight vulnerabilities, detections, incidents), and Google Workspace (2-Step Verification coverage, account lifecycle, Chromebook + mobile MDM). Further integrations on the roadmap: Qualys, Tenable, Splunk, SentinelOne.
If you run a Deep Analysis on any assessment with at least one tool connected, your results also include a Connected Tools Evidence card: a short set of bullet points comparing live figures from your connected tools (MFA enforcement rate, device coverage, endpoint protection, and similar) against what you answered in the assessment, calling out where they agree or contradict each other. With no tools connected yet, this card instead shows a short prompt inviting you to connect one — so the feature is visible even before you've tried it. Standard Analysis and Self-Score are unaffected.
Your Assessments grid
The Status tab's Your Assessments grid shows every framework you have access to in one place, regardless of state: completed and in-progress-and-analysed cards (score, RAG rating, top critical issues), in-progress drafts (progress bar, last-saved time), and — for anything you haven't started yet — a Start assessment → card linking straight to the questionnaire. This includes any bespoke framework granted via the custom_frameworks claim (e.g. a sector-specific or confidential compliance programme granted to your organisation alone) — contact your administrator to request access to a specific framework.
Phronesis AI
Phronesis is the AI analysis layer built into every assessment. It runs via a secure server-side Cloud Function that adds authentication, rate limiting, and prompt engineering — your data is never sent directly to any external AI service from the browser.
Three modes
- Analysis — Full assessment report: scores, critical gaps, strengths, next steps, timeline, and action items. Triggered by the main "Analyse with Phronesis" button. Capped at 1 run per assessment type on free trial. Standard and Deep Analysis require every question to be answered first — this protects your analysis allowance from being spent on a partial result. Use Self-Score (free, instant, no AI narrative) for a quick read at any point, complete or not.
- Guidance — Per-question help explaining what the question is really asking, what good evidence looks like, and common pitfalls. Available during the assessment; not subject to the trial cap.
- Chat — Conversational follow-up after analysis. Ask Phronesis to explain specific gaps, suggest remediation approaches, or compare frameworks. Not capped on trial; individual messages are limited to 2,000 characters.
Rate limits
Authenticated users: 20 API requests per minute. Anonymous users (Compliance Readiness only): 3 analysis runs per day. These limits are enforced server-side and cannot be bypassed.
Attack Surface Scan
An optional External Attack Surface & Breach Check widget appears near the top of the questions on Cyber Essentials, NCSC CAF, DORA, ISO 27001, Cyber Resilience Maturity, PE Due Diligence, NIST CSF 2.0, CMMC Level 2, FedRAMP Moderate, CIS Controls v8, NIS2 Directive, and HIPAA Security Rule assessments (not on AI Governance, SOC Maturity, or Compliance Readiness). Enter your organisation's domain, confirm you're authorised to run external checks against it, and it queries free, no-API-key sources — Shodan InternetDB for open ports, known CVEs, and discovered subdomains, and Have I Been Pwned / Enzoic for disclosed data breaches — showing the combined result as a single severity-ranked card. Free and unlimited; results are saved with your assessment and reappear when you return.
If you run Standard or Deep Analysis after scanning, the same findings are handed to Phronesis, which is asked to flag only genuine, material mismatches against your declared answers (for example, a control claiming restricted remote access alongside a high-risk port left exposed) — routine findings your answers already acknowledge are not flagged. The scan also appears as a read-only card in your results report, right alongside the rest of the analysis. Self-Score never sends anything to the server, so a scan run before choosing Self-Score is shown to you only, never to Phronesis.
Evidence Vault
Attach supporting evidence files to individual assessment questions. The Evidence Vault is available on CE, CAF, DORA, ISO 27001, AI Governance, PE Due Diligence, NIST CSF 2.0, CMMC Level 2, FedRAMP Moderate, CIS Controls v8, NIS2 Directive, and HIPAA Security Rule assessments. Requires Assessment Bundle, CE One-Shot, PE DD access, SOC access, or CMMC/FedRAMP/HIPAA access.
How to upload
A paperclip icon appears on each question. Click it to select a file — the upload uses a signed GCS resumable URL, so large files transfer directly to Google Cloud Storage without going through Cloud Functions. Once confirmed, a chip appears below the question showing the file name.
Storage quota
500 MB per account across all assessments. The Dashboard shows your current usage in the Evidence Vault section. Files are stored per-user and per-question; deleting a chip removes the file from storage and reclaims the quota.
Supported formats
Any file type is accepted. Common evidence types: PDF policy documents, Excel risk registers, Word procedure documents, screenshots, network diagrams, and penetration testing reports.
Importing from SharePoint
If your organisation's Microsoft 365 / Entra integration is connected, a SharePoint button appears beside the paperclip on each question. Click it to open the SharePoint file browser, navigate your connected libraries, and attach a file directly from SharePoint — no download required. The file is copied to the Evidence Vault and counts against your 500 MB quota in the same way as a local upload. Supported file types mirror the standard Vault list (PDF, Word, Excel, PowerPoint, images, text, CSV, JSON). See Integrations for how to connect Microsoft 365.
