Assessments
An assessment is only worth running if you can run it again.
Most organisations have done one. Very few can put this year’s next to last year’s, because the questions moved, the scale was never written down, and the answers ended up in a document with nobody’s name against them. Sentinel holds the set, the scale and the scope steady — and answers every questionnaire out of one control set rather than from scratch.
Self-service signup opens shortly — we will set you up in the meantime
| Control | Owner | Status | Evidence | Last tested |
|---|---|---|---|---|
| A.5.1Policies for information security | Priya Raman | Passed | Accepted | 28 Jul 2026 |
| A.5.18Access rights | Priya Raman | Passed | Accepted | 26 Jun 2026 |
| A.8.5Secure authentication | Priya Raman | Passed | Accepted | 14 Aug 2026 |
| A.8.13Information backup | Jordan Blake | Passed | Accepted | 18 Jun 2026 |
| A.8.2Privileged access rights | Priya Raman | Failed | Needs Review | 20 Aug 2026 |
| A.8.7Protection against malware | Jordan Blake | Tested | Accepted | 28 Aug 2026 |
| CC9.2Vendor and business partner risk management | Elena Kowalski | Failed | Accepted | 12 Aug 2026 |
| PR.AA-01Identities and credentials are managed | Unassigned | Not Tested | Missing | — |
- A.5.1Policies for information security
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 28 Jul 2026
- A.5.18Access rights
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 26 Jun 2026
- A.8.5Secure authentication
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 14 Aug 2026
- + 5 more in the workspace
One control set, answered once. Every questionnaire below draws from it. Figures are from the example workspace — Northstar Manufacturing Ltd. is fictional.
Who is asking
Four senders. One set of questions.
They arrive in different formats, from different departments, with different deadlines. Underneath, they are asking about the same control areas — which is why answering them one at a time is the expensive way to do it.
- Your largest customer
“Complete our vendor security assessment before we renew.”
Eighty-one questions in their format, in a spreadsheet, with a revenue line behind it.
Deadline: their procurement cycle
- A prospect
“Send us your security questionnaire and your last penetration test.”
A different form asking the same things in a different order, and a deal waiting on it.
Deadline: their legal review
- Your insurer
“Answer these nine control questions before we can quote.”
The same access, backup and vendor questions again, in an underwriter’s wording.
Deadline: the renewal date
- Your board
“Are we better than we were last year?”
The one question a single assessment cannot answer, because there is nothing to compare.
Deadline: the next meeting
The overlap
Nobody is asking you a new question.
Six control areas account for most of what any of them want to know. Answer the control once, attach the evidence once, and each questionnaire becomes a rewording exercise instead of a research project.
| Insurer renewal | Customer security review | ISO/IEC 27001:2022 | SOC 2 | |
|---|---|---|---|---|
| Multi-factor authentication | Question 1 — email, remote access, admin | Which systems, and what the exceptions are | A.5.16 Identity management | Logical access (CC6) |
| Backup and restore testing | Question 3 — immutable, offline, restore-tested | Recovery objectives and the date of the last restore | A.8.13 Information backup | Availability (A1) |
| Patch and vulnerability management | Question 5 — a critical-vulnerability SLA | Scan cadence and how long remediation takes | A.8.8 Management of technical vulnerabilities | Change management and operations (CC7, CC8) |
| Incident response | Question 6 — documented and tested plan | Notification terms, and who you call at 2am | A.5.24 Incident management planning | System operations (CC7) |
| Supplier and third-party risk | Question 8 — critical vendor reviews | Your subprocessor list and how you review it | A.5.19 Supplier relationships | Risk mitigation (CC9) |
| Security awareness training | Question 7 — training and phishing simulations | Completion rates, and who is exempt | A.6.3 Awareness, education and training | Control environment (CC1) |
- Multi-factor authentication
- Question 1 — email, remote access, admin
- Backup and restore testing
- Question 3 — immutable, offline, restore-tested
- Patch and vulnerability management
- Question 5 — a critical-vulnerability SLA
- Incident response
- Question 6 — documented and tested plan
- Supplier and third-party risk
- Question 8 — critical vendor reviews
- Security awareness training
- Question 7 — training and phishing simulations
- Multi-factor authentication
- Which systems, and what the exceptions are
- Backup and restore testing
- Recovery objectives and the date of the last restore
- Patch and vulnerability management
- Scan cadence and how long remediation takes
- Incident response
- Notification terms, and who you call at 2am
- Supplier and third-party risk
- Your subprocessor list and how you review it
- Security awareness training
- Completion rates, and who is exempt
- Multi-factor authentication
- A.5.16 Identity management
- Backup and restore testing
- A.8.13 Information backup
- Patch and vulnerability management
- A.8.8 Management of technical vulnerabilities
- Incident response
- A.5.24 Incident management planning
- Supplier and third-party risk
- A.5.19 Supplier relationships
- Security awareness training
- A.6.3 Awareness, education and training
- Multi-factor authentication
- Logical access (CC6)
- Backup and restore testing
- Availability (A1)
- Patch and vulnerability management
- Change management and operations (CC7, CC8)
- Incident response
- System operations (CC7)
- Supplier and third-party risk
- Risk mitigation (CC9)
- Security awareness training
- Control environment (CC1)
What still needs a person is the wording each recipient expects, and the handful of questions that really are specific to them. That is a fraction of the form. The rest is already answered, with the evidence attached and one expiry date everybody works from.
