Metrics we track

Simple, audit-focused metrics that show program maturity and certification readiness.

PricingServices

Control coverage

% of Annex A controls selected with defined owners and implemented status.

Evidence freshness

% of artifacts updated inside 90 days (policies, tickets, logs, screenshots).

Internal audit pass rate

% of sampled items passing internal audit without CARs; CAR aging trend.

Risk treatment velocity

% of high risks with accepted/treated status within defined timelines.

What “good” looks like

  • Owners assigned for 100% of in-scope controls
  • 80%+ artifacts refreshed within 90 days
  • Internal audit CARs closed within 30–60 days
  • Risk register current; high risks treated or accepted with clear justification
Get a Sample ISO PackHow We Scope