Remediation Tracker
After a Phronesis analysis, action items are automatically created in the Remediation Tracker — a collapsible panel at the top of each assessment page and summarised on My Hub.
Supported assessments
The tracker is wired on all 14 assessments: Cyber Essentials, NCSC CAF, DORA, ISO 27001, AI Governance, PE Due Diligence, SOC Maturity, Cyber Resilience Maturity (CRMA), NIST CSF 2.0, CMMC Level 2, FedRAMP Moderate, CIS Controls v8, NIS2 Directive, and HIPAA Security Rule.
Action item properties
- Urgency — Critical, High, or Medium. Items are sorted by urgency.
- Effort estimate — Time estimate provided by Phronesis (Quick win / 1 day / 1 week / 1 month+).
- Owner — Free-text assignee field (e.g. "IT Lead", a colleague's name).
- Due date — Optional target completion date.
- Status — Tick to complete; progress bar shows X of N done.
Standalone tracker page
The My Hub "Continue →" links open remediation.html?type=<framework> — a dedicated page showing only the tracker for that framework, without loading the full assessment. This is the preferred entry point when you want to review or update action items without re-running the assessment.
For MSP practitioners, each framework row in the MSP Portal's remediation widget has a "Continue →" link that opens the tracker scoped to that client and framework directly. A "View full tracker →" link at the bottom of the widget opens all frameworks for the client in one view. When opened in MSP context, the page shows a teal 🏢 MSP Client: <name> chip so you can confirm you are viewing a client's actions, not your own.
Share a read-only link
From the standalone tracker page, click Share read-only link to generate a public URL (no login required) showing all action items, urgency, effort, due dates, owner, and status. Options:
- Expiry — 7, 30, or 90 days, or no expiry.
- Anonymise owners — replaces all assignee names with "[assigned]" before snapshotting. Recommended when sharing with external parties (auditors, board).
The shared viewer (shared-remediation.html?token=…) is a static read-only page with a "Print / Save as PDF" button. Tick, edit, and delete controls are not available to viewers.
Behaviour
Re-running analysis on the same assessment replaces existing action items — there is no duplication. The tracker collapse state is persisted per assessment type. When all items are ticked, a green "all done" banner appears in-session (and on My Hub).
Team and MSP scoping
For Team Tenant subscribers, action items are shared across all team members automatically — any teammate can tick, edit, or assign items. Members with the Viewer role can see but not modify items. For MSP users, each client's action items are isolated under their client namespace.
Collaborative Drafts
In-progress assessments are saved to the cloud automatically so you can pick up where you left off on a different device, and — for Team Tenant subscribers — share an in-progress assessment with teammates.
Cross-device sync
While you work through an assessment, your answers are saved locally first and synced to the cloud when you hide the tab, navigate away, or every 30 seconds (whichever comes first). When you open the same assessment on another device, a teal banner appears at the top of the page:
☁ Progress from another device found — 26% complete, saved 4 minutes ago. Load it? [Load progress] [Dismiss]
Choosing Load progress replaces your local state with the cloud version and reloads the page. Dismiss keeps your current local state untouched.
Team sharing (Team Tenants only)
If your account is part of a Team Tenant (owner + members), draft assessments are scoped to the tenant rather than to a single user. Anyone in the tenant can open the same in-progress CRMA, CAF, DORA, ISO 27001, AI Governance, or Compliance Readiness assessment and continue editing.
- CE, PE Due Diligence and SOC Maturity are always personal (user-scoped) regardless of tenant membership — these are typically single-author assessments.
- Trial users do not get tenant sharing. Upgrade to the Assessment Bundle (or join a tenant) to enable it.
"Last saved by" and live presence
On My Hub, each in-progress card shows the last person who edited it:
- Last saved by [Name] — appears under the progress bar when no-one currently has the assessment open.
- 🔒 Being edited by [Name] — amber chip that appears when a teammate has the assessment open right now (presence pings every 60 s; the chip clears within 2 minutes of them closing the tab).
Tenant owners, tenant admins, and platform admins also see a Take over button on locked cards — clicking it clears the active presence so they can open the assessment without conflict (useful if a teammate has left a tab open and won't be returning).
Conflict resolution
If two teammates save changes to the same assessment at the same time, the second save will trigger an amber banner:
⚠ [Teammate] saved newer changes 2 minutes ago. Load their version, or overwrite? [Load newer] [Overwrite]
Load newer pulls in their changes and discards yours; Overwrite retains yours and discards theirs. The dashboard's presence indicator is designed to prevent this by warning you before you start editing — the banner is a safety net for the rare case it happens anyway.
Sharing Results
Generate a tokenised read-only link to share your assessment results with stakeholders, auditors, or clients — no account required to view the shared page.
Creating a share link
Click the Share button in the results panel of any assessment except SOC Maturity and Compliance Readiness (CE, CAF, DORA, ISO 27001, AI Governance, PE Due Diligence, CRMA, NIST CSF 2.0, CMMC Level 2, FedRAMP Moderate, CIS Controls v8, NIS2 Directive, HIPAA Security Rule). Set an optional title and pick expiry: 7, 30, or 90 days, or no expiry (30 days is pre-selected). Copy the generated link and share it.
