Assessments

An assessment is only worth running if you can run it again.

Most organisations have done one. Very few can put this year’s next to last year’s, because the questions moved, the scale was never written down, and the answers ended up in a document with nobody’s name against them. Sentinel holds the set, the scale and the scope steady — and answers every questionnaire out of one control set rather than from scratch.

Self-service signup opens shortly — we will set you up in the meantime

ControlsSentinel interface, reproduced
Control LibraryFramework ReadinessTest ScheduleTest HistoryFindings
Operating
18
Needs evidence
6
Not implemented
2
Owners assigned
24/26
  • A.5.1Policies for information security
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    28 Jul 2026
  • A.5.18Access rights
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    26 Jun 2026
  • A.8.5Secure authentication
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    14 Aug 2026
  • + 5 more in the workspace

One control set, answered once. Every questionnaire below draws from it. Figures are from the example workspace — Northstar Manufacturing Ltd. is fictional.

Who is asking

Four senders. One set of questions.

They arrive in different formats, from different departments, with different deadlines. Underneath, they are asking about the same control areas — which is why answering them one at a time is the expensive way to do it.

  • Your largest customer

    Complete our vendor security assessment before we renew.

    Eighty-one questions in their format, in a spreadsheet, with a revenue line behind it.

    Deadline: their procurement cycle

  • A prospect

    Send us your security questionnaire and your last penetration test.

    A different form asking the same things in a different order, and a deal waiting on it.

    Deadline: their legal review

  • Your insurer

    Answer these nine control questions before we can quote.

    The same access, backup and vendor questions again, in an underwriter’s wording.

    Deadline: the renewal date

  • Your board

    Are we better than we were last year?

    The one question a single assessment cannot answer, because there is nothing to compare.

    Deadline: the next meeting

The overlap

Nobody is asking you a new question.

Six control areas account for most of what any of them want to know. Answer the control once, attach the evidence once, and each questionnaire becomes a rewording exercise instead of a research project.

Insurer renewal
Multi-factor authentication
Question 1 — email, remote access, admin
Backup and restore testing
Question 3 — immutable, offline, restore-tested
Patch and vulnerability management
Question 5 — a critical-vulnerability SLA
Incident response
Question 6 — documented and tested plan
Supplier and third-party risk
Question 8 — critical vendor reviews
Security awareness training
Question 7 — training and phishing simulations
Customer security review
Multi-factor authentication
Which systems, and what the exceptions are
Backup and restore testing
Recovery objectives and the date of the last restore
Patch and vulnerability management
Scan cadence and how long remediation takes
Incident response
Notification terms, and who you call at 2am
Supplier and third-party risk
Your subprocessor list and how you review it
Security awareness training
Completion rates, and who is exempt
ISO/IEC 27001:2022
Multi-factor authentication
A.5.16 Identity management
Backup and restore testing
A.8.13 Information backup
Patch and vulnerability management
A.8.8 Management of technical vulnerabilities
Incident response
A.5.24 Incident management planning
Supplier and third-party risk
A.5.19 Supplier relationships
Security awareness training
A.6.3 Awareness, education and training
SOC 2
Multi-factor authentication
Logical access (CC6)
Backup and restore testing
Availability (A1)
Patch and vulnerability management
Change management and operations (CC7, CC8)
Incident response
System operations (CC7)
Supplier and third-party risk
Risk mitigation (CC9)
Security awareness training
Control environment (CC1)

What still needs a person is the wording each recipient expects, and the handful of questions that really are specific to them. That is a fraction of the form. The rest is already answered, with the evidence attached and one expiry date everybody works from.

Sentinel supports readiness, governance, assessment, evidence organisation and control management. CyberWave does not certify compliance, issue audit opinions, guarantee compliance, or replace independent auditors, certification bodies or legal counsel. Framework references are informational readiness mappings.

The first assessment tells you where you are. The second one tells you whether any of it worked.

A round you cannot repeat is an opinion with a date on it. The value of an assessment is almost entirely in the second one, which is why the first one has to be recorded as though somebody will check it — because eventually somebody does.

The starting position

A new workspace reads Not assessed. That is not a missing feature.

Sign up for most readiness products and a percentage appears within a minute. Nothing was examined to produce it — it came from an industry template, four onboarding questions, or a default profile that shipped with the software. It is the least defensible number in your programme.

Day one, most readiness products
  • A percentage, within a minute of signing up
  • Derived from a template and four onboarding answers
  • Controls default to “mostly in place” until somebody checks
  • Real assessment work makes the number go down
  • Unknown and absent look identical
  • The first question a serious reader asks has no answer
Day one, Sentinel
  • Structure arrives. The number does not.
  • Requirements load as records, controls wait to be owned
  • Anything nobody has looked at reads Not assessed
  • The first readiness figure in the workspace is one you produced
  • Not assessed and a gap are different states with different work
  • Every figure can be opened and traced to what is behind it

Unknown and absent need different work

Not assessed means nobody has looked. A gap means somebody looked and it is not there. One costs an hour of a person’s afternoon and the other costs a project — and a single blended percentage throws that distinction away at exactly the moment you need it to plan.