Sentinel supports readiness, governance, assessment, evidence organisation and control management. CyberWave does not certify compliance, issue audit opinions, guarantee compliance, or replace independent auditors, certification bodies or legal counsel. Framework references are informational readiness mappings.
The first assessment tells you where you are. The second one tells you whether any of it worked.
A round you cannot repeat is an opinion with a date on it. The value of an assessment is almost entirely in the second one, which is why the first one has to be recorded as though somebody will check it — because eventually somebody does.
The starting position
A new workspace reads Not assessed. That is not a missing feature.
Sign up for most readiness products and a percentage appears within a minute. Nothing was examined to produce it — it came from an industry template, four onboarding questions, or a default profile that shipped with the software. It is the least defensible number in your programme.
- A percentage, within a minute of signing up
- Derived from a template and four onboarding answers
- Controls default to “mostly in place” until somebody checks
- Real assessment work makes the number go down
- Unknown and absent look identical
- The first question a serious reader asks has no answer
- Structure arrives. The number does not.
- Requirements load as records, controls wait to be owned
- Anything nobody has looked at reads Not assessed
- The first readiness figure in the workspace is one you produced
- Not assessed and a gap are different states with different work
- Every figure can be opened and traced to what is behind it
Unknown and absent need different work
Not assessed means nobody has looked. A gap means somebody looked and it is not there. One costs an hour of a person’s afternoon and the other costs a project — and a single blended percentage throws that distinction away at exactly the moment you need it to plan.
Real work would otherwise look like regression
Assess honestly against a flattering baseline and the score drops. The person who did the right thing appears to have broken something, which is how a programme gets abandoned in month three. The same rule applies to a partial round: assess thirty requirements of ninety and the result covers thirty, and says so.
Two kinds
Where are we as a programme, and where are we against this framework.
Different questions, and they want different instruments. A maturity round rates the domains a security programme lives in and is the one you repeat. A framework readiness round walks the requirements of something you have in scope, requirement by requirement, with the control and the evidence behind each.
- Maturity — a profile by domain, not one mark — strong access control and no restore testing is one specific problem, not a middling programme
- Framework readiness — ISO/IEC 27001:2022, SOC 2, NIST CSF 2.0 and CIS Controls v8.1, with applicability decisions and their reasoning on the record
- Neither is a pass or a fail — certification is a decision for a certification body, and an audit opinion is a decision for an auditor
Framework readiness
Example data- ISO/IEC 27001:202280% ready42 controls in the catalogue
- SOC 2 (Trust Services Criteria)71% ready45 criteria in the catalogue
- Cyber Insurance Readiness82% ready22 underwriter controls in the catalogue
- NIST CSF 2.0Available59 subcategories in the catalogue
- CIS Controls v8.1Available56 safeguards in the catalogue
Control coverage against each framework in scope. Readiness, not certification.
Repeatable
Six things that make the second round comparable with the first.
None of it is exotic. It is the discipline a spreadsheet cannot enforce, which is why assessments run in spreadsheets are not comparable however carefully the first one was done.
- The question set does not move
- A second round only compares if it asks the same things. When the set does change, that is recorded against the result — so movement in the numbers is never quietly movement in the questions.
- The scale is written down
- What a rating means is defined once and sits beside the answer. Otherwise a 3 means whatever the person answering thought it meant that afternoon, and the average of those is not information.
- Every answer carries a name and a date
- An assessment is a set of statements by identifiable people. Six months later the useful questions are who said this, and what they had in front of them when they did.
- Answers point at evidence
- An answer references the item in the evidence library rather than restating it in prose. When that item expires, the answer leaning on it stops being supported.
- Scope and as-of date travel with the result
- A round covering four control domains of nine is a partial result, and is recorded as one. The figure cannot be lifted out and presented as the whole programme.
- Previous rounds are kept, not overwritten
- Last year’s answers stay as they were, with their scope and their date. Comparison is only possible if the earlier round still exists in its original form.
From answer to action
Six stages, and the order is doing work.
A finding cannot exist before somebody answered something, and re-assessing means nothing until the actions from the last round have had time to move. Most assessment processes fail between stage three and stage four: the findings get written down, and then nobody is named.
- 01
Scope it
Which framework or which control domains, who answers each part, and the date the result speaks for. Ten domains done properly beats ninety requirements skimmed, and the scope is part of the record rather than a caveat somebody remembers.