What the recipient sees
The shared page (shared-result.html) shows score overview, section bars, critical issues, strengths, next steps, and the Phronesis summary. It includes a "Save as PDF" button. No login is required.
Expiry and revocation
Expired or revoked tokens return HTTP 410 to recipients. You cannot revoke a link from the UI directly — if needed, contact support. Sharing is not available during the free trial.
PDF, JSON & PPTX Export
PDF export
Available on all assessments. Click Save as PDF in the results panel. You'll be prompted to enter your organisation/company name; this is added to the report header. The browser's native print dialogue opens — choose "Save as PDF" as the destination.
The PDF includes scores, radar chart, critical gaps, remediation steps, and the Phronesis AI narrative. The nav bar and browser chrome are automatically hidden before printing.
PowerPoint export (PPTX)
Available on all 14 core assessments after a Phronesis analysis. Click 💾 Export PPTX in the results panel to download a branded slide deck generated entirely in the browser — no server round-trip required.
Each deck contains a cover slide, executive summary (score badge, stat chips, and the AI summary), a radar chart (for frameworks with ≤8 sections), per-section score bars coloured green/amber/red, critical issues, strengths, next steps, and a 90-day roadmap slide (CRMA only). The deck is ready to drop into a board report or client presentation and can be edited in PowerPoint or Google Slides.
JSON export
Available on all assessments. The exported JSON contains your raw responses, calculated scores per section, and the full Phronesis analysis result — useful for feeding into GRC tools or for records retention.
Policy Coverage Checker
The Policy Coverage Checker analyses whether your existing security policies adequately cover the controls where your assessment score is below 70%. It appears inside the CE and ISO 27001 results panels after a Phronesis analysis completes, and uses a short structured questionnaire (no document upload required) to assess coverage without sensitive policy content ever leaving your organisation.
How it works
- Run a Phronesis analysis on a CE or ISO 27001 assessment.
- A Check Policy Coverage → button appears in the results panel for any control or section scoring below 70%.
- A slide-in panel shows 2–3 targeted questions per weak control: does a relevant policy exist, how specifically does it address the control, and is there supporting evidence?
- Answers are sent to Phronesis (structured data only — no document content), which returns a per-control coverage verdict and a prioritised action list.
- Suggested policy templates are shown with a Generate → deep-link that opens the Policy Generator pre-scrolled to the relevant template.
Coverage verdicts
- Covered — a specific, relevant policy exists and there is evidence of implementation
- Partially covered — a policy exists but it is generic, outdated, or lacks evidence of enforcement
- Not covered — no relevant policy exists or it is missing for this control area
mode: 'guidance' path and counts against the existing Phronesis guidance cap (trial: 20 total turns; Assessment Bundle: 100/day). No document upload is used — only your structured answers are sent to Phronesis.
Audit Pack
The Audit Pack generates a certifier-ready ZIP bundle containing your assessment data and evidence files. Designed for external auditors, certification bodies, and procurement partners who need a structured, verifiable evidence set rather than a PDF screenshot.
What's in the ZIP
- README.txt — pack metadata, generation timestamp, organisation name, and a summary of included files
- assessment-data.json — your full assessment snapshot: overall score, section scores, critical issues, strengths, next steps, and Phronesis summary
- assessment-record.json — the full question-by-question record as answered, when available (see below)
- assessment-report.html — a self-contained HTML report with inline styles, an Assessment Record section (plus a Scope Declaration section for Cyber Essentials), and SHA-256 integrity hashes of the JSON files for tamper detection
- evidence/{questionId}/{fileName} — all evidence files attached to the assessment, downloaded via 1-hour signed URLs at generation time
Assessment Record
Every finalised run of the 14 core assessment types is snapshotted into a retained record at the moment it's finalised — every question, its text and answer options as they read at the time, your answer, any evidence note, and any attached files, grouped by section. The Audit Pack includes this full record (both as a human-readable table in assessment-report.html and as machine-readable assessment-record.json) so an auditor can check the section score against the individual answers that produced it, not just take the score on trust.
Scope Declaration (Cyber Essentials only)
A finalised Cyber Essentials Audit Pack also includes your completed Scope Declaration — legal entity, scope type and boundary, locations, remote working, device counts, operating systems, cloud services, and your CE vs CE Plus target — as its own section in assessment-report.html, positioned after the Assessment Record. It's the same declaration your on-screen results report shows as its closing appendix page, so a certification body working from the downloaded pack sees the identical boundary. This section only appears for Cyber Essentials; every other assessment type's Audit Pack is unaffected.
Generating an Audit Pack
- Complete your assessment and run a Phronesis analysis so a score snapshot is saved to your account.
- Upload evidence files via the paperclip buttons on individual questions (Evidence Vault must be enabled).
- Click 📦 Audit Pack in the results export bar.
- A progress modal appears while the pack is assembled. The ZIP downloads automatically when ready.
files: []. The Assessment Record section covers the same 14 types.
Trust Centre
Your Trust Centre is a permanent, publicly accessible security posture page at a unique URL. Share it with clients, partners, and procurement teams so they can verify your compliance posture without requesting a report or signing an NDA.