Not assessedGap— two different problems, two different plans

Real work would otherwise look like regression

Assess honestly against a flattering baseline and the score drops. The person who did the right thing appears to have broken something, which is how a programme gets abandoned in month three. The same rule applies to a partial round: assess thirty requirements of ninety and the result covers thirty, and says so.

Two kinds

Where are we as a programme, and where are we against this framework.

Different questions, and they want different instruments. A maturity round rates the domains a security programme lives in and is the one you repeat. A framework readiness round walks the requirements of something you have in scope, requirement by requirement, with the control and the evidence behind each.

  • Maturitya profile by domain, not one mark — strong access control and no restore testing is one specific problem, not a middling programme
  • Framework readinessISO/IEC 27001:2022, SOC 2, NIST CSF 2.0 and CIS Controls v8.1, with applicability decisions and their reasoning on the record
  • Neither is a pass or a failcertification is a decision for a certification body, and an audit opinion is a decision for an auditor

See the framework mappings

Framework readiness

Example data
  • ISO/IEC 27001:202280% ready
    42 controls in the catalogue
  • SOC 2 (Trust Services Criteria)71% ready
    45 criteria in the catalogue
  • Cyber Insurance Readiness82% ready
    22 underwriter controls in the catalogue
  • NIST CSF 2.0Available
    59 subcategories in the catalogue
  • CIS Controls v8.1Available
    56 safeguards in the catalogue

Control coverage against each framework in scope. Readiness, not certification.

Repeatable

Six things that make the second round comparable with the first.

None of it is exotic. It is the discipline a spreadsheet cannot enforce, which is why assessments run in spreadsheets are not comparable however carefully the first one was done.

The question set does not move
A second round only compares if it asks the same things. When the set does change, that is recorded against the result — so movement in the numbers is never quietly movement in the questions.
The scale is written down
What a rating means is defined once and sits beside the answer. Otherwise a 3 means whatever the person answering thought it meant that afternoon, and the average of those is not information.
Every answer carries a name and a date
An assessment is a set of statements by identifiable people. Six months later the useful questions are who said this, and what they had in front of them when they did.
Answers point at evidence
An answer references the item in the evidence library rather than restating it in prose. When that item expires, the answer leaning on it stops being supported.
Scope and as-of date travel with the result
A round covering four control domains of nine is a partial result, and is recorded as one. The figure cannot be lifted out and presented as the whole programme.
Previous rounds are kept, not overwritten
Last year’s answers stay as they were, with their scope and their date. Comparison is only possible if the earlier round still exists in its original form.

From answer to action

Six stages, and the order is doing work.

A finding cannot exist before somebody answered something, and re-assessing means nothing until the actions from the last round have had time to move. Most assessment processes fail between stage three and stage four: the findings get written down, and then nobody is named.

  1. 01

    Scope it

    Which framework or which control domains, who answers each part, and the date the result speaks for. Ten domains done properly beats ninety requirements skimmed, and the scope is part of the record rather than a caveat somebody remembers.

  2. 02

    Answer it

    Each item gets a rating against the defined scale, a short narrative in your own words, and a link to the evidence behind it. “We think so” is allowed, and is recorded as exactly that.

  3. 03

    Findings, not a report

    Anything rated below where you need it, or asserted without evidence, becomes a finding with a description and a severity — not paragraph nine of a document nobody opens twice.

  4. 04

    Owners and dates

    Each finding becomes a tracked action with a named person and a due date, in the same backlog as evidence gaps and risk treatments. One list that tells you whether any of it moved.

  5. 05

    Close the loop

    An action closes when the evidence exists and somebody has accepted it, which moves the control register and therefore the readiness figures. Closing work updates the report.

  6. 06

    Assess again

    The next round opens with the previous answers in place, so the work is revising what changed rather than starting from an empty form. That is the difference between an annual assessment and one you repeat.

A finding with no name on it is a note

The reason most assessments change nothing is that they end at a document. The findings are accurate, the recommendations are sensible, none of it is assigned, and the same observations appear next year with a year added to their age. Here a finding is not finished until it is an action with an owner and a date, in the same backlog as evidence gaps and risk treatments — 2 of them Critical Now in the example workspace, and one already overdue.

