Scoring Methodology
Version 0.9 is scored from public documentation only: the vendor's own product, pricing and documentation pages, listings the vendor controls on a public marketplace, and review volume on independent platforms. Every score links to the pages it was read from. A capability we could not confirm on the vendor's own pages scores as absent, and the scorecard says so. Vendors can send us the page that confirms it. Hands-on criteria arrive in version 1.0.
Scope
Compliance automation platforms that prepare a company for, and keep it in, SOC 2, ISO 27001, HIPAA, PCI DSS and adjacent frameworks.
Criteria
Each criterion has five levels. Level 0 is the absence of the capability. Level 5 is the strongest confirmed form. The weighted score contribution for a criterion is: (level / 5) * weight.
FC
Framework coverage
Weight: 15 · How many frameworks can a customer run out of the box, without building them by hand?
| Level | Description |
|---|---|
| 5 | All of level 3, plus three or more of ISO 42001, NIST CSF, NIST 800-53, FedRAMP or CMMC. |
| 4 | All of level 3, plus one or two of ISO 42001, NIST CSF, NIST 800-53, FedRAMP or CMMC. |
| 3 | SOC 2, ISO 27001, HIPAA, PCI DSS and GDPR. |
| 2 | SOC 2, ISO 27001 and one of HIPAA, PCI DSS or GDPR. |
| 1 | SOC 2 plus one other framework. |
| 0 | SOC 2 only. |
EV
Automated evidence
Weight: 20 · How much evidence does the platform collect and test on its own, and how much does a person still have to upload?
| Level | Description |
|---|---|
| 5 | 300 or more published integrations, continuous tests, and a public API or custom integration builder. |
| 4 | 200 to 299 published integrations, continuous tests, and a public API or custom integration builder. |
| 3 | 100 to 199 published integrations, with continuous automated control tests. |
| 2 | 50 to 99 published integrations, with automated control tests. |
| 1 | Fewer than 50 published integrations. |
| 0 | No integrations. Evidence is uploaded by hand. |
AU
Audit path
Weight: 15 · When the platform says you are ready, how short is the road to a signed report?
| Level | Description |
|---|---|
| 5 | The audit is delivered inside the platform by the vendor's own or affiliated audit firm, as one engagement. |
| 4 | The audit can be bought as part of the platform deal, through partner firms, with auditors working inside the platform. |
| 3 | Both a named partner network and auditor review of evidence inside the platform. |
| 2 | A named partner network of audit firms, or auditors can review evidence inside the platform. |
| 1 | A referral list of audit firms, with no auditor access to the platform. |
| 0 | No auditor pathway. The customer finds and manages an auditor alone. |
PT
Pricing transparency
Weight: 10 · Can a buyer estimate the cost before speaking to sales?
| Level | Description |
|---|---|
| 5 | Per-plan prices are published, and the price of the audit or the main add-ons is published too. |
| 4 | Per-plan prices are published, with what each plan includes. |
| 3 | Starting prices are published for more than one plan. |
| 2 | A single starting price is published. |
| 1 | Plan names and inclusions are published, with no numbers. |
| 0 | No price and no plan details published by the vendor. |
TR
Trust and questionnaires
Weight: 10 · Once certified, does the platform help the customer prove it to their own buyers?
| Level | Description |
|---|---|
| 5 | Both, with AI-assisted answering drawn from the customer's own live evidence and policies. |
| 4 | Both, with AI-assisted questionnaire answering. |
| 3 | Both a trust center and questionnaire automation. |
| 2 | A trust center or questionnaire automation, not both. |
| 1 | A basic public security page, or questionnaire answering by hand from a library. |
| 0 | No trust center and no questionnaire tooling. |
VR
Vendor risk management
Weight: 10 · Can the customer assess and track the risk of their own suppliers inside the platform?
| Level | Description |
|---|---|
| 5 | All of level 4, plus continuous monitoring of vendor risk after onboarding. |
| 4 | All of level 3, plus automated review of vendor security documents. |
| 3 | Inventory, risk ratings, and questionnaires sent to vendors from the platform. |
| 2 | Inventory plus risk ratings entered by hand. |
| 1 | A vendor inventory only. |
| 0 | Not offered. |
CF
Customisation
Weight: 10 · Can the customer adapt the platform to controls and frameworks it does not ship?
| Level | Description |
|---|---|
| 5 | Custom frameworks, custom automated tests, and control mapping across frameworks so one test satisfies several. |
| 4 | Custom frameworks, plus custom automated tests. |
| 3 | Custom frameworks can be built. |
| 2 | Custom controls and custom policies. |
| 1 | Custom controls can be added to shipped frameworks. |
| 0 | No custom controls or frameworks. |
US
User sentiment
Weight: 10 · What do verified users report, weighted by how many of them there are?
| Level | Description |
|---|---|
| 5 | Average 4.5 or higher with 200 or more reviews. |
| 4 | Average 4.5 or higher with 25 to 199 reviews. |
| 3 | Average 4.0 to 4.4 with 25 or more reviews. |
| 2 | Average 3.5 to 3.9, or fewer than 25 reviews at any score. |
| 1 | Average below 3.5. |
| 0 | No verified review profile on any independent platform. |
Score bands
Totals range from 0 to 100. Five bands describe the result.
| Band | Range |
|---|---|
| Deficient | 0 to 34 |
| Limited | 35 to 54 |
| Adequate | 55 to 69 |
| Strong | 70 to 84 |
| Exemplary | 85 to 100 |
Planned for v1.0
- Version 1.0 adds hands-on criteria: time from signup to first passing test, accuracy of automated evidence, and the auditor's experience inside the platform.
Changelog
v0.9 · 2026-09-23
Public draft. Eight criteria, weights sum to 100, scored from public documentation only.