What it shows
- Framework score cards for any assessment types you choose to publish, with section bars and RAG ratings
- A SOC 2 Readiness chip derived from your CE and ISO 27001 scores (shown when both are present)
- Microsoft Entra ID signals: MFA coverage rate, Conditional Access status, device compliance rate, and Secure Score (requires Entra integration)
- Active certifications and accreditations you list manually (up to 10 per organisation)
- An embeddable trust badge SVG you can add to your website or email footer
Setting up your Trust Centre
- Go to My Hub and scroll to the "Your Trust Centre" panel.
- Toggle visibility to Public and select which framework scores to publish.
- Add certifications, an optional headline, and configure Entra signal display.
- Click Save. A unique slug is generated on first save and your public URL is shown.
- Share the URL or copy the badge snippet to embed on your website.
Sector Benchmarking
After each completed analysis, your overall and section scores are anonymously contributed to a sector benchmark dataset. Once 10+ organisations in your sector have contributed, you'll see a "How You Compare" block in the results.
How scores are collected
Scores are hashed (SHA-256 of your user ID) before storage — your identity is never linked to the benchmark data. You can opt out at any time in Dashboard Settings.
What the benchmark shows
- Your score vs. sector median and mean
- A percentile badge (Top quartile / 50–75th / 25–50th / Bottom quartile)
- A colour-coded distribution bar (p25 → median → p75)
- Dual bars for each section: your score vs. sector mean
Benchmarks are aggregated every 6 hours by a scheduled Cloud Function. Sector categories are standardised — see Dashboard Settings to ensure your sector is correctly set.
Supply Chain Risk Manager
A supplier security questionnaire distribution and portfolio risk tracking system. Requires supply_chain_access custom claim. Supports up to 200 suppliers. Custom questions (up to 100 authored, 100 per send) are included for all subscribers.
Core flow
- Add a supplier to your portfolio and send them a secure questionnaire link (no account required for the supplier).
- The supplier completes 8 domains of security questions. Optional per-question comments are included in your analysis.
- Trigger a Risk Purview scan against the supplier's domain — external verification signals covering DNS health, TLS certificate validity, open ports, breach history, and company registration are gathered and analysed.
- The platform detects contradictions between self-reported questionnaire answers and externally observed signals (e.g. "claimed MFA everywhere" vs exposed RDP on port 3389).
- A monthly automated re-scan diffs against the previous result and raises alerts for new signals, severity escalations, or score drops.
Risk scoring
Questionnaire risk: weighted radio answers (Achieved / Partial / Not Achieved / N/A) scored server-side. Risk Purview score: composite 0–100 across all probe signals. Levels: Strong / Moderate / Weak / Critical.
Questionnaire Library
Click the Custom Questions toolbar button to open the Questionnaire Library panel. The panel shows the 28 canonical questions (read-only, grouped by domain) alongside your authored custom questions. You can add, edit, and delete custom questions from the library, or import a batch via CSV (text,help,domain,weight columns — the importer validates each row before committing).
Custom questions
All subscribers can author up to 100 bespoke questions (weighted 1–3, same 4-option scale) and append up to 100 per send. Custom questions genuinely affect the risk score — they're not informational-only. A canonical-only benchmarkScore is computed separately so sector benchmarking remains comparable across organisations.
Sending a questionnaire (3-step flow)
After filling in the supplier details and clicking Next →, a 3-step overlay guides you through the send:
- Pick questions — tick which of your custom questions to append to the canonical 28 for this specific send.
- Preview — read the full questionnaire (canonical + selected custom) exactly as the supplier will see it, grouped by domain.
- Expiry + Send — choose the link expiry (7 / 30 / 90 days / No expiry) and click Send. The supplier receives a one-time link; no account required.
Annual renewal reminders
Once a supplier completes a questionnaire, the platform tracks the response and emails you when re-assessment is approaching — 30 days out, 7 days out, on the day, and once if overdue. All due suppliers for a given account are bundled into a single daily digest so a batch send a year ago doesn't produce dozens of separate emails. Configure the destination mailbox (e.g. infosec@acme.com) and on/off toggle via the 🔔 Reminders button on the Supply Chain portfolio toolbar; if left blank, reminders go to your account email. Completed supplier cards show a "Renews in Nd" chip within 30 days and a "Renewal overdue" chip if past due.
MSP / vCISO Portal
The MSP/vCISO Portal lets managed service providers and virtual CISOs run and manage compliance assessments across an entire client portfolio from a single account. Requires the msp_access custom claim — contact the MSP & vCISO Partner Hub to arrange access.
Portfolio view
The portal home shows all managed clients in a searchable grid with aggregate stats (total clients, assessed count, average score). Each client card links to a detail view showing per-framework assessment tiles, policy documents, and the Remediation Tracker for that client.
Above the grid, a chip bar lets you narrow the list to Unassessed, Stale (>90d), or Recent (<30d) clients — useful for spotting clients you haven't touched in a while or new clients you've added but never run an assessment against. Chips combine with the search box (AND logic), and the portfolio resets to "All" every time you reopen the portal.