Action centre

Findings, gaps and treatments in one backlog
  • Run and document the Q3 backup restore test
    Module
    Audit
    Owner
    Jordan Blake
    Priority
    Critical
    Due
    30 Sep 2026
    Status
    Not started
  • Deploy privileged access management for shared admin accounts
    Module
    Risk
    Owner
    Priya Raman
    Priority
    Critical
    Due
    15 Oct 2026
    Status
    In progress
  • Obtain SOC 2 report from Great Lakes Logistics
    Module
    Vendors
    Owner
    Elena Kowalski
    Priority
    High
    Due
    05 Oct 2026
    Status
    In progress
  • + 2 more in the workspace

Round over round

What “better than last year” is allowed to mean.

One thing only: the same questions, on the same scale, answered by named people, produced a different result — and you can open any part of the difference and see what changed.

  • Movement by domain, not one figure

    “Access management improved and vendor management slipped” is something an executive can act on. A two-point rise in an overall score is not.

  • Regression has a cause you can open

    A domain drops because two evidence items expired, or because a control lost its owner when somebody left. The change links to the record that caused it.

  • Findings raised, closed and overdue

    The count that matters is not how many findings this round produced. It is how many from the last round are closed, and how many are still open past their date.

  • One set of records underneath

    Assessment results feed the readiness score and the executive summary directly, so there is no separate deck to reconcile and no quarter where the two disagree.

See executive reporting

Twelve months of rounds

Example data
AprSep

46 in Apr to 76 in Sep. The dip is an evidence refresh that lapsed — a line that only ever rises is the signature of a chart nobody is measuring.

Framework position now

  • ISO/IEC 27001:202280% ready
    42 controls in the catalogue
  • SOC 2 (Trust Services Criteria)71% ready
    45 criteria in the catalogue

The example workspace scores 76 — the product’s own “Expected” band: reasonable maturity with real gaps still open. A demonstration that scored 98 would be easier to draw and would tell you nothing.

Questions

What buyers ask about assessments.

Starting with the three that come up every time: is this an audit, does one control set really answer every questionnaire, and what does the workspace show before we have done any of it.

Assessment programme and maturity tracking are part of Full Platform at $249 per month. The control register, evidence and action tracking start at Essentials, $99 per month.

Compare plans
What does the workspace show before we have assessed anything?
Structure, and no score. The framework you put in scope arrives with its requirements as records, the control register is there to be filled in, and every control nobody has looked at reads Not assessed. Readiness per framework reads Not assessed, and the Sentinel Score is withheld until something is behind it. That is an accurate picture of an empty programme, which is the only accurate picture available on day one.
Is a Sentinel assessment an audit?
No. It is a structured self-assessment by your own people, recorded so it can be defended and repeated. CyberWave does not certify compliance, issue audit opinions or verify your answers — an auditor, a certification body and an underwriter each form their own view, and each will ask for the evidence behind an answer rather than for a rating of it. What the assessment does is make sure you already know what they are about to find.
Do we really answer one control set instead of each questionnaire?
You answer the control, once, with the evidence attached. Each questionnaire then draws from that: the insurer’s nine control questions, a customer’s vendor assessment and a framework requirement are three wordings of the same underlying facts about access, backups, patching, incident response, vendors and training. What still takes a person is the wording each recipient expects and anything genuinely specific to them — which is a fraction of the form rather than all of it.
How long does a first assessment take?
It depends on how much you put in scope and how many people own parts of it, and any figure quoted on a website is guesswork. What works is a narrow first round — the control domains an insurer or a customer is asking about — answered honestly, with the gaps raised as actions. A partial result recorded as partial is worth more than a complete round of optimistic answers.
Can the AI answer the assessment for us?
It can draft. Once the answers are in, AI assistance writes up the results from what is already in your own workspace — evidence, risks, policies — as a draft narrative. A person sets every answer and reviews the draft. Nothing is rated, scored or accepted by AI, and the AI cannot see another organisation’s tenant.
What happens to last year’s round when we run a new one?
It stays as it was, with its scope, its as-of date and the names against each answer. A new round is a new record rather than an edit of the old one. That is what makes the movement between them real, and what lets you show that an improvement is not a change of method.
Which plan includes the assessment programme?
The assessment programme and maturity tracking sit in Full Platform, alongside multiple frameworks in scope and the audit engagement workspace. Essentials covers one framework with its control register, the evidence library, risk and action tracking — enough to work the gaps, without the round-over-round maturity view.

Assess the four domains somebody is about to ask about.

Not the whole programme, and not ninety requirements in a fortnight. One scoped round, answered honestly, with the findings named and dated — then a second round that is genuinely comparable with it.

Book a walkthrough

Self-service signup opens shortly — we will set you up in the meantime

  • Published pricing — no quote-on-request tier
  • No credit card required for the trial
  • No automatic charge when a trial ends
  • Tenant-isolated architecture, data stored in Canada
  • Clear data-processing terms
  • No compliance guarantee — human judgement still required