Simple, audit-focused metrics that show program maturity and certification readiness.
% of Annex A controls selected with defined owners and implemented status.
% of artifacts updated inside 90 days (policies, tickets, logs, screenshots).
% of sampled items passing internal audit without CARs; CAR aging trend.
% of high risks with accepted/treated status within defined timelines.