Portfolio Insights
The Insights tab (next to the Clients tab at the top of the portfolio) gives you a risk-ranked view across your entire client portfolio. It shows four summary stats — stale assessments (>90 days since last run), open critical and high remediation actions, integration coverage, and number of ranked clients — plus a Top Risk Clients list ranked by a composite score that combines low assessment scores, critical gaps, open high-urgency actions, and staleness. Clicking a row opens that client's detail view directly.
Insights are computed on demand and cached for 30 minutes. Use the Refresh button to bypass the cache and recompute immediately.
Per-client assessments
From a client's detail view, open any assessment framework tile to run or view results scoped to that client. Once finalised, the button reads View completed assessment → and calls GET /api/msp/get-snapshot, which returns the client's latest scores, strengths, next steps, and section-level control scores — the same shape as the standard results viewer — plus the full Assessment Record when that client's run has one (see My Hub above). From the same view you can re-run a Phronesis analysis on behalf of the client.
Cross-Framework Map
Once you've completed two or more of CAF, DORA, ISO 27001, CRMA, or Cyber Essentials for a client, a Cross-Framework Map tile appears in the client's completed-assessments section. It opens the Unified Compliance Dashboard scoped to that client, showing their scores side by side alongside a derived SOC 2 readiness coverage estimate — useful for a single board-ready posture view that spans every framework you've measured.
Risk Scenarios
Once at least one framework assessment has been completed for a client, a Risk Scenarios section appears below the assessment tiles. It uses the client's saved section scores to surface the most relevant threat scenarios — ranked Critical → High → Moderate → Low — alongside defensive controls and an optional Phronesis narrative. When multiple frameworks are complete, framework selector pills let you switch the view between CRMA, CAF, DORA, ISO 27001, PE DD, and CE; the view defaults to CRMA (broadest coverage) or the lowest-scoring framework when CRMA is unavailable. No additional data fetch is required — scenarios compute from the section scores already loaded for the assessment tiles.
Supply Chain Portfolio (MSP add-on)
MSP subscribers who hold the Supply Chain add-on (msp_sc_access claim) can manage supplier security questionnaires scoped per client. The client detail view shows a Supply Chain Portfolio tile with four stat cards (high-risk suppliers, unacked alerts, total suppliers, awaiting response). Opening the tile launches supply-chain.html?mspClient=<id>&mspClientName=<name> — every API call automatically scopes to the client's supplier sub-collection rather than the practitioner's personal portfolio. The monthly Risk Purview re-scan also routes alerts to each client's sc_alerts sub-collection automatically.
Evidence Vault scoping
When uploading evidence files on behalf of a client, the optional clientId parameter namespaces files under evidence/{uid}/clients/{clientId}/…. This keeps each client's audit documentation isolated within the MSP account's storage quota (500 MB shared across all clients).
Multi-tenant teams access
MSP subscribers can invite colleagues to share their client portfolio without purchasing an additional licence. The owner chooses two things for each invite, independently: what the member can do (Editor — full read/write, the same as the owner — or Viewer — read-only) and which clients they can see (the whole portfolio, or a specific list). The only owner-exclusive actions are managing billing, sending further team invites, and changing another member's access. By default an invited member is an Editor who sees the whole portfolio; either setting can be narrowed at invite time or at any point afterwards — see "Editor/Viewer role and per-client access" below.
Inviting a team member
- The portfolio owner clicks the Team button in the MSP Portal header, enters a colleague's email address, chooses Editor or Viewer, chooses All clients or Specific clients, and clicks Send invite.
- The colleague receives a branded invite email — worded for their actual access level, so a Viewer invite says so up front rather than implying they can make changes.
- They click the link, which opens
msp-team-onboarding.html?token=…. The invite preview shows their access level (Practitioner, or read-only Viewer) before they sign in. They sign in with any provider (Google, Microsoft, or email/password). A new SCH account is created automatically if needed. - On sign-in, the token is atomically consumed. The
msp_accesscustom claim is set on their account along with atenantId(linking them to the owner's portfolio) and atenantRolematching the role chosen at invite time. Their client access — full portfolio or the specific clients chosen at invite time — is recorded on their member record, not as a claim. - The team view in the portal updates immediately to show the new member, their role and access scope, and any pending invites.
To remove a team member, open the Team view and click Remove next to their name. Their access is revoked immediately — they will be signed out of the portal on their next page load.
Editor/Viewer role and per-client access
By default, an invited team member is an Editor who sees every client in your portfolio. Two independent settings can each be narrowed for a specific member, at invite time or afterwards: their role (Editor — can run assessments, save scores, and manage clients; or Viewer — can see everything within their scope but cannot make changes) and their client scope (all clients, or a specific list — useful for a subcontractor, a junior analyst, or someone brought on for a single engagement).
- Open the Team view. Each member's row shows two badges: a teal Editor or amber Viewer role badge, and a teal All clients or amber N client(s) scope badge.
- Click Edit access next to a member's name to open the access editor.
- Choose Editor or Viewer, choose All clients or Specific clients (ticking the clients this member should see for the latter), then click Save access.
