Rubric v0.9 ยท Public draft

Scoring Methodology

Version 0.9 is scored from public documentation only: the vendor's own product, pricing and documentation pages, listings the vendor controls on a public marketplace, and review volume on independent platforms. Every score links to the pages it was read from. A capability we could not confirm on the vendor's own pages scores as absent, and the scorecard says so. Vendors can send us the page that confirms it. Hands-on criteria arrive in version 1.0.

Scope

Compliance automation platforms that prepare a company for, and keep it in, SOC 2, ISO 27001, HIPAA, PCI DSS and adjacent frameworks.

Criteria

Each criterion has five levels. Level 0 is the absence of the capability. Level 5 is the strongest confirmed form. The weighted score contribution for a criterion is: (level / 5) * weight.

FC

Framework coverage

Weight: 15 · How many frameworks can a customer run out of the box, without building them by hand?

Level Description
5 All of level 3, plus three or more of ISO 42001, NIST CSF, NIST 800-53, FedRAMP or CMMC.
4 All of level 3, plus one or two of ISO 42001, NIST CSF, NIST 800-53, FedRAMP or CMMC.
3 SOC 2, ISO 27001, HIPAA, PCI DSS and GDPR.
2 SOC 2, ISO 27001 and one of HIPAA, PCI DSS or GDPR.
1 SOC 2 plus one other framework.
0 SOC 2 only.

EV

Automated evidence

Weight: 20 · How much evidence does the platform collect and test on its own, and how much does a person still have to upload?

Level Description
5 300 or more published integrations, continuous tests, and a public API or custom integration builder.
4 200 to 299 published integrations, continuous tests, and a public API or custom integration builder.
3 100 to 199 published integrations, with continuous automated control tests.
2 50 to 99 published integrations, with automated control tests.
1 Fewer than 50 published integrations.
0 No integrations. Evidence is uploaded by hand.

AU

Audit path

Weight: 15 · When the platform says you are ready, how short is the road to a signed report?

Level Description
5 The audit is delivered inside the platform by the vendor's own or affiliated audit firm, as one engagement.
4 The audit can be bought as part of the platform deal, through partner firms, with auditors working inside the platform.
3 Both a named partner network and auditor review of evidence inside the platform.
2 A named partner network of audit firms, or auditors can review evidence inside the platform.
1 A referral list of audit firms, with no auditor access to the platform.
0 No auditor pathway. The customer finds and manages an auditor alone.

PT

Pricing transparency

Weight: 10 · Can a buyer estimate the cost before speaking to sales?

Level Description
5 Per-plan prices are published, and the price of the audit or the main add-ons is published too.
4 Per-plan prices are published, with what each plan includes.
3 Starting prices are published for more than one plan.
2 A single starting price is published.
1 Plan names and inclusions are published, with no numbers.
0 No price and no plan details published by the vendor.

TR

Trust and questionnaires

Weight: 10 · Once certified, does the platform help the customer prove it to their own buyers?

Level Description
5 Both, with AI-assisted answering drawn from the customer's own live evidence and policies.
4 Both, with AI-assisted questionnaire answering.
3 Both a trust center and questionnaire automation.
2 A trust center or questionnaire automation, not both.
1 A basic public security page, or questionnaire answering by hand from a library.
0 No trust center and no questionnaire tooling.

VR

Vendor risk management

Weight: 10 · Can the customer assess and track the risk of their own suppliers inside the platform?

Level Description
5 All of level 4, plus continuous monitoring of vendor risk after onboarding.
4 All of level 3, plus automated review of vendor security documents.
3 Inventory, risk ratings, and questionnaires sent to vendors from the platform.
2 Inventory plus risk ratings entered by hand.
1 A vendor inventory only.
0 Not offered.

CF

Customisation

Weight: 10 · Can the customer adapt the platform to controls and frameworks it does not ship?

Level Description
5 Custom frameworks, custom automated tests, and control mapping across frameworks so one test satisfies several.
4 Custom frameworks, plus custom automated tests.
3 Custom frameworks can be built.
2 Custom controls and custom policies.
1 Custom controls can be added to shipped frameworks.
0 No custom controls or frameworks.

US

User sentiment

Weight: 10 · What do verified users report, weighted by how many of them there are?

Level Description
5 Average 4.5 or higher with 200 or more reviews.
4 Average 4.5 or higher with 25 to 199 reviews.
3 Average 4.0 to 4.4 with 25 or more reviews.
2 Average 3.5 to 3.9, or fewer than 25 reviews at any score.
1 Average below 3.5.
0 No verified review profile on any independent platform.

Score bands

Totals range from 0 to 100. Five bands describe the result.

Band Range
Deficient 0 to 34
Limited 35 to 54
Adequate 55 to 69
Strong 70 to 84
Exemplary 85 to 100

Planned for v1.0

  • Version 1.0 adds hands-on criteria: time from signup to first passing test, accuracy of automated evidence, and the auditor's experience inside the platform.

Changelog

v0.9 · 2026-09-23

Public draft. Eight criteria, weights sum to 100, scored from public documentation only.