Metrics we track

Simple, audit‑focused metrics that show readiness and sustain compliance over time.

PricingServices

Control readiness

% of 4.0 requirements with verified evidence, by requirement family and overall.

Evidence freshness

% of artifacts updated inside 90 days (logs, screenshots, configs, tickets).

Sampling pass rate

% of sampled items passing pre‑assessor dry‑run (policies, tech, process).

Remediation SLOs

We align fix SLOs (e.g., S1 ≤14d) with your vulnerability program; MTTR kept below SLO windows.

What “good” looks like

  • 90%+ of scoped requirements with evidence verified pre‑assessment
  • 80%+ artifacts refreshed within 90 days
  • Sampling pass rate ≥ 85% before the QSA arrives
  • Remediation MTTR below agreed SLO windows by severity
Get a Sample PCI PackHow We Scope