How CyberSentien assesses

Our whole pitch is that we assess honestly. This page states exactly how — how evidence is graded, what “manual assessment required” means, how coverage is measured, and why every report can be verified independently. If you only read one page before a demo, read this one.

Watch it run on sample docs →

The evidence standard

1. Evidence-led, not checkbox-led

Every control is assessed against the artefacts you actually provide — uploaded documents and connector-collected evidence — not against a self-attestation.

2. “Manual assessment required”

A control with insufficient evidence is never passed. It is marked manual assessment required and surfaced — the honest state, never a fabricated green.

3. Coverage against the full catalogue

Verdicts are measured against the whole control catalogue, so “80% compliant” means 80% of the real catalogue — not 80% of a convenient subset.

4. Deterministic verdicts

The same evidence yields the same verdict. Reasoning is grounded in the evidence and the control text — not a probabilistic guess dressed up as a result.

5. Tamper-evident lineage

Every report carries a validation run id and a SHA-256 integrity anchor chained into a ledger, so an auditor, a regulator or your client can verify a CyberSentien report is genuine and unmodified.

6. Readiness vs certification

For ISO/IEC 27001, SOC 2 and ISO 42001 we map your evidence to a readiness / crosswalk view. We get you audit-ready; an accredited certifier issues the certificate. We don't claim to certify.

Where the edges are — stated honestly

The limits of what software can and can't do.

Software assesses; people decide

CyberSentien produces evidence-grounded verdicts and reports. Accountability for a control — and for the decision to accept a risk — stays with your organisation.

Depth is badged, not assumed

We go consultant-grade where we go deepest (ISM/IRAP, Essential Eight) and badge Tier-A breadth honestly elsewhere. We never overstate depth to win a logo on a slide.

An assessor still assesses

For IRAP, an ASD-endorsed assessor does the endorsement. CyberSentien gets your evidence and rationale to the depth and structure an assessor expects — it doesn't replace them.

See the standard in action

Run the engine on a synthetic sample library spanning strong evidence to poor, and watch it stay honest no matter what it's fed.

Open the gated demo →About CyberSentien