Verisight Help Center Support ticket Open portal

Compliance readiness

See how your findings map to NIST CSF 2.0, Cyber Essentials, PCI DSS 4.0, GDPR and the HIPAA Security Rule.

The Compliance page shows, for each framework, which controls your findings relate to and where the open gaps are.

Frameworks

  • NIST Cybersecurity Framework 2.0
  • Cyber Essentials v3.3
  • PCI DSS 4.0
  • GDPR
  • HIPAA Security Rule

Each framework has its own tab. Open one to see its controls, then filter by status or search for a control.

How it's built

Readiness is built from the findings your assessments have produced. Every finding carries mappings to the framework controls it relates to. The page appears once at least one assessment has produced mapped findings. Before that, it says no frameworks are available yet.

What this does and doesn't tell you

  • An open finding on a control is real evidence of a gap.
  • No finding on a control only means Verisight hasn't observed a problem there. It is not proof the control is in place. Many controls, such as policies, training or physical security, can't be observed from outside at all.
  • Compliance readiness is not a certification or audit opinion.

Use it to prioritise work before an audit, and pair it with Questionnaire Autopilot to answer control questions with evidence.