# Scoring rubric v0.9

**URL:** https://theauditrail.com/rubric/
**Published:** 2026-09-29
**Modified:** 2026-09-29
**Author:** The Audit Trail editorial desk

> The Audit Trail scores compliance platforms on eight criteria totalling 100 points. Version 0.9 is a public draft. All scores come from public documentation only.

---

Rubric v0.9 · Public draft

# Scoring Methodology

Version 0.9 is scored from public documentation only: the vendor's own product, pricing and documentation pages, listings the vendor controls on a public marketplace, and review volume on independent platforms. Every score links to the pages it was read from. A capability we could not confirm on the vendor's own pages scores as absent, and the scorecard says so. Vendors can send us the page that confirms it. Hands-on criteria arrive in version 1.0.

## Scope

Compliance automation platforms that prepare a company for, and keep it in, SOC 2, ISO 27001, HIPAA, PCI DSS and adjacent frameworks.

## Criteria

Each criterion has five levels. Level 0 is the absence of the capability. Level 5 is the strongest confirmed form. The weighted score contribution for a criterion is: (level / 5) \* weight.

FC

### Framework coverage

Weight: 15 · How many frameworks can a customer run out of the box, without building them by hand?

Level

Description

5

All of level 3, plus three or more of ISO 42001, NIST CSF, NIST 800-53, FedRAMP or CMMC.

4

All of level 3, plus one or two of ISO 42001, NIST CSF, NIST 800-53, FedRAMP or CMMC.

3

SOC 2, ISO 27001, HIPAA, PCI DSS and GDPR.

2

SOC 2, ISO 27001 and one of HIPAA, PCI DSS or GDPR.

1

SOC 2 plus one other framework.

0

SOC 2 only.

EV

### Automated evidence

Weight: 20 · How much evidence does the platform collect and test on its own, and how much does a person still have to upload?

Level

Description

5

300 or more published integrations, continuous tests, and a public API or custom integration builder.

4

200 to 299 published integrations, continuous tests, and a public API or custom integration builder.

3

100 to 199 published integrations, with continuous automated control tests.

2

50 to 99 published integrations, with automated control tests.

1

Fewer than 50 published integrations.

0

No integrations. Evidence is uploaded by hand.

AU

### Audit path

Weight: 15 · When the platform says you are ready, how short is the road to a signed report?

Level

Description

5

The audit is delivered inside the platform by the vendor's own or affiliated audit firm, as one engagement.

4

The audit can be bought as part of the platform deal, through partner firms, with auditors working inside the platform.

3

Both a named partner network and auditor review of evidence inside the platform.

2

A named partner network of audit firms, or auditors can review evidence inside the platform.

1

A referral list of audit firms, with no auditor access to the platform.

0

No auditor pathway. The customer finds and manages an auditor alone.

PT

### Pricing transparency

Weight: 10 · Can a buyer estimate the cost before speaking to sales?

Level

Description

5

Per-plan prices are published, and the price of the audit or the main add-ons is published too.

4

Per-plan prices are published, with what each plan includes.

3

Starting prices are published for more than one plan.

2

A single starting price is published.

1

Plan names and inclusions are published, with no numbers.

0

No price and no plan details published by the vendor.

TR

### Trust and questionnaires

Weight: 10 · Once certified, does the platform help the customer prove it to their own buyers?

Level

Description

5

Both, with AI-assisted answering drawn from the customer's own live evidence and policies.

4

Both, with AI-assisted questionnaire answering.

3

Both a trust center and questionnaire automation.

2

A trust center or questionnaire automation, not both.

1

A basic public security page, or questionnaire answering by hand from a library.

0

No trust center and no questionnaire tooling.

VR

### Vendor risk management

Weight: 10 · Can the customer assess and track the risk of their own suppliers inside the platform?

Level

Description

5

All of level 4, plus continuous monitoring of vendor risk after onboarding.

4

All of level 3, plus automated review of vendor security documents.

3

Inventory, risk ratings, and questionnaires sent to vendors from the platform.

2

Inventory plus risk ratings entered by hand.

1

A vendor inventory only.

0

Not offered.

CF

### Customisation

Weight: 10 · Can the customer adapt the platform to controls and frameworks it does not ship?

Level

Description

5

Custom frameworks, custom automated tests, and control mapping across frameworks so one test satisfies several.

4

Custom frameworks, plus custom automated tests.

3

Custom frameworks can be built.

2

Custom controls and custom policies.

1

Custom controls can be added to shipped frameworks.

0

No custom controls or frameworks.

US

### User sentiment

Weight: 10 · What do verified users report, weighted by how many of them there are?

Level

Description

5

Average 4.5 or higher with 200 or more reviews.

4

Average 4.5 or higher with 25 to 199 reviews.

3

Average 4.0 to 4.4 with 25 or more reviews.

2

Average 3.5 to 3.9, or fewer than 25 reviews at any score.

1

Average below 3.5.

0

No verified review profile on any independent platform.

## Score bands

Totals range from 0 to 100. Five bands describe the result.

Band

Range

**Deficient**

0 to 34

**Limited**

35 to 54

**Adequate**

55 to 69

**Strong**

70 to 84

**Exemplary**

85 to 100

## Planned for v1.0

-   Version 1.0 adds hands-on criteria: time from signup to first passing test, accuracy of automated evidence, and the auditor's experience inside the platform.

## Changelog

v0.9 · 2026-09-23

Public draft. Eight criteria, weights sum to 100, scored from public documentation only.

**How to cite:** The Audit Trail. (2026). Compliance Platform Scoring Rubric v0.9. Published 2026-09-23. https://theauditrail.com/rubric/