- Client scope changes take effect on the member's next request — restricted clients disappear from their client list, and a deep-link to a client they no longer have access to shows a clear "you don't have access" message rather than an error. Portfolio-wide summary counts (e.g. in Portfolio Insights) reflect the whole book of business regardless of a member's own scope, but any list of named clients is filtered to what that member can see. Role changes take a little longer — since read-only enforcement is carried on the member's sign-in token, a role change takes effect the next time they sign in, or automatically within about an hour.
Integrations — Bringing Tool Data into Assessments
SCH offers two complementary ways to enrich your assessments with real data from your existing security toolstack, replacing manual self-declaration with evidence pulled from live systems.
Option A — Live connection (Microsoft Entra ID)
Connect your Azure AD / Entra ID tenant once and SCH pulls live security signals directly into your Cyber Essentials, CAF, ISO 27001, and DORA assessments as inline hints alongside relevant questions.
What data is pulled
- MFA coverage across user accounts
- Authentication method policy (FIDO2 passkeys, Microsoft Authenticator, SMS)
- Conditional Access policy state
- Risky user counts from Entra ID Protection
- Device compliance posture (Intune)
- Microsoft Defender alerts — including Sentinel-routed alerts when Microsoft Sentinel is linked to your Defender XDR workspace
- Security incidents (requires SecurityIncident.Read.All and a Sentinel licence)
- Microsoft Secure Score and Secure Score control breakdown
- Sign-in log availability
- Guest / external user count
How hints appear in assessments
- Blue hints — live tenant metrics shown beside the relevant question (e.g. "84 % of users have MFA enabled").
- Amber hints — licence warnings flagging when a data point requires a licence you may not hold (Entra P1/P2, Intune, or Defender plans).
- CE+ check (Cyber Essentials only) — a green/amber/red sub-line beneath the hint explaining what a Cyber Essentials Plus assessor will actually do to verify that control (for example, testing that MFA is enforced at sign-in, or running the authenticated patch scan), and whether your connected signal suggests you're ready for the audited test.
How to connect
- Go to My Hub → Settings → Integrations.
- Under the Microsoft Entra ID card, enter your Azure Tenant ID and click Connect.
- An admin consent flow opens in a new tab. Grant the required application permissions (read-only Graph API scopes) on behalf of your tenant.
- Once consented, hints appear automatically on your next Cyber Essentials, CAF, ISO 27001, or DORA assessment visit. No per-user OAuth redirect is required — the integration uses an app-only (client credentials) flow.
MSP Portal — connecting a client's M365 tenant
If you are an MSP practitioner running assessments on behalf of a client, you can connect that client's Microsoft 365 tenant separately from your own. When connected, their live Entra signals populate the assessment hints for that client with a teal Client tenant badge, keeping it visually distinct from your own data.
Steps for MSP practitioners
- Open the MSP Portal and click into the client's detail page.
- Scroll to the Microsoft 365 Integration section and click Get consent link.
- The portal generates a one-time consent link (valid for 1 hour). Copy it and share it with the client's Microsoft 365 global administrator — by email, Teams message, or ticket.
- The client admin visits the link, reviews the requested permissions, and clicks Accept in the Microsoft consent portal.
- Microsoft redirects to a confirmation page. Back in the MSP Portal, click Connect to perform the first data sync.
Hints for that client's assessments will now show live data from their tenant. The practitioner's own personal Entra integration is completely unaffected. If the client's tenant is later disconnected, hints revert to empty rather than ever falling back to personal data.
For your Azure Global Administrator
When you (or your client) visits the Microsoft consent page, the Azure Global Administrator will be asked to approve a set of application permissions for Security Compliance Hub. Here is what each permission enables:
Reports.Read.All— MFA registration counts, authentication method usage, sign-in log availability. Requires: Azure AD Free / Entra ID Free.Policy.Read.All— Conditional Access policy list and state, authentication methods policy (which methods are enabled tenant-wide). Requires: Entra ID P1 for CA data; Free tier for auth policy.AuditLog.Read.All— Confirms that sign-in logs are available in the tenant. Requires: Entra ID Free.User.Read.All— Guest / external user count. Requires: Entra ID Free.Organization.Read.All— Tenant display name (shown in the integration card). Requires: Entra ID Free.IdentityRiskyUser.Read.All— Risky user counts from Entra ID Protection. Requires: Entra ID P2.DeviceManagementManagedDevices.Read.All— Intune device compliance posture (compliant / non-compliant / total). Requires: Microsoft Intune (or EMS E3/E5).SecurityEvents.Read.All— Microsoft Defender alerts and Microsoft Secure Score. Requires: Defender for Business or Defender for Endpoint P1/P2.SecurityIncident.Read.All— Security incidents and Sentinel-linked alert data. Requires: Microsoft Sentinel.
All permissions are application permissions (app-only) — SCH never signs in as a user and never performs write actions. Every permission is read-only.
SecurityIncident.Read.All permission was added in June 2026. If your tenant was connected before this date, a Global Administrator will need to re-consent to grant the new permission. Go to My Hub → Workspace → Integrations, disconnect the existing connection, then reconnect to trigger the updated consent flow.