- 02
Answer it
Each item gets a rating against the defined scale, a short narrative in your own words, and a link to the evidence behind it. “We think so” is allowed, and is recorded as exactly that.
- 03
Findings, not a report
Anything rated below where you need it, or asserted without evidence, becomes a finding with a description and a severity — not paragraph nine of a document nobody opens twice.
- 04
Owners and dates
Each finding becomes a tracked action with a named person and a due date, in the same backlog as evidence gaps and risk treatments. One list that tells you whether any of it moved.
- 05
Close the loop
An action closes when the evidence exists and somebody has accepted it, which moves the control register and therefore the readiness figures. Closing work updates the report.
- 06
Assess again
The next round opens with the previous answers in place, so the work is revising what changed rather than starting from an empty form. That is the difference between an annual assessment and one you repeat.
A finding with no name on it is a note
The reason most assessments change nothing is that they end at a document. The findings are accurate, the recommendations are sensible, none of it is assigned, and the same observations appear next year with a year added to their age. Here a finding is not finished until it is an action with an owner and a date, in the same backlog as evidence gaps and risk treatments — 2 of them Critical Now in the example workspace, and one already overdue.
Action centre
Findings, gaps and treatments in one backlog| Action | Module | Owner | Priority | Due | Status |
|---|---|---|---|---|---|
| Run and document the Q3 backup restore test | Audit | Jordan Blake | Critical | 30 Sep 2026 | Not started |
| Deploy privileged access management for shared admin accounts | Risk | Priya Raman | Critical | 15 Oct 2026 | In progress |
| Obtain SOC 2 report from Great Lakes Logistics | Vendors | Elena Kowalski | High | 05 Oct 2026 | In progress |
| Approve the Data Retention & Disposal Policy | Policies | Dana Whitfield | High | 10 Oct 2026 | Not started |
| Tabletop exercise with plant leadership — ransomware scenario | Risk | Dana Whitfield | Medium | 20 Nov 2026 | Not started |
- Run and document the Q3 backup restore test
- Module
- Audit
- Owner
- Jordan Blake
- Priority
- Critical
- Due
- 30 Sep 2026
- Status
- Not started
- Deploy privileged access management for shared admin accounts
- Module
- Risk
- Owner
- Priya Raman
- Priority
- Critical
- Due
- 15 Oct 2026
- Status
- In progress
- Obtain SOC 2 report from Great Lakes Logistics
- Module
- Vendors
- Owner
- Elena Kowalski
- Priority
- High
- Due
- 05 Oct 2026
- Status
- In progress
- + 2 more in the workspace
Round over round
What “better than last year” is allowed to mean.
One thing only: the same questions, on the same scale, answered by named people, produced a different result — and you can open any part of the difference and see what changed.
Movement by domain, not one figure
“Access management improved and vendor management slipped” is something an executive can act on. A two-point rise in an overall score is not.
Regression has a cause you can open
A domain drops because two evidence items expired, or because a control lost its owner when somebody left. The change links to the record that caused it.
Findings raised, closed and overdue
The count that matters is not how many findings this round produced. It is how many from the last round are closed, and how many are still open past their date.
One set of records underneath
Assessment results feed the readiness score and the executive summary directly, so there is no separate deck to reconcile and no quarter where the two disagree.
Twelve months of rounds
Example data46 in Apr to 76 in Sep. The dip is an evidence refresh that lapsed — a line that only ever rises is the signature of a chart nobody is measuring.
Framework position now
- ISO/IEC 27001:202280% ready42 controls in the catalogue
- SOC 2 (Trust Services Criteria)71% ready45 criteria in the catalogue
The example workspace scores 76 — the product’s own “Expected” band: reasonable maturity with real gaps still open. A demonstration that scored 98 would be easier to draw and would tell you nothing.
Questions
What buyers ask about assessments.
Starting with the three that come up every time: is this an audit, does one control set really answer every questionnaire, and what does the workspace show before we have done any of it.
Assessment programme and maturity tracking are part of Full Platform at $249 per month. The control register, evidence and action tracking start at Essentials, $99 per month.
Compare plansWhat does the workspace show before we have assessed anything?
Is a Sentinel assessment an audit?
Do we really answer one control set instead of each questionnaire?
How long does a first assessment take?
Can the AI answer the assessment for us?
What happens to last year’s round when we run a new one?
Which plan includes the assessment programme?
Assess the four domains somebody is about to ask about.
Not the whole programme, and not ninety requirements in a fortnight. One scoped round, answered honestly, with the findings named and dated — then a second round that is genuinely comparable with it.
Self-service signup opens shortly — we will set you up in the meantime
- Published pricing — no quote-on-request tier
- No credit card required for the trial
- No automatic charge when a trial ends
- Tenant-isolated architecture, data stored in Canada
- Clear data-processing terms
- No compliance guarantee — human judgement still required