An honest position on where you stand against the framework, tested at the objective level rather than asserted at the control level, with a plan that closes rather than carries forward.
Requirements expand into assessment objectives, and a control marked met at the requirement level frequently fails at the objective level. That gap is where scores collapse under review, so it is where we test.
The number matters less than the basis for it. We document how each determination was reached, so the position is still defensible a year from now when the person who ran the assessment has moved on.
Sequenced by risk and by what unblocks the most other items, with owners and dates. Items that roll forward unchanged from one review to the next are read as bad faith, and reasonably so.
A prime, an enterprise client or an insurer wants to know where you stand, and the honest internal answer is that the current number came from somewhere nobody can reconstruct.
Self-assessment, third party, or a government review, and the sensible thing is to know what will be found while there is still time to act on it.
The same items have been on the Plan of Action for two review cycles. This is usually an ownership problem rather than a technical one, and it is worth naming as such.
The ones that come up most often before a scoping call.
No. An audit produces an opinion for a third party. A readiness assessment produces an honest internal picture for you, with no obligation to report it to anyone. That difference is the point of having one.
No, and no consultant can. Certification comes from an accredited assessor, and we stay on the other side of that line deliberately.
For a small organization with a contained boundary, commonly three to six weeks from kickoff to a documented position. Environments where the boundary has never been defined take longer, because that work has to happen first.
Then you have them in a document you control, rather than in an assessor's report. Nearly every environment we have assessed had findings, and the ones that went well were the ones that found them early.
© 2026 CARMhaus Consulting LLC. All rights reserved. Cybersecurity · Assurance · Risk Management
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.