Platform / Assessments

Every control scored, with reasoning.

Answer in plain English and attach your evidence. Assura scores each control on the framework's own scale with written reasoning you can read, challenge and override - grounded in your documents and the live checks from your stack.

A short call about your organisation, then a full demo if it fits - no obligation.

The frameworks

From Cyber Essentials to DORA.

Twenty frameworks on one subscription, assessed from one pool of evidence - and if yours is missing, build it from your internal controls or request it from inside the app.

NIST CSF 2.0 ISO 27001 SOC 2 Type II PCI DSS HIPAA GDPR CIS Controls NIST 800-171 Cyber Essentials Essential Eight ISO 22301 CSA CCM FFIEC CAT Cyber Basics DORA NIS2 ISO 27701 SOC 1 CMMC 2.0 ISO 42001
How it runs

From first question to finished picture.

01

Pick a framework

Start with the one your customers or regulators ask for - or import an existing consulting workbook and carry on from where it left off.

02

Answer with evidence

Plain-English questions, one control at a time. Attach policies, exports and screenshots as you go - and your connected stack contributes live checks automatically.

03

Assura scores, you decide

Each control gets a score on the framework's own scale with written reasoning. Disagree? Override it - your call stands and is recorded alongside the reasoning.

04

Results go to work

Gaps become risks with owners and treatment. Reports generate in one click. And the mapping engine shows how far this framework carries you toward the next.

Native scales

Scored in the framework's own language.

Cyber Essentials talks in compliant, partially compliant and not compliant. Maturity frameworks talk in tiers. Assura scores each framework in its own vocabulary - while keeping one consistent scale underneath, so your dashboard, reports and exposure model never disagree with each other.

  • Each framework's own labels, not a one-size-fits-all percentage
  • One canonical 0-4 scale underneath, shared by every surface
  • Results read the way your auditor or assessor expects
Cyber Essentials Compliant
NIST CSF 2.0 Tier 3 · Repeatable
CIS Controls IG2 · Implemented
Evidence

Grounded in evidence, honest about confidence.

A score is only as good as what backs it. Assura grounds every score in the evidence you attach and the live checks from your connectors - and it is honest about the difference: a self-asserted answer can never score as confidently as a verified document or a live check.

  • Confidence-ranked: live check, then document, then self-attested
  • Provenance on every score - see exactly what backed it
  • Override any score; your judgement is recorded and learned from
  • Upload once - the same evidence serves every framework it fits
Live check Highest confidence
Document High confidence
Self-asserted Capped confidence
Mapping

One framework pre-fills the next.

The second framework should never be a blank page. Assura maps controls across all twenty frameworks: finish one and see exactly how far it carries you toward the others, with mapped controls pre-filled and your evidence already attached.

  • Readiness percentages for every other framework, the moment you finish
  • Mapped controls pre-fill with your answers and evidence
  • Consistency alerts when two frameworks would disagree
ISO 27001 · complete NIST CSF 2.0 64% ready
ISO 27001 · complete SOC 2 58% ready
ISO 27001 · complete Cyber Essentials 81% ready
When you finish

An assessment that keeps working.

Finishing isn't a PDF and a handshake. Everything the assessment learned feeds the rest of the platform.

Gap analysis

A prioritised list of what's missing and what to fix first, ranked by severity - with a remediation plan your team can actually work through.

Risk register entries

Every material gap lands in the risk register with severity, ownership and treatment tracking - nothing discovered gets forgotten.

Board-ready reports

Executive PDF and slide exports generated from your results in one click, with an inline studio to refine the narrative first.

Cross-framework readiness

Live percentages showing how far this assessment carries you toward every other framework you might take on next.

Exposure in your currency

Your results feed the exposure model, so the board sees what the posture means as an estimated annual loss - not just a score.

AskAssura

Ask questions about your own results in plain English - where the biggest gaps are, what changed, what to do next - answered from your data only.

Questions

Asked and answered.

Do I need to finish one framework before starting another?

No. You can run several in parallel from the same evidence pool - and finishing any one of them pre-fills its mapped controls in the others, so each additional framework starts partly done.

Can I trust the scores?

Every score is grounded in the evidence you attached, capped by how strong that evidence is, and explained in written reasoning you can read. And if you disagree, you override it - your call stands and is recorded alongside the reasoning.

We already paid a consultancy for an assessment. Can we import it?

Yes. Upload the workbook or spreadsheet and Assura imports it as an assessment you can carry on from - so the work you paid for becomes the starting point, not shelf-ware.

Does completing an assessment certify us?

No - certifications like ISO 27001 still require accredited auditors. Assura gets you ready, shows you exactly where you'd fall short, and hands your auditor organised evidence when the time comes.

Get started

Start with the framework they keep asking for.

Book a demo and we'll walk you through an assessment on the framework that matters most to you.

Prefer to pick a time? Book a 15-minute intro · or leave your email and we'll come to you.