Where to find your Tenant ID
- Sign in to the Microsoft Entra admin centre (
entra.microsoft.com). - Go to Identity → Overview.
- Copy the Tenant ID — a GUID in the format
xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx. - Paste it into the Tenant ID field in My Hub → Workspace → Integrations → Microsoft Entra ID → Connect.
Option A2 — Live connection (Okta Identity Engine)
Connect your Okta organisation once and SCH pulls live IAM posture signals into your Cyber Essentials, CAF, ISO 27001, and DORA assessments as inline hints.
What data is pulled
- MFA enrolment coverage across user accounts
- Authenticator policy state (phishing-resistant methods vs SMS/voice)
- Number of active sign-on policies
- Assigned app count and group membership
- Risk event counts
How to connect
- Go to My Hub → Settings → Integrations.
- Under the Okta card, enter your Okta domain (e.g.
yourorg.okta.com), an API token (read-only), and choose the credential type (OAuth private-key or SSWS token). - Click Connect. SCH performs an initial data sync. Hints appear automatically on your next assessment visit.
Option A3 — Live connection (CrowdStrike Falcon)
Connect your CrowdStrike Falcon environment once and SCH pulls live EDR signals (sensor coverage, prevention policies, detections, vulnerabilities, incidents) into your Cyber Essentials, CAF, ISO 27001, and DORA assessments as inline hints.
What data is pulled
- Sensor health: total devices, normally-reporting count, reduced-functionality-mode (RFM) count, healthy coverage percentage, stale sensor count
- Prevention policies: enabled / total count, NGAV policy presence
- Detections: open count, critical and high severity breakdown
- Spotlight vulnerabilities (requires Falcon Spotlight licence): open count, critical, high, exploitable
- Incidents (requires Falcon Insight access): active count, high fine-score (≥70) count
Assessment questions covered
How hints appear
- CrowdStrike red hints — live Falcon signals shown beside the relevant question (e.g. "Falcon: 50 of 50 sensors reporting normally — 100% healthy coverage").
- Amber hints — licence warnings when a data point requires a Falcon module you may not hold (Spotlight for vulnerability data, Falcon Insight for incident data).
How to connect
- Create a Falcon API client in your CrowdStrike console with read-only scopes:
Detections:Read,Hosts:Read,Prevention policies:Read,Spotlight vulnerabilities:Read,Incidents:Read. - Go to My Hub → Settings → Integrations.
- Under the CrowdStrike card, enter your Falcon Cloud URL, Client ID, and Client Secret.
- Click Connect. SCH performs an OAuth2 client-credentials sync. Hints appear automatically on your next assessment visit.
Option A4 — Live connection (Google Workspace)
Connect your Google Workspace tenant once and SCH pulls live identity-layer signals (2-Step Verification coverage, account lifecycle, managed-device counts) into your Cyber Essentials, CAF, ISO 27001, and DORA assessments as inline hints. Designed for organisations on Google Workspace rather than Microsoft 365.
What data is pulled
- 2-Step Verification — enrolment percentage (Google's own metric) and admin-enforced coverage percentage
- Accounts — active / suspended / super-admin / delegated-admin counts
- ChromeOS devices — active and disabled Chromebooks under enterprise enrolment
- Mobile devices — Android and iOS devices under Google MDM (approved / blocked / compromised counts)
Assessment questions covered
How to connect
The auth flow differs from Microsoft Entra and Okta: Google Workspace uses Domain-wide Delegation (DWD), not OAuth admin consent. You will not need to generate any credentials — your Workspace super-admin grants access by pasting SCH's service account identity into Admin Console.
- Go to My Hub → Security Tool Integrations → Google Workspace (or, for MSPs, the client detail view in the MSP Portal).
- Enter your Workspace primary domain and a super-admin email. We recommend creating a dedicated account like
sch-readonly@yourdomain.comwith the Super Admin role used only for SCH impersonation — but a live human super-admin works as a fallback. - Click Save & continue. SCH displays a modal showing its service account Client ID and the four read-only OAuth scopes — both copyable.
- Your Workspace super-admin signs in to admin.google.com, goes to Security → Access and data control → API controls → Manage Domain-wide Delegation, clicks Add new, and pastes the Client ID and scopes.
- Back in SCH, click Verify now. SCH probes Google to confirm DWD is live and the super-admin role is held, then flips the tile to Connected and runs the first data pull.
How hints appear
- Google blue hints — live Workspace signals shown beside the relevant question (e.g. "Google Workspace: 87% of users have 2-Step Verification enrolled (87/100); 62% enforced by admin policy").
- "Client tenant" badge — when an MSP practitioner is viewing in a specific client's context, every hint shows a teal badge so the source of the data is unmistakable.
- CE+ readiness notes — Cyber Essentials questions also show a short note describing what a CE+ assessor would verify for that control, so you can judge readiness for the audited test.
Coming soon
The following integrations are on the roadmap. Contact us to register interest and get early access:
Platform Terms
pedd_access, soc_access, supply_chain_access). Claims are signed by Google and cannot be spoofed client-side. Changes require a sign-out/sign-in to take effect.Framework Terms
Security Terms
Frequently Asked Questions
My auto-save isn't working across devices — why?
