From creating your first assessment to generating a final report — here's the full workflow.
Choose from industry-standard templates like NIST CSF or build your own. Define groupings, set weightings, add questions, and specify whether evidence is required. Each assessment becomes a snapshot of the template — changes to the template later won't affect active assessments.
Add buyer-side and seller-side organizations to the assessment. Invite team members via email — they'll be guided through signup and onboarding automatically. Assign roles (Admin, Analyst, Reviewer, Viewer) to control who can do what.
Sellers (or self-assessors) work through the questionnaire — providing answers, uploading evidence, and marking questions as ready for review. Multiple team members can be assigned to different areas for parallel work.
Buyer-side analysts review each answer and evidence. They can add internal comments (visible only to buyer-side), leave public comments, and accept or decline each question. Risk scores are assigned per question.
Every assessment produces a live report with overall risk scores, per-grouping breakdowns, an AI-generated executive summary, and a full appendix of all questions, answers, and evidence links. Reports update in real time as the assessment progresses.
The right permissions for every team member
Each person on the assessment has a clearly defined role with specific capabilities.
Buyer or Seller
Buyer Side Only
Seller Side Only
Buyer or Seller
Start your first assessment in minutes.