Cross-device draft sync is included in the Assessment Bundle, demo accounts, CE One-Shot, and the PE Due Diligence / SOC Maturity / CMMC Level 2 / FedRAMP Moderate claims. Sign in on the second device and open the same assessment — a teal banner offers to load progress from the cloud. Trial users save to local browser storage only and cannot sync across devices. See Collaborative Drafts for the full sync behaviour, including tenant sharing and the "Last saved by" / "🔒 Being edited by" indicators on My Hub.
I ran analysis but I'm seeing the local analysis fallback (yellow banner)
When the Phronesis API returns a 502 or the response cannot be parsed, the platform falls back to a local JavaScript scoring engine. The yellow banner indicates this happened. Try clicking Analyse again — transient Cloud Function cold-starts are usually the cause. If the problem persists, check your internet connection or contact support.
My trial has expired but I can still see results — can I export them?
Results remain visible after trial expiry, but export (PDF/JSON) and sharing remain gated behind a subscription or one-shot purchase. Your saved scores in My Hub are retained indefinitely. Upgrade via Pricing or MSP & vCISO.
I updated my sector in Dashboard Settings but benchmarks haven't changed
Benchmark data is pre-aggregated every 6 hours per (type × sector) segment. After changing your sector, re-run any completed assessment's analysis (or simply reload the dashboard after 6 hours) to see the updated sector comparison. Note that your historical scores contribute to the previous sector's dataset until the next aggregation run.
Can I share a PE Due Diligence report with a client?
Yes — the Share button is available on PE Due Diligence results. Shared links require no login to view and expire on the schedule you select (7/30/90 days or no expiry). The shared page includes scores, gaps, strengths, next steps, and the Phronesis deal analysis. Evidence Vault files are not included in the shared view.
The NCSC CAF assessment is very long — can I save progress and return later?
Yes. All assessments auto-save every second to localStorage. When you return to the page, your previous answers are automatically restored. The sidebar progress tracker shows your completion percentage per principle. On My Hub, in-progress drafts appear as cards in the "Your Assessments" grid so you can navigate back easily.
Do you use tracking cookies or web analytics?
No. The platform uses only essential browser storage (Firebase Authentication session cookies for sign-in) and functional localStorage entries that auto-save your assessment progress and remember dialog dismissals. We do not run Google Analytics, advertising, retargeting, or any third-party tracking. The first time you visit you will see a one-line consent banner; you can re-open the preferences (and a "Clear local data" reset) at any time from the Cookie preferences link in the page footer. Full breakdown in our privacy notice.
Reporting Issues
The fastest way to get a technical issue investigated is the 🐛 Report button in the top navigation bar. Subscribers and paid one-shot users see it on every page; trial users do not (use the consultancy form instead).
What the Report modal captures
When you click 🐛 Report, a modal asks for three short fields:
- Title (≤120 chars) — one-line summary.
- Description (≤2000 chars) — what went wrong, what you saw on screen.
- What were you trying to do? (≤500 chars) — helps the engineer understand the goal, not just the symptom.
Alongside what you type, the modal automatically attaches read-only context that helps diagnosis: your email, the page URL, browser and viewport, timezone, the precise timestamp, your active access claims, and the last 10 client-side errors captured silently in the background (network failures, JavaScript exceptions). None of this is hidden — it's shown in the modal before you submit. Personal information beyond your email is never collected.
What happens after you submit
Your ticket is created with a unique reference (e.g. SCH-20260602-A4F2) and you'll receive an on-screen confirmation. Two things then happen in parallel:
- Auto-triage — within seconds of submission, an AI support engineer reads your ticket alongside your recent Cloud Logging entries (scoped to your user ID and the time around your problem). It produces a first-pass diagnosis: what it thinks went wrong, what evidence supports that, and a suggested next step. This runs automatically — you don't need to do anything.
- Human review — a real support engineer reviews your ticket and the auto-triage analysis. They will reply by email when the ticket is closed, including a resolution note that explains what was found and any action taken.
What auto-triage cannot do
Auto-triage is intentionally diagnose only — it never modifies your account, your data, or your claims. It looks at logs and makes a recommendation; only a human engineer takes action. If the auto-triage gets the diagnosis wrong, the human review catches it.
Rate limits
To prevent accidental ticket floods (e.g. an automated retry loop), submissions are capped at 5 tickets per hour per user. If you genuinely have multiple unrelated problems, please consolidate them into one ticket or wait a few minutes between submissions.
Ctrl+Shift+R / Cmd+Shift+R) fixes the majority of display-only issues. If the problem persists after refreshing, click 🐛 Report from the page where it happens — the captured context is most useful when fresh.
Getting Help
If you have a question not covered here:
- Technical bugs and broken features — Use the 🐛 Report button in the top nav (see Reporting Issues above). Trial users without paid claims should use the consultancy contact form.
- General enquiries and access requests — Use the contact form on the MSP & vCISO Partner Hub.
- Billing and subscription — Contact via the consultancy page with "Billing" in the subject.
Ctrl+Shift+R / Cmd+Shift+R) and clear site data for securitycompliancehub.io. Most display issues are